Live data from Hacker News

Evidence that the FBI can hack into private Signal messages on a locked iPhone

forbes.com

111–120 of 243 posts

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#111
post #7

How is it possible that the FBI has so much advanced stuff when I’ve never met a skilled developer willing to work for what the government pays? Are their tools developed by high paid contractors?

The gobertment does not need to use advanced stuff when they can just use coercion.

https://xkcd.com/538/

When the Roman Empire wanted something like water engineering or gold mining they found out who did it best, and then did invade the territory and enslave those who knew how to do it.

Steel traders from India will tell Romans it came from China so they did not invade it.

When the US three letter agencies want something from some company, they use a similar strategy: You are with us or against us. You can let us install backdoors in your software or you are a terrorist that support terrorists.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#113

Earlier quoted context omitted.

I've upvoted you but wanted to nitpick (sorry) - innocent unless proven guilty doesn't have the temporal connotations that 'until' has.

If we're going to nitpick I think HN is the place that this is acceptable, especially when done in a good manner. I do think you make a good point since "until" implies that anyone is guilty given enough time. I'll try to adopt this change into my vernacular. I updated my comment in an effort to acknowledge and support this idea.

> “ until" implies that anyone is guilty given enough time

Sadly, I think that’s considered a “feature” by modern law enforcement and judicial systems. Plea bargains and the sheer volume of laws that cannot possibly be understood by normal people make for a prosecutorial power balance that genuinely means everybody really is just “innocent until they decide to prove you guilty”.

The well known “Don’t talk to police” lecture is extremely on point here: https://youtu.be/d-7o9xYp7eE

Your _are_ guilty of something. If you come to the attention of the wrong LEO, they will find something to prosecute you for, and like Al Capone, they’ll perfectly happily send you to jail for tax evasion if they’ve decided but cannot prove you are guilty of something else.

That’s totally fucked up.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#114
post #100

Earlier quoted context omitted.

No they don't, they just force the police to do regular police work and infiltrate the group the old fashioned way rather than using mass surveillance.

They do. The reality is that there's plenty of non-secret, boring warrants which go nowhere because the police can't decrypt the traffic or read the phone memory (and here in Germany, they have less access to fancy tech). At the same time, an unprecedented amount of private conversation happens using phones, raising the stakes and the default expectation of privacy. The pendulum swung from insane dragnet surveillance…

Talking quietly at the local pub is resistant to all but the most sophisticated surveillance efforts too.

It's only very recently that people have been communicating over the internet, allowing the mass surveillance. All encryption does is return us back to the pre 1990s in terms of surveillance capabilities.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#115

Universal encryption is a defense against blanket vacuuming of communications for later offline analysis. Its a defense against a massive parallel MITM attack against the world's communications infrastructure. Its not a defense against targeted attacks of individual devices.

In addition to this, I frequently hear people talk about how Signal would prevent monitoring of groups like those that stormed the capital. As if you can create a secret communication channel that members of the public can join but the FBI is unable to infiltrate. Signal and E2EE stop dragnets, not targeted efforts. Which honestly is exactly what I want and seems like what we want in a free and open society. Monitori…

Fun fact for the UK: "UK police have a new tactic to circumvent strong iPhone encryption: steal the unlocked phone out of the criminal’s hand"

(https://9to5mac.com/2016/12/05/uk-police-have-a-new-tactic-f...)

I remember reading this a few years back. The title says it all. Why bother cracking codes etc when you can get a judge to sign THAT for you? :)

Going through the PDF of the legal document, on page 10, the screenshots have a description of the "Source extraction" (point): "..../private/var/Containers/Shared/AppGroup//telegram-data/account/postbox/db/db_sqlite"

I got so many questions.. I believe Telegram does NOT encrypt group chats. And the default setting is that it does NOT encrypt 1-1 chats. You have to jump the extra hoop (a couple of taps) to start a new and encrypted chat (you cannot encrypt an existing chat).

So.. the chat was not encrypted? So they 'just' managed to bypass iPhone's lock, and dump all the storage, look for messaging SQLITE files, read them. Are we sure they didn't get that data from iCloud (and hiding it - with permission?). Page 11 writes: "Several videos from his iCloud depict him apparently showing off his cash." Could the authorities have gotten an automated backup from iCloud, the guy was using an unencrypted Telegram chat, so basically not much hacking took place?

Side note: big Supernatural fan here - page 10, the second 'blue' message writes "..Poughkeepsie". In the Supernatural universe "Poughkeepsie" is the Winchesters' secret distress signal to each other meaning that something is wrong and they are to drop everything and run.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#117
post #100

Earlier quoted context omitted.

They do. The reality is that there's plenty of non-secret, boring warrants which go nowhere because the police can't decrypt the traffic or read the phone memory (and here in Germany, they have less access to fancy tech). At the same time, an unprecedented amount of private conversation happens using phones, raising the stakes and the default expectation of privacy. The pendulum swung from insane dragnet surveillance…

Talking quietly at the local pub is resistant to all but the most sophisticated surveillance efforts too. It's only very recently that people have been communicating over the internet, allowing the mass surveillance. All encryption does is return us back to the pre 1990s in terms of surveillance capabilities.

Exactly. Or going for a walk in the forest - many of these conversations are now happening online.

On the flip side, even ordinary phone calls and messages are often encrypted by default now, which used to be much more readily available to law enforcement.

It's such an interesting situation, society-wise.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#118
post #100

Earlier quoted context omitted.

No they don't, they just force the police to do regular police work and infiltrate the group the old fashioned way rather than using mass surveillance.

They do. The reality is that there's plenty of non-secret, boring warrants which go nowhere because the police can't decrypt the traffic or read the phone memory (and here in Germany, they have less access to fancy tech). At the same time, an unprecedented amount of private conversation happens using phones, raising the stakes and the default expectation of privacy. The pendulum swung from insane dragnet surveillance…

> and here in Germany, they have less access to fancy tech

Interestingly, there’s a sort of perverse incentive going on here. If cops and governments hadn’t historically abused phone taps and sms interception - then strongly encrypted e2e tech like Signal wouldn’t have become “necessary” in the minds of non criminal users concerned about privacy, and we probably wouldn’t have had well known and widely used services/platforms like Signal and Telegram already in place for people to flock to when WhatsApp made their privacy blunder.

I’m sure GreyKey and NSO are perfectly happy with a cyber arms race requiring cops to buy more and more expensive “fancy tech” every year...

Interesting times indeed.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#119
post #21

If you own the phone, the messages are decrypted. This seems to be more about the phone access than anything to do with Signal, right?

Of course. All these articles and "criticisms" of Signal started popping up right after the recent WhatsApp mini exodus. What a coincidence.

If you raise Signal's profile then I think you can expect some half-informed tech journalists to start writing about it without fully understanding it.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#120

Earlier quoted context omitted.

This is why I keep a "universal hammer" at my desk. If the gov boys walk in all I have to do is use it on my phone / laptop. Problem solved. Thinking about upgrading to a small commercial grade shredder or microwave.

> Problem solved. Now you have a new problem: Destruction of evidence.

IANAL, but my understanding is that obstruction of justice via spoliation, tampering, or destruction of evidence is a charge that requires your investigation to have already begun, the raid to have already started, or the arrest to have been made, and that you are free to destroy any of your own property prior to these events.

Specifically, you need to knowingly be the subject of an investigation. I'd assume destroying the phone when you see the cops coming but before you've seen the warrant would be a grey area. Please, lawyers, clarify.

Post reply on HN