Live data from Hacker News

Grand jury subpoena for Signal user data, Central District of California

signal.org

11–20 of 618 posts

Re: Grand jury subpoena for Signal user data, Central District of California

#11
post #8

surely signal has at least the IP address used to connect to their service? aren't they by law required to log that?

No, why would they be? Just because everyone else logs more info than they should doesn't mean everyone has too.

Re: Grand jury subpoena for Signal user data, Central District of California

#13
>Because everything in Signal is end-to-end encrypted by default, the broad set of personal information that is typically easy to retrieve in other apps simply doesn’t exist on Signal’s servers.

The E2EE in Signal only protects the actual content of messages. In the case where Signal takes an assertive action, and the users are not paying any attention to their "safety numbers" (probably the most common case) they could in theory get message content with a MITM attack.

With an less assertive action (simply saving the data) Signal could get access to things like contacts and phone numbers.

Tutanota and Protonmail have both been forced in the past to take assertive actions to retain data as a result of legal warrants. Does American law even allow such warrants? If not then perhaps the USA is underrated as a place to base privacy oriented services.

Re: Grand jury subpoena for Signal user data, Central District of California

#14

The latest installment in the "Government doesn't understand math" series

I think that’s uncharitable. Everyone is going through the motions required of them, and this is the public demonstration of those mechanizations (although Signal is a bit cheeky, which is fun). The next step would be government requiring, through legislation, more invasive logging and data collection (Australia and parts of Europe have already seen the beginnings of this discussion) of messaging apps (“we’ve asked f…

Isn't this what happened to Protonmail? They were required by legal order to start logging activity for a specific group of users. It's not outside the realm of possibility that the govt could try to force a company to either start logging Signal metadata or provide a backdoored app to a user. Not that it would necessarily work, but I do expect them to try at some point.

Re: Grand jury subpoena for Signal user data, Central District of California

#15
Reminder that this does not hold true for Apple's fake "end to end encrypted" iMessage: iCloud Backup, which is not end to end encrypted, uploads all of your iMessages* to Apple each night in a format that Apple can read without you (and turn over to the state upon legal demand such as this).

Note that disabling iCloud Backup won't help you, as it's turned on by default and everyone else you iMessage with will be leaking your conversation plaintext to Apple for you.

Disable iMessage. Use Signal exclusively.

* if you use Messages in iCloud, iCloud Backup instead backs up the cross-device sync key instead of the iMessages themselves, which means Apple gets your iMessages in real time as they sync between your iCloud devices, instead of once per day

https://mobile.reuters.com/article/amp/idUSKBN1ZK1CT is why fake pro-privacy Apple will never be able to run a story like Signal has here today.

Re: Grand jury subpoena for Signal user data, Central District of California

#19

Reminds me to donate to Signal again

Speaking of donations (a guy from a food bank whom I see in the Safeway parking lot didn't know this, so I think we can assume not everyone does):

Most "donate" pages do not allow for "donor-advised funds (DAF)." They assume you're giving it with your before-tax money and presumably taking a tax deduction for it.

In a DAF, which your financial institution surely offers, you can donate appreciated assets, e.g. your FAANG stock, and take the entire amount as a tax deduction. So if your 10 shares of Facebook (excuse me, "Meta") stock are at 322, you can take a deduction of $32,200 this year.

What's the catch? That money's gone, and you can't get it back. You can only "advise" your DAF to give it to a 501(c)(3) organization, which Signal is. There are no time limits.

The good part, though, is you can probably have your DAF give the money anonymously, so the charity can't bug you every time they're having a fund drive.

Post reply on HN