Live data from Hacker News

FBI's ability to legally access secure messaging app content and metadata [pdf]

propertyofthepeople.org

131–140 of 474 posts

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#131

Earlier quoted context omitted.

> do not use face or fingerprint to secure your phone but can't they force you to put your password in that case, instead of your finger?

I think a fingerprint is easier to get if you’re not willing to cooperate. However, I think if they really, I mean really want your password, they will probably find a way to get it out of you. I think it also depends if it’s the local sheriff asking for your password or someone from the FBI while you’re tied up in a bunker somewhere in Nevada.

Apple should allow for 2 PWs, one the real PW, the other triggers a "self-destruct" mode.

Knowing that is possible law enforcement would then hesitate to ask.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#132
post #4

So if you have something to hide, don't use iCloud backup. And Whatsapp will give them the target's full contactbook (was to be expected), but also everyone that has the target in their contact list. That last one is quite far reaching.

Can you turn that off if you have icloud or do you need to not use icloud all together?

Yes, and you can delete old backups on iCloud - and then switch to local, automatic, fully encrypted backups to a Mac or PC running iTunes.

HN tends to get very frothy-at-the-mouth over Apple and privacy but the reality is that iPhones can be easily set up to offer security and privacy that best in class, they play well with self-hosted sync services like Nextcloud....and unlike the Android-based "privacy" distros you're not running an OS made by a bunch of random nameless people, you can use banking apps, etc.

The only feature I miss is being able to control background data usage like Android does.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#133

Earlier quoted context omitted.

On recent iPhones, the way to disable biometrics is to hold the side button and either volume button until a prompt appears, then tap cancel. Mashing the side button 5 times does not work.

Not sure how recent you're talking but I have an iPhone 11 Pro and I just tested pressing the side button 5 times and it takes me to the power off screen and prompts me for my password the same way that side button + volume does. Apple's docs also say that pressing the side button 5 times still works. > If you use the Emergency SOS shortcut, you need to enter your passcode to re-enable Touch ID, even if you don't com…

Pressing it five times starts the emergency SOS countdown (and requires the passcode next time) on my iPhone XS. Maybe you have the auto-calling disabled?

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#134

Earlier quoted context omitted.

There's also: * Law enforcement simply asks nicely: can render all message content for the last 1-7 years

The Stored Communications Act makes disclosing the contents of messages without a search warrant unlawful

The reality is that many times the only barrier to sensitive information is a shared login which many people know and a statement that users represent that they have legal authority to access that info.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#135
post #38
post #6

It says Telegram has no message content. Isn't telegram not E2EE by default, instead required explicit steps to make a conversation encrypted? Either way looks like Signal wins by a lot. The size of it spot is so small, it seems almost squeezed in. But only because they have nothing to share.

for signal users this means the messages of course do exist on your phone, which will be the first thing these agencies seek to abscond with once youre detained as its infinitely more crackable in their hands. as a casual reminder: The fifth amendment protects your speech, not your biometrics. do not use face or fingerprint to secure your phone. use a strong passphrase, and if in doubt, power down the phone (android)…

The fifth amendment doesn't protect either speech or biometrics. Nor does it protect passwords.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#136

Earlier quoted context omitted.

I think a fingerprint is easier to get if you’re not willing to cooperate. However, I think if they really, I mean really want your password, they will probably find a way to get it out of you. I think it also depends if it’s the local sheriff asking for your password or someone from the FBI while you’re tied up in a bunker somewhere in Nevada.

Apple should allow for 2 PWs, one the real PW, the other triggers a "self-destruct" mode. Knowing that is possible law enforcement would then hesitate to ask.

using such a self-destruct mode would be a certain way getting yourself charged with destroying evidence/contempt of court/... though.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#137
post #38
post #6

It says Telegram has no message content. Isn't telegram not E2EE by default, instead required explicit steps to make a conversation encrypted? Either way looks like Signal wins by a lot. The size of it spot is so small, it seems almost squeezed in. But only because they have nothing to share.

for signal users this means the messages of course do exist on your phone, which will be the first thing these agencies seek to abscond with once youre detained as its infinitely more crackable in their hands. as a casual reminder: The fifth amendment protects your speech, not your biometrics. do not use face or fingerprint to secure your phone. use a strong passphrase, and if in doubt, power down the phone (android)…

Also IOS has a panic button. Hit the main/screen button (on the right) five times really fast and faceid/touchid is disabled and passcode is required

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#138

Earlier quoted context omitted.

> do not use face or fingerprint to secure your phone but can't they force you to put your password in that case, instead of your finger?

In general, no. The contents of your mind are protected because you must take an active part of disclose them. Of course, they can still order you to give them the password and stick you in jail for Contempt of Court charges if you don't. Check out Habeas Data. It's a fascinating/horrifying book detailing much of this.

[deleted]

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#139

Earlier quoted context omitted.

My advice if you’re not on the level where three letter agencies are actively interested in your comings and goings: - Use a strong pass phrase - Enable biometrics so you don’t need to type that pass phrase 100 times per day - Learn the shortcut to have your phone disable biometrics and require the pass phrase so you can use it when police is coming for you, you’re entering the immigration line in the airport etc. -…

On recent iPhones, the way to disable biometrics is to hold the side button and either volume button until a prompt appears, then tap cancel. Mashing the side button 5 times does not work.

Works fine on my 11, my wifes 12, her backup SE gen 2 and my backup SE gen1.

Just tested all of them

Post reply on HN