Live data from Hacker News

On Confirmed Assumptions or, Not Trusting Google is a Good Idea

anarchism.is

211–220 of 230 posts

Re: On Confirmed Assumptions or, Not Trusting Google is a Good Idea

#211
post #64
post #62

Earlier quoted context omitted.

people lawfully present in the US, not just citizens.

My understanding as well; noncitizens on US soil are protected by the Fourth Amendment; outside of actual border crossings, the USG cannot search them without a warrant or probable cause.

I would love to see evidence that non-citizens on US soil, as a class, are protected by the Fourth Amendment.

It only took ten seconds on google to note that the NSA apparently doesn't agree with you.

http://www.nsa.gov/sigint/faqs.shtml#sigint4

    Federal law and executive order define a U.S. Person as:
        a citizen of the United States;
        an alien lawfully admitted for permanent residence;
        an unincorporated association with a substantial number
              of members who are citizens of the U.S. or are
              aliens lawfully admitted for permanent residence; or
        a corporation that is incorporated in the U.S.

I doubt that "permanent residence" includes H1-b workers, or other work visas, and I very strongly doubt that it includes people on business or pleasure trips.

The NSA's language seems to derive very closely from FISA (the law itself, title 50 chapter 36),

http://uscode.house.gov/download/pls/50C36.txt

..which in 1801 (i) has similar language, though it clarifies that the definition of "lawfully admitted for permanent residence" should be taken from "section 1101(a)(20) of title 8"

According to http://www.law.cornell.edu/uscode/text/8/1101 , here is that section:

(20) The term “lawfully admitted for permanent residence” means the status of having been lawfully accorded the privilege of residing permanently in the United States as an immigrant in accordance with the immigration laws, such status not having changed.

I don't feel enlightened.

The EFF, in a surprising turn, claims that any legal resident is a US Person... normally I expect the EFF to (a) do their research correctly, and then (b) point out the worst-case scenario. This appears to be neither. https://ssd.eff.org/foreign/fisa

IANAL (though sometimes I play one on HN), TINLA.

Re: On Confirmed Assumptions or, Not Trusting Google is a Good Idea

#212

Earlier quoted context omitted.

> Compare this to Apple's iMessage or FaceTime - Apple > cannot decrypt the contents of the messages, and > therefore cannot give the contents to the government. This is not correct. First, when you buy a new iPhone, the way you authenticate yourself is by entering your Apple ID and password. Once entered, your new device will begin receiving iMessage data. This means that Apple is capable of provisioning a virtual d…

First, when you buy a new iPhone, the way you authenticate yourself is by entering your Apple ID and password. Once entered, your new device will begin receiving iMessage data. This means that Apple is capable of provisioning a virtual device with your credentials, which will receive your messages. From there, they can be either stored or forwarded to third parties. Wrong. As others who have examined the protocol hav…

  > As others who have examined the protocol have noted,
  > your password is used to unlock a keybag on the device
  > itself. Apple doesn't have your password (only a secure
  > hash) and therefore can't unlock the keybag.
Re-read what I wrote, and think about what it means.

Setting up iMessage on a new iPhone does not involve copying a "keybag" (sic), inputting a private key, or any other form of strong client-side authentication. All you have to do is sign into the device using your Apple ID, and you can then receive iMessage messages.

If there were any additional barrier preventing Apple from provisioning iMessage entpoints, iPhone users would not be able to activate iMessage with only their Apple ID.

Do you understand now?

  > Yes, the binaries of any system can contain arbitrary
  > spyware or be infected with such at any stage from
  > development through to decommissioning. Open source is
  > no absolute protection against that.
It's not an absolute protection, but it is very good protection.

Staying inside your house is not absolute protection against being eaten by bears, but your chances of being eaten by bears are much much lower than if you walk around Yellowstone dressed in steak.

Re: On Confirmed Assumptions or, Not Trusting Google is a Good Idea

#213
post #48

Earlier quoted context omitted.

The legal theory that the bill of rights only applies to US citizens is dangerous and wrong. It applies to actions of the United States government. It is a list of things they may not do.

No, tptacek is right... if you are a foreigner living abroad, the bill of rights does not apply to you: In 1957, the court changed its position, overturning decades of precedent to declare that American citizens are in fact protected against U.S. government misbehavior by the Bill of Rights even outside the country. Unfortunately for the rest of the world, the court limited its ruling to U.S. citizens. Foreigners rem…

"No, tptacek is right... if you are a foreigner living abroad, the bill of rights does not apply to you:"

This is becoming abundantly obvious from where I sit, outside the US as a non-US citizen.

I wonder just how long it's going to take for non US businesses and governments to realise the consequences of that?

I look forward to the startup opportunities in what are currently considered "major player consolidated verticals" for non US based disruption?

Who's currently planning an ad network or web analytics service or auction site or microblogging service or social network or online retail conglomerate - all marketed to national government and non-US based businesses as "all data stored outside US jurisdiction, all data SSL/TLS with PFS on the wire to minimise consequences of interception", then lobby governments to advice citizens to switch away from "US monitored services" and for corporations to forbid use of "US monitored service" via corporate networks.

It's all but impossible to break into markets dominated by Google/eBay/Amazon/Facebook/Twitter - but what if the Australian government started recommending people use a secure local alternative, and big companies started blocking those services at the firewall?

Re: On Confirmed Assumptions or, Not Trusting Google is a Good Idea

#214

Earlier quoted context omitted.

First, when you buy a new iPhone, the way you authenticate yourself is by entering your Apple ID and password. Once entered, your new device will begin receiving iMessage data. This means that Apple is capable of provisioning a virtual device with your credentials, which will receive your messages. From there, they can be either stored or forwarded to third parties. Wrong. As others who have examined the protocol hav…

> As others who have examined the protocol have noted, > your password is used to unlock a keybag on the device > itself. Apple doesn't have your password (only a secure > hash) and therefore can't unlock the keybag. Re-read what I wrote, and think about what it means. Setting up iMessage on a new iPhone does not involve copying a "keybag" (sic), inputting a private key, or any other form of strong client-side authen…

   Re-read what I wrote, and think about what it means.
I think it means you have a false belief about the limits of the system.

   If there were any additional barrier preventing Apple from provisioning iMessage entpoints, iPhone users would not be able to activate iMessage with only their Apple ID.
Wrong. Apple doesn't have your password. Only a hash. Verifying against the hash allows apple to add another device to the backend but does not unlock the keys to the message history. Only the password does that.

There is some understanding about how the protocol works here: https://news.ycombinator.com/item?id=5493514

There are other sources around the net that you can refer to to understand more about how such a protocol can be built, but I don't have a lot of faith in you as a conversation partner now that you've demonstrated that you can't be bothered to inform yourself before responding incorrectly with condescending certainty.

Re: On Confirmed Assumptions or, Not Trusting Google is a Good Idea

#215

Earlier quoted context omitted.

> As others who have examined the protocol have noted, > your password is used to unlock a keybag on the device > itself. Apple doesn't have your password (only a secure > hash) and therefore can't unlock the keybag. Re-read what I wrote, and think about what it means. Setting up iMessage on a new iPhone does not involve copying a "keybag" (sic), inputting a private key, or any other form of strong client-side authen…

Re-read what I wrote, and think about what it means. I think it means you have a false belief about the limits of the system. If there were any additional barrier preventing Apple from provisioning iMessage entpoints, iPhone users would not be able to activate iMessage with only their Apple ID. Wrong. Apple doesn't have your password. Only a hash. Verifying against the hash allows apple to add another device to the b…

  > Verifying against the hash allows apple to add another
  > device to the backend but does not unlock the keys to
  > the message history
Isn't this what I've been claiming? If Apple can provision additional endpoints, they can provision a virtual endpoint which receives messages and forwards them to third parties.

Re: On Confirmed Assumptions or, Not Trusting Google is a Good Idea

#216

Earlier quoted context omitted.

Re-read what I wrote, and think about what it means. I think it means you have a false belief about the limits of the system. If there were any additional barrier preventing Apple from provisioning iMessage entpoints, iPhone users would not be able to activate iMessage with only their Apple ID. Wrong. Apple doesn't have your password. Only a hash. Verifying against the hash allows apple to add another device to the b…

> Verifying against the hash allows apple to add another > device to the backend but does not unlock the keys to > the message history Isn't this what I've been claiming? If Apple can provision additional endpoints, they can provision a virtual endpoint which receives messages and forwards them to third parties.

Doing that wouldn't provide access to the history. Unless they always do this for every single device, there is no mountain of data to analyze.

The point we are discussing is not whether iMessage provides perfect security. The point is that iMessage doesn't give Apple a stockpile of personal data that can be indiscriminately targeted at any time the way GMail can.

I'm not saying it's a panacea or arguing in favor of Apple. iMessage proves that Google could engineer a system to protect users privacy by not stockpiling data if they wanted to, which you have incorrectly denied.

Re: On Confirmed Assumptions or, Not Trusting Google is a Good Idea

#217

Earlier quoted context omitted.

> Verifying against the hash allows apple to add another > device to the backend but does not unlock the keys to > the message history Isn't this what I've been claiming? If Apple can provision additional endpoints, they can provision a virtual endpoint which receives messages and forwards them to third parties.

Doing that wouldn't provide access to the history. Unless they always do this for every single device, there is no mountain of data to analyze. The point we are discussing is not whether iMessage provides perfect security. The point is that iMessage doesn't give Apple a stockpile of personal data that can be indiscriminately targeted at any time the way GMail can. I'm not saying it's a panacea or arguing in favor of…

  > iMessage proves that Google could engineer a system
  > to protect users privacy
iMessage does not protect privacy, because Apple is capable of intercepting your messages messages and sending them to third parties. To be a private communications medium, it should be considered impossible for messages to be intercepted.

The only thing worse than a product that doesn't offer privacy is a product which claims to, but actually doesn't.

IMO, Apple's claim that iMessage is private is irresponsible because it endangers people who take that claim at face value.

Re: On Confirmed Assumptions or, Not Trusting Google is a Good Idea

#218

Earlier quoted context omitted.

Doing that wouldn't provide access to the history. Unless they always do this for every single device, there is no mountain of data to analyze. The point we are discussing is not whether iMessage provides perfect security. The point is that iMessage doesn't give Apple a stockpile of personal data that can be indiscriminately targeted at any time the way GMail can. I'm not saying it's a panacea or arguing in favor of…

> iMessage proves that Google could engineer a system > to protect users privacy iMessage does not protect privacy, because Apple is capable of intercepting your messages messages and sending them to third parties. To be a private communications medium, it should be considered impossible for messages to be intercepted. The only thing worse than a product that doesn't offer privacy is a product which claims to, but ac…

Any evidence of this? I had read and posted about the same, but more recently found an older discussion on HN (which, absurdly, I cannot find now) which explains in more detail how the end to end encryption actually works and does so in a way that Apple almost definitely cannot intercept the plaintext messages.

Re: On Confirmed Assumptions or, Not Trusting Google is a Good Idea

#219

Earlier quoted context omitted.

> iMessage proves that Google could engineer a system > to protect users privacy iMessage does not protect privacy, because Apple is capable of intercepting your messages messages and sending them to third parties. To be a private communications medium, it should be considered impossible for messages to be intercepted. The only thing worse than a product that doesn't offer privacy is a product which claims to, but ac…

Any evidence of this? I had read and posted about the same, but more recently found an older discussion on HN (which, absurdly, I cannot find now) which explains in more detail how the end to end encryption actually works and does so in a way that Apple almost definitely cannot intercept the plaintext messages.

See my first post in this thread.

Short version: Users can enable iMessage on their devices by signing in to their Apple account. Therefore, Apple is capable by themselves of configuring which devices receive messages from particular accounts. Therefore, Apple is capable of configuring a device you do not control to receive your messages.

Re: On Confirmed Assumptions or, Not Trusting Google is a Good Idea

#220

Earlier quoted context omitted.

Doing that wouldn't provide access to the history. Unless they always do this for every single device, there is no mountain of data to analyze. The point we are discussing is not whether iMessage provides perfect security. The point is that iMessage doesn't give Apple a stockpile of personal data that can be indiscriminately targeted at any time the way GMail can. I'm not saying it's a panacea or arguing in favor of…

> iMessage proves that Google could engineer a system > to protect users privacy iMessage does not protect privacy, because Apple is capable of intercepting your messages messages and sending them to third parties. To be a private communications medium, it should be considered impossible for messages to be intercepted. The only thing worse than a product that doesn't offer privacy is a product which claims to, but ac…

No modern computer can be constructed by an individual without trusting a corporation not to have coopted some part of the system. Therefore no communication system can exist that meets your criteria. (E.g. Because the CPU could be compromised)

Your argument is the equivalent of 'we can't trust any corporation'. It's a coherent position to take but it is extreme and doesn't lead to meaningful discussions about what is possible.

Post reply on HN