Live data from Hacker News

Governments spying on Apple, Google users through push notifications

reuters.com

251–260 of 649 posts

Re: Governments spying on Apple, Google users through push notifications

#251

This, to me, is the more disturbing part of the article: > In this case, the federal government prohibited us from sharing any information," the company said in a statement. "Now that this method has become public we are updating our transparency reporting to detail these kinds of requests. What is the point of transparency reports if they don't include major vectors of government surveillance? IMO such gag orders sh…

If I’m not mistaken they’re called NSLs and the legality of them when challenged are reviewed by a secret court with secret laws that have secret interpretations of words. The whole thing as far as I can tell is an out of control nightmare and our corrupt congress doesn’t give a shit.

Actually quite a few members of congress do give a shit. Unfortunately they're the same members of congress maligned as MAGA extremists or whatever (in some cases that might be accurate, but it doesn't mean they're wrong about every political position they hold).

If you actually take a second to listen to Matt Gaetz, for example, you might be surprised to learn his (rather principled) positions are much closer to those of AOC than to President Orange, at least in some dimensions. He wants to require single-issue bills, and to completely eliminate FISA-702. Ironically, it seems like FISA will be reauthorized as part of an omnibus spending bill...

Re: Governments spying on Apple, Google users through push notifications

#252
post #192

Earlier quoted context omitted.

Would you prefer elected bureacrats with guns? That scares me more. Perhaps we just go with rock solid transparency laws...

At least elected bureaucrats are theoretically accountable to the electorate. The gripe comes from things like the unelected bureaucrats at the US Department of Justice deciding that as part of implementing the Americans with Disabilities Act, there are only two limited and inadequate questions you can ask of someone with an apparently bogus service dog or else . That rule didn't come from the people who wrote the la…

In practice that shouldn’t matter, as the law states that any service animal can be turned away so long as the business provides accommodation to the human (which is the point of the limited questions).

The fact this rarely happens is more due to people not actually knowing the law and typically wanting to avoid potential conflict.

Re: Governments spying on Apple, Google users through push notifications

#253
post #248
post #143

Earlier quoted context omitted.

That's awfully generous. He co-sponsored a bad law that he didn't actually want to see passed?

He may definitely want to see it passed. But elected officials should not be engaging in pushing bills that won't pass their first legal challenge.

Similar bills have already passed legal challenges https://www.lawfaremedia.org/article/eighth-circuit-upholds-...

I think it's a bad law and he's making a big mistake. I'm still a fan though.

Re: Governments spying on Apple, Google users through push notifications

#254

>> Reuters' source would not identify which governments were making the data requests but described them as "democracies allied to the United States." It feels so liberating to be spied upon by "democracies allied to the United States." vs. others. LOL.

Now you know how the rest of us [abroad in the world] feel regarding the US.

Re: Governments spying on Apple, Google users through push notifications

#256

Earlier quoted context omitted.

That doesn't make sense. I would expect Signal notifications to happen completely out-of-band with "normal" push notifications (e.g. NYT news alert). Otherwise that completely defeats the purpose of the service. Basically you're saying Apple/Google are MITM'ing Signal.

I'm not so familiar with Signal, but could you explain why you would expect Signal notifications to happen out-of-band with normal push notifications? Assuming Signal sends push notifications of some sort, as most messaging services do, that would make them vulnerable to the metadata-level attacks described in this thread. What kind of "out-of-band" are you thinking of that would mitigate this issue?

Not using APN I assume, but then you are not allowed(or rather won't pass the review) to publish the app in the App Store.

Re: Governments spying on Apple, Google users through push notifications

#257
post #142
post #23

Earlier quoted context omitted.

Yeah he's awesome. /s In May 2017, Wyden co-sponsored the Israel Anti-Boycott Act, Senate Bill 720, which made it a federal crime, punishable by a maximum sentence of 20 years imprisonment,[88] for Americans to encourage or participate in boycotts against Israel and Israeli settlements in the occupied Palestinian territories if protesting actions by the Israeli government. The bill would make it legal for U.S. states…

Pobody's Nerfect

This is a far cry from an "oopsie"

Re: Governments spying on Apple, Google users through push notifications

#258
post #209

Earlier quoted context omitted.

If they use IP to deliver notifications, then the gov can demand they hand over the IP address a notification was delivered to. From there, location isn’t hard.

IP geolocation isn’t exactly the most precise though. 600M+ IPs have a default location to some farm in Kansas [1] [1] https://www.washingtonpost.com/news/morning-mix/wp/2016/08/1...

I should have been more specific. Although they could use IP geolocation, they can also get data from the cell carrier that delivered the notification to that IP address.

So a gov finds that IP address 7.8.9.0 received one of these notifications at 12:34. They then see that 7.8.9.0 is one of ATT’s addresses. They go to ATT and learn that address was used by their customer onionisafruit at 12:34 and the device was 5ms away from tower A.

Re: Governments spying on Apple, Google users through push notifications

#259
post #169

Earlier quoted context omitted.

In general, I agree DNS-over-HTTPS is a step in the right direction, in terms of eliminating the low-hanging fruit of snooping over the wire. But it's still the same major companies providing the resolvers. And if you're sending them an NSL for push notifications, you may as well send one for DNS too.

That’s usually untrue - for example, if I’m on Comcast but I use Firefox, my DoH requests go instead to Cloudflare who don’t log IPs – but also the larger point is that DNS isn’t complete enough: sometimes it’s unique companies but a lot of the time it’s just a shared endpoint. Push notifications don’t have that problem and happen every time, not just when a cache expires.

Cloudflare is one of the "major companies" I was alluding to. It's still an issue of centralized authorities that are accountable to governments. But I do trust Cloudflare more than my ISP or Apple, and in fact I route much of my traffic through them so I hope I'm right in giving them my trust.
Post reply on HN