Live data from Hacker News

FBI used iPhone notification data to retrieve deleted Signal messages

9to5mac.com

171–180 of 322 posts

Re: FBI used iPhone notification data to retrieve deleted Signal messages

#171

Earlier quoted context omitted.

There is if they have repeatedly said no

imagine someone shows up to your door and tries to sell you garbage. you ask him to leave and he says he'll show up again soon. and these idiots defend this behavior. at the end of the day, the people on this site are muppets, they just dont like facebook is all.

What I don’t understand is why anyone can’t imagine scenarios where folks don’t want to turn on notifications. Also, why on a site where all I ever read is “users should be allowed to choose, users should be allowed to control their computers, users should have their consent respected,” etc. (especially when Linux comes up) are we seeing “no, users should keep getting nagged to turn on a feature they explicitly said they don’t want to use”? It’s not like it’s hard to go enable notifications. They can easily change their mind.

Re: FBI used iPhone notification data to retrieve deleted Signal messages

#172
post #106

Just curious, how come at least once a month signal bugs me to turn on notifications? I said no for a reason, every single time - why does it keep asking? Not implying anything evil but it feels a bit weird esp after this.

> why does it keep asking? Why does any software keep asking you to do things you explicitly told them you don't want to do? Because it's in the software developer's best interest to get you to do them, not yours. We've gotten way past the point in software where we no longer expect the software to serve the user's interest and solve the user's problems. Now, the expectation is that the user gets nagged and coerced i…

“Their support problem” is a regular person’s problem getting the software to work how they want. That frustrated them enough to complain about.

I don’t follow how it’s necessarily selfish for the developer to reduce that.

There certainly are selfish ways to reduce support load, like making it harder to ask for help at all. But this way seems like the right way: listen to users’ problems and act to avoid them.

If your remedy causes more pain and frustration than the status quo, you’ll end up with more support load, not less.

Sure it’s greyer when the developer’s trying to sell something, but what does Signal gain from pushing notifications on users?

This seems to be about making the software humane and forgiving—meeting users where they are, not tricking them into something they don’t want.

Re: FBI used iPhone notification data to retrieve deleted Signal messages

#173
post #123
post #109

Earlier quoted context omitted.

If you care about security at all, you disable any previews on the lock screen. The lock screen is by definition visible to anyone without any authorization. Showing anything on it immediately destroys any secrecy. It must be obvious to anyone capable of elementary logic inference. If you don't know how to disable it, you use your favorite search engine / LLM / knowledgeable relative to find out, and disable it. But…

> If you care about security at all, you disable any previews on the lock screen. The lock screen is by definition visible to anyone without any authorization. Showing anything on it immediately destroys any secrecy. It must be obvious to anyone capable of elementary logic inference. With at least one combination of settings, it shows the message content only when the lockscreen has been unlocked, but not yet swiped…

This is insidious indeed. Still I would suggest that any secret message, as it leaves the app that handles secrecy, ceases to be secret. This BTW also applies to copy-paste operations, screen readers, etc.

Re: FBI used iPhone notification data to retrieve deleted Signal messages

#174
post #79

So this is where we find out the one end of e2e is the phone and not the app. Semi-related, in whatsapp reading the text in the notification doesn't mark the message as read, so the OS is kinda mitm here.

Signal creates the notification, does it not? That's like claiming `echo "my_private_data" | notify-send` is insecure. If piping encrypted content resulted in a plaintext notification then you'd have a right to be concerned.

What prevents the phone from taking screenshots of you reading the messages in the app?

The actual one end is the phone, not the app, period.

Re: FBI used iPhone notification data to retrieve deleted Signal messages

#175

Earlier quoted context omitted.

Signal developer here. It's just because notification reliability is always a top support complaint, and a lot of people turn off notifications and don't realize they've done so. Admittedly, once a month is likely too aggressive.

How about instead of prompting to enable notifications, you leave a small banner or other unintrusive/non-annoying UI noting that they're off, which users can tap in order to learn more about how to reenable them? For an app that prides itself on privacy, it's kind of crazy that you're making it so easy to accidentally blow it.

That would drive me nuts. I do not want a banner permanently on I cannot remove.

And before someone suggests it: If the banner can be removed, you’re back to having lots of complaints for users that did not realise they turned off notifications.

Re: FBI used iPhone notification data to retrieve deleted Signal messages

#177

"However, it appears the defendant did not have that setting enabled, which, in turn, seemingly allowed the system to store the content in the database." "[A]llowing the system to store the content in the database" where a third party, such as Apple or a government, can access it is the default Only a small minority of users know about settings and how to change them. The vast majority of users do not change default…

“Only a small minority of users know about settings and how to change them. The vast majority of users do not change default settings.”

Even worse, whatever critical settings you may set as a sophisticated user will frequently be reset, or changed, or re-organized under different settings… And of course, set back to insecure defaults… With subsequent software updates.

This is a regular occurrence with Firefox and privacy settings.

Whatever the actual impetus is, we should act as if this is intentional.

Re: FBI used iPhone notification data to retrieve deleted Signal messages

#178
post #117

Earlier quoted context omitted.

Signal developer here. It's just because notification reliability is always a top support complaint, and a lot of people turn off notifications and don't realize they've done so. Admittedly, once a month is likely too aggressive.

Is there some "no means no" additional setting that could be added where someone has to go into settings that would prevent that? I fear that with the notifications pop up asking me this I might hit the wrong button and woops turn it on.

Try from inside the signal app itself instead of system settings? On android Signal has an option at hamburger menu > Settings > Notifications > Notifications (toggle switch)

Oh... hmm, two toggles actually. One at Settings > Notifications > Calls > Notifications toggle, and the other at Settings > Notifications > Messages > Notifications toggle

Re: FBI used iPhone notification data to retrieve deleted Signal messages

#179
post #71

Earlier quoted context omitted.

Yes. And technically, from a privacy perspective, it's even worse than that. What's additionally happening is they're still 'syncing' back to Apple servers via APNS (and to Alphabet servers via Firebase on Android)—even with notifications completely disabled , that's correct. If the app generates them, the OS receives them. That's why the Signal app offers this setting.

>it's even worse than that. What's additionally happening is they're still 'syncing' back to Apple servers via APNS (and to Alphabet servers via Firebase on Android)—even with notifications completely disabled, that's correct. Source? I don't think either OS implements notification syncing between devices, it's only one way, and as others have mentioned, the actually push notification doesn't contain any message cont…

I do wonder how notifications that are synced/mirrored to the Apple Watch and newer versions of Mac are handled.

Re: FBI used iPhone notification data to retrieve deleted Signal messages

#180
Putting on my user hat...

"OK. Signal has forward secrecy. So messages are gone after I receive them. Great!"

Oh, you didn't turn on disappearing messages? Oh, right, then forensic tools like Cellebrite can get them. You have to turn on disappearing messages. The default is off.

Oh, you did turn on disappearing messages? We send the messages in notifications. So the OS can keep them. Turns out Apple was doing that. There is an option you can turn on to prevent that. It is off by default.

"I'll just delete the entire app!" No, sorry, the OS still has your messages...

At what point does the usability get so bad that we can blame the messaging system?

This same app had a usability issue that turned into a security issue just last year:

End to End Encrypted Messaging in the News: An Editorial Usability Case Study (my article)

https://articles.59.ca/doku.php?id=em:sg

Post reply on HN