Live data from Hacker News

FBI's ability to legally access secure messaging app content and metadata [pdf]

propertyofthepeople.org

221–230 of 474 posts

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#221
post #87

Earlier quoted context omitted.

> do not use face or fingerprint to secure your phone but can't they force you to put your password in that case, instead of your finger?

How? They can physically overpower you and place the sensor against your finger, or in front of your eye and pry it open without your consent and gain access with 0 input from you. How do they similarly force you to type something that requires deliberate, repeated concrete actions on your part?

In my case they threatened to harm my wife if I didn't stop refusing. After my case is over I'll happily release the video tapes so you can see how this shit works.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#222

Earlier quoted context omitted.

over the wire is when its encrypted during transmission between the User and Telegram's servers. HTTPS or SSL/TLS, etc. At Rest is when its encrypted in their DBs or hard drives, etc. Theoretically, Telegram can still read the contents if they wished to do so if they setup the appropriate code, or tools inbetween these steps. E2EE means that the users exchange encryption keys, and they encrypt the data at the client,…

I very much doubt that Telegram really does encrypt messages "at rest": their server side full text search works extremely fast.

That's a fair assessment, I didn't make the original claim, just answered the definitions of the encryption states.

I haven't dug enough to know what telegram does or claims to do.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#223
post #162

This seems like a good place to say that I strongly recommend Yasha Levine's Surveillance Valley book ( https://www.goodreads.com/book/show/34220713-surveillance-va... ) where he suggests that all of this is working as intended, going all the way back to the military counter-insurgency roots of the arpanet first in places like Vietnam, and then back home in anti-war and leftist movements. The contemporary themes that…

Where is any evidence of Tor being a military surveillance project? I find it hard to believe an open source project like this has been infiltrated. Yes, there is suspicion some ECC curves are compromised, but only the ones provided by NIST. I'd really like to see evidence of Tor.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#224
post #4

So if you have something to hide, don't use iCloud backup. And Whatsapp will give them the target's full contactbook (was to be expected), but also everyone that has the target in their contact list. That last one is quite far reaching.

> if you have something to hide Most people don't realize that most people have something to hide. The USA has so many laws on its books. Many of which are outright bizarre[0] and some of which normal people might normally break[1]. And that's only counting current/past laws. It wasn't that long ago a US President was suggesting all Muslims should be forced to carry special IDs[2]. If you have a documented history be…

I always liked this one I found in the Illinois statutes - it basically criminalizes every person online:

Barratry. If a person wickedly and willfully excites and stirs up actions or quarrels between the people of this State with a view to promote strife and contention, he or she is guilty of the petty offense of common barratry[.]

https://www.ilga.gov/legislation/ilcs/ilcs4.asp?DocName=0720...

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#226

Earlier quoted context omitted.

My advice if you’re not on the level where three letter agencies are actively interested in your comings and goings: - Use a strong pass phrase - Enable biometrics so you don’t need to type that pass phrase 100 times per day - Learn the shortcut to have your phone disable biometrics and require the pass phrase so you can use it when police is coming for you, you’re entering the immigration line in the airport etc. -…

On recent iPhones, the way to disable biometrics is to hold the side button and either volume button until a prompt appears, then tap cancel. Mashing the side button 5 times does not work.

The side button 5 times thing is disabled by default, but can be enabled from Settings > Emergency SOS.

I just verified this on iOS 15.1 on an iPhone 12.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#227
post #191

Earlier quoted context omitted.

IIRC the only reason this amendment was made was because the 180 day limit was found unconstitutional anyway by an appellate court. So, technically the amendment did nothing. It doesn't matter where your data is held, locally or cloud, (if you are an American resident and your data is in the USA) as it is _your_ data and it is unconstitutional for them to read it without a warrant. In theory.

> It doesn't matter where your data is held, locally or cloud In the US it does

Citation?

This ruling has been adopted by the US Supreme Court: https://privacylaw.proskauer.com/2007/06/articles/electronic...

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#228
post #46

I'm wondering how this was obtained, and how old this is? For WhatsApp: > if target is using an iPhone and iCloud backups enabled, iCloud returns may contain WhatsApp data, to include message content Probably not true since WhatsApp launched encrypted backups.

I mean the document says the data is accurate "as of November/2020", and the slide was prepared 7-Jan-2021

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#229

Earlier quoted context omitted.

The fifth amendment doesn't protect either speech or biometrics. Nor does it protect passwords.

You are wrong. It protects passwords as speech, as they are testimonial, per many court rulings. It does not protect biometrics based on law that basically says the police can force you to give up your fingerprints for their records, so they can sure as fuck force your finger onto a reader.

Can they force someone to LOOK at the phone? FaceID with attention check will need you to look before it opens.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#230
Some FBI agents came to my house once and told me that my home Internet had been used to visit Islamic Extremist websites. They brought a local police office with them and a 'threat assessment' coordinator from my workplace. They asked me if my family was Muslim and wanted to know if we had been radicalized.

We are not religious (at all). We do not attend church, synagogue or mosque. We are lower middle class white Americans born and raised in the USA and have never traveled outside the country.

I have no idea why they thought this about us. Maybe it was an IP mix-up, but it was very disturbing. I feared that I may lose my job. I became very afraid of the FBI that day. I think this could happen to anyone at anytime.

Post reply on HN