Live data from Hacker News

FBI's ability to legally access secure messaging app content and metadata [pdf]

propertyofthepeople.org

111–120 of 474 posts

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#111

Earlier quoted context omitted.

But they have to fake the voice, if I call the other person and say "my emoji sequence is this, this and that" for the other person to verify and vice-versa.

Person A calls you. I intercept the call, so person A is calling me , and then I call you (spoofing so I look like Person A). When you pick up, I pick up, then I transmit what you're saying to Person A (and vice versa). How do you know I'm intercepting the transmission? Does the emoji sequence verify the call , perhaps?

The emoji sequence is a hash of the secret key values generated as part of a modified/extended version of the Diffie-Hellman key exchange. The emoji sequence is generated and displayed independently on both devices before the final necessary key exchange message is transmitted over the wire, so a man-in-the-middle has no way of modifying messages in flight to ensure that both parties end up generating the same emoji sequence.

I'm not a cryptographer, but that's what I glean from their explanation: https://core.telegram.org/api/end-to-end/video-calls#key-ver...

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#112

Earlier quoted context omitted.

My advice if you’re not on the level where three letter agencies are actively interested in your comings and goings: - Use a strong pass phrase - Enable biometrics so you don’t need to type that pass phrase 100 times per day - Learn the shortcut to have your phone disable biometrics and require the pass phrase so you can use it when police is coming for you, you’re entering the immigration line in the airport etc. -…

On recent iPhones, the way to disable biometrics is to hold the side button and either volume button until a prompt appears, then tap cancel. Mashing the side button 5 times does not work.

Not sure how recent you're talking but I have an iPhone 11 Pro and I just tested pressing the side button 5 times and it takes me to the power off screen and prompts me for my password the same way that side button + volume does.

Apple's docs also say that pressing the side button 5 times still works.

> If you use the Emergency SOS shortcut, you need to enter your passcode to re-enable Touch ID, even if you don't complete a call to emergency services.

https://support.apple.com/en-us/HT208076

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#113
post #88

Earlier quoted context omitted.

For somebody who isn’t super cyprtography-savvy, what’s the difference between over the wire and e2ee? Does the former mean that telegram itself can read non-private-chat messages if it so chooses?

yes. worth remembering also that even with e2ee, a ad-tech-driven company could have endpoints determine marketing segments based on content of conversations ad report those to the company to better target ad spend.

Also, as is the case with WhatsApp, they siphon off your metdata and even have the gall to make an agreement with Google to download message content unencrypted to Google when one enable backups.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#114
post #17

This discussion is not very interesting from a security perspective. I tuned out at “cloud”. If it’s not in your physical possession, it’s not your computer. If it’s not your computer, then whoever administers the computer, or whoever [points a gun at/gives enough money to] the administrator of that system can access whatever you put on that system. If a “cloud” or “service” is involved, then you can trivially use th…

> if you did not write (or at least read) the code that you’re using to do all of the above, then you’re at the mercy of whoever wrote it. It's worse than that. Even if you read the code, you have to trust that the code you read is the code a service is actually using. Even if you deploy the code yourself, you have to trust that the infrastructure you're running on does not have some type of backdoor. Even if you run…

> the likelihood of any of these things actually becoming a problem decreases significantly as you read through the paragraph.

And yet, "likelihood" doesn't necessarily mean "hasn't been done".

Just look at:

* [0]: Intel ME

* [1]: Solarwinds attack and CI systems

* [2]: Ubiquiti attack and complete infrastructure compromise

* [3]: And the famous Ken Thompson statement

[0a]: https://news.ycombinator.com/item?id=15298833

[0b]: https://www.blackhat.com/eu-17/briefings/schedule/#how-to-ha...

[1]: https://www.cisecurity.org/solarwinds/

[2]: https://krebsonsecurity.com/2021/04/ubiquiti-all-but-confirm...

[3]: https://users.ece.cmu.edu/~ganger/712.fall02/papers/p761-tho...

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#115
The way these became bullet points on the slide is ~

An active investigation leads an agent to a suspect known to have used one of these applications

An administrative subpoena is issued to the company asking for what information is available

The company is then ordered by a federal judge to provide information related to a particular account or accounts

The company complies.

This is why it is important to understand how your messaging service handles data and how you can compromise your own safekeeping of all or part of that data.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#116

Earlier quoted context omitted.

There's also: * Law enforcement simply asks nicely: can render all message content for the last 1-7 years

The Stored Communications Act makes disclosing the contents of messages without a search warrant unlawful

The people responsible for investigating and prosecuting such crimes have some not so great incentives to avoid doing so and keep the whole thing secret though, don't they?

And then when they get caught, they do this:

https://cdt.org/insights/the-truth-about-telecom-immunity/

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#117

Isn’t this simply imaginary, where in practice all the FBI has to do to up the ante is to request military-grade interception from a willing foreign counterpart?

The point of promoting and using privacy respecting software is not necessarily to make it impossible for law enforcement to get what they want. It's to make it somewhat expensive and require targeted probes. You simply want it to be cost prohibitive to engage in mass surveillance on everyone, because that is an immensely powerful tool of totalitarian oppression that get really bad if we happen to elect the wrong per…

I agree with you on the level of my person, and naturally flag that this economic argument is extremely poor policy. It’s quite unclear that the marginal cost is non-zero, or even flat by person. One might reasonably conclude we are already each inside a high-resolution springing trap, waiting for the moment we find ourselves athwart the powers that be. Imagine in physical space where the local police could simply call in foreign air strikes upon domestic citizens, with only economics to prevent otherwise. We must have transparent and firm laws, reformed at a fundamental level.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#118
post #4

So if you have something to hide, don't use iCloud backup. And Whatsapp will give them the target's full contactbook (was to be expected), but also everyone that has the target in their contact list. That last one is quite far reaching.

> if you have something to hide Most people don't realize that most people have something to hide. The USA has so many laws on its books. Many of which are outright bizarre[0] and some of which normal people might normally break[1]. And that's only counting current/past laws. It wasn't that long ago a US President was suggesting all Muslims should be forced to carry special IDs[2]. If you have a documented history be…

Did you even read the snopes article you referenced before making what seems like a definitive claim about how Trump was suggesting muslims carry special IDs? Because Snope's own rating is "Mixture" of truth and false and if you read the assessment, it is grasping at straws to even make that conclusion.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#119
post #88

Earlier quoted context omitted.

For somebody who isn’t super cyprtography-savvy, what’s the difference between over the wire and e2ee? Does the former mean that telegram itself can read non-private-chat messages if it so chooses?

> For somebody who isn’t super cyprtography-savvy, what’s the difference between over the wire and e2ee? E2EE: As long as it is correctly set up and no significant breakthroughs happens in math, nobody except the sender, the receiver can read the messages. > Does the former mean that telegram itself can read non-private-chat messages if it so chooses? Correct. They say they store messages encrypted and store keys and…

> nobody except the sender, the receiver and the service provider can read the messages

E2EE means the service provider cannot read the messages.

Only the sender and receiver can.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#120
post #82
post #6

It says Telegram has no message content. Isn't telegram not E2EE by default, instead required explicit steps to make a conversation encrypted? Either way looks like Signal wins by a lot. The size of it spot is so small, it seems almost squeezed in. But only because they have nothing to share.

Telegram is encrypted OVER THE WIRE and AT REST by default with strong encryption no matter what you do. It's E2EE if you select private chat with someone. Lots of FUD out there there about Telegram not being encrypted that's just not true. There's nothing either side can to do send a message in clear text / unencrypted.

(how) does the telegram server prevent unencrypted content?

also curious - how does telegram support encryption for chatrooms without the parties being known in advance? or are those chats not encrypted?

Post reply on HN