Live data from Hacker News

Governments spying on Apple, Google users through push notifications

reuters.com

391–400 of 649 posts

Re: Governments spying on Apple, Google users through push notifications

#391

I'm probably naive, but what insights could a government gleam from Push Notifications? And why aren't push notifications E2EE?

> I'm probably naive, but what insights could a government gleam from Push Notifications? Looking at my own phone right now, it just got a push notification that my wife has arrived at home. That could be useful if you wanted to track my wife. > And why aren't push notifications E2EE? That's a great question. And I hope the answer is "we're on it, they will be E2EE in the next release."

If the notifications were to be truly E2EE, it would have to work something like this:

1. Generate a local key pair per app (never uploaded to Apple). 2. Each app can request their public key from iOS (or provided with (void) application:(UIApplication )application didRegisterForRemoteNotificationsWithDeviceToken:(NSData )deviceToken andPublickKey: (NSData *)publicKey;). 3. App uploads token + public key to their own server. 4. Server encrypts notification payload with the public key before sending to APNS. 5. Apple forwards encrypted payload to device. 6. Device uses the bundle name to look up the local private key and uses it to decrypt the payload.

Re: Governments spying on Apple, Google users through push notifications

#392
post #97
post #49

Earlier quoted context omitted.

And now we understand why they do that.

It is driven entirely by battery life. Android used to allow 3rd party apps to receive push notifications, and it caused battery life to be terrible compared to Apple. Forcing a single path was done for that reason. Btw, here's the telegram team complaining about the change: https://github.com/Telegram-FOSS-Team/Telegram-FOSS/blob/mas... Facebook abused this a bunch. https://www.theguardian.com/technology/2016/feb/01…

This complain is nonsense. Android _still_ allows background applications, the only limitation they added in that release is that such background applications have to show a notification that they are running (actually a feature if you ask me). You are still allowed to listen on a gazillion sockets perfectly fine.

It's more problematic that some Android "skins" tend to kill background applications at random https://dontkillmyapp.com/, but at least, one cannot squarely blame Google for that one...

The "battery life" argument that that they constantly use is also a very poor excuse. Even when Conversations (the Jabber client) didn't use push notifications at all and would just listen on noisy XMPP sockets, it still had about the lowesst power consumption of all Android messaging programs, lower than Google's own push notifications client app (play services).

Certainly I might imagine that if all 1,000 adware apps your average Android user installs all needed to be wired and listening to a socket in order to receive the latest offers (all in the legitimate interest of the user, of course) you might literally run out of memory. But even then there are many solutions (such as inetd like services) that do not require centralizing everything into Google.

Re: Governments spying on Apple, Google users through push notifications

#393

Metadata in this case apparently means Apple and Google are helping find “this real user connected to that real user at this time”. So governments may or may not be able to decrypt a push message payload, or data delivered because of that payload.

They already "kill people" based on metadata alone, at least since 2014.[0] [0]: https://www.nybooks.com/online/2014/05/10/we-kill-people-bas...

This is a widely under-appreciated fact!

Re: Governments spying on Apple, Google users through push notifications

#394

We at the Home Assistant Companion for iOS team have been wanting to implement end to end encryption for our push notifications for a while now but Apple has denied our request for the com.apple.developer.usernotifications.filtering [0] entitlement multiple times. Wondering if with today's news we could apply again and get it. For context, we are sending ~35 million push notifications per month on iOS and ~67 million…

Just curious, why do you need filtering permissions for your use case? Decrypting a push notification appears to be supported using 'mutable-content' with a notification service. In fact that is the example used here: https://developer.apple.com/documentation/usernotifications/...

The filtering entitlement allows us to decrypt messages and, depending on the content, choose to not send any notification (for example if a user sends an app specific command, like asking for a location update). The example you linked requires that a notification is emitted at the end, which we don't want.

Zac also just let me know the other reason we need filtering is so we can properly unsubscribe users from notifications when one is received from a server they no longer are connected to.

Re: Governments spying on Apple, Google users through push notifications

#395
post #379

Earlier quoted context omitted.

Thirty years ago, one perceived element of moral superiority in the West was revelations of the extensive internal surveillance in places like East Germany and own-spying. There used to be news items and documentaries mocking this behavior and intimating how backward and uncouth those governments were to stoop to furiously wiretapping irrelevant private conversations. So, whether the world has changed enough to justi…

It is my opinion that people do not about privacy as much as they did in your mention Cold War-era times (or the tail end of it, anyway). They've been shown how easy it is to trade their privacy for considerable convenience and now they're in so deep that the idea of our governments tracking us seems remarkably mundane. Normalization is a helluva drug.

Great point. Convenience plays a hell of a role in a lot of society's issues. I go back to a song by Deee-lite where she sings "Convenience is the enemy" - I've always thought that was pretty pertinent in a lot of ways, this is just one more example.

Re: Governments spying on Apple, Google users through push notifications

#396

Earlier quoted context omitted.

> I believe the risk to our freedom is much greater from the latter. I’ll take power being consolidated in a democratically elected government over a privately controlled corporation any day of the week. Let’s put the spotlight on the stuff that isn’t democratically controlled, and subject to much more limited oversight.

The US government isn't really democratically controlled, which is obvious to anyone paying attention, and this Princeton paper proves it: https://www.princeton.edu/~mgilens/idr.pdf

The person you're replying to is making a statement about democratically accountable consolidation of power; not necessarily today's current (and broken) implementations of such things.

Re: Governments spying on Apple, Google users through push notifications

#397
post #62

Ron Ryden has been barking up this tree for a long time: https://www.wyden.senate.gov/issues/secret-law https://www.wyden.senate.gov/news/press-releases/wyden-colle... https://www.wyden.senate.gov/news/press-releases/wyden-intro... https://www.wyden.senate.gov/priorities/gps-act https://www.wyden.senate.gov/news/press-releases/wyden-relea...

He even inspired Snowden to expose the illegal mass surveillance programs. IIRC Snowden reached a breaking point when James Clapper, then director of national intelligence, lied under oath to Congress when pressed about domestic surveillance by senator Wyden.

It's sad we don't hear more about people like this in positions of power.

Re: Governments spying on Apple, Google users through push notifications

#398

It should only[0] be meta data, though. The push notification should signal the app that there is data to fetch, then the app goes and fetches it. The push notification itself should carry none of the data. [0] still bad though and they should stop.

[flagged]

Re: Governments spying on Apple, Google users through push notifications

#399
This reminds me, whatever happened to mesh networks? If you wanted to be out and about in public, you could simply carry a very anonymized device that had only more basic abilities. But among those abilities, you could certain send messages and maybe even smaller-sized files - all over a mesh network. Feds could infiltrate it, but it wouldn't be nearly as trivial as it is right now. And users could rotate their devices. Furthermore, if the device in question wasn't a real phone, but rather something more generic (a wifi-capable device with a keyboard, virtual or physical), then it wouldn't even need to have an IMEI.

Re: Governments spying on Apple, Google users through push notifications

#400

> " "In this case, the federal government prohibited us from sharing any information," the company said in a statement. "Now that this method has become public we are updating our transparency reporting to detail these kinds of requests." " When they were building the CSAM detector: "what if the government asks you to extend the detection to include other media such as political meme images?" "we would refuse".

wow. Yahoo have a better track record than google or apple on figthing against that https://money.cnn.com/2014/09/11/technology/security/yahoo-f... I guess now the yahoo phone doesn't sound like that bad of a joke https://www.slashgear.com/wp-content/uploads/2010/05/nokia_y...

Better public track record. It's very difficult to reason about a hidden private track record.
Post reply on HN