Live data from Hacker News

FBI's ability to legally access secure messaging app content and metadata [pdf]

propertyofthepeople.org

91–100 of 474 posts

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#91
post #38
post #6

It says Telegram has no message content. Isn't telegram not E2EE by default, instead required explicit steps to make a conversation encrypted? Either way looks like Signal wins by a lot. The size of it spot is so small, it seems almost squeezed in. But only because they have nothing to share.

for signal users this means the messages of course do exist on your phone, which will be the first thing these agencies seek to abscond with once youre detained as its infinitely more crackable in their hands. as a casual reminder: The fifth amendment protects your speech, not your biometrics. do not use face or fingerprint to secure your phone. use a strong passphrase, and if in doubt, power down the phone (android)…

Your statement on the 5th amendment is no longer accurate broadly, but the matter still has some cross-jurisdictional disagreement: https://americanlegalnews.com/biometrics-covered-by-fifth-am...

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#92
post #88
post #82

Earlier quoted context omitted.

Telegram is encrypted OVER THE WIRE and AT REST by default with strong encryption no matter what you do. It's E2EE if you select private chat with someone. Lots of FUD out there there about Telegram not being encrypted that's just not true. There's nothing either side can to do send a message in clear text / unencrypted.

For somebody who isn’t super cyprtography-savvy, what’s the difference between over the wire and e2ee? Does the former mean that telegram itself can read non-private-chat messages if it so chooses?

Pretty much. End to end uses the encryption keys of both _users_ to send. Over the wire has both sides use the platforms keys so the platform decrypts, stores in plain text, and sends it encrypted again to the other side. Over the wire is basically just HTTPS.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#93

If this is what it takes to keep us safe, I and most americans are ok with it. We live in dangerous times. The US has a balanced criminal justice system -- as long as due process is preserved privacy from the state should not be a major issue

> if it's not we have bigger problems anyway

Really, we shouldn't do anything; we have the bigger problem of the eventual heat death of the universe.

Take into account not only the size of the problem, but how easy it is to do something about it.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#94

Earlier quoted context omitted.

Signal recently added 'disappearing messages' which lets you specify how long a chat you initiate remains before being deleted.

And a screenshot, or another camera, or a rooted phone can easily defeat that. The analog hole ALWAYS exists. Pretending it doesnt is ridiculous.

What made you think I was pretending it doesn't?

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#95

They left off one very popular messenger, SMS: * Message content: All * Subpoena: can render all message content for the last 1-7 years * 18 U.S.C 2703(d): can render all message content for the last 1-7 years * Search warrant: can render all message content for the last 1-7 years * Vague suspicion plus a small fee to the carrier: can render all message content for the last 1-7 years

There's also: * Law enforcement simply asks nicely: can render all message content for the last 1-7 years

The Stored Communications Act makes disclosing the contents of messages without a search warrant unlawful

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#96
post #88
post #82

Earlier quoted context omitted.

Telegram is encrypted OVER THE WIRE and AT REST by default with strong encryption no matter what you do. It's E2EE if you select private chat with someone. Lots of FUD out there there about Telegram not being encrypted that's just not true. There's nothing either side can to do send a message in clear text / unencrypted.

For somebody who isn’t super cyprtography-savvy, what’s the difference between over the wire and e2ee? Does the former mean that telegram itself can read non-private-chat messages if it so chooses?

over the wire is when its encrypted during transmission between the User and Telegram's servers. HTTPS or SSL/TLS, etc. At Rest is when its encrypted in their DBs or hard drives, etc. Theoretically, Telegram can still read the contents if they wished to do so if they setup the appropriate code, or tools inbetween these steps.

E2EE means that the users exchange encryption keys, and they encrypt the data at the client, so that only the other client can decrypt it. Meaning Telegram can never inspect the data if they wanted to.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#97

Now I just have to get my friends and family to use Signal.

I switched to signal and got few people to switch too, then they started their shit coin(MOB). IMO Signal Messenger is just a way for that company to reach their shit coin goals. Uninstalled and never recommending that again.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#98
post #41

Earlier quoted context omitted.

Then you only have to trust that AMD did not accidentally or intentionally introduce a bug in the system. Remember Spectre? Remember all the security bugs in the Intel management code? You also have to trust that AMD generated and have always managed the encryption keys for that system properly and in accordance with their documentation. And are you even sure that you’re actually running on an AMD system? If the syst…

puts on tinfoil hat You'd also need to consider AMD's management engine, the Platform Security Processor. If we're really slinging conspiracy theories, AMD processors are likely just as backdoored as Intel one. I don't mean to be grim, but I think it's safe to assume that the US government has direct memory access to the vast majority of computer processors you can buy these days. [/conspiracy]

if you're going to that level, then have a look at five-eyes (and it's derivatives) https://en.wikipedia.org/wiki/Five_Eyes / Echelon

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#99
post #88
post #82

Earlier quoted context omitted.

Telegram is encrypted OVER THE WIRE and AT REST by default with strong encryption no matter what you do. It's E2EE if you select private chat with someone. Lots of FUD out there there about Telegram not being encrypted that's just not true. There's nothing either side can to do send a message in clear text / unencrypted.

For somebody who isn’t super cyprtography-savvy, what’s the difference between over the wire and e2ee? Does the former mean that telegram itself can read non-private-chat messages if it so chooses?

Yeah, if you connect to https://facebook.com and use messenger, it's encrypted over the wire because you're using HTTPS (TLS). But it's not E2EE.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#100
post #88
post #82

Earlier quoted context omitted.

Telegram is encrypted OVER THE WIRE and AT REST by default with strong encryption no matter what you do. It's E2EE if you select private chat with someone. Lots of FUD out there there about Telegram not being encrypted that's just not true. There's nothing either side can to do send a message in clear text / unencrypted.

For somebody who isn’t super cyprtography-savvy, what’s the difference between over the wire and e2ee? Does the former mean that telegram itself can read non-private-chat messages if it so chooses?

yes. worth remembering also that even with e2ee, a ad-tech-driven company could have endpoints determine marketing segments based on content of conversations ad report those to the company to better target ad spend.
Post reply on HN