Live data from Hacker News

FBI's ability to legally access secure messaging app content and metadata [pdf]

propertyofthepeople.org

101–110 of 474 posts

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#102
post #38

Earlier quoted context omitted.

for signal users this means the messages of course do exist on your phone, which will be the first thing these agencies seek to abscond with once youre detained as its infinitely more crackable in their hands. as a casual reminder: The fifth amendment protects your speech, not your biometrics. do not use face or fingerprint to secure your phone. use a strong passphrase, and if in doubt, power down the phone (android)…

My advice if you’re not on the level where three letter agencies are actively interested in your comings and goings: - Use a strong pass phrase - Enable biometrics so you don’t need to type that pass phrase 100 times per day - Learn the shortcut to have your phone disable biometrics and require the pass phrase so you can use it when police is coming for you, you’re entering the immigration line in the airport etc. -…

On recent iPhones, the way to disable biometrics is to hold the side button and either volume button until a prompt appears, then tap cancel. Mashing the side button 5 times does not work.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#103
post #89

Earlier quoted context omitted.

My advice if you’re not on the level where three letter agencies are actively interested in your comings and goings: - Use a strong pass phrase - Enable biometrics so you don’t need to type that pass phrase 100 times per day - Learn the shortcut to have your phone disable biometrics and require the pass phrase so you can use it when police is coming for you, you’re entering the immigration line in the airport etc. -…

I just tried this an it does not work for iPhone is it only on a certain iOS? I am a bit behind on updates. Thanks

That's actually the old method for iPhone 7 and before. Now, you can activate emergency SOS by holding the power button and one of the volume buttons. Assuming you don't need to contact any emergency contacts or services, just cancel out of that and your passcode will be required to unlock.

https://support.apple.com/en-us/HT208076

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#104

Earlier quoted context omitted.

puts on tinfoil hat You'd also need to consider AMD's management engine, the Platform Security Processor. If we're really slinging conspiracy theories, AMD processors are likely just as backdoored as Intel one. I don't mean to be grim, but I think it's safe to assume that the US government has direct memory access to the vast majority of computer processors you can buy these days. [/conspiracy]

if you're going to that level, then have a look at five-eyes (and it's derivatives) https://en.wikipedia.org/wiki/Five_Eyes / Echelon

I probably shouldn't have removed my tinfoil lining yet but yes, you're correct. Any information the US government has access to through these channels is also probably accessible by our surveillance/intelligence allies. It raises a lot of questions about how deep the rabbit hole goes, but I won't elucidate them here since I've been threatened with bans for doing so. I guess it's a do-your-own research situation, but always carry a healthy degree of skepticism when you read about anything government-adjacent.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#105
post #89

Earlier quoted context omitted.

My advice if you’re not on the level where three letter agencies are actively interested in your comings and goings: - Use a strong pass phrase - Enable biometrics so you don’t need to type that pass phrase 100 times per day - Learn the shortcut to have your phone disable biometrics and require the pass phrase so you can use it when police is coming for you, you’re entering the immigration line in the airport etc. -…

I just tried this an it does not work for iPhone is it only on a certain iOS? I am a bit behind on updates. Thanks

Try: Hold "volume up" and "power" for 2 seconds

You'll feel a vibration, and biometric login will be disabled until you enter your passcode.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#106
post #14

Well, who cares when all they need is to use something like Pegasus to obtain full access to your phone simply by sending you a WhatsApp message (without having you even open the message). Knowing how well guarded IOS is against app developers, I wonder what kind of zero-day would suddenly turn a message received in WhatsApp to full system access. I think NSO found a WhatsApp backdoor, not a zero-day bug.

NSO can't send you an WhatsApp message if you don't have WhatsApp on your iPhone.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#107

Earlier quoted context omitted.

And a screenshot, or another camera, or a rooted phone can easily defeat that. The analog hole ALWAYS exists. Pretending it doesnt is ridiculous.

> And a screenshot, or another camera, or a rooted phone can easily defeat that. Not if the message has already been deleted. Auto-deleting messages are so the recipient doesn't have to delete them manually, not so the recipient can't possibly keep a copy.

Exactly this. Even more: Auto-deleting messages are also that the sender doesn't have to delete them manually. Most people do not understand this. I even had a discussion with an open source chat app implementer who insisted on not implementing disappearing messages because they couldn't be really enforced.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#108

Earlier quoted context omitted.

But they have to fake the voice, if I call the other person and say "my emoji sequence is this, this and that" for the other person to verify and vice-versa.

Person A calls you. I intercept the call, so person A is calling me , and then I call you (spoofing so I look like Person A). When you pick up, I pick up, then I transmit what you're saying to Person A (and vice versa). How do you know I'm intercepting the transmission? Does the emoji sequence verify the call , perhaps?

Both connections would show different emojis on both sides then. So you would need to somehow deep fake the voice of the one telling their emojis to the other one.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#109

Earlier quoted context omitted.

> do not use face or fingerprint to secure your phone but can't they force you to put your password in that case, instead of your finger?

In general, no. The contents of your mind are protected because you must take an active part of disclose them. Of course, they can still order you to give them the password and stick you in jail for Contempt of Court charges if you don't. Check out Habeas Data. It's a fascinating/horrifying book detailing much of this.

To err on the side of caution, it's best to make all your passcodes themselves an admission to a crime.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#110
post #88
post #82

Earlier quoted context omitted.

Telegram is encrypted OVER THE WIRE and AT REST by default with strong encryption no matter what you do. It's E2EE if you select private chat with someone. Lots of FUD out there there about Telegram not being encrypted that's just not true. There's nothing either side can to do send a message in clear text / unencrypted.

For somebody who isn’t super cyprtography-savvy, what’s the difference between over the wire and e2ee? Does the former mean that telegram itself can read non-private-chat messages if it so chooses?

> For somebody who isn’t super cyprtography-savvy, what’s the difference between over the wire and e2ee?

E2EE: As long as it is correctly set up and no significant breakthroughs happens in math, nobody except the sender, the receiver can read the messages.

> Does the former mean that telegram itself can read non-private-chat messages if it so chooses?

Correct. They say they store messages encrypted and store keys and messages in different jurisdictions, effectively preventing themselves from abusing it or being coerced into giving it away, but this cannot be proven.

If your life depends on it, use Signal, otherwise use the one you prefer and can get your friends to use (preferably not WhatsApp though as it leaks all your connections to Facebook and uploads your data unencrypted to Google for indexing(!) if you enable backups.

Edited to remove ridiculously wrong statement, thanks kind SquishyPanda23 who pointed it out.

Post reply on HN