Live data from Hacker News

FBI's ability to legally access secure messaging app content and metadata [pdf]

propertyofthepeople.org

161–170 of 474 posts

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#161
post #80
post #61

Earlier quoted context omitted.

Refusing a valid court issued search warrant/order is a criminal offense. I think 180 days for each refusal of a legal order.

The issue is a bit more complex. I was thinking more on the lines of "will I get bothered for making crypto available for the masses that nobody can crack?"

IRRC Didn't they jail a guy for that?

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#162
This seems like a good place to say that I strongly recommend Yasha Levine's Surveillance Valley book (https://www.goodreads.com/book/show/34220713-surveillance-va...) where he suggests that all of this is working as intended, going all the way back to the military counter-insurgency roots of the arpanet first in places like Vietnam, and then back home in anti-war and leftist movements. The contemporary themes that are relevant are the fact that current privacy movements like Tor, Signal, OTF, BBG are fundamentally military funded and survive on government contracts. It distracts from the needed political discourse into a technology one where "encryption is the great equalizer" and everyone can resist big brother in their own way on the platforms the government has built. Encryption does exist, but it also distracts from other vectors like vulnerabilities (that led to Ulbricht getting caught), what services you would e2e connect to, how you get the clients to connect to those services, what store can push binaries for said clients etc.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#163
post #18
post #4

So if you have something to hide, don't use iCloud backup. And Whatsapp will give them the target's full contactbook (was to be expected), but also everyone that has the target in their contact list. That last one is quite far reaching.

Has Apple made any public statements regarding iCloud's lack of privacy features. It takes the wind out of their privacy marketing that is effectively hurting ad tech but not truly protecting consumers from state-level actors with data access.

E2EE was in the iOS 15 beta for backups but it was removed? (Did not land for release) after they changed the time table of CSAM scanning feature. So we will see if we get E2EE backups once that image scanning lands.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#167

Isn’t this simply imaginary, where in practice all the FBI has to do to up the ante is to request military-grade interception from a willing foreign counterpart?

Can't the FBI do a Pegasus style remote access thing on an appropriate warrant themselves?

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#168

Earlier quoted context omitted.

I read somewhere that Tox's security was compromised.

I'd like to see that. Was it not fixed?

I found https://media.ccc.de/v/rc3-709912-adopting_the_noise_key_exc... which might be it.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#169
post #125

Earlier quoted context omitted.

To err on the side of caution, it's best to make all your passcodes themselves an admission to a crime.

My passwords are so obscene it's a crime to write them down.

great, so they'll just be able to hit you with lewd charges on top of everything else they are filing.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#170

Check the difference between Telegram and WhatsApp. Add to this the fact that WhatsApp - uploads messages unencrypted to Google if you or someone you chat with enable backups - and send all your metadata to Facebook. Then remember how many people here have tried to tell us that Telegram is unusable abd WhatsApp is the bees knees. Then think twice before taking security advice from such people again. PS: as usual, if…

Telegram defaults to no encryption, does not do encrypted group chats, has a home-rolled encryption protocol which almost guarantees it's weak as nearly every home-rolled encryption system always is (if not also backdoored). Coupled with it being headquartered in Russia means it is completely untrustable. The only reason Telegram comes out on top of Whatsapp in the document in question is because Telegram is a foreig…

That is a lot of speculation. If you read the encryption protocol, actual methods being used for encryption are well known. Client is open source and supports reproducible builds. If there is a backdoor, it is in front of our eyes.

> What that list doesn't show is what Telegram does when the FSB knocks. By all means, give your potentially embarassing message content to a hostile nation's intelligence service.

Telegram is in a lot of trouble in operating in Russia. It was blocked for two years. [1]

If they are so co-operative, why pass the opportunity to watch on their own people. Or did they become co-operative after unblock? It seems, that they help on some level [2], but does this threaten to other countries? Hard to say so.

[1] https://en.wikipedia.org/wiki/Blocking_Telegram_in_Russia

[2] https://www.independent.co.uk/news/world/europe/telegram-rus...

Post reply on HN