Earlier quoted context omitted.
Not if they want to operate in the United States or have access to our banking system. You don’t get to pick your jurisdiction and then operate globally. You’re obligated to follow the laws where you want to operate.
I wonder how this affects nonprofits like Matrix/Element and Signal. What can they do with them? Gangstalk their developers? Coerce big tech to ban them from their appstores?
FBI's ability to legally access secure messaging app content and metadata [pdf]
51–60 of 474 posts
Re: FBI's ability to legally access secure messaging app content and metadata [pdf]
#52Now I just have to get my friends and family to use Signal.
The day facebook went down for some hours I got phone calls.
Re: FBI's ability to legally access secure messaging app content and metadata [pdf]
#53Earlier quoted context omitted.
That is correct. By default all messages sent over Telegram are stored permanently in their servers unencrypted.
Not exactly. Non-secret chats are stored encrypted on Telegram's servers, and separately from keys. The goal seems to be to require multiple jurisdictions to issue a court order before data can be decrypted. https://telegram.org/privacy#3-3-1-cloud-chats https://telegram.org/faq#q-do-you-process-data-requests
Telegram doesn't store your messages forever and they are encrypted and seizing the servers won't allow you to decrypt them unless you also seize the correct servers from another country
Re: FBI's ability to legally access secure messaging app content and metadata [pdf]
#54Earlier quoted context omitted.
If i'm reading this page correctly, AMD is working on something that would allow you to run trusted code that not even someone with physical access to the hardware could read (without breaking this system). https://www.amd.com/en/processors/epyc-confidential-computin... And this tech is already implemented by GCP: https://cloud.google.com/confidential-computing > With the confidential execution environments provided…
Then you only have to trust that AMD did not accidentally or intentionally introduce a bug in the system. Remember Spectre? Remember all the security bugs in the Intel management code? You also have to trust that AMD generated and have always managed the encryption keys for that system properly and in accordance with their documentation. And are you even sure that you’re actually running on an AMD system? If the syst…
You'd also need to consider AMD's management engine, the Platform Security Processor. If we're really slinging conspiracy theories, AMD processors are likely just as backdoored as Intel one. I don't mean to be grim, but I think it's safe to assume that the US government has direct memory access to the vast majority of computer processors you can buy these days.
[/conspiracy]
Re: FBI's ability to legally access secure messaging app content and metadata [pdf]
#55Isn’t this simply imaginary, where in practice all the FBI has to do to up the ante is to request military-grade interception from a willing foreign counterpart?
Re: FBI's ability to legally access secure messaging app content and metadata [pdf]
#56They left off one very popular messenger, SMS: * Message content: All * Subpoena: can render all message content for the last 1-7 years * 18 U.S.C 2703(d): can render all message content for the last 1-7 years * Search warrant: can render all message content for the last 1-7 years * Vague suspicion plus a small fee to the carrier: can render all message content for the last 1-7 years
* Law enforcement simply asks nicely: can render all message content for the last 1-7 years
Re: FBI's ability to legally access secure messaging app content and metadata [pdf]
#57Well, who cares when all they need is to use something like Pegasus to obtain full access to your phone simply by sending you a WhatsApp message (without having you even open the message). Knowing how well guarded IOS is against app developers, I wonder what kind of zero-day would suddenly turn a message received in WhatsApp to full system access. I think NSO found a WhatsApp backdoor, not a zero-day bug.
I don't know any detail of the whatsapp vulnerability that NSO exploited.
Re: FBI's ability to legally access secure messaging app content and metadata [pdf]
#58So if you have something to hide, don't use iCloud backup. And Whatsapp will give them the target's full contactbook (was to be expected), but also everyone that has the target in their contact list. That last one is quite far reaching.
Most people don't realize that most people have something to hide. The USA has so many laws on its books. Many of which are outright bizarre[0] and some of which normal people might normally break[1].
And that's only counting current/past laws. It wasn't that long ago a US President was suggesting all Muslims should be forced to carry special IDs[2]. If you have a documented history being a Muslim, it could be harder to fight a non-compliance charge.
[0] https://www.quora.com/Why-is-there-a-law-where-you-can-t-put...
[1] https://unusualkentucky.blogspot.com/2008/05/weird-kentucky-...
[2] https://www.snopes.com/fact-check/donald-trump-muslims-id/
Re: FBI's ability to legally access secure messaging app content and metadata [pdf]
#59Now I just have to get my friends and family to use Signal.
I have been trying to get people to install signal for 2 years. No one has budged. The day facebook went down for some hours I got phone calls.
Re: FBI's ability to legally access secure messaging app content and metadata [pdf]
#60If this is what it takes to keep us safe, I and most americans are ok with it. We live in dangerous times. The US has a balanced criminal justice system -- as long as due process is preserved privacy from the state should not be a major issue