Live data from Hacker News

FBI's ability to legally access secure messaging app content and metadata [pdf]

propertyofthepeople.org

41–50 of 474 posts

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#41
post #17

This discussion is not very interesting from a security perspective. I tuned out at “cloud”. If it’s not in your physical possession, it’s not your computer. If it’s not your computer, then whoever administers the computer, or whoever [points a gun at/gives enough money to] the administrator of that system can access whatever you put on that system. If a “cloud” or “service” is involved, then you can trivially use th…

If i'm reading this page correctly, AMD is working on something that would allow you to run trusted code that not even someone with physical access to the hardware could read (without breaking this system). https://www.amd.com/en/processors/epyc-confidential-computin... And this tech is already implemented by GCP: https://cloud.google.com/confidential-computing > With the confidential execution environments provided…

Then you only have to trust that AMD did not accidentally or intentionally introduce a bug in the system. Remember Spectre? Remember all the security bugs in the Intel management code?

You also have to trust that AMD generated and have always managed the encryption keys for that system properly and in accordance with their documentation.

And are you even sure that you’re actually running on an AMD system? If the system is in the cloud, then it’s hard to be sure what is executing your code.

And are you sure that your code didn’t accidentally break the security guarantees of the underlying system?

I have worked on all these problems in my day job, working on HSMs. At the end of the day there are still some leaps of faith.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#42
post #13
post #6

It says Telegram has no message content. Isn't telegram not E2EE by default, instead required explicit steps to make a conversation encrypted? Either way looks like Signal wins by a lot. The size of it spot is so small, it seems almost squeezed in. But only because they have nothing to share.

That is correct. By default all messages sent over Telegram are stored permanently in their servers unencrypted.

Not exactly. Non-secret chats are stored encrypted on Telegram's servers, and separately from keys. The goal seems to be to require multiple jurisdictions to issue a court order before data can be decrypted.

https://telegram.org/privacy#3-3-1-cloud-chats https://telegram.org/faq#q-do-you-process-data-requests

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#43
They left off one very popular messenger, SMS:

* Message content: All

* Subpoena: can render all message content for the last 1-7 years

* 18 U.S.C 2703(d): can render all message content for the last 1-7 years

* Search warrant: can render all message content for the last 1-7 years

* Vague suspicion plus a small fee to the carrier: can render all message content for the last 1-7 years

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#44
post #9
post #6

It says Telegram has no message content. Isn't telegram not E2EE by default, instead required explicit steps to make a conversation encrypted? Either way looks like Signal wins by a lot. The size of it spot is so small, it seems almost squeezed in. But only because they have nothing to share.

I don't know whether Telegram is E2EE by default (probably not.) When you do a call on telegram you are given a series of emoji and they are supposed to match what the person on the other side has, and that's supposed to indicate E2EE for that call.

It is not, by default, and none of the group chats are.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#45

Now I just have to get all my friends and family to use Signal.

My family has really taken to it. Granted it's mostly just message family app to them, but they are very not technically fluent but yet seemed to have picked it up just fine. I really think this is not discussed when hacker news brings up secure messaging. The user experience is so much more important than the underlying tech. My family doesn't care about end to end encryption. They care about video calling with the press of a button, and easy features that are just there and work like zoom or the many other software products that they have to use work.

Thank you Signal team for focusing so hard on the user experience.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#46
I'm wondering how this was obtained, and how old this is?

For WhatsApp:

> if target is using an iPhone and iCloud backups enabled, iCloud returns may contain WhatsApp data, to include message content

Probably not true since WhatsApp launched encrypted backups.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#47
post #38
post #6

It says Telegram has no message content. Isn't telegram not E2EE by default, instead required explicit steps to make a conversation encrypted? Either way looks like Signal wins by a lot. The size of it spot is so small, it seems almost squeezed in. But only because they have nothing to share.

for signal users this means the messages of course do exist on your phone, which will be the first thing these agencies seek to abscond with once youre detained as its infinitely more crackable in their hands. as a casual reminder: The fifth amendment protects your speech, not your biometrics. do not use face or fingerprint to secure your phone. use a strong passphrase, and if in doubt, power down the phone (android)…

Signal recently added 'disappearing messages' which lets you specify how long a chat you initiate remains before being deleted.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#49

Earlier quoted context omitted.

Verification in band seems pretty meaningless, approaching security theatre.

For voice? It's hard to fake the voice of someone you know.

you don't have to fake the voice, just mitm and record cleartext

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#50
If this is what it takes to keep us safe, I and most americans are ok with it. We live in dangerous times.

The US has a balanced criminal justice system -- as long as due process is preserved privacy from the state should not be a major issue

Post reply on HN