Live data from Hacker News

FBI used iPhone notification data to retrieve deleted Signal messages

9to5mac.com

291–300 of 322 posts

Re: FBI used iPhone notification data to retrieve deleted Signal messages

#291
post #290

Earlier quoted context omitted.

Then that's basically what I said right? That there is in practice no way to opt out of using Firebase if you want consistent notifications.

Not clear what your point is. The Signal server wakes up the app via an empty message. At most the info this conveys is that a Signal app got a message to pull.

My point is there is no reasonable way to remove oneself from Google and Apple even with a fully custom application, they control the notification servers for their devices.

Re: FBI used iPhone notification data to retrieve deleted Signal messages

#292

Earlier quoted context omitted.

How about instead of prompting to enable notifications, you leave a small banner or other unintrusive/non-annoying UI noting that they're off, which users can tap in order to learn more about how to reenable them? For an app that prides itself on privacy, it's kind of crazy that you're making it so easy to accidentally blow it.

That would drive me nuts. I do not want a banner permanently on I cannot remove. And before someone suggests it: If the banner can be removed, you’re back to having lots of complaints for users that did not realise they turned off notifications.

Doesn't have to be prominent and doesn't even have to be a banner. The ultimate point is to make it hard to reenable by accident, and to not make it annoying. Lots of ways to do that.

Re: FBI used iPhone notification data to retrieve deleted Signal messages

#293
post #279
post #259

Earlier quoted context omitted.

Given the shoddy state of network security at large, especially on infrastructure projects (power plants, hospitals, dams, etc.) I always feel like major governments sit on so destructive potential to disrupt communications and anything connected to the Internet of its adversaries to have mutual assured destruction potential of a nuclear bomb. No one’s crazy enough to push that button, because once you do there is no…

I have often wondered about this exact situation. Like there are many instances of companies who depend on keeping their network secure and are actively taking preventative measures to keep their network safe that end up getting hacked. So surely there has to have been infiltration to some of the critical infrastructure keeping cities running. Why don't we hear more about it?

Only semi-conscientious companies will even KNOW they were compromised.

Suspect the rest are either not even looking and/or the attackers removed all their traces before anyone could possibly see.

When was the last time YOU inspected the authorization logs in systemd or the event log in Windows on your personal computer…

In Windows Defender we trust…

Re: FBI used iPhone notification data to retrieve deleted Signal messages

#294

Putting on my user hat... "OK. Signal has forward secrecy. So messages are gone after I receive them. Great!" Oh, you didn't turn on disappearing messages? Oh, right, then forensic tools like Cellebrite can get them. You have to turn on disappearing messages. The default is off. Oh, you did turn on disappearing messages? We send the messages in notifications. So the OS can keep them. Turns out Apple was doing that. T…

Use SimpleX if you really want a secure messenger. Endorsed by Whonix, which in endorsed by Snowden. https://www.whonix.org/wiki/Chat#Recommendation

SimpleX has the same problem with notifications. You still have to properly configure it. Opsec is hard.

Re: FBI used iPhone notification data to retrieve deleted Signal messages

#296
post #238

Earlier quoted context omitted.

In my recollection, which may be imperfect: 1. On android if Google Play isn't available (or you install the no Google apk version) it'll use a websocket for notifications. Apple doesn't allow a persistent connection except through their own notification framework. 2. In either case Signal doesn't send message contents through the notification framework (not even encrypted). Once Signal receives a notification the ap…

> Apple doesn't allow a persistent connection except through their own notification framework. How can iOS not allow persistent connections at all? How would a long download work or a call in the background work at all? > Regardless when signal shows the contents of your message in the notification menu of your device your device keeps a record on your device of that message content. How is that not treated as a back…

1. I'm not an iOS dev, but I know they have a specific framework for doing calls (CallKit I think), so you'd be using specific APIs that allow for a persistent connection for that purpose. Probably something similar for downloads. But generally iOS kills apps running in the background after a while so there's no way to persist an open connection indefinitely.

2. To be clear it's my understanding that the notifications weren't exfiltrated off the device. The notifications are stored in a database on the device that iPhone and can only be accessed by unlocking the phone. So I wouldn't call it a backdoor. Both Android and iOS retain notifications in a database, in Android you can disable it, I don't know about iOS.

Re: FBI used iPhone notification data to retrieve deleted Signal messages

#297

Earlier quoted context omitted.

So in that case, the system has access to the plaintext, therefore the Alphabet boys have access to it as well. Unless, of course, you believe Apple isn't cooperating with them. Am I missing something here? Maybe I'm missing a subtle detail.

A system like the one in "my phone's operating system". Do you assume that "Alphabet boys" have access to all parts of all Android file systems of all the phones ever produced?

I think the confusion here is that Signal does in fact encrypt the notification in transit [1]. The FBI had access to the user's unlocked iPhone and went through the notification history on the device. The issue the user faced is that even though they deleted the signal app they were unaware that iOS (and Android by default) retain a database of past notifications even after they're dismissed from the notification pane.

[1] Well actually they just send a blank notification, the signal app then reaches out to the signal server for the actual encrypted message content when it receives the empty notification.

Re: FBI used iPhone notification data to retrieve deleted Signal messages

#298

Earlier quoted context omitted.

That would drive me nuts. I do not want a banner permanently on I cannot remove. And before someone suggests it: If the banner can be removed, you’re back to having lots of complaints for users that did not realise they turned off notifications.

Doesn't have to be prominent and doesn't even have to be a banner. The ultimate point is to make it hard to reenable by accident, and to not make it annoying. Lots of ways to do that.

True. Lots of ways to do it wrong too. I have seen this done wrong significantly more often than right.

Anyway, I agree it’s worth a try.

Re: FBI used iPhone notification data to retrieve deleted Signal messages

#299

Putting on my user hat... "OK. Signal has forward secrecy. So messages are gone after I receive them. Great!" Oh, you didn't turn on disappearing messages? Oh, right, then forensic tools like Cellebrite can get them. You have to turn on disappearing messages. The default is off. Oh, you did turn on disappearing messages? We send the messages in notifications. So the OS can keep them. Turns out Apple was doing that. T…

We send the messages in notifications. So the OS can keep them. Turns out Apple was doing that. There is an option you can turn on to prevent that. It is off by default.

At least on my iPhone the default is to preview messages only when unlocked [0]. This user went out of their way to show previews in a locked state which meant it was vulnerable by digital acquisition without unlock code.

[0] https://files.catbox.moe/3gwjoy.png

Re: FBI used iPhone notification data to retrieve deleted Signal messages

#300

"However, it appears the defendant did not have that setting enabled, which, in turn, seemingly allowed the system to store the content in the database." "[A]llowing the system to store the content in the database" where a third party, such as Apple or a government, can access it is the default Only a small minority of users know about settings and how to change them. The vast majority of users do not change default…

Imagine a parallel universe where stories about use of personal computers were written from a different perspective. For example, "However, it appears Apple's system uses a default setting which, in turn, seemingly allowed it to store the defandant's content in Apple's database" instead of "However, it appears the defendant did not have that setting enabled which, in turn, seemingly allowed the system to stoire the c…

*store
Post reply on HN