Live data from Hacker News

FBI's ability to legally access secure messaging app content and metadata [pdf]

propertyofthepeople.org

231–240 of 474 posts

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#231
post #170

Earlier quoted context omitted.

That is a lot of speculation. If you read the encryption protocol, actual methods being used for encryption are well known. Client is open source and supports reproducible builds. If there is a backdoor, it is in front of our eyes. > What that list doesn't show is what Telegram does when the FSB knocks. By all means, give your potentially embarassing message content to a hostile nation's intelligence service. Telegra…

Telegram's block in Russia was likely a very successful PR action coordinated with authorities. It was never removed from national appstores, and Google/Apple usually comply with such requests, and the fact that it was unbanned is unprecedented.

Apple did stop updates for the Telegram. Google and Apple has weak history on compiling Russian requests. Maybe they complie with other countries more, but not Russian.

https://www.pcmag.com/news/after-almost-2-months-apple-stops...

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#232
post #82
post #6

It says Telegram has no message content. Isn't telegram not E2EE by default, instead required explicit steps to make a conversation encrypted? Either way looks like Signal wins by a lot. The size of it spot is so small, it seems almost squeezed in. But only because they have nothing to share.

Telegram is encrypted OVER THE WIRE and AT REST by default with strong encryption no matter what you do. It's E2EE if you select private chat with someone. Lots of FUD out there there about Telegram not being encrypted that's just not true. There's nothing either side can to do send a message in clear text / unencrypted.

Encryption over the wire and at rest is a basic expectancy of any web service today. They would meet that criteria just by using SSL and disk encryption on their servers. E2EE is a much stronger criteria.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#234

They left off one very popular messenger, SMS: * Message content: All * Subpoena: can render all message content for the last 1-7 years * 18 U.S.C 2703(d): can render all message content for the last 1-7 years * Search warrant: can render all message content for the last 1-7 years * Vague suspicion plus a small fee to the carrier: can render all message content for the last 1-7 years

It's about secure messaging

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#235
post #191

Earlier quoted context omitted.

IIRC the only reason this amendment was made was because the 180 day limit was found unconstitutional anyway by an appellate court. So, technically the amendment did nothing. It doesn't matter where your data is held, locally or cloud, (if you are an American resident and your data is in the USA) as it is _your_ data and it is unconstitutional for them to read it without a warrant. In theory.

> It doesn't matter where your data is held, locally or cloud In the US it does

If they are local and encrypted... oops, forgot the encryption key.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#236
post #14

Well, who cares when all they need is to use something like Pegasus to obtain full access to your phone simply by sending you a WhatsApp message (without having you even open the message). Knowing how well guarded IOS is against app developers, I wonder what kind of zero-day would suddenly turn a message received in WhatsApp to full system access. I think NSO found a WhatsApp backdoor, not a zero-day bug.

Or compromise the device in some other way.

At the risk of being cliche here's a relevant xkcd - https://xkcd.com/538/

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#238
post #162

This seems like a good place to say that I strongly recommend Yasha Levine's Surveillance Valley book ( https://www.goodreads.com/book/show/34220713-surveillance-va... ) where he suggests that all of this is working as intended, going all the way back to the military counter-insurgency roots of the arpanet first in places like Vietnam, and then back home in anti-war and leftist movements. The contemporary themes that…

Signal isn't funded by the military, by OTF/BBG, or any branch of the USG government. People who claim otherwise are confused (deeply) about a program OTF ran that sponsored third-party security reviews and development projects (summer-of-code style), none of which was mediated through OTF --- it was just a bucket of money. You should be extremely skeptical about people who bring OTF/BBG up in these discussions. I ha…

As I understand it the technology behind Tor is strengthened by an arms race. You want several different well-funded entities running nodes, because that makes the service better for everybody. Even if some of those entities are hostile they still help unless one entity controls a large portion of interior nodes and even then you're only giving metadata to that single entity (whichever it is) by using Tor, not anybody else - which is better than you're going to do with alternative technologies.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#239

Earlier quoted context omitted.

The people responsible for investigating and prosecuting such crimes have some not so great incentives to avoid doing so and keep the whole thing secret though, don't they? And then when they get caught, they do this: https://cdt.org/insights/the-truth-about-telecom-immunity/

Sounds like an easy way to have your case tossed out in court. It's funny how much this differs from my own personal experience with law enforcement. The friends I know are timid as hell and don't do anything without a warrant just to stay on the safe side- even if they probably don't need one.

Imagine a world where the entire law enforcement complex followed the law. What a world.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#240

They left off one very popular messenger, SMS: * Message content: All * Subpoena: can render all message content for the last 1-7 years * 18 U.S.C 2703(d): can render all message content for the last 1-7 years * Search warrant: can render all message content for the last 1-7 years * Vague suspicion plus a small fee to the carrier: can render all message content for the last 1-7 years

Source is a few years old, but I suppose we can make another FOIA request to find out how long carriers store text messages these days - it was basically 0-5 days a decade ago:

https://www.nbcnews.com/technolog/how-long-do-wireless-carri...

Post reply on HN