LINE,telegram,threema and WeChat are not even american companies. Can't they just tell the FBI to suck a fat one when they ask for user data?
FBI's ability to legally access secure messaging app content and metadata [pdf]
21–30 of 474 posts
Re: FBI's ability to legally access secure messaging app content and metadata [pdf]
#22What about regular text messages?
Re: FBI's ability to legally access secure messaging app content and metadata [pdf]
#23What about regular text messages?
Re: FBI's ability to legally access secure messaging app content and metadata [pdf]
#24This discussion is not very interesting from a security perspective. I tuned out at “cloud”. If it’s not in your physical possession, it’s not your computer. If it’s not your computer, then whoever administers the computer, or whoever [points a gun at/gives enough money to] the administrator of that system can access whatever you put on that system. If a “cloud” or “service” is involved, then you can trivially use th…
https://www.amd.com/en/processors/epyc-confidential-computin...
And this tech is already implemented by GCP:
https://cloud.google.com/confidential-computing
> With the confidential execution environments provided by Confidential VM and AMD SEV, Google Cloud keeps customers' sensitive code and other data encrypted in memory during processing. Google does not have access to the encryption keys. In addition, Confidential VM can help alleviate concerns about risk related to either dependency on Google infrastructure or Google insiders' access to customer data in the clear.
Re: FBI's ability to legally access secure messaging app content and metadata [pdf]
#25This discussion is not very interesting from a security perspective. I tuned out at “cloud”. If it’s not in your physical possession, it’s not your computer. If it’s not your computer, then whoever administers the computer, or whoever [points a gun at/gives enough money to] the administrator of that system can access whatever you put on that system. If a “cloud” or “service” is involved, then you can trivially use th…
It's worse than that. Even if you read the code, you have to trust that the code you read is the code a service is actually using. Even if you deploy the code yourself, you have to trust that the infrastructure you're running on does not have some type of backdoor. Even if you run your own infrastructure, hardware can still have backdoors. Of course, the likelihood of any of these things actually becoming a problem decreases significantly as you read through the paragraph.
Re: FBI's ability to legally access secure messaging app content and metadata [pdf]
#26link seems to be broken https://propertyofthepeople.org/document-detail/?doc-id=2111...
Here's a direct link to the PDF: https://assets.documentcloud.org/documents/21114562/jan-2021...
Re: FBI's ability to legally access secure messaging app content and metadata [pdf]
#27link seems to be broken https://propertyofthepeople.org/document-detail/?doc-id=2111...
Re: FBI's ability to legally access secure messaging app content and metadata [pdf]
#28Earlier quoted context omitted.
I don't know whether Telegram is E2EE by default (probably not.) When you do a call on telegram you are given a series of emoji and they are supposed to match what the person on the other side has, and that's supposed to indicate E2EE for that call.
Verification in band seems pretty meaningless, approaching security theatre.
Re: FBI's ability to legally access secure messaging app content and metadata [pdf]
#29So if you have something to hide, don't use iCloud backup. And Whatsapp will give them the target's full contactbook (was to be expected), but also everyone that has the target in their contact list. That last one is quite far reaching.
Can you turn that off if you have icloud or do you need to not use icloud all together?
Re: FBI's ability to legally access secure messaging app content and metadata [pdf]
#30LINE,telegram,threema and WeChat are not even american companies. Can't they just tell the FBI to suck a fat one when they ask for user data?
Not if they want to operate in the United States or have access to our banking system. You don’t get to pick your jurisdiction and then operate globally. You’re obligated to follow the laws where you want to operate.