Live data from Hacker News

FBI's ability to legally access secure messaging app content and metadata [pdf]

propertyofthepeople.org

421–430 of 474 posts

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#421
post #42

Earlier quoted context omitted.

Not exactly. Non-secret chats are stored encrypted on Telegram's servers, and separately from keys. The goal seems to be to require multiple jurisdictions to issue a court order before data can be decrypted. https://telegram.org/privacy#3-3-1-cloud-chats https://telegram.org/faq#q-do-you-process-data-requests

"Not exactly" means "completely incorrect" now? Telegram doesn't store your messages forever and they are encrypted and seizing the servers won't allow you to decrypt them unless you also seize the correct servers from another country

Of course they store your messages forever... They've kept all of my messages for over 7 years now.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#422

Earlier quoted context omitted.

> Telegram defaults to no encryption, This is plain false as can be verified by anyone who can check Telegram GitHub repos or run the app in a debugging environment. Telegram defaults to point-to-point encryption. Same as banks and gmail. Fun fact: back in the days WhatsApp sent messages unencrypted (i.e. as plain text) over port 443(!). > does not do encrypted group chats, again, point-to-point encryption > has a ho…

I obviously was referring to e2ee; everything is point to point encrypted these days. e2ee is turned off by default and cannot be enabled for group chats. I stand by my assertion that Telegram's proprietary secret encryption is nearly guaranteed to be weaker than industry-standard encryption. "Home grown is always weaker" is a well known position of almost the entire crypto community. I further stand by my assertion…

> I obviously was referring to e2ee;

So you admit you weren't just spreading inaccuracies you heard from someone else but you knew you were posting disinformation.

> I further stand by my assertion that Telegram's encryption is nearly guaranteed to be backdoored, because there is literally zero reason for a startup to invest the massive engineering resources needed to successfully develop and maintain its own encryption algorithms, unless they were being paid to do so.

This is a good argument.

> Do you seriously think Putin would allow a domestic company to develop a communication tool that would allow Russians to communicate with each other in complete privacy?

Telegram is not a Russian company?

>> prove it or shut up.

> Go read the HN commenting policy (specifically around civility) or shut up.

Sorry. I was too harsh. I actually regret.

Compared to willfully spreading disinformation however it seems pretty minor though?

-----

A bit more: I know local police used to use Telegram. That worries me.

It is actually even more complicated:

If Putin reads my most personal messages I don't care.

If NSA or even worse, local police actually took their time to read my messages I'd be mad or worried.

However if FSB asked for help they would need a very good reason and I'd try to consult with local law enforcement first.

If local police however asked for help I'd go out of my way to help them.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#423

Earlier quoted context omitted.

> if you did not write (or at least read) the code that you’re using to do all of the above, then you’re at the mercy of whoever wrote it. It's worse than that. Even if you read the code, you have to trust that the code you read is the code a service is actually using. Even if you deploy the code yourself, you have to trust that the infrastructure you're running on does not have some type of backdoor. Even if you run…

> the likelihood of any of these things actually becoming a problem decreases significantly as you read through the paragraph. And yet, "likelihood" doesn't necessarily mean "hasn't been done". Just look at: * [0]: Intel ME * [1]: Solarwinds attack and CI systems * [2]: Ubiquiti attack and complete infrastructure compromise * [3]: And the famous Ken Thompson statement [0a]: https://news.ycombinator.com/item?id=152988…

Indeed. I mentioned those specific things because it has been done. However, I think the likelihood of the average user being affected by things near the end of the list is generally quite small. If we aren't willing to accept this, at some point, we can't use technology for anything important.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#424

Earlier quoted context omitted.

> If such background checks were performed, then they either don't have much data or their threat weightings are set to red-scare levels of paranoia. Either way, it's scary. They're not gonna have anything happen to them if they go tough on (and fuck over an) innocent guy. They're gonna look bad if they miss a terrorist. So they have no incentive to not have "red-scare levels of paranoia".

That's true, I still remember the fact that the Boston Bomber(s) were on international watch lists and their home countries warned the US (whichever TLA, may have been an issue of crossed wires) that these guys were on the move, and it was all ignored. Now, visit a 'bad' website, or somehow be mistaken for someone that visited a 'bad' website, and you'll get some deep personal treatment. Feds can't win, but it seems…

Or maybe because it's motives, and what level of capture they have over their 'customers'? Seems pretty simple to me. They have a monopoly of service and the only retribution people can take is political which means everything is done on appearance.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#425
post #402

Earlier quoted context omitted.

The only words you should ever say to the FBI "on advice of counsel I am taking the fifth".

This is awful advice for this specific situation. OP apparently managed to clear up the mistake without much bother by speaking to them (although they were understandably shaken up by the experience). This presumably wouldn't have happened if they'd done what you suggest.

On the other hand, they could accuse OP of lying (something that's highly subjective), which is a serious federal crime.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#426

Some FBI agents came to my house once and told me that my home Internet had been used to visit Islamic Extremist websites. They brought a local police office with them and a 'threat assessment' coordinator from my workplace. They asked me if my family was Muslim and wanted to know if we had been radicalized. We are not religious (at all). We do not attend church, synagogue or mosque. We are lower middle class white A…

This is why you and everyone should use DNS over HTTPS (DoH). Next day they might visit you to ask you why you are visiting an opposition party web site.

How exactly is DoH a protection? Wouldn't they just see that as a red flag? Then, get the data from cloudflare or whomever.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#427
post #351

Earlier quoted context omitted.

Wtf, who doesn’t add extra y’s to hey sometimes? That wasn’t evidence.

I don't want to spoil the book; but, yes, that detail got him caught.

It’s not fiction you’re spoiling, but a factual conversation about events that you’re not going into due to spoilers. It is an odd defence that kills the conversation when other people bring up good points.

The parallel construction argument seems way more plausible if there’s nothing else besides “heyy”. If there is more, please say what it is instead of mentioning it exists but refusing to say it.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#428
post #136

Earlier quoted context omitted.

Apple should allow for 2 PWs, one the real PW, the other triggers a "self-destruct" mode. Knowing that is possible law enforcement would then hesitate to ask.

using such a self-destruct mode would be a certain way getting yourself charged with destroying evidence/contempt of court/... though.

No 5th Amendment protection? If you spoke the command / "password", would it matter?

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#429
post #338

Earlier quoted context omitted.

"threat assessment' coordinator from my workplace" "I feared that I may lose my job." I understand that police/FBI have to conduct investigation. What dont understand is involvement of the employer , it's extremely disturbing - you have not been convincted, you have not been charged, you are not even a suspect or accused of anything at this point - how is your private life the business of your employer? Why is your p…

Employer might have been defense contractor. Most jobs without clearance don't even have "threat assessment coordinaror".

Companies that employ software engineers likely are divided into those that have that role and those that don't have it yet.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#430

Earlier quoted context omitted.

This is why you and everyone should use DNS over HTTPS (DoH). Next day they might visit you to ask you why you are visiting an opposition party web site.

How exactly is DoH a protection? Wouldn't they just see that as a red flag? Then, get the data from cloudflare or whomever.

Most of the time they log your plain DNS queries. But DoH is encrypted, thus they won't be able to log your DNS queries. Cloudflare is not the only DoH provider. There are many. If you want you can grab a several lines of PHP code and create your own DoH link in another country. Becouse DoH is https they cannot distinguish it from normal https. Of course if the use deep packet analyses tool they will know what website you are visiting but they are not being used widely but are used to target specific people. To sum up; DoH is better than plain text DNS queris.
Post reply on HN