Live data from Hacker News

Code from the FBI’s Anom encrypted messaging app

vice.com

71–80 of 107 posts

Re: Code from the FBI’s Anom encrypted messaging app

#71

Earlier quoted context omitted.

Do you have any examples?

Unfortunately Google is failing me right now. There was a case within the last few years where someone was convicted because their VPN provider was sharing raw traffic (not logs) with the government. If anyone knows what I'm referring to, please chime in. But given the existence of Room 641A[0], and other extra-judicial mass surveillance, I am confident in my assertion. Moreover, the explosion of VPN companies with l…

https://blog.hidemyass.com/en/lulzsec-fiasco

Re: Code from the FBI’s Anom encrypted messaging app

#72
post #23
post #2

> The code shows that the messages were secretly duplicated and sent to a “ghost” contact that was hidden from the users’ contact lists. Lots of "secure" messaging apps do this for intel and surveillance and not just the white hats. Other areas that "secure" messaging apps have holes in is the anti-spam/moderation systems that need to view messages and in the clients themselves who have access to the unencrypted cont…

> Lots of "secure" messaging apps do this for intel and surveillance and not just the white hats. It's how Apple would do iMessage intercepts for the FBI.

You can't really do this in iMessage.

Re: Code from the FBI’s Anom encrypted messaging app

#73
post #66

Earlier quoted context omitted.

You also have to keep in mind that spreading FUD about secure messaging apps can be a type of manipulation, in some cases planted by the FBI. If you don't have confidence in say, iMessage, which is pretty secure, you might instead go for a "secure" messaging app that's actually a plant (Like Anom).

I would be bewildered if the FBI doesn't have a back door into every messaging app allowed on american cell phones. That being said there is one chat app that cannot be easily broken by the FBI: Pictochat on the nintendo DS. You would need an FBI agent with a nintendo DS searching for chat rooms in physical proximity to the communicators.

I'm not sure if this is 100% serious but if it is, how could the FBI having a backdoor into every messaging app fit in with the relative ineffectiveness of the FBI?[0] If they truly did have the ability to spy on any messaging app without issue then you would expect them to have far more success than they actually do. For comparison, a quick Google search says China has a 99.9% conviction rate. Remember security and intelligence agencies also want people to think they are some omnipotent and omniscient entity that you cannot escape from, even though we know this is far from true[1][2].

[0]: https://time.com/magazine/us/5264136/may-14th-2018-vol-191-n...

[1]: https://www.nytimes.com/2017/05/20/world/asia/china-cia-spie...

[2]: https://www.nytimes.com/2021/10/05/us/politics/cia-informant...

Re: Code from the FBI’s Anom encrypted messaging app

#74
post #21

I wish somebody would create some scheme to like self host the backend of an app.. like you launch Signal and it has a button to type in the name of your own server, where that server runs a VM that you configure and setup on your own PC locally then upload to AWS or something and has some facility to constantly report to you the hash of the memory and disk contents, along with some contract from AWS that states that…

You could still have holes in a self hosted setup. The self hosted version could forward stuff on to someone else… so you could setup a firewall. But is it really blocking everything or is it just telling you it’s blocking things. This can go on forever, it all depends on the threat model and how far down the rabbit hole you have time to go.

Re: Code from the FBI’s Anom encrypted messaging app

#75

Earlier quoted context omitted.

In my opinion the goal is similar to the MPAA's goals with movie piracy: Make it harder, and many people will stop doing it. Ultimately, that is what banks do when they put money into vaults. Someone could still steal the money, but it's insanely difficult.

But in many cases, movie piracy is faster, more convenient and more agreeable than consuming through locked down ad funnels like Netflix or Disney+ which don't let me outright own the content or the viewing experience, or Blu-rays which enforce DRM and specific region-locked devices.

You're the pirate equivalent of a master jewel thief. "It's so easy! Just hotwire the security system, dance through the laser field, duh!" It's stochastic. They want to cut out casual piracy, those of us who know how to pirate are acceptable losses.

Re: Code from the FBI’s Anom encrypted messaging app

#76
post #69
post #64

Earlier quoted context omitted.

I don't know why radicals can't go back to physical written works and spoken word. No surveillance from someone sitting in a cubical 1000 miles a way at least. Suddenly the agency needs to spend a lot more money and effort to physically infiltrate your group and intercept written communication. It's worked for thousands of years, and the internet has not made it obsolete contrary to popular belief.

Still easier to do it digitally and e.g. physically exchange digital encryption keys?

Yes lol. You can share your AES key physically and write/edit an application that encrypts with that. You could share one time pads, or other preshared secrets for techniques like winnowing and chaffing and whatnot. Always amusing that these guys always opt for trust in some bizarre app.

Re: Code from the FBI’s Anom encrypted messaging app

#78

Last year the author of this story was on Darknet Diaries talking about ANOM and encrypted phones in general. It was a good episode. https://darknetdiaries.com/episode/105/

Great podcast, I really like the stories. Unfortunately it's a little basic technically. Any suggestions for more techy podcasts on netsec / the scene?

Re: Code from the FBI’s Anom encrypted messaging app

#79
post #21

I wish somebody would create some scheme to like self host the backend of an app.. like you launch Signal and it has a button to type in the name of your own server, where that server runs a VM that you configure and setup on your own PC locally then upload to AWS or something and has some facility to constantly report to you the hash of the memory and disk contents, along with some contract from AWS that states that…

We're basically working on this at Comm: https://github.com/CommE2E/comm

Re: Code from the FBI’s Anom encrypted messaging app

#80
post #10

Earlier quoted context omitted.

> What other services might be run, controlled, or surveilled by the US investigative authorities? Any service that is marketed to you as privacy- or security-as-a-service, or software sold as privacy- or security-enhancing, is virtually guaranteed to be secretly working against the interests of its users. You can't buy security or privacy in the form of software or services, because privacy and security are a set of…

I don't follow your logic here. Why can't a company legitimately focus on a niche sub set of users who value privacy in their products? I'm thinking of products like protonmail, standard notes, and signal.

> Why can't a company legitimately focus on a niche sub set of users who value privacy in their products?

No one is saying that they can't, somebody is saying that they are, but not in that customer's best interest.

-----

edit: with parallel construction, there are absolutely no drawbacks to narking on your users, assuming that the way you do it is an obvious possibility that you just minimize or ridicule the likelihood of.

e.g. "Everybody knows that they can use Method A to break your encryption, but that would be company suicide! Do you seriously think they're stupid enough to do that!? They even made the client open source to be open about what they can or can't do."

rather than

"Guys, I just noticed a process running on my phone that isn't supposed to be there."

Which is what we've been taught to watch out for.

Post reply on HN