Code from the FBI’s Anom encrypted messaging app
21–30 of 107 posts
Re: Code from the FBI’s Anom encrypted messaging app
#22Earlier quoted context omitted.
I don't follow your logic here. Why can't a company legitimately focus on a niche sub set of users who value privacy in their products? I'm thinking of products like protonmail, standard notes, and signal.
Yeah ... i mean ... everyone who uses protonmail non-ironically is a dupe. It is virtually certain that it is a front for state intelligence agencies.
The government doesn’t have the resources to compromise every online service. There’s money on the line for entities like proton.
Re: Code from the FBI’s Anom encrypted messaging app
#23> The code shows that the messages were secretly duplicated and sent to a “ghost” contact that was hidden from the users’ contact lists. Lots of "secure" messaging apps do this for intel and surveillance and not just the white hats. Other areas that "secure" messaging apps have holes in is the anti-spam/moderation systems that need to view messages and in the clients themselves who have access to the unencrypted cont…
It's how Apple would do iMessage intercepts for the FBI.
Re: Code from the FBI’s Anom encrypted messaging app
#24I wish somebody would create some scheme to like self host the backend of an app.. like you launch Signal and it has a button to type in the name of your own server, where that server runs a VM that you configure and setup on your own PC locally then upload to AWS or something and has some facility to constantly report to you the hash of the memory and disk contents, along with some contract from AWS that states that…
https://github.com/ricochet-im/ricochet
Every user is their own Tor onion service, so you get E2E encryption and no centralized servers. The whole thing hinges on the security of Tor itself which is probably a safe enough bet.
Re: Code from the FBI’s Anom encrypted messaging app
#25> The code shows that the messages were secretly duplicated and sent to a “ghost” contact that was hidden from the users’ contact lists. Lots of "secure" messaging apps do this for intel and surveillance and not just the white hats. Other areas that "secure" messaging apps have holes in is the anti-spam/moderation systems that need to view messages and in the clients themselves who have access to the unencrypted cont…
Lots of VPNs, too!
"We don't keep any logs! We just pipe a direct feed to the government so they can keep logs!"
Re: Code from the FBI’s Anom encrypted messaging app
#26I wish somebody would create some scheme to like self host the backend of an app.. like you launch Signal and it has a button to type in the name of your own server, where that server runs a VM that you configure and setup on your own PC locally then upload to AWS or something and has some facility to constantly report to you the hash of the memory and disk contents, along with some contract from AWS that states that…
Re: Code from the FBI’s Anom encrypted messaging app
#27So what's the strategy moving forward? The operation clearly hasn't permanently solved crime, the next generation of organized crime bosses won't trust any apps to handle their secrets, so I guess their communication just moves offline again? Or maybe each develops their own methods in house that they know they can trust (such as shooting holes in a wall on call of duty)?
Re: Code from the FBI’s Anom encrypted messaging app
#28> The code shows that the messages were secretly duplicated and sent to a “ghost” contact that was hidden from the users’ contact lists. Lots of "secure" messaging apps do this for intel and surveillance and not just the white hats. Other areas that "secure" messaging apps have holes in is the anti-spam/moderation systems that need to view messages and in the clients themselves who have access to the unencrypted cont…
> Lots of "secure" messaging apps do this for intel and surveillance and not just the white hats. It's how Apple would do iMessage intercepts for the FBI.
Re: Code from the FBI’s Anom encrypted messaging app
#29Earlier quoted context omitted.
> What other services might be run, controlled, or surveilled by the US investigative authorities? Any service that is marketed to you as privacy- or security-as-a-service, or software sold as privacy- or security-enhancing, is virtually guaranteed to be secretly working against the interests of its users. You can't buy security or privacy in the form of software or services, because privacy and security are a set of…
I don't follow your logic here. Why can't a company legitimately focus on a niche sub set of users who value privacy in their products? I'm thinking of products like protonmail, standard notes, and signal.
If you are seeking out a way to hide information, you are part of a market that is signalling you have something worth hiding (to you, at minimum). As a bad analogy, it's a bit like putting up a sign in front of your house that says "We went on vacation, but the door is locked!"... basically, begging to be exploited.
Short of regular, independent audits, you are mostly reduced to guessing who to trust, and even then (as demonstrated by Lavabit) the trustworthiness of the actor isn't always the only relevant factor.
Re: Code from the FBI’s Anom encrypted messaging app
#30Earlier quoted context omitted.
> We already know Apple has preserved a backdoor in the end-to-end cryptography of iMessage at the FBI's behest, as reported by Reuters. WhatsApp has always had the same backdoor (unencrypted backups to cloud services). The largest services are all unsafe for privacy. I don't agree with your characterization of that as a "backdoor" and I think that dilutes the term dangerously. There is no need to use Apple's backup…
As long as iCloud backup is a) on by default, and b) isn’t clearly marked as being readable to Apple, it is a back door in practice, especially since the FBI is the reason that they did this. Let’s not even talk about Chinese users, as apparently Apple bending over to store all their data in CCP data centers doesn’t count.
Tough to disagree.