Earlier quoted context omitted.
You and the person you are communicating with must both not use iCloud backup. And since apple pushes the backup features pretty heavily, you can be reasonable sure that the person you are communicating is using backups. IE, you cannot use iMessage.
I got off all Apple products when they showed me their privacy stance is little more than marketing during the CSAM fiasco, but IIRC the trouble with iCloud backup is it stores the private key used to encrypt your iMessages backup. Not ideal to be sure, but wouldn't iMessage users be well protected against dragnet surveillance, or do we know that they're decrypting these messages en masse and sharing them with state…
FBI's ability to legally access secure messaging app content and metadata [pdf]
381–390 of 474 posts
Re: FBI's ability to legally access secure messaging app content and metadata [pdf]
#382It says Telegram has no message content. Isn't telegram not E2EE by default, instead required explicit steps to make a conversation encrypted? Either way looks like Signal wins by a lot. The size of it spot is so small, it seems almost squeezed in. But only because they have nothing to share.
This chart is showing what messaging providers are willing to give to law enforcement, not a reflection of the technical capabilities of the messaging provider. I assume what they're showing for Telegram (basically no data except IP/phone data if Telegram decides it's for a legit counter-terrorism activity) is a matter of Telegram business policy. Signal gives the limited information they do because I assume they are…
This is what puzzles me about Apple, they absolutely have the capability to mitm iMessage pretty discreetly. Because Apple just completely hand waves away key distribution and they can silently add and remove keys at their leisure it's largely only policy that underpins their security. They're not Telegram, they aren't structured to be in a position to be able to ignore demands from the justice system to assist with some agent's latest fishing expidition. How are they getting away with not providing stuff that they obviously have access to? The PDF lists "Pen Register: no capability"
Re: FBI's ability to legally access secure messaging app content and metadata [pdf]
#383Some FBI agents came to my house once and told me that my home Internet had been used to visit Islamic Extremist websites. They brought a local police office with them and a 'threat assessment' coordinator from my workplace. They asked me if my family was Muslim and wanted to know if we had been radicalized. We are not religious (at all). We do not attend church, synagogue or mosque. We are lower middle class white A…
I never use a VPN. That changes today.
Re: FBI's ability to legally access secure messaging app content and metadata [pdf]
#384Earlier quoted context omitted.
> Surely the FBI is not allowed to publicise random dirt they find on innocent people? If they're doing an investigation, they very likely got the employer involved in order to get more information on the person they're investigating, and companies have liaisons for law enforcement, as well. If the FBI comes knocking and says, "we think you've hired a terrorist," it's going to ruffle some feathers at the company no m…
"If they're doing an investigation, they very likely got the employer involved in order to get more information on the person they're investigating" What is an employer going to contibute, realistically. "Oh yeah, he always carries potassium nitrate and makes explosions during lunch breaks!"
Re: FBI's ability to legally access secure messaging app content and metadata [pdf]
#385Earlier quoted context omitted.
But they have to fake the voice, if I call the other person and say "my emoji sequence is this, this and that" for the other person to verify and vice-versa.
Person A calls you. I intercept the call, so person A is calling me , and then I call you (spoofing so I look like Person A). When you pick up, I pick up, then I transmit what you're saying to Person A (and vice versa). How do you know I'm intercepting the transmission? Does the emoji sequence verify the call , perhaps?
Re: FBI's ability to legally access secure messaging app content and metadata [pdf]
#386Earlier quoted context omitted.
Yasha Levine is a conspiracy theorist hack. There’s really no other way to say it. His narrative is attractive to a left leaning audience with shallow knowledge in this area, but the reality is that without publicly funded software like Tor, Signal, OTF, and my own Lantern, our world would be more fully saturated with corporate control of the internet. We need more public funding for open source software (with public…
>my own Lantern Brilliant reposte, but I am curious what software are you referring to here?
https://news.ycombinator.com/item?id=20824759#20826587Re: FBI's ability to legally access secure messaging app content and metadata [pdf]
#387Some FBI agents came to my house once and told me that my home Internet had been used to visit Islamic Extremist websites. They brought a local police office with them and a 'threat assessment' coordinator from my workplace. They asked me if my family was Muslim and wanted to know if we had been radicalized. We are not religious (at all). We do not attend church, synagogue or mosque. We are lower middle class white A…
Next day they might visit you to ask you why you are visiting an opposition party web site.
Re: FBI's ability to legally access secure messaging app content and metadata [pdf]
#388Earlier quoted context omitted.
I was visited by the FBI for doing security research that made them at least pretend to assume I was a blackhat they wanted to take down. Use Tor browser if you are going to research anything a criminal might regardless of pure motives. If you so much as want to research lock picking, use Tor. ISP traffic logs can and will be twisted against you in a court of law.
I openly participate in locksport communities and I haven't had any visits from the FBI.
So "keyword" (could be a word, domain or some other pattern) X may trigger only if Y and Z was already triggered. And some keyword A may only trigger if B was NOT present.
This way you can distinguish doctors, reporters or people studying history or chemistry from those who plan something.
Or e.g. ML applied to patterns over time. Globally.
And yes I do not like it at all, HN is full of people that may likely research some kind of bomb, religion or whatever else out of pure curiosity, but since there are not many such people it can be problem in court one day.
Mix in some Snowden, your hardware stack, gag orders and the fact that we have more laws that anybody can read and you may feel like watching some stupid memes.
Re: FBI's ability to legally access secure messaging app content and metadata [pdf]
#389Earlier quoted context omitted.
> The trick is to untangle it. USAID is specifically designed and called that so as to tangle it , tell me, how would your average joe understand that USAID is a intelligence agency spinoff designed to sound "good" while doing evil all over the world rather than what its name suggests? You know... Aid? The NSA, CIA, Extraordinary Rendition and so many other things dont exist there by accident, if said """government""…
It seems obvious that USAID is an intelligence front (I've encountered a few instances where it was mentioned that someone worked for USAID at the time, while it was simultaneously obvious that it would make way more sense if they were Intelligence), but is there any concrete evidence for that?
What do you mean by "concrete evidence"?
Nothing of this is disputed, they even have their own wikipedia pages for their different operations and branches within USAID
https://en.wikipedia.org/wiki/Office_of_Public_Safety
*Specially* that we are talking of USAID, on the case of NED for example, things get slightly murkier because then it is a matter of private rather than public record, but it still works as a tool for management of semi-clandestine operations and operations which need plausible deniability from CIA's end, or at least as much deniability as it can muster, tho these days they prefer to work with shell groups and other associated partners such as for example Atlas Network, Radio Free Asia also falls on that category, same with Voice Of America
If you are interested in books both, Killing Hope by William Blum and Legacy Of Ashes by Weiner are very, very, very good authoritative sources on the matter
If you prefer podcasts, Warnerd Radio has a couple very good episodes on the National Endowment For Democracy, tho they both quote excerpts of the books above
Radio War Nerd EP 274 — National Endowment for Democracy, Part 1 https://podcastaddict.com/episode/121232504
Radio War Nerd EP 275 — National Endowment for Democracy, Part 2 https://podcastaddict.com/episode/121522126
Re: FBI's ability to legally access secure messaging app content and metadata [pdf]
#390Earlier quoted context omitted.
> It's (scarily) interesting that they react with actual personal attendance based purely on a very limited set of electronic information. Either their intel is better than they let on and didnt think they would be walking into an ambush or they are more stupid than we think.
Actually, I think they had no intel. You NEED intel for a judge to order a subpoena—and if a subpoena was issued, the ISP would open their firehose, and overwhelm the FBI with evidence suggesting that there’s nothing to investigate. And having visited extremist sites a handful of times—even if advertantly—is probably not going to meet the threshold for a subpoena. If the FBI visited me and casually asked about my web…
Or - you know - “weeeelp, I’ve been sitting at this desk all morning, let’s go talk to someone”.