Live data from Hacker News

FBI's ability to legally access secure messaging app content and metadata [pdf]

propertyofthepeople.org

211–220 of 474 posts

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#211

Now I just have to get my friends and family to use Signal.

The best advice I have to give to get people to switch is showing that you have cross platform capabilities. Essentially everyone can have the features of iMessage/WA: full resolution images and videos, responding to messages with emojis (WA doesn't have), stickers (unfortunately you have to grab from signalstickers.com instead of in-app), voice and video calling, etc. If Apple didn't have such a closed ecosystem then I think it would be harder to get people to switch. In this respect, Signal is more feature rich than anything else (except Telegram, but Telegram doesn't have the same security and isn't trustless).

I think the common mistake is trying to convince people with the security. Use that as a bonus, not the main feature. You're talking geek to people that don't speak geek (convince geeks with these arguments, not mom and dad). I also suggest strong arming people and using momentum (if 4 people in a group of 5 have Signal, switch the group to Signal. Or respond to WA messages on Signal).

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#212

Now I just have to get my friends and family to use Signal.

I've had surprisingly good luck with strong-arming people into switching. The important part is having their trust, if they don't believe you they won't listen. The next part is to make simple, verifiable, and non-technical arguments for switching. Believe it or not, almost everybody is willing to take small steps if they're free. Instead of rambling on and on about "end to end encryption" or "double-ratchet cryptogr…

Also, a big one that works for me (especially iPhone users, which are the hardest to convert): "You can send full quality images and videos to Android users." The fact that Apple shots themselves in the foot is an advantage to Signal.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#213
post #82

Earlier quoted context omitted.

Telegram is encrypted OVER THE WIRE and AT REST by default with strong encryption no matter what you do. It's E2EE if you select private chat with someone. Lots of FUD out there there about Telegram not being encrypted that's just not true. There's nothing either side can to do send a message in clear text / unencrypted.

"Encrypted OVER THE WIRE and AT REST" means that telegram has easy and unfettered access to chat logs. So they can give it up to authorities. (I don't argue that they DO, just that they very much CAN). This is proven by an extremely simple experiment: you log in on your new phone, enter password and instantly see all chats. Another simple experiment points that chats are unlikely to be even encrypted at rest is that…

It kinda depends on if images and videos are encrypted separately and only indexed at first.

How much data there are on your chats? 1 megabyte is around one thick book in plaintext.

AES-CBC as example method decrypts more than 2 gigabits per second with hardware opcodes (2012 processor), for example if we look this data https://www.bearssl.org/speed.html

It is impossible to say based on delay when searching plaintext on this level whether there is encryption.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#214

Earlier quoted context omitted.

To err on the side of caution, it's best to make all your passcodes themselves an admission to a crime.

"Your honor, the state agrees to not prosecute on any information inferrable from the text of the password." "Understood. The defendant's Fifth Amendment right to protection from self-incrimination is secured. As per the prior ruling, the defendant will remain in custody for contempt of court until such time as they divulge the necessary password to comply with the warrant."

I don't know why you're being downvoted. For a start, if it was a third party that had the passcode and refused to divulge it they can be held in jail until they release it, e.g. if your wife knows it. (There are many cases where people have been sentenced to years or decades in prison for not testifying)

If it is you not divulging your own passcode, then legally the judge can't give you contempt, but in reality they could give you contempt until you fought it through the appellate court. Contempt is a special type of thing - certainly here in Illinois you have no right to a jury trial on contempt charges. You're just fucked.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#215
post #97

Earlier quoted context omitted.

I switched to signal and got few people to switch too, then they started their shit coin(MOB). IMO Signal Messenger is just a way for that company to reach their shit coin goals. Uninstalled and never recommending that again.

I remember many people being pissed off when these features were announced some months ago. As far as I can tell, nothing really happened afterwards. I use Signal on a daily basis and haven't noticed any coin-related functionalities. Either they were canceled, haven't been released yet or they're just buried somewhere deep and not advertised. Do you have a different experience?

MOB is in beta and I think getting moved (if not already) to main soon. But it is non-intrusive and you won't notice it unless you look for it. People are just complaining about a feature that you have to look for. I'm not a fan of MOB and how the situation was handled, but I also think the reactions people are having are a bit over the top.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#216
post #162

This seems like a good place to say that I strongly recommend Yasha Levine's Surveillance Valley book ( https://www.goodreads.com/book/show/34220713-surveillance-va... ) where he suggests that all of this is working as intended, going all the way back to the military counter-insurgency roots of the arpanet first in places like Vietnam, and then back home in anti-war and leftist movements. The contemporary themes that…

Signal isn't funded by the military, by OTF/BBG, or any branch of the USG government. People who claim otherwise are confused (deeply) about a program OTF ran that sponsored third-party security reviews and development projects (summer-of-code style), none of which was mediated through OTF --- it was just a bucket of money.

You should be extremely skeptical about people who bring OTF/BBG up in these discussions. I have complicated feelings about Tor stemming mostly from culture and effectiveness concerns and would push back on claims that it's co-opted by the Navy or corporate interests, but at least I can see a clear (if silly) line connecting Tor to these supposed conflicts of interest.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#217

Earlier quoted context omitted.

I remember many people being pissed off when these features were announced some months ago. As far as I can tell, nothing really happened afterwards. I use Signal on a daily basis and haven't noticed any coin-related functionalities. Either they were canceled, haven't been released yet or they're just buried somewhere deep and not advertised. Do you have a different experience?

It's in beta, you can enable it in settings. It's still a pain to buy MOB in the US so it's not that usable in the states. It would have been interesting to me if they just used Zcash instead of rolling their own, but I'm not sure what's supposed to be special about MOB vs. Zcash. I also don't think it's that big of a deal.

I'd love Zcash (forced private transactions). But honestly I'd also like if we could use different currencies. My dream was that you could send cash and they would just use MOB as the intermediate transaction (so your bank would just see a transaction to/from Signal and not who you were sending/receiving to/from). But that also has technical challenges and legal issues so I understand why not. I think a multi-currency wallet is the next best option imo.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#218

Earlier quoted context omitted.

My advice if you’re not on the level where three letter agencies are actively interested in your comings and goings: - Use a strong pass phrase - Enable biometrics so you don’t need to type that pass phrase 100 times per day - Learn the shortcut to have your phone disable biometrics and require the pass phrase so you can use it when police is coming for you, you’re entering the immigration line in the airport etc. -…

In most cases you are going to want to separately passphrase your messaging stuff so it is locked up when you are not using it. That makes every thing else a lot easier. For example, there is a Signal fork that supports such operation: * https://github.com/mollyim/mollyim-android

So you're saying I should have to type a secure passcode every single time I want to read or send a message on my phone?

No thanks.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#219
post #136

Earlier quoted context omitted.

Apple should allow for 2 PWs, one the real PW, the other triggers a "self-destruct" mode. Knowing that is possible law enforcement would then hesitate to ask.

using such a self-destruct mode would be a certain way getting yourself charged with destroying evidence/contempt of court/... though.

This would be difficult to prove. They would have to know for certain the evidence was on there to begin with. I don't see the prosecutor easily meeting their burden of proof on this charge.

This is how the statute is worded here in Illinois:

"A person obstructs justice when, with intent to prevent the apprehension or obstruct the prosecution or defense of any person, he or she knowingly commits any of the following acts: (1) Destroys, alters, conceals or disguises physical evidence."

Ugh. It's a vague law. I don't even know how they would prosecute that for virtual evidence held on a device that they didn't already have a view inside of.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#220
post #162

This seems like a good place to say that I strongly recommend Yasha Levine's Surveillance Valley book ( https://www.goodreads.com/book/show/34220713-surveillance-va... ) where he suggests that all of this is working as intended, going all the way back to the military counter-insurgency roots of the arpanet first in places like Vietnam, and then back home in anti-war and leftist movements. The contemporary themes that…

Ulbricht was caught via poor OPSEC and not via a Firefox/Tor 0day afaik. Though there was/is speculation that a Firefox/Tor 0day was used to bring down some Tor markets and possibly to locate the Silk Road's server. Silk Road 2.0 was brought down in like a few months, which could indicate such a 0day existed. Or that it was ran by some former Silk Road staff members who got doxed when Silk Road 1.0 was shut down.
Post reply on HN