Live data from Hacker News

FBI's ability to legally access secure messaging app content and metadata [pdf]

propertyofthepeople.org

341–350 of 474 posts

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#341
post #339

Some FBI agents came to my house once and told me that my home Internet had been used to visit Islamic Extremist websites. They brought a local police office with them and a 'threat assessment' coordinator from my workplace. They asked me if my family was Muslim and wanted to know if we had been radicalized. We are not religious (at all). We do not attend church, synagogue or mosque. We are lower middle class white A…

I’ll be the dissenting voice and say this reads like a “sow discord in the US 101”. Why on earth would the FBI bring both the police and a “threat assessment” coordinator from your work to interview you? Why would your workplace ever agree to it? That screams lawsuit waiting to happen. And on that note, why didn’t you sue your workplace for harassment? Whether you’re religious or not isn’t any of their business and i…

A decade ago the FBI harassed me at my home waking me up from sleeping twice and at a past employer before on entirely unfounded claims.

They didn't care what the consequences were for targeting someone innocent.

They also made nasty threats like "Someone has to go down for this, and if you help us collect intel on your industry peers we suspect then someone else can be that person"

I told them politely to go die in a fire because I was not about to help them harass other innocent people but it was terrifying none the less that they seemingly had the power to end my whole universe.

I became convinced through that ordeal that the FBI is a deeply corrupt organization that creates pressure to close cases by any means needed.

The OPs post seems totally believable and consistent with stories I have heard from others, particularly if they work for an organization that has the US government as a customer like a defense contractor.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#342
post #338

Earlier quoted context omitted.

"threat assessment' coordinator from my workplace" "I feared that I may lose my job." I understand that police/FBI have to conduct investigation. What dont understand is involvement of the employer , it's extremely disturbing - you have not been convincted, you have not been charged, you are not even a suspect or accused of anything at this point - how is your private life the business of your employer? Why is your p…

Employer might have been defense contractor. Most jobs without clearance don't even have "threat assessment coordinaror".

> Most jobs without clearance don't even have "threat assessment coordinaror"

The title may vary from place to place but all companies have people filling this role, even if you've never met them.

Normally falls somewhere under a team like Global Intelligence, Workplace Security, Business Continuity, etc.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#343

Some FBI agents came to my house once and told me that my home Internet had been used to visit Islamic Extremist websites. They brought a local police office with them and a 'threat assessment' coordinator from my workplace. They asked me if my family was Muslim and wanted to know if we had been radicalized. We are not religious (at all). We do not attend church, synagogue or mosque. We are lower middle class white A…

Is it prohibited to visit those websites? I once was interested to understand the way radicals think, to read about their arguments, so I spent some time hanging around some radical websites.

I was visited by the FBI for doing security research that made them at least pretend to assume I was a blackhat they wanted to take down.

Use Tor browser if you are going to research anything a criminal might regardless of pure motives.

If you so much as want to research lock picking, use Tor.

ISP traffic logs can and will be twisted against you in a court of law.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#344

They left off one very popular messenger, SMS: * Message content: All * Subpoena: can render all message content for the last 1-7 years * 18 U.S.C 2703(d): can render all message content for the last 1-7 years * Search warrant: can render all message content for the last 1-7 years * Vague suspicion plus a small fee to the carrier: can render all message content for the last 1-7 years

Major service providers do not maintain SMS history beyond 24 hours, let alone 1-7 years (last time I worked a case that is). They’re transparent about it as well. Look up the LE liaison contacts on their sites and they’ll clearly list what is available or not available. That’s why it’s crucial to get the actual devices themselves. Reason: the infrastructure to manage SMS content for every customer for 7 years with z…

I went to a major cell provider and asked them nicely for access to SMS for all their customers and they happily took money and gave me an API.

This was for a startup.

I have no doubt they do the same for governments.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#345
Do you want this to stop? Raise awareness, add this to your mail sig:

  > This electronic communication has been processed by the United
  > States National Security Agency.
If it makes people uncomfortable, GOOD. Pretending that your mail - and their mail - is not being accessed is not the way to resolve this uncomfortable situation. Ending it is the way. And that demands awareness.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#346

Check the difference between Telegram and WhatsApp. Add to this the fact that WhatsApp - uploads messages unencrypted to Google if you or someone you chat with enable backups - and send all your metadata to Facebook. Then remember how many people here have tried to tell us that Telegram is unusable abd WhatsApp is the bees knees. Then think twice before taking security advice from such people again. PS: as usual, if…

Telegram defaults to no encryption, does not do encrypted group chats, has a home-rolled encryption protocol which almost guarantees it's weak as nearly every home-rolled encryption system always is (if not also backdoored). Coupled with it being headquartered in Russia means it is completely untrustable. The only reason Telegram comes out on top of Whatsapp in the document in question is because Telegram is a foreig…

> Telegram defaults to no encryption,

This is plain false as can be verified by anyone who can check Telegram GitHub repos or run the app in a debugging environment.

Telegram defaults to point-to-point encryption. Same as banks and gmail.

Fun fact: back in the days WhatsApp sent messages unencrypted (i.e. as plain text) over port 443(!).

> does not do encrypted group chats,

again, point-to-point encryption

> has a home-rolled encryption protocol which almost guarantees it's weak as nearly every home-rolled encryption system always is (if not also backdoored).

Earlier versions had serious problems. Newer versions are supposedly better.

Also there is a lot of difference between home-grown cryptography by a math wizard, made open source for everyone to inspect and various secret sauce variants.

HN has a long history of claiming it can be trivially broken, yet despite source code being available no one has done it? Lazyness or incompetence? Or maybe it isn't so simple?

I don't know but if you want to shut me up and make your claim to fame: do break Telegram cryptography. You'll do the world a service both by exposing it and by shutting up people like me.

Meanwhile, stop spreading lies. Telegram is not unencrypted. It is point-to-point encrypted by default.

If the encryption is weak, prove it or shut up.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#347

Earlier quoted context omitted.

> For somebody who isn’t super cyprtography-savvy, what’s the difference between over the wire and e2ee? E2EE: As long as it is correctly set up and no significant breakthroughs happens in math, nobody except the sender, the receiver can read the messages. > Does the former mean that telegram itself can read non-private-chat messages if it so chooses? Correct. They say they store messages encrypted and store keys and…

> nobody except the sender, the receiver and the service provider can read the messages E2EE means the service provider cannot read the messages. Only the sender and receiver can.

Forgot to upvote you yesterday, done now ;-)

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#348

Earlier quoted context omitted.

My advice if you’re not on the level where three letter agencies are actively interested in your comings and goings: - Use a strong pass phrase - Enable biometrics so you don’t need to type that pass phrase 100 times per day - Learn the shortcut to have your phone disable biometrics and require the pass phrase so you can use it when police is coming for you, you’re entering the immigration line in the airport etc. -…

On recent iPhones, the way to disable biometrics is to hold the side button and either volume button until a prompt appears, then tap cancel. Mashing the side button 5 times does not work.

I’m on an iPhone 13 and the latest iOS and it does work here. But so does your method…

But I guess yours is the “official” way to do it indeed:

https://www.imore.com/how-quickly-disable-face-id

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#349
I use LINE a fairbit, have a number of Japanese friends as well as friends that have traveled to Japan. I had no idea they had implemented much better encryption [1]. I'm convincing all my contacts to turn on the option now.

[1]https://engineering.linecorp.com/en/blog/new-generation-of-s...

Post reply on HN