I thought the ACLU was more of a protection against smaller entities who didn't have funding/legal firepower?
Grand jury subpoena for Signal user data, Central District of California
21–30 of 618 posts
Re: Grand jury subpoena for Signal user data, Central District of California
#22Does anybody know if Apple's notifications are E2EE? I doubt that gov't doesn't have access to the push notifications...
Re: Grand jury subpoena for Signal user data, Central District of California
#23I actually believe that law enforcement has the legal right to subpoena information, with a judge's consent, while investigating criminal activity. This is exactly the solution to that problem. These platforms should want to know as little about you as possible.
Re: Grand jury subpoena for Signal user data, Central District of California
#24Just curious, why does signal have the ACLU respond for them? I thought the ACLU was more of a protection against smaller entities who didn't have funding/legal firepower?
Re: Grand jury subpoena for Signal user data, Central District of California
#25What I don't understand about the whole Signal E2EE model is that while your messages themselves may be encrypted, they are still sending push notifications over Apple's servers, which have to go through APNS. Often the entire message contents can be contained in the push notification. Does anybody know if Apple's notifications are E2EE? I doubt that gov't doesn't have access to the push notifications...
Re: Grand jury subpoena for Signal user data, Central District of California
#26What I don't understand about the whole Signal E2EE model is that while your messages themselves may be encrypted, they are still sending push notifications over Apple's servers, which have to go through APNS. Often the entire message contents can be contained in the push notification. Does anybody know if Apple's notifications are E2EE? I doubt that gov't doesn't have access to the push notifications...
Re: Grand jury subpoena for Signal user data, Central District of California
#27Earlier quoted context omitted.
This is why messaging apps need to be decentralized and built on top of protocols that cannot be censored or meaningfully monitored.
With enough effort, anyone can go to jail. America held a taxi driver for 17 years at Guantanamo Bay with no evidence. Tech won’t save you from the state. As always, if your threat model includes a state actor, you are going to have a bad time. For all intents and purposes, their resources are unlimited. Freedom is won in the courts and the legislature, not in the code (although tech is as useful tool for keeping gov…
Re: Grand jury subpoena for Signal user data, Central District of California
#28What I don't understand about the whole Signal E2EE model is that while your messages themselves may be encrypted, they are still sending push notifications over Apple's servers, which have to go through APNS. Often the entire message contents can be contained in the push notification. Does anybody know if Apple's notifications are E2EE? I doubt that gov't doesn't have access to the push notifications...
Re: Grand jury subpoena for Signal user data, Central District of California
#29>Because everything in Signal is end-to-end encrypted by default, the broad set of personal information that is typically easy to retrieve in other apps simply doesn’t exist on Signal’s servers. The E2EE in Signal only protects the actual content of messages. In the case where Signal takes an assertive action, and the users are not paying any attention to their "safety numbers" (probably the most common case) they co…
Re: Grand jury subpoena for Signal user data, Central District of California
#30What I don't understand about the whole Signal E2EE model is that while your messages themselves may be encrypted, they are still sending push notifications over Apple's servers, which have to go through APNS. Often the entire message contents can be contained in the push notification. Does anybody know if Apple's notifications are E2EE? I doubt that gov't doesn't have access to the push notifications...
I'm guessing here, but wouldn't they just push the e2ee message through APNS? Then decrypt client side. Or does Apple require plaintext messages for push notifications (that seems bad if they do)?