Live data from Hacker News

FBI's ability to legally access secure messaging app content and metadata [pdf]

propertyofthepeople.org

331–340 of 474 posts

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#331

They left off one very popular messenger, SMS: * Message content: All * Subpoena: can render all message content for the last 1-7 years * 18 U.S.C 2703(d): can render all message content for the last 1-7 years * Search warrant: can render all message content for the last 1-7 years * Vague suspicion plus a small fee to the carrier: can render all message content for the last 1-7 years

Major service providers do not maintain SMS history beyond 24 hours, let alone 1-7 years (last time I worked a case that is). They’re transparent about it as well. Look up the LE liaison contacts on their sites and they’ll clearly list what is available or not available. That’s why it’s crucial to get the actual devices themselves. Reason: the infrastructure to manage SMS content for every customer for 7 years with zero business justification/use case is phenomenal. They’d spend most of their time responding to civil and criminal subpoenas/warrants. That would be a feat the NSA would be proud of. Been there and done that a 100 times. (This also aligns with certain VPN providers refusing to keep logs. It’s a cost that provides zero returns, so they cut it as a business decision, not because they’re trying to stick it to the man.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#332

Earlier quoted context omitted.

There's also: * Law enforcement simply asks nicely: can render all message content for the last 1-7 years

The Stored Communications Act makes disclosing the contents of messages without a search warrant unlawful

You are correct. There’s also varying 2-party/1-party consent required depending on the state in the absence of a warrant. But unless you’re targeting the devices, you will not get much at all from service providers. They simply don’t keep it contrary to what I read here.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#333

They left off one very popular messenger, SMS: * Message content: All * Subpoena: can render all message content for the last 1-7 years * 18 U.S.C 2703(d): can render all message content for the last 1-7 years * Search warrant: can render all message content for the last 1-7 years * Vague suspicion plus a small fee to the carrier: can render all message content for the last 1-7 years

Major service providers do not maintain SMS history beyond 24 hours, let alone 1-7 years (last time I worked a case that is). They’re transparent about it as well. Look up the LE liaison contacts on their sites and they’ll clearly list what is available or not available. That’s why it’s crucial to get the actual devices themselves. Reason: the infrastructure to manage SMS content for every customer for 7 years with z…

There's no reason for them to keep those records, other than for law enforcement's sake. No use case for calling up your operator to ask about that text message you got "from Fred at 4am one day a couple years ago."

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#334

They left off one very popular messenger, SMS: * Message content: All * Subpoena: can render all message content for the last 1-7 years * 18 U.S.C 2703(d): can render all message content for the last 1-7 years * Search warrant: can render all message content for the last 1-7 years * Vague suspicion plus a small fee to the carrier: can render all message content for the last 1-7 years

Source is a few years old, but I suppose we can make another FOIA request to find out how long carriers store text messages these days - it was basically 0-5 days a decade ago: https://www.nbcnews.com/technolog/how-long-do-wireless-carri...

You’ll be lucky if it’s any longer than 24-hours now. There’s no business use case for building and maintaining the technological infrastructure to manage it for years. It’s private info and they can’t sell it to anyone without legal liability. If LE gave them the funds to build this infrastructure and use it for retention then the service provider is essentially an agent of the state at that point.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#335
post #87

Earlier quoted context omitted.

How? They can physically overpower you and place the sensor against your finger, or in front of your eye and pry it open without your consent and gain access with 0 input from you. How do they similarly force you to type something that requires deliberate, repeated concrete actions on your part?

In my case they threatened to harm my wife if I didn't stop refusing. After my case is over I'll happily release the video tapes so you can see how this shit works.

Please do. Very few people realize just how bad things can get with law enforcement.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#336

They left off one very popular messenger, SMS: * Message content: All * Subpoena: can render all message content for the last 1-7 years * 18 U.S.C 2703(d): can render all message content for the last 1-7 years * Search warrant: can render all message content for the last 1-7 years * Vague suspicion plus a small fee to the carrier: can render all message content for the last 1-7 years

Major service providers do not maintain SMS history beyond 24 hours, let alone 1-7 years (last time I worked a case that is). They’re transparent about it as well. Look up the LE liaison contacts on their sites and they’ll clearly list what is available or not available. That’s why it’s crucial to get the actual devices themselves. Reason: the infrastructure to manage SMS content for every customer for 7 years with z…

I'm surprised to hear this has changed so significantly since the snowden leaks. Especially after the blatant attack on Qwest CEO Joseph Nacchio for refusing to spy. It was established then that the major mobile telcos in the USA were keeping and providing sms full data for 2-5 years (t-mobile, at&t, verizon, etc).

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#337

Some FBI agents came to my house once and told me that my home Internet had been used to visit Islamic Extremist websites. They brought a local police office with them and a 'threat assessment' coordinator from my workplace. They asked me if my family was Muslim and wanted to know if we had been radicalized. We are not religious (at all). We do not attend church, synagogue or mosque. We are lower middle class white A…

Is it prohibited to visit those websites? I once was interested to understand the way radicals think, to read about their arguments, so I spent some time hanging around some radical websites.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#338

Some FBI agents came to my house once and told me that my home Internet had been used to visit Islamic Extremist websites. They brought a local police office with them and a 'threat assessment' coordinator from my workplace. They asked me if my family was Muslim and wanted to know if we had been radicalized. We are not religious (at all). We do not attend church, synagogue or mosque. We are lower middle class white A…

"threat assessment' coordinator from my workplace" "I feared that I may lose my job." I understand that police/FBI have to conduct investigation. What dont understand is involvement of the employer , it's extremely disturbing - you have not been convincted, you have not been charged, you are not even a suspect or accused of anything at this point - how is your private life the business of your employer? Why is your p…

Employer might have been defense contractor. Most jobs without clearance don't even have "threat assessment coordinaror".

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#339

Some FBI agents came to my house once and told me that my home Internet had been used to visit Islamic Extremist websites. They brought a local police office with them and a 'threat assessment' coordinator from my workplace. They asked me if my family was Muslim and wanted to know if we had been radicalized. We are not religious (at all). We do not attend church, synagogue or mosque. We are lower middle class white A…

I’ll be the dissenting voice and say this reads like a “sow discord in the US 101”. Why on earth would the FBI bring both the police and a “threat assessment” coordinator from your work to interview you? Why would your workplace ever agree to it? That screams lawsuit waiting to happen.

And on that note, why didn’t you sue your workplace for harassment? Whether you’re religious or not isn’t any of their business and is a protected class.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#340

Earlier quoted context omitted.

In most cases you are going to want to separately passphrase your messaging stuff so it is locked up when you are not using it. That makes every thing else a lot easier. For example, there is a Signal fork that supports such operation: * https://github.com/mollyim/mollyim-android

So you're saying I should have to type a secure passcode every single time I want to read or send a message on my phone? No thanks.

I think that it would stay unlocked for a time, possibly till you locked it. Possibly such an arraignment would be more practical for something offline like encrypted email.

A compromise would be to just save the messages to a passphrase. You could use a public key so that you would only need the passphrase to read the old messages. I haven't heard about anything that actually does this.

Post reply on HN