Live data from Hacker News

FBI's ability to legally access secure messaging app content and metadata [pdf]

propertyofthepeople.org

31–40 of 474 posts

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#32
post #18
post #4

So if you have something to hide, don't use iCloud backup. And Whatsapp will give them the target's full contactbook (was to be expected), but also everyone that has the target in their contact list. That last one is quite far reaching.

Has Apple made any public statements regarding iCloud's lack of privacy features. It takes the wind out of their privacy marketing that is effectively hurting ad tech but not truly protecting consumers from state-level actors with data access.

Kind of. These details are indeed publicly written on their website[0]. Do many users ever read this page? Probably not.

[0] https://support.apple.com/en-us/HT202303

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#35
post #30

Earlier quoted context omitted.

Not if they want to operate in the United States or have access to our banking system. You don’t get to pick your jurisdiction and then operate globally. You’re obligated to follow the laws where you want to operate.

I wonder how this affects nonprofits like Matrix/Element and Signal. What can they do with them? Gangstalk their developers? Coerce big tech to ban them from their appstores?

Doesn't Signal's dev already get bothered every single time they travel?

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#36
post #11

LINE,telegram,threema and WeChat are not even american companies. Can't they just tell the FBI to suck a fat one when they ask for user data?

Not if they want to operate in the United States or have access to our banking system. You don’t get to pick your jurisdiction and then operate globally. You’re obligated to follow the laws where you want to operate.

Fwiw if you want to do any sort of FX whatsoever or accept credit cards, you need access to the American banking system.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#37
post #8
post #4

So if you have something to hide, don't use iCloud backup. And Whatsapp will give them the target's full contactbook (was to be expected), but also everyone that has the target in their contact list. That last one is quite far reaching.

You and the person you are communicating with must both not use iCloud backup. And since apple pushes the backup features pretty heavily, you can be reasonable sure that the person you are communicating is using backups. IE, you cannot use iMessage.

I got off all Apple products when they showed me their privacy stance is little more than marketing during the CSAM fiasco, but IIRC the trouble with iCloud backup is it stores the private key used to encrypt your iMessages backup. Not ideal to be sure, but wouldn't iMessage users be well protected against dragnet surveillance, or do we know that they're decrypting these messages en masse and sharing them with state authorities?

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#38
post #6

It says Telegram has no message content. Isn't telegram not E2EE by default, instead required explicit steps to make a conversation encrypted? Either way looks like Signal wins by a lot. The size of it spot is so small, it seems almost squeezed in. But only because they have nothing to share.

for signal users this means the messages of course do exist on your phone, which will be the first thing these agencies seek to abscond with once youre detained as its infinitely more crackable in their hands.

as a casual reminder: The fifth amendment protects your speech, not your biometrics. do not use face or fingerprint to secure your phone. use a strong passphrase, and if in doubt, power down the phone (android) as this offers the greatest protection against offline bruteforce and sidechannel attacks used currently to exploit running processes in the phone.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#39
post #6

It says Telegram has no message content. Isn't telegram not E2EE by default, instead required explicit steps to make a conversation encrypted? Either way looks like Signal wins by a lot. The size of it spot is so small, it seems almost squeezed in. But only because they have nothing to share.

> the FBI's ability to legally access secure content

Maybe there are laws preventing legal access to message content? Maybe related to wherever Telegram is incorporated.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#40

What about regular text messages?

Assume anything sent over a cellular network carrier via normal SMS can not only be retrieved, but intercepted.

Thank goodness a lot of companies regularly use it for 2FA.
Post reply on HN