Live data from Hacker News

FBI's ability to legally access secure messaging app content and metadata [pdf]

propertyofthepeople.org

241–250 of 474 posts

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#241

Some FBI agents came to my house once and told me that my home Internet had been used to visit Islamic Extremist websites. They brought a local police office with them and a 'threat assessment' coordinator from my workplace. They asked me if my family was Muslim and wanted to know if we had been radicalized. We are not religious (at all). We do not attend church, synagogue or mosque. We are lower middle class white A…

It absolutely can.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#242
post #82
post #6

It says Telegram has no message content. Isn't telegram not E2EE by default, instead required explicit steps to make a conversation encrypted? Either way looks like Signal wins by a lot. The size of it spot is so small, it seems almost squeezed in. But only because they have nothing to share.

Telegram is encrypted OVER THE WIRE and AT REST by default with strong encryption no matter what you do. It's E2EE if you select private chat with someone. Lots of FUD out there there about Telegram not being encrypted that's just not true. There's nothing either side can to do send a message in clear text / unencrypted.

> It's E2EE if you select private chat with someone. And its not E2EE if you fail to select private chat.

What this means is that any conversations where you do select E2EE are the ones the "authorities" will take interest in, even if only to the extent of metadata.

That's the fundamental problem with E2EE-by-exception, rather than by default. It calls attention to specific data, even if its not cleartext, rather than obscuring everything.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#243

Earlier quoted context omitted.

> if you have something to hide Most people don't realize that most people have something to hide. The USA has so many laws on its books. Many of which are outright bizarre[0] and some of which normal people might normally break[1]. And that's only counting current/past laws. It wasn't that long ago a US President was suggesting all Muslims should be forced to carry special IDs[2]. If you have a documented history be…

Did you even read the snopes article you referenced before making what seems like a definitive claim about how Trump was suggesting muslims carry special IDs? Because Snope's own rating is "Mixture" of truth and false and if you read the assessment, it is grasping at straws to even make that conclusion.

Yes, "mixed" means you have to read the nuance. I think I accurately captured the reality. If you have a correction to offer, please do.

EDIT: Ultimately, the nuance in that history is not relevant to the point that criminal law changes to include new categories in unexpected ways.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#244

Earlier quoted context omitted.

The people responsible for investigating and prosecuting such crimes have some not so great incentives to avoid doing so and keep the whole thing secret though, don't they? And then when they get caught, they do this: https://cdt.org/insights/the-truth-about-telecom-immunity/

Sounds like an easy way to have your case tossed out in court. It's funny how much this differs from my own personal experience with law enforcement. The friends I know are timid as hell and don't do anything without a warrant just to stay on the safe side- even if they probably don't need one.

"Sounds like an easy way to have your case tossed out in court."

This is terribly naive in my experience.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#245

Earlier quoted context omitted.

The Stored Communications Act makes disclosing the contents of messages without a search warrant unlawful

EO12333 makes it lawful without a warrant.

> EO12333

An EO making it lawful for a federal agency to collect doesn't mean it is lawful for a private company to disclose, it doesn't change when a company is permitted to disclose the content of messages under the SCA

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#246
post #201

Earlier quoted context omitted.

"are the fact that current privacy movements like Tor, Signal, OTF, BBG are fundamentally military funded and survive on government contracts." Are those "facts" avaiable for investigating, without having to buy the book? (that Tor is partly US administration funded is known, but Signal? And what is OTF and BGG?)

https://www.opentech.fund/results/supported-projects/open-wh... Funded by Open Technology Fund (OTF) https://en.wikipedia.org/wiki/Open_Technology_Fund Which is funded by Radio Free Asia (RFA) https://en.wikipedia.org/wiki/Radio_Free_Asia . It had a few reboots but was created as a CIA program in 1951 ( https://en.wikipedia.org/wiki/Radio_Free_Asia_(Committee_for... ) to blast shortwaves into China from Manilla to tr…

Wow, that is so thin it is transparent. If this is the sort of 'proof' that we are going to find then I am glad you posted the ref here so that I could add yet another kook to the list of those whose privacy/security rantings and books I can ignore. The biggest danger to long-term privacy projects is not the risk of taking advantage of an opportune partnership with a government agency when incentives align, it is conspiracy nutjobs poisoning the well with their paranoia and delusions.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#247
post #162

This seems like a good place to say that I strongly recommend Yasha Levine's Surveillance Valley book ( https://www.goodreads.com/book/show/34220713-surveillance-va... ) where he suggests that all of this is working as intended, going all the way back to the military counter-insurgency roots of the arpanet first in places like Vietnam, and then back home in anti-war and leftist movements. The contemporary themes that…

Yasha Levine is a conspiracy theorist hack. There’s really no other way to say it. His narrative is attractive to a left leaning audience with shallow knowledge in this area, but the reality is that without publicly funded software like Tor, Signal, OTF, and my own Lantern, our world would be more fully saturated with corporate control of the internet. We need more public funding for open source software (with public…

This comment is an incredibly naive attempt at a smear.

> Without them, we’d basically be left with Wikipedia as the only popular entity on the internet outside of corporate control.

Wikipedia is absolutely not "outside of corporate control". It is trivially astroturfed to advance special interests.

> All of these projects are more properly grouped with government funding in other spheres, such as the BBC or PBS in media

Both BBC and PBS routinely publish outright disinformation to advance the special interests of their corporate/government clients, including the intelligence community. For example, look at PBS Frontline's ridiculous puff piece for the violent extremist group HTS last year.

> Levine overlooks basic details, such as reproducible builds

Reproducible builds are also easily circumvented by selectively deploying backdoors and other malware, based on IP or other fingerprints.

If there are good reasons to dispute Levine's investigative journalism, they're not here.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#248
post #162

This seems like a good place to say that I strongly recommend Yasha Levine's Surveillance Valley book ( https://www.goodreads.com/book/show/34220713-surveillance-va... ) where he suggests that all of this is working as intended, going all the way back to the military counter-insurgency roots of the arpanet first in places like Vietnam, and then back home in anti-war and leftist movements. The contemporary themes that…

Where is any evidence of Tor being a military surveillance project? I find it hard to believe an open source project like this has been infiltrated. Yes, there is suspicion some ECC curves are compromised, but only the ones provided by NIST. I'd really like to see evidence of Tor.

The seed for that line of thinking is the fact that a US Navy lab built it.[0] Having said that, I believe that's the only basis and is a far cry from making the theory convincing or even probable.

[0] https://en.m.wikipedia.org/wiki/Tor_(network)

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#249

Earlier quoted context omitted.

Sounds like an easy way to have your case tossed out in court. It's funny how much this differs from my own personal experience with law enforcement. The friends I know are timid as hell and don't do anything without a warrant just to stay on the safe side- even if they probably don't need one.

Good luck with that. In my case there was a ton of violations of the SCA. Violations of the SCA are only actionable if they are "constitutional" in nature. (That essentially means that if the government indict you based on information they illegally gathered through violating the SCA but the information did not belong to you - say it belonged your wife or business partner - then you can't get the information suppress…

Yep, the courts side with law enforcement. The whole 'truth comes out in a fair fight' is completely undermined by this. The system protects itself above all else.

I was involved with a case that sounds similar - the judges don't care about your rights and blatantly missapply the law. Also, magistrates are also complete BS, and don't even know basic legal stuff. I had one think I called him prejudice when requesting a case be dismissed with prejudice... Complaints do nothing. There's no real oversight, leading to a completely incompetent system.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#250

Earlier quoted context omitted.

EO12333 makes it lawful without a warrant.

> EO12333 An EO making it lawful for a federal agency to collect doesn't mean it is lawful for a private company to disclose, it doesn't change when a company is permitted to disclose the content of messages under the SCA

I mean, this whole discussion is moot since nobody will enforce things like this, especially against themselves.
Post reply on HN