Live data from Hacker News

FBI's ability to legally access secure messaging app content and metadata [pdf]

propertyofthepeople.org

21–30 of 474 posts

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#21
post #11

LINE,telegram,threema and WeChat are not even american companies. Can't they just tell the FBI to suck a fat one when they ask for user data?

Depends on whether the countries these companies exist in have agreements with the U.S for surveillance and stuff

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#24
post #17

This discussion is not very interesting from a security perspective. I tuned out at “cloud”. If it’s not in your physical possession, it’s not your computer. If it’s not your computer, then whoever administers the computer, or whoever [points a gun at/gives enough money to] the administrator of that system can access whatever you put on that system. If a “cloud” or “service” is involved, then you can trivially use th…

If i'm reading this page correctly, AMD is working on something that would allow you to run trusted code that not even someone with physical access to the hardware could read (without breaking this system).

https://www.amd.com/en/processors/epyc-confidential-computin...

And this tech is already implemented by GCP:

https://cloud.google.com/confidential-computing

> With the confidential execution environments provided by Confidential VM and AMD SEV, Google Cloud keeps customers' sensitive code and other data encrypted in memory during processing. Google does not have access to the encryption keys. In addition, Confidential VM can help alleviate concerns about risk related to either dependency on Google infrastructure or Google insiders' access to customer data in the clear.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#25
post #17

This discussion is not very interesting from a security perspective. I tuned out at “cloud”. If it’s not in your physical possession, it’s not your computer. If it’s not your computer, then whoever administers the computer, or whoever [points a gun at/gives enough money to] the administrator of that system can access whatever you put on that system. If a “cloud” or “service” is involved, then you can trivially use th…

> if you did not write (or at least read) the code that you’re using to do all of the above, then you’re at the mercy of whoever wrote it.

It's worse than that. Even if you read the code, you have to trust that the code you read is the code a service is actually using. Even if you deploy the code yourself, you have to trust that the infrastructure you're running on does not have some type of backdoor. Even if you run your own infrastructure, hardware can still have backdoors. Of course, the likelihood of any of these things actually becoming a problem decreases significantly as you read through the paragraph.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#26
post #2

link seems to be broken https://propertyofthepeople.org/document-detail/?doc-id=2111...

Not only is there main link broken, but their silly PDF reader is broken for me.

Here's a direct link to the PDF: https://assets.documentcloud.org/documents/21114562/jan-2021...

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#28
post #9

Earlier quoted context omitted.

I don't know whether Telegram is E2EE by default (probably not.) When you do a call on telegram you are given a series of emoji and they are supposed to match what the person on the other side has, and that's supposed to indicate E2EE for that call.

Verification in band seems pretty meaningless, approaching security theatre.

For voice? It's hard to fake the voice of someone you know.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#29
post #4

So if you have something to hide, don't use iCloud backup. And Whatsapp will give them the target's full contactbook (was to be expected), but also everyone that has the target in their contact list. That last one is quite far reaching.

Can you turn that off if you have icloud or do you need to not use icloud all together?

You can turn it off individually just for Messages, but you're still left not knowing the state of the setting on the other end.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#30
post #11

LINE,telegram,threema and WeChat are not even american companies. Can't they just tell the FBI to suck a fat one when they ask for user data?

Not if they want to operate in the United States or have access to our banking system. You don’t get to pick your jurisdiction and then operate globally. You’re obligated to follow the laws where you want to operate.

I wonder how this affects nonprofits like Matrix/Element and Signal. What can they do with them? Gangstalk their developers? Coerce big tech to ban them from their appstores?
Post reply on HN