Live data from Hacker News

FBI's ability to legally access secure messaging app content and metadata [pdf]

propertyofthepeople.org

461–470 of 474 posts

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#461

Some FBI agents came to my house once and told me that my home Internet had been used to visit Islamic Extremist websites. They brought a local police office with them and a 'threat assessment' coordinator from my workplace. They asked me if my family was Muslim and wanted to know if we had been radicalized. We are not religious (at all). We do not attend church, synagogue or mosque. We are lower middle class white A…

I never use a VPN. That changes today.

Or worse yet, the VPN provider can sell your data.

Build your own VPN https://github.com/hwdsl2/setup-ipsec-vpn

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#462

Earlier quoted context omitted.

> nobody except the sender, the receiver and the service provider can read the messages E2EE means the service provider cannot read the messages. Only the sender and receiver can.

Thanks! I edited a whole lot and that came out ridiculously wrong! :-)

Haha, no problem. I do that a lot too :)

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#463
post #82
post #6

It says Telegram has no message content. Isn't telegram not E2EE by default, instead required explicit steps to make a conversation encrypted? Either way looks like Signal wins by a lot. The size of it spot is so small, it seems almost squeezed in. But only because they have nothing to share.

Telegram is encrypted OVER THE WIRE and AT REST by default with strong encryption no matter what you do. It's E2EE if you select private chat with someone. Lots of FUD out there there about Telegram not being encrypted that's just not true. There's nothing either side can to do send a message in clear text / unencrypted.

are you trolling? telegram (are therefore the fbi) has full access to all content of every message. unless you use private chat, which nobody does, and isn't even available on desktop. i use it. but it's about as private as discord. which is to say not at all

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#464

Earlier quoted context omitted.

How about a State felony case that has taken nearly two years?

How about it? Without specifics, or some indication of who is triggering the delay (e.g., defendants may request delays), I couldn't possibly comment. Given law and legal processes are not my baliwick, I'd probably not be able to comment intelligently regardless. But you've posed a null-content question.

The State Attorney General dragging the case out because they refuse to look at it. They also filed it under the wrong statue so their arguments are incorrect.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#465

Earlier quoted context omitted.

How about it? Without specifics, or some indication of who is triggering the delay (e.g., defendants may request delays), I couldn't possibly comment. Given law and legal processes are not my baliwick, I'd probably not be able to comment intelligently regardless. But you've posed a null-content question.

The State Attorney General dragging the case out because they refuse to look at it. They also filed it under the wrong statue so their arguments are incorrect.

Seems possible grounds for a challenge. The entire case can be dismissed if the right is denied.

https://www.justia.com/criminal/procedure/right-to-a-speedy-...

https://www.nolo.com/legal-encyclopedia/the-right-speedy-tri...

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#466

Earlier quoted context omitted.

The State Attorney General dragging the case out because they refuse to look at it. They also filed it under the wrong statue so their arguments are incorrect.

Seems possible grounds for a challenge. The entire case can be dismissed if the right is denied. https://www.justia.com/criminal/procedure/right-to-a-speedy-... https://www.nolo.com/legal-encyclopedia/the-right-speedy-tri...

Not during COVID times...

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#467
post #243

Earlier quoted context omitted.

Did you even read the snopes article you referenced before making what seems like a definitive claim about how Trump was suggesting muslims carry special IDs? Because Snope's own rating is "Mixture" of truth and false and if you read the assessment, it is grasping at straws to even make that conclusion.

Yes, "mixed" means you have to read the nuance. I think I accurately captured the reality. If you have a correction to offer, please do. EDIT: Ultimately, the nuance in that history is not relevant to the point that criminal law changes to include new categories in unexpected ways.

Sure, I can accept there is some nuance but the phrasing and definitive manner of your original statement is very misleading. I'm not the biggest fan of the guy but casually mentioning that he suggested the idea when in actuality it was an idea posed by a reporter is bad faith in my opinion.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#468
post #402

Earlier quoted context omitted.

The only words you should ever say to the FBI "on advice of counsel I am taking the fifth".

This is awful advice for this specific situation. OP apparently managed to clear up the mistake without much bother by speaking to them (although they were understandably shaken up by the experience). This presumably wouldn't have happened if they'd done what you suggest.

Not speaking to law enforcement outside the presence of your attorney is excellent advice. There's no downside to having the attorney there, and potentially life shattering downsides to attempt otherwise.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#469

Earlier quoted context omitted.

The emoji comparison thing is mathematically solid. Assuming the clients aren't backdoored (and the Telegram client is open source, so that's not that easy), there is no way for an attacker to make both sides show the same emoji. If they want to convince two users that they have en E2EE connection while performing a man in the middle attack, they'd have to fake their voices to each other to change what emoji sequence…

Telegram can potentially perform mitm at any time and generate matching emoji images for both sides of conversation, since you can't really trust the app code to be the same they put on GitHub. If you've built it yourself, that'd reduce the risk, but nobody does that because blind trust is much more easy.

This is true, and IMHO somewhere that App-Stores could potentially assist in building trust for OSS Apps being distributed.

What I'm envisioning is a 'build hash' that is reproducible based on the public source code with a given set of compiler settings (i.e. same used for publish.) The systems app-management widget could then display this build hash in the app-check menu.

This would likely require more care in packaging, as well as some form of secure config API that allows companies to provide certain bits of configuration (i.e. remote servers to contact) without impacting the build output. This would mean that yes, people would still need to audit the code, but at least it's easy for anyone to canary out to the internet that the hashes are mismatching, same for when someone does find something on an audit.

OTOH, I'm sure Telegram's competitors in the chat space would love a reason to de-legitimize them, so it wouldn't surprise me if -someone- out there was already doing some sort of compare on published builds.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#470

Earlier quoted context omitted.

Imagine being a muslim and e.g. having a kid visiting those sites. Or just going there out of intellectual curiosity, like how a leftie might read Main Kampf to check what that shit is. You can end up in a very bad position...

A couple years after 9/11, my father and I had donated to the Holy Land foundation. The IRS proceeded to audit me (16 years old) and my $8k a year woodselling business I had with my dad. You tell me.

That's absolutely fucked. The whole story of the Holy Land Foundation being railroaded and labeled as terrorists when all they did was advocate for human rights of Palestinians...it's an incredibly chilling story. To hear that those who merely donated to a worthy cause were also then audited...the outrageous injustice makes my blood boil.
Post reply on HN