I'd like to see Tox and Jami.
I read somewhere that Tox's security was compromised.
FBI's ability to legally access secure messaging app content and metadata [pdf]
101–110 of 474 posts
Re: FBI's ability to legally access secure messaging app content and metadata [pdf]
#102Earlier quoted context omitted.
for signal users this means the messages of course do exist on your phone, which will be the first thing these agencies seek to abscond with once youre detained as its infinitely more crackable in their hands. as a casual reminder: The fifth amendment protects your speech, not your biometrics. do not use face or fingerprint to secure your phone. use a strong passphrase, and if in doubt, power down the phone (android)…
My advice if you’re not on the level where three letter agencies are actively interested in your comings and goings: - Use a strong pass phrase - Enable biometrics so you don’t need to type that pass phrase 100 times per day - Learn the shortcut to have your phone disable biometrics and require the pass phrase so you can use it when police is coming for you, you’re entering the immigration line in the airport etc. -…
Re: FBI's ability to legally access secure messaging app content and metadata [pdf]
#103Earlier quoted context omitted.
My advice if you’re not on the level where three letter agencies are actively interested in your comings and goings: - Use a strong pass phrase - Enable biometrics so you don’t need to type that pass phrase 100 times per day - Learn the shortcut to have your phone disable biometrics and require the pass phrase so you can use it when police is coming for you, you’re entering the immigration line in the airport etc. -…
I just tried this an it does not work for iPhone is it only on a certain iOS? I am a bit behind on updates. Thanks
Re: FBI's ability to legally access secure messaging app content and metadata [pdf]
#104Earlier quoted context omitted.
puts on tinfoil hat You'd also need to consider AMD's management engine, the Platform Security Processor. If we're really slinging conspiracy theories, AMD processors are likely just as backdoored as Intel one. I don't mean to be grim, but I think it's safe to assume that the US government has direct memory access to the vast majority of computer processors you can buy these days. [/conspiracy]
if you're going to that level, then have a look at five-eyes (and it's derivatives) https://en.wikipedia.org/wiki/Five_Eyes / Echelon
Re: FBI's ability to legally access secure messaging app content and metadata [pdf]
#105Earlier quoted context omitted.
My advice if you’re not on the level where three letter agencies are actively interested in your comings and goings: - Use a strong pass phrase - Enable biometrics so you don’t need to type that pass phrase 100 times per day - Learn the shortcut to have your phone disable biometrics and require the pass phrase so you can use it when police is coming for you, you’re entering the immigration line in the airport etc. -…
I just tried this an it does not work for iPhone is it only on a certain iOS? I am a bit behind on updates. Thanks
You'll feel a vibration, and biometric login will be disabled until you enter your passcode.
Re: FBI's ability to legally access secure messaging app content and metadata [pdf]
#106Well, who cares when all they need is to use something like Pegasus to obtain full access to your phone simply by sending you a WhatsApp message (without having you even open the message). Knowing how well guarded IOS is against app developers, I wonder what kind of zero-day would suddenly turn a message received in WhatsApp to full system access. I think NSO found a WhatsApp backdoor, not a zero-day bug.
Re: FBI's ability to legally access secure messaging app content and metadata [pdf]
#107Earlier quoted context omitted.
And a screenshot, or another camera, or a rooted phone can easily defeat that. The analog hole ALWAYS exists. Pretending it doesnt is ridiculous.
> And a screenshot, or another camera, or a rooted phone can easily defeat that. Not if the message has already been deleted. Auto-deleting messages are so the recipient doesn't have to delete them manually, not so the recipient can't possibly keep a copy.
Re: FBI's ability to legally access secure messaging app content and metadata [pdf]
#108Earlier quoted context omitted.
But they have to fake the voice, if I call the other person and say "my emoji sequence is this, this and that" for the other person to verify and vice-versa.
Person A calls you. I intercept the call, so person A is calling me , and then I call you (spoofing so I look like Person A). When you pick up, I pick up, then I transmit what you're saying to Person A (and vice versa). How do you know I'm intercepting the transmission? Does the emoji sequence verify the call , perhaps?
Re: FBI's ability to legally access secure messaging app content and metadata [pdf]
#109Earlier quoted context omitted.
> do not use face or fingerprint to secure your phone but can't they force you to put your password in that case, instead of your finger?
In general, no. The contents of your mind are protected because you must take an active part of disclose them. Of course, they can still order you to give them the password and stick you in jail for Contempt of Court charges if you don't. Check out Habeas Data. It's a fascinating/horrifying book detailing much of this.
Re: FBI's ability to legally access secure messaging app content and metadata [pdf]
#110Earlier quoted context omitted.
Telegram is encrypted OVER THE WIRE and AT REST by default with strong encryption no matter what you do. It's E2EE if you select private chat with someone. Lots of FUD out there there about Telegram not being encrypted that's just not true. There's nothing either side can to do send a message in clear text / unencrypted.
For somebody who isn’t super cyprtography-savvy, what’s the difference between over the wire and e2ee? Does the former mean that telegram itself can read non-private-chat messages if it so chooses?
E2EE: As long as it is correctly set up and no significant breakthroughs happens in math, nobody except the sender, the receiver can read the messages.
> Does the former mean that telegram itself can read non-private-chat messages if it so chooses?
Correct. They say they store messages encrypted and store keys and messages in different jurisdictions, effectively preventing themselves from abusing it or being coerced into giving it away, but this cannot be proven.
If your life depends on it, use Signal, otherwise use the one you prefer and can get your friends to use (preferably not WhatsApp though as it leaks all your connections to Facebook and uploads your data unencrypted to Google for indexing(!) if you enable backups.
Edited to remove ridiculously wrong statement, thanks kind SquishyPanda23 who pointed it out.