Live data from Hacker News

Governments spying on Apple, Google users through push notifications

reuters.com

321–330 of 649 posts

Re: Governments spying on Apple, Google users through push notifications

#321
post #150

Would be great to see an example of notification metadata that can supposedly link it to real users. Seems like this is what is being implied: Given: - users with notifications enabled - have X app installed - targeted user(s) reside in USA - targeted users(s) following “foo” on X app When: - issue FISA warrant for all smartphone users that received notifications in regards to “foo” user Then: - able to pull all Appl…

So, don’t have Twitter account and/or app installed and you should be good?

I think your comment comes after reading this line:

> - targeted users(s) following “foo” on X app

It seems "X app" means just any placeholder app (not the new Twitter rebrand), although I might be wrong.

Re: Governments spying on Apple, Google users through push notifications

#322

Earlier quoted context omitted.

That doesn't make sense. I would expect Signal notifications to happen completely out-of-band with "normal" push notifications (e.g. NYT news alert). Otherwise that completely defeats the purpose of the service. Basically you're saying Apple/Google are MITM'ing Signal.

I'm not so familiar with Signal, but could you explain why you would expect Signal notifications to happen out-of-band with normal push notifications? Assuming Signal sends push notifications of some sort, as most messaging services do, that would make them vulnerable to the metadata-level attacks described in this thread. What kind of "out-of-band" are you thinking of that would mitigate this issue?

Why: because otherwise the service, which is supposed to be private, is no longer private.

I dunno how it would work, maybe something like a third-party push? Why does everything have to be channeled through central service? A service like Signal could operate its own push channel.

Re: Governments spying on Apple, Google users through push notifications

#323
post #96

Given a lot of journalists and activists use encrypted communications to be able to do their job without being unduly or unjustly persecuted (yes, the bad guys use them too!), and 12 US State Attorney Generals just signed a letter and delivered it to the major news agencies (NYT, CNN, Reuters, AP, etc.) that warns of any "support to terrorist organizations" and specifically points out Hamas, but is not very clear on…

[flagged]

At this point any “both sides are the same” argument should be seen as either incredibly misguided or intentionally malicious.

Look for representatives who represent more or at least some of our actual interests.

An ideologically united group which has been working to actively disrupt the election process and turn women into breeding property, combined with unlimited surveillance? Might not be the “same”.

Re: Governments spying on Apple, Google users through push notifications

#324
post #317

We at the Home Assistant Companion for iOS team have been wanting to implement end to end encryption for our push notifications for a while now but Apple has denied our request for the com.apple.developer.usernotifications.filtering [0] entitlement multiple times. Wondering if with today's news we could apply again and get it. For context, we are sending ~35 million push notifications per month on iOS and ~67 million…

for my understanding, you need that entitlement so you can send an encrypted invisible notification which you can then decrypt locally in your app and push out again as a local notification that doesn't go over the network (i.e. not use apns)? Or is doing this kind of stuff just weirdly tied to that specific entitlement?

Correct, we need to be able to filter to properly unencrypt notifications and pass them on as a local notification.

Re: Governments spying on Apple, Google users through push notifications

#325
post #252
post #192

Earlier quoted context omitted.

At least elected bureaucrats are theoretically accountable to the electorate. The gripe comes from things like the unelected bureaucrats at the US Department of Justice deciding that as part of implementing the Americans with Disabilities Act, there are only two limited and inadequate questions you can ask of someone with an apparently bogus service dog or else . That rule didn't come from the people who wrote the la…

In practice that shouldn’t matter, as the law states that any service animal can be turned away so long as the business provides accommodation to the human (which is the point of the limited questions). The fact this rarely happens is more due to people not actually knowing the law and typically wanting to avoid potential conflict.

"people not knowing the law" can be a symptom of bureaucracy though. How many pages of law do you think exist to open a bagel shop or add a room to your house in SFO?

Re: Governments spying on Apple, Google users through push notifications

#326

One question I have as someone who tries to maintain (some) data sovereignty: is there any way as an end-user to circumvent/mitigate this kind of surveillance — aside from abandoning iOS and Android completely?

Disable notifications on all applications you do not want to be tracked via metadata.

Absolutely and confidently incorrect. Local notification settings have no bearing on this metadata, which is generated, collected and stored with your consent by using Apple/Google app stores.

Re: Governments spying on Apple, Google users through push notifications

#327
> ""In this case, the federal government prohibited us from sharing any information," the company said in a statement. "Now that this method has become public we are updating our transparency reporting to detail these kinds of requests.""

When they were building the CSAM detector: "what if the government asks you to extend the detection to include other media such as political meme images?" "we would refuse".

Re: Governments spying on Apple, Google users through push notifications

#328

Metadata in this case apparently means Apple and Google are helping find “this real user connected to that real user at this time”. So governments may or may not be able to decrypt a push message payload, or data delivered because of that payload.

They already "kill people" based on metadata alone, at least since 2014.[0]

[0]: https://www.nybooks.com/online/2014/05/10/we-kill-people-bas...

Re: Governments spying on Apple, Google users through push notifications

#329

Earlier quoted context omitted.

God forbid if you are just going on a date with someone who works at an abortion clinic.

Yeah, false positives are a doozy, and I don't see many guardrails in place to prevent the intelligence community from acting upon them :/

> doozy

They’re not just a “doozy” they’re downright fascist authoritarian. Even the positive positives are infringements.

Re: Governments spying on Apple, Google users through push notifications

#330

I know Pinephone isn't ready for daily use from all the threads here, but I just ordered one to get some stick time with it. Getting real tired of having to fight my phone to keep my data mine. I just want the equivalent of debian, but on mobile. I understand I'll have to give up a bunch of apps, but honestly I think its worth it. As soon as its possible I'd like off this ride.

Alternatively, consider Librem 5, which is more stable, since its software is developed by a dedicated team.

Librem needs to do something PR-wise to fix the reputation they developed regarding massive product/delivery delays.

They exist in the frustrating spot of “I want to like them, but I can’t trust the purchase based off of everyone I know who tried getting burned, so now I’ll just look at a Pinephone because it’s easier”.

Post reply on HN