Live data from Hacker News

Governments spying on Apple, Google users through push notifications

reuters.com

351–360 of 649 posts

Re: Governments spying on Apple, Google users through push notifications

#351

Earlier quoted context omitted.

Then those who are victimized take it to court. If the agency committed an actual crime, then there's a path for that to be prosecuted as well. It's certainly not a perfect system, but it's successfully done all the time.

>> The only teeth congress has with these bureaucracies is the power of the purse. >Not true. Congress can make laws defining what those agencies are and are not allowed to do. >And if the agencies go outside the bounds of those laws like some currently do? >Then those who are victimized take it to court. Right, the court isn't congress. My point was the only teeth congress has in regards to the bureaucracies is the…

Congress can impeach the appointed officers that allowed those violations to happen.

Congress can create new criminal/civil remedies and then create an office tasked just with enforcing them.

Re: Governments spying on Apple, Google users through push notifications

#352

One question I have as someone who tries to maintain (some) data sovereignty: is there any way as an end-user to circumvent/mitigate this kind of surveillance — aside from abandoning iOS and Android completely?

Read at least the summary of James Scott's Seeing Like a State (https://en.wikipedia.org/wiki/Seeing_Like_a_State) and let the concept of legibility percolate for a bit.

Governments view legibility of their constituencies as a feature, not a bug. They want to be able to query the population like a database in order to manage it better. This is exactly like a product manager at a tech company who wants to know whether a certain feature is being used, and asks for more instrumentation in the next release of the product if needed. Over time the product (the population) becomes better and better instrumented.

Of course, the other side of the coin of better legibility is worse privacy. Their feature is your bug.

Are there ways to circumvent or mitigate what's happening? For you, personally, sure. You can turn on all the buried options, add VPNs, proxies, additional profiles/accounts, etc. And for a while it will work.

But you're defeating legibility by doing that, so you're fighting against a very strong opposing force. Over time, the bugs that reduce legibility coverage will be fixed. The options will go away, VPNs will be banned or at least instrumented well enough to nullify their utility, COPPA and porn age-verification laws will extend to make multiple or anonymous identities impractical, and so on. And the few of us who do manage to go online fully anonymously might as well be wearing a "CRIMINAL" hat, because the public will have been trained that only bad actors want privacy, but not to worry if they themselves have nothing to hide.

You can see this already happening with financial transactions. Try to conduct a significant low-legibility transaction (in other words, buy something big with cash). Your bank will ask why you want to withdraw $20,000. Cops might seize the cash, legally and without probable cause, while you're driving to the seller. And when the seller deposits the cash, the bank might file a SAR. This is all working as designed. You're being punished for adding friction to legibility.

Even on HN, where you think people would be ahead of the curve, the PR campaign against financial privacy and censorship resistance is winning. Mention The Digital Currency That Shall Not Be Named, and suddenly the Four Horsemen of the Infocalypse are in control. Why HNers are pro-VPN but anti-Bitcoin, when both stand for privacy and censorship resistance at the price of reduced legibility, is beyond me.

The battle to fight is not just protecting your own privacy. It's protecting your right to protect your privacy without being ipso facto declared a criminal for doing so. Turn on all the options, hold Bitcoin, use VPNs, pay with cash, delete cookies, etc. But above all, be an ordinary, conscientious, law-abiding citizen. Render unto Caesar what is Caesar's. Be average. Be unremarkable. Privacy should be the default. Not unsavory, not for those with something to hide. Just the default.

Re: Governments spying on Apple, Google users through push notifications

#353

Some issues could be prevented if push messages added end-to-end encryption by default, something that shouldn’t be particularly hard to use if it was built into the dev tooling. Instead, developer recommendations like this one [0] suggest that you should put content into your push messages and optionally use a separate library to encrypt them. Clearly developers aren’t doing this, hence the opportunity for surveilla…

The timing would still give you away - with a privileged network position you can tell that a user sent a message to an messaging service, and that some set of users got notifications from that messaging service moments later. Observe that enough times and you'll have good confidence in the members of a group. If you're trying to hide from that type of attack you need to send a fixed rate stream of messages (most of…

Isn’t this somewhat defeated if the service is large enough?

E.g: if I get a signal notification and the notification has no data except “event happened, call server for updates” - and then you fetch updates as a batch - doesn’t the sheer number of people making that same generic batch update call somewhat mask it?

I’m curious where Apple prohibits dummy notifications, by the way - I used them for a financial app I worked on a few years back and never got dinged for it.

Re: Governments spying on Apple, Google users through push notifications

#354
post #149

"The source declined to identify the foreign governments involved in making the requests but described them as democracies allied to the United States" - why not identify them?

We already know, it's the Five Eyes

Most likely group, since they info share and this is the standard end-around on laws prohibiting "domestic" surveillance; government has some other country run the surveillance on their nationals.

Re: Governments spying on Apple, Google users through push notifications

#355

It's crazy to me that so much effort is being expended pretending that companies and the government are doing anything in the name of privacy, when we have all the proof by Assange and Snowden that they're doing realtime surveillance of ALL communications, 24x7 -- no matter what any laws say -- and we don't even talk about it any more. What's the point of any of this? All we can do is assume that our every position,…

I don't think many people actually care much about privacy. There are a few, and they're loud. But look at what matters in politics -- both major political tribes in the US are only interested in privacy and protection from the government as it relates to their own interest, but they are perfectly happy to use that power against their perceived opponents.

Thirty years ago, one perceived element of moral superiority in the West was revelations of the extensive internal surveillance in places like East Germany and own-spying. There used to be news items and documentaries mocking this behavior and intimating how backward and uncouth those governments were to stoop to furiously wiretapping irrelevant private conversations.

So, whether the world has changed enough to justify it, people still do care and when adequately informed about some magistrate furiously eavesdropping on private matters, people universally recognize this is antisocial bizarre conduct.

Re: Governments spying on Apple, Google users through push notifications

#356

Just an evil life pro-tip... if you're doing criminal things, leave your phone at home. Or better yet, grab a "buddy's" phone.

Here is a better pro-tip- don't do criminal things.

I bet you've committed at least a ticketable offense in the past 48 hours, unless you are a true hermit.

Our laws were not designed for a society with perfect surveillance.

Re: Governments spying on Apple, Google users through push notifications

#357

Earlier quoted context omitted.

I think where we go wrong is to allow the conversation to revolve around what evil corporations are doing with our information, rather than what the evil government is doing with it. I believe the risk to our freedom is much greater from the latter. Of course governments can extract the information from corporations that have it, but let's keep the spotlight on the government itself, and use THAT as a reason to give…

Wouldn't the exact opposite focus have a better effect? Going after the "evil corporations" would mean nobody was collecting the data in the first place, which would also take away the "evil government" as they have nobody to buy that data from. Right now they just write fat checks to Google, Apple, Amazon and the telcos and badda bing, badda boom it's done.

A government can (in some cases) force a company to collect information they otherwise wouldn't have. The reverse is not true. So I do think the bigger danger here is the legal framework that not only permits this but keeps it secret, rather than the mere fact of information collection.

Re: Governments spying on Apple, Google users through push notifications

#358

Earlier quoted context omitted.

Here is a better pro-tip- don't do criminal things.

where's the fun in that??? Live a little, be a little bit evil. Like 5% evil

I take a penny but I never leave one.

Re: Governments spying on Apple, Google users through push notifications

#359

Earlier quoted context omitted.

I'm not so familiar with Signal, but could you explain why you would expect Signal notifications to happen out-of-band with normal push notifications? Assuming Signal sends push notifications of some sort, as most messaging services do, that would make them vulnerable to the metadata-level attacks described in this thread. What kind of "out-of-band" are you thinking of that would mitigate this issue?

Why: because otherwise the service, which is supposed to be private, is no longer private. I dunno how it would work, maybe something like a third-party push? Why does everything have to be channeled through central service? A service like Signal could operate its own push channel.

Apple doesn't support any third-party push platforms, and they are restricted on Android to preserve battery life.

Re: Governments spying on Apple, Google users through push notifications

#360

Earlier quoted context omitted.

Google-free Android will allow you (force you) to use alternative push servers. That could be your own server (using something like Unified Push) or querying your apps' servers directly. This comes at the cost of battery life, sometimes significantly so, but it does decentralise the notification system. Of course, your data will still be in the hands of app vendors unless you choose your apps wisely. You should also…

Parent is asking about government surveillance. You're suggesting a deviation from the norm (99.99% of users) by installing a custom operating system (which they will now also be on the hook to secure and update regularly) by developers with nothing to lose. This will greatly increase scrutiny on you, or colloquially speaking definitely put you on a watch list, the opposite of what is allegedly desired. Rather, accep…

AOSP is not a deviation from the norm. It's the thing Google ships, vendors install play services as separate apps on top, so there is nothing oddball about your device fingerprint just by not installing Google specific services like the push handler. Your traffic will look like any other android making web requests, but then those requests will only be tracked by the servers they target instead of the OS itself betraying you and sharing metadata about them with various 3rd parties. Running non-vendor ROM alone will not get you "on a list".

"Custom" ROMs also get OTA updates, so keeping up to date is as easy as it is on a vendor spyware ROM. In fact, you will usually get updates from the community well beyond when vendors stop support.

Post reply on HN