Governments spying on Apple, Google users through push notifications
71–80 of 649 posts
Re: Governments spying on Apple, Google users through push notifications
#72What sort of metadata or information can be gathered from a push notification from an app like iMessage? I know a timestamp is there and most likely the sender's phone number. But is there some sort of sensitive info that these governments are trying to glean? Or is it more so they can build info maps and communication maps on targets?
Chat message content?
Re: Governments spying on Apple, Google users through push notifications
#73> In this case, the federal government prohibited us from sharing any information," the company said in a statement. "Now that this method has become public we are updating our transparency reporting to detail these kinds of requests.
What is the point of transparency reports if they don't include major vectors of government surveillance?
IMO such gag orders shouldn't be legal when applied to dragnet surveillance. If you want to gag a company from notifying an individual they're being surveilled (with a warrant), then fine. But gagging a company from disclosing untargeted or semi-targeted surveillance, especially if it involves American citizens, seems like it should be unconstitutional on free speech grounds.
Re: Governments spying on Apple, Google users through push notifications
#74Re: Governments spying on Apple, Google users through push notifications
#75Some issues could be prevented if push messages added end-to-end encryption by default, something that shouldn’t be particularly hard to use if it was built into the dev tooling. Instead, developer recommendations like this one [0] suggest that you should put content into your push messages and optionally use a separate library to encrypt them. Clearly developers aren’t doing this, hence the opportunity for surveilla…
Re: Governments spying on Apple, Google users through push notifications
#76It should only[0] be meta data, though. The push notification should signal the app that there is data to fetch, then the app goes and fetches it. The push notification itself should carry none of the data. [0] still bad though and they should stop.
They know you rang a phone sex line at 2:24 am and spoke for 18 minutes. But they don't know what you talked about.
They know you called the suicide prevention hotline from the Golden Gate Bridge. But the topic of the call remains a secret.
They know you got an email from an HIV testing service, then called your doctor, then visited an HIV support group website in the same hour. But they don't know what was in the email or what you talked about on the phone.
They know you received an email from a digital rights activist group with the subject line “Let’s Tell Congress: Stop SESTA/FOSTA” and then called your elected representative immediately after. But the content of those communications remains safe from government intrusion.
They know you called a gynecologist, spoke for a half hour, and then called the local abortion clinic’s number later that day.Re: Governments spying on Apple, Google users through push notifications
#77Earlier quoted context omitted.
Because the requests likely contain legal cladding to forbid disclosing the request, as is the case in Australia. A lot of people would be vindicated if it turned out one of the “democracies” making these requests was Australia.
Australia was my first guess when I read that sentence. But I expect it's not the only one.
Re: Governments spying on Apple, Google users through push notifications
#78Metadata in this case apparently means Apple and Google are helping find “this real user connected to that real user at this time”. So governments may or may not be able to decrypt a push message payload, or data delivered because of that payload.
An interesting point in Glenn Greenwald’s book is that metadata is often more informative than the “real” data. Consider: 1. A phone call in which Mrs. Smith talks to a receptionist to set an appointment with a doctor for 9:30 next Wednesday. Vs. 2. Knowing that Mrs. Smith called an abortion clinic. #2 seems like a bigger violation of privacy. Metadata is the real data.
Re: Governments spying on Apple, Google users through push notifications
#79I noted that Apple says the governments in question are allies of the United States. I wonder if this is a case of American intelligence outsourcing the surveillance of American citizens to foreign intelligence. If that is indeed the case, I’d expect a quid pro quo.
Re: Governments spying on Apple, Google users through push notifications
#80It should only[0] be meta data, though. The push notification should signal the app that there is data to fetch, then the app goes and fetches it. The push notification itself should carry none of the data. [0] still bad though and they should stop.
I so hate when people put words "only" and "metadata" in the same sentence... They know you rang a phone sex line at 2:24 am and spoke for 18 minutes. But they don't know what you talked about. They know you called the suicide prevention hotline from the Golden Gate Bridge. But the topic of the call remains a secret. They know you got an email from an HIV testing service, then called your doctor, then visited an HIV…