Live data from Hacker News

FBI's ability to legally access secure messaging app content and metadata [pdf]

propertyofthepeople.org

121–130 of 474 posts

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#121
post #38

Earlier quoted context omitted.

for signal users this means the messages of course do exist on your phone, which will be the first thing these agencies seek to abscond with once youre detained as its infinitely more crackable in their hands. as a casual reminder: The fifth amendment protects your speech, not your biometrics. do not use face or fingerprint to secure your phone. use a strong passphrase, and if in doubt, power down the phone (android)…

Your statement on the 5th amendment is no longer accurate broadly, but the matter still has some cross-jurisdictional disagreement: https://americanlegalnews.com/biometrics-covered-by-fifth-am...

District courts don't make law. Magistrates working for those district courts even less so. The case this news article cites has no precedential value anywhere - not even within N.D.Cal. - and should not be relied upon.

IAAL but IANYL

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#122
Check the difference between Telegram and WhatsApp.

Add to this the fact that WhatsApp

- uploads messages unencrypted to Google if you or someone you chat with enable backups

- and send all your metadata to Facebook.

Then remember how many people here have tried to tell us that Telegram is unusable abd WhatsApp is the bees knees.

Then think twice before taking security advice from such people again.

PS: as usual, if your life depends on it I recommend using Signal, and also being generally careful. For post card messaging use whatever makes you happy (except WhatsApp ;-)

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#123

Earlier quoted context omitted.

> For somebody who isn’t super cyprtography-savvy, what’s the difference between over the wire and e2ee? E2EE: As long as it is correctly set up and no significant breakthroughs happens in math, nobody except the sender, the receiver can read the messages. > Does the former mean that telegram itself can read non-private-chat messages if it so chooses? Correct. They say they store messages encrypted and store keys and…

> nobody except the sender, the receiver and the service provider can read the messages E2EE means the service provider cannot read the messages. Only the sender and receiver can.

Thanks! I edited a whole lot and that came out ridiculously wrong! :-)

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#124

Earlier quoted context omitted.

In general, no. The contents of your mind are protected because you must take an active part of disclose them. Of course, they can still order you to give them the password and stick you in jail for Contempt of Court charges if you don't. Check out Habeas Data. It's a fascinating/horrifying book detailing much of this.

To err on the side of caution, it's best to make all your passcodes themselves an admission to a crime.

"Your honor, the state agrees to not prosecute on any information inferrable from the text of the password."

"Understood. The defendant's Fifth Amendment right to protection from self-incrimination is secured. As per the prior ruling, the defendant will remain in custody for contempt of court until such time as they divulge the necessary password to comply with the warrant."

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#125

Earlier quoted context omitted.

In general, no. The contents of your mind are protected because you must take an active part of disclose them. Of course, they can still order you to give them the password and stick you in jail for Contempt of Court charges if you don't. Check out Habeas Data. It's a fascinating/horrifying book detailing much of this.

To err on the side of caution, it's best to make all your passcodes themselves an admission to a crime.

My passwords are so obscene it's a crime to write them down.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#126
post #17

This discussion is not very interesting from a security perspective. I tuned out at “cloud”. If it’s not in your physical possession, it’s not your computer. If it’s not your computer, then whoever administers the computer, or whoever [points a gun at/gives enough money to] the administrator of that system can access whatever you put on that system. If a “cloud” or “service” is involved, then you can trivially use th…

> if you did not write (or at least read) the code that you’re using to do all of the above, then you’re at the mercy of whoever wrote it. It's worse than that. Even if you read the code, you have to trust that the code you read is the code a service is actually using. Even if you deploy the code yourself, you have to trust that the infrastructure you're running on does not have some type of backdoor. Even if you run…

> Even if you read the code, you have to trust that the code you read is the code a service is actually using.

Don't forget to verify the code for the compiler to ensure that hasn't been compromised in order to inject an exploit into the binary at compile time.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#127

Now I just have to get my friends and family to use Signal.

I've had surprisingly good luck with strong-arming people into switching. The important part is having their trust, if they don't believe you they won't listen. The next part is to make simple, verifiable, and non-technical arguments for switching. Believe it or not, almost everybody is willing to take small steps if they're free.

Instead of rambling on and on about "end to end encryption" or "double-ratchet cryptographic algorithms" or other junk only nerds care about, approach it like this:

* There are no ads, and none of the messages you send can be used for advertising

* It's not owned by Facebook, Google, Microsoft, or any of the other mega-corporations, and you don't need an account on one of their sites to use it

* It will still work great if you travel, change providers, etc

* It's much safer to use on public Wi-Fi than other services or SMS

Honestly, don't even touch on law enforcement access as in the OP. That can strike a nerve for some people. The best appeals are the simple ones.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#128

Earlier quoted context omitted.

In general, no. The contents of your mind are protected because you must take an active part of disclose them. Of course, they can still order you to give them the password and stick you in jail for Contempt of Court charges if you don't. Check out Habeas Data. It's a fascinating/horrifying book detailing much of this.

To err on the side of caution, it's best to make all your passcodes themselves an admission to a crime.

They don't actually need your passphrase to unlock your phone - they just need somebody with the passphrase to unlock in for them. And if there's any doubt about who that is, then having that passphrase counts as testimonial; but if there's not - it might not count as testimonial.

Although there are apparently a whole bunch of legal details that matter here; courts have in some cases held that defendants can be forced to decrypt a device when the mere act of being able to decrypt it is itself a foregone conclusion.

(If you want to google a few of these cases, the all writs act is a decent keyword to include in the search).

The defendant never needs to divulge the passphrase - they simply need to provide a decrypted laptop.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#129

Earlier quoted context omitted.

Signal recently added 'disappearing messages' which lets you specify how long a chat you initiate remains before being deleted.

And a screenshot, or another camera, or a rooted phone can easily defeat that. The analog hole ALWAYS exists. Pretending it doesnt is ridiculous.

That's a different threat model, no messaging app is trying to protect the sender from the receiver. Disappearing messages are meant to protect two parties communicating with each other against a 3rd party who would eventually gain access to the device and its data.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#130
post #97

Now I just have to get my friends and family to use Signal.

I switched to signal and got few people to switch too, then they started their shit coin(MOB). IMO Signal Messenger is just a way for that company to reach their shit coin goals. Uninstalled and never recommending that again.

I remember many people being pissed off when these features were announced some months ago.

As far as I can tell, nothing really happened afterwards. I use Signal on a daily basis and haven't noticed any coin-related functionalities. Either they were canceled, haven't been released yet or they're just buried somewhere deep and not advertised.

Do you have a different experience?

Post reply on HN