Live data from Hacker News

Code from the FBI’s Anom encrypted messaging app

vice.com

41–50 of 107 posts

Re: Code from the FBI’s Anom encrypted messaging app

#41
post #7
post #3

> Last year, the FBI and its international partners announced Operation Trojan Shield, in which the FBI secretly ran an encrypted phone company called Anom for years and used it to hoover up tens of millions of messages from Anom users. What other services might be run, controlled, or surveilled by the US investigative authorities? What other services might have operators that can be extorted or blackmailed by those…

> We already know Apple has preserved a backdoor in the end-to-end cryptography of iMessage at the FBI's behest, as reported by Reuters. WhatsApp has always had the same backdoor (unencrypted backups to cloud services). The largest services are all unsafe for privacy. I don't agree with your characterization of that as a "backdoor" and I think that dilutes the term dangerously. There is no need to use Apple's backup…

> There is no need to use Apple's backup at all, iDevices can still be backed up to your own computer same as always.

Even if you disable iCloud Backup, Apple can still read all of your iMessages.

They'll be in the (on by default) iCloud Backups of everyone you chat with.

It is absolutely a backdoor: https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...

You may not be aware that Signal endpoint keys are of a device-local storage class that are excluded from backups of any kind, and consequently they do not leave the device. iMessage endpoint keys are backed up to Apple, effectively without encryption.

There is no step you can take that will easily compromise your Signal endpoint keys to a second party. Simply logging in to an iPhone (required to install apps!) will configure your device to escrow your iMessage keys to Apple.

That's a backdoor any way you slice it.

Re: Code from the FBI’s Anom encrypted messaging app

#43
post #40
post #11

Earlier quoted context omitted.

As long as iCloud backup is a) on by default, and b) isn’t clearly marked as being readable to Apple, it is a back door in practice, especially since the FBI is the reason that they did this. Let’s not even talk about Chinese users, as apparently Apple bending over to store all their data in CCP data centers doesn’t count.

No, you're just wrong, even if your statements were right which they aren't either. Again, by your logic every single communication system on iOS is "backdoored" simply because iCloud Backup exists. Or for that matter any comms method on Linux or FreeBSD or macOS or Windows if someone makes unencrypted backups. That's horse shit, and it degrades the specificity and value of the term "backdoor" in the same way as "bri…

> Again, by your logic every single communication system on iOS is "backdoored" simply because iCloud Backup exists.

You seem to be unfamiliar with the concept of iOS storage classes. The iOS security overview pdf from Apple will explain better than I can.

> I've never seen it on by default, it's a toggle.

I set up dozens of iOS devices per year. Logging into even the App Store (after declining to log in during initial setup) silently enables iCloud, and iCloud Backup. It is on by default and most users are never once presented with the toggle. You can accidentally enable it just by installing an app.

Re: Code from the FBI’s Anom encrypted messaging app

#44

Earlier quoted context omitted.

> Lots of "secure" messaging apps do this for intel and surveillance and not just the white hats. Lots of VPNs, too! "We don't keep any logs! We just pipe a direct feed to the government so they can keep logs!"

Do you have any examples?

Unfortunately Google is failing me right now. There was a case within the last few years where someone was convicted because their VPN provider was sharing raw traffic (not logs) with the government. If anyone knows what I'm referring to, please chime in.

But given the existence of Room 641A[0], and other extra-judicial mass surveillance, I am confident in my assertion. Moreover, the explosion of VPN companies with large marketing budgets over the past few years has always made me suspicious.

[0] https://en.m.wikipedia.org/wiki/Room_641A

Re: Code from the FBI’s Anom encrypted messaging app

#45

Earlier quoted context omitted.

Do you have any examples?

Unfortunately Google is failing me right now. There was a case within the last few years where someone was convicted because their VPN provider was sharing raw traffic (not logs) with the government. If anyone knows what I'm referring to, please chime in. But given the existence of Room 641A[0], and other extra-judicial mass surveillance, I am confident in my assertion. Moreover, the explosion of VPN companies with l…

You're probably thinking of the big story from January of this year:

https://www.pcmag.com/news/nordvpn-actually-we-do-comply-wit...

NordVPN says they don't collect logs, but then it came out that they send information to law enforcement. So the big question is what information is being sent to law enforcement. Despite what NordVPN maintains, it seems like they do keep incriminating data about their users.

Re: Code from the FBI’s Anom encrypted messaging app

#46
post #21

I wish somebody would create some scheme to like self host the backend of an app.. like you launch Signal and it has a button to type in the name of your own server, where that server runs a VM that you configure and setup on your own PC locally then upload to AWS or something and has some facility to constantly report to you the hash of the memory and disk contents, along with some contract from AWS that states that…

There’s plenty of that stuff. Jabber and XMPP. And also more up to date is Matrix.org which nobody seems to want to use and I’m not sure why.

The problem though is that you’re still trusting the code. Nothing stops self hosted from rotting on you unless you look and read the code yourself.

Re: Code from the FBI’s Anom encrypted messaging app

#48

So what's the strategy moving forward? The operation clearly hasn't permanently solved crime, the next generation of organized crime bosses won't trust any apps to handle their secrets, so I guess their communication just moves offline again? Or maybe each develops their own methods in house that they know they can trust (such as shooting holes in a wall on call of duty)?

The goal is not to end organized crime for all eternity. It's to arrest as many criminals as they can today.

Tomorrow they'll think of a carrier pigeon spy.

Re: Code from the FBI’s Anom encrypted messaging app

#49
post #21

I wish somebody would create some scheme to like self host the backend of an app.. like you launch Signal and it has a button to type in the name of your own server, where that server runs a VM that you configure and setup on your own PC locally then upload to AWS or something and has some facility to constantly report to you the hash of the memory and disk contents, along with some contract from AWS that states that…

There’s plenty of that stuff. Jabber and XMPP. And also more up to date is Matrix.org which nobody seems to want to use and I’m not sure why. The problem though is that you’re still trusting the code. Nothing stops self hosted from rotting on you unless you look and read the code yourself.

> Matrix.org which nobody seems to want to use and I’m not sure why

Lots of people are using it (and probably more every day), but there are also some quite vocal haters. Of course it has its share of problems (availability of non-Electron clients and different servers among then), but many of them constantly improve as the ecosystem grows.

Re: Code from the FBI’s Anom encrypted messaging app

#50
post #23

Earlier quoted context omitted.

> Lots of "secure" messaging apps do this for intel and surveillance and not just the white hats. It's how Apple would do iMessage intercepts for the FBI.

I wonder if Messages will be available at all in lockdown mode? If Apple can be compelled to build in surveillance (and it's not clear to me that they can be), then it really should be.

In a word, yes.

> Messages: Most message attachment types other than images are blocked. Some features, like link previews, are disabled.

https://www.apple.com/newsroom/2022/07/apple-expands-commitm...

Post reply on HN