Live data from Hacker News

FBI's ability to legally access secure messaging app content and metadata [pdf]

propertyofthepeople.org

191–200 of 474 posts

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#191
post #175

Earlier quoted context omitted.

You forgot email... and they don't need a warrant for messages older then 180 days if in the cloud (they never delete them, too): https://www.consumerreports.org/consumerist/house-passes-bil...

IIRC the only reason this amendment was made was because the 180 day limit was found unconstitutional anyway by an appellate court. So, technically the amendment did nothing. It doesn't matter where your data is held, locally or cloud, (if you are an American resident and your data is in the USA) as it is _your_ data and it is unconstitutional for them to read it without a warrant. In theory.

> It doesn't matter where your data is held, locally or cloud

In the US it does

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#192
post #136

Earlier quoted context omitted.

Apple should allow for 2 PWs, one the real PW, the other triggers a "self-destruct" mode. Knowing that is possible law enforcement would then hesitate to ask.

using such a self-destruct mode would be a certain way getting yourself charged with destroying evidence/contempt of court/... though.

[deleted]

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#193
post #133

Earlier quoted context omitted.

Not sure how recent you're talking but I have an iPhone 11 Pro and I just tested pressing the side button 5 times and it takes me to the power off screen and prompts me for my password the same way that side button + volume does. Apple's docs also say that pressing the side button 5 times still works. > If you use the Emergency SOS shortcut, you need to enter your passcode to re-enable Touch ID, even if you don't com…

Pressing it five times starts the emergency SOS countdown (and requires the passcode next time) on my iPhone XS. Maybe you have the auto-calling disabled?

It doesn't on my 2nd Gen iPhone SE (2020). That said, anything that causes the "swipe to power off" screen to appear has the same affect, so essentially holding down the button for 5 seconds does the trick.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#194
post #87

Earlier quoted context omitted.

> do not use face or fingerprint to secure your phone but can't they force you to put your password in that case, instead of your finger?

How? They can physically overpower you and place the sensor against your finger, or in front of your eye and pry it open without your consent and gain access with 0 input from you. How do they similarly force you to type something that requires deliberate, repeated concrete actions on your part?

https://arstechnica.com/tech-policy/2020/02/man-who-refused-...

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#195
post #38
post #6

It says Telegram has no message content. Isn't telegram not E2EE by default, instead required explicit steps to make a conversation encrypted? Either way looks like Signal wins by a lot. The size of it spot is so small, it seems almost squeezed in. But only because they have nothing to share.

for signal users this means the messages of course do exist on your phone, which will be the first thing these agencies seek to abscond with once youre detained as its infinitely more crackable in their hands. as a casual reminder: The fifth amendment protects your speech, not your biometrics. do not use face or fingerprint to secure your phone. use a strong passphrase, and if in doubt, power down the phone (android)…

Don't have any family or friends, either. If you refuse to talk and invoke your rights the government will just threaten to hurt those you love until you break and give up your passwords. From experience.

I liked it in Wrath of Man where one guy is acting tough as fuck until they bring his girl into the room.

Also, if you can, if you are encrypting data, use a hidden volume inside the first - that way you can give the government the outer password and they'll be happy thinking they have everything.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#196

Earlier quoted context omitted.

I think a fingerprint is easier to get if you’re not willing to cooperate. However, I think if they really, I mean really want your password, they will probably find a way to get it out of you. I think it also depends if it’s the local sheriff asking for your password or someone from the FBI while you’re tied up in a bunker somewhere in Nevada.

Apple should allow for 2 PWs, one the real PW, the other triggers a "self-destruct" mode. Knowing that is possible law enforcement would then hesitate to ask.

FaceID can already prevent a device from unlocking if someone is sleeping. In theory devices could detect if they were being unlocked "under duress" by using biometrics to look at facial expressions, heartbeat, etc, and then wipe themselves. I don't know how practical in reality but perhaps it could be a feature you turn on in a sensitive environment.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#197

Earlier quoted context omitted.

I'm just glad you're here to stick up for your friends without any corroboration or linking story. It's just a good thing to do.

Being charitable, let’s assume his friends work as homicide or theft detectives. If so, they need a high standard for admissible evidence to build their case. If on the other hand his friends are street cops tasked with clearing a corner of drug dealers because some neighbor complained to their council person who complained to the police chief then those cops don’t necessarily care about extrajudicial activities. Hav…

They definitely need a high standard for admissible evidence, that doesn't stop them from purchasing large amounts of data from all-too-willing communications companies and using parallel construction to build their case once they find out what happened via warantless spying.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#198
post #6

It says Telegram has no message content. Isn't telegram not E2EE by default, instead required explicit steps to make a conversation encrypted? Either way looks like Signal wins by a lot. The size of it spot is so small, it seems almost squeezed in. But only because they have nothing to share.

Telegram isn’t E2EE by default.

My bet is on the fact that they are based in Russia, so they don’t give a shit about a US warrant or subpoena.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#199
post #38

Earlier quoted context omitted.

for signal users this means the messages of course do exist on your phone, which will be the first thing these agencies seek to abscond with once youre detained as its infinitely more crackable in their hands. as a casual reminder: The fifth amendment protects your speech, not your biometrics. do not use face or fingerprint to secure your phone. use a strong passphrase, and if in doubt, power down the phone (android)…

My advice if you’re not on the level where three letter agencies are actively interested in your comings and goings: - Use a strong pass phrase - Enable biometrics so you don’t need to type that pass phrase 100 times per day - Learn the shortcut to have your phone disable biometrics and require the pass phrase so you can use it when police is coming for you, you’re entering the immigration line in the airport etc. -…

If you _are_ at the level where TLAs are interested in you they will not give you a chance to mash that button. You will have a loaded gun pointed at your head out of nowhere and you will freeze. From experience.
Post reply on HN