Live data from Hacker News

FBI's ability to legally access secure messaging app content and metadata [pdf]

propertyofthepeople.org

321–330 of 474 posts

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#321

Earlier quoted context omitted.

"threat assessment' coordinator from my workplace" "I feared that I may lose my job." I understand that police/FBI have to conduct investigation. What dont understand is involvement of the employer , it's extremely disturbing - you have not been convincted, you have not been charged, you are not even a suspect or accused of anything at this point - how is your private life the business of your employer? Why is your p…

You deserve to be always assumed innocent until proven guilty, and you will have to be proven guilty to be found guilty, and realistically speaking, those premises are extremely technical.

You don't have to be found guilty to be punished, lookup "case load". That can keep you on probation and monitoring as long as they want to draw out the case and the whole time you are required to make monthly payments or risk going to jail.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#322

Earlier quoted context omitted.

But they have to fake the voice, if I call the other person and say "my emoji sequence is this, this and that" for the other person to verify and vice-versa.

Person A calls you. I intercept the call, so person A is calling me , and then I call you (spoofing so I look like Person A). When you pick up, I pick up, then I transmit what you're saying to Person A (and vice versa). How do you know I'm intercepting the transmission? Does the emoji sequence verify the call , perhaps?

The emoji sequence represents the secret key exchange between you and the other party. If you intercept the call, you are making one key exchange with person A, and another key exchange with person B. Due to the mathematics involved, there is no way for you to force both key exchanges to yield the same result.

For a "standard" DH key exchange it would be possible to brute force the emoji sequence to be the same (since it's too short to be resistant to brute forcing), but the protocol that Telegram uses specifically defends against that by having both sides commit to their share of the key ahead of time, so they cannot try different numbers.

https://core.telegram.org/api/end-to-end/video-calls#key-ver...

So person A and person B are going to see different emojis no matter what you do. To fake a phone verification while performing a main-in-the-middle attack you'd also have to fake their voices to each other. That's hard.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#323

Earlier quoted context omitted.

> That's all he said to the interviewer And then the next day, he clarified: Reporter: "Should there be a database or system that tracks Muslims in this country?" Trump: "There should be a lot of systems, beyond databases. I mean, we should have a lot of systems." And then he tried to backpedal. Decided it was a watch list, not a database, etc. Basically the usual shtick of his where he tries to say everything and no…

Again that's a generic response: > There should be a lot of systems, beyond databases. I mean, we should have a lot of systems Beyond databases. What does that mean? That could be analog systems, that could be anything not stored in a computer. Nothing to do with identification which would need a database. It's a generic answer to avoid a hypothetical. It's a nonanswer. He said nothing, not everything. You are attrib…

You're kind of quibbling over details. The below quote is already bad enough:

> "We’re going to have to look at the mosques. We’re going to have to look very, very carefully."

I already do not trust the person who has said that. Does it really matter if he proposed a full-fledged ID system? He still proposed monitoring mosques. He still proposed surveillance based on religious identity.

The correct answer to that question, "should Muslims be subject to special scrutiny" is a simple "no". I don't really get the debate about hypotheticals; this a question that does have a straightforward, right answer. And the implications here in regards to surveillance and ordinary people having stuff to hide -- those implications are all the same regardless of whether or not Trump actually proposed a literal database.

He was open to increased surveillance on Americans based on their religious identity, he didn't immediately shut the idea down.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#324

Earlier quoted context omitted.

Verification in band seems pretty meaningless, approaching security theatre.

Real privacy is too burdensome for most users, so they feel just fine if the service owner promises in a stern voice that their chats are really secure . It is not necessary to provide real security, do fingerprint verification, etc if the users are already happy with the level of security they are promised.

The emoji comparison thing is mathematically solid. Assuming the clients aren't backdoored (and the Telegram client is open source, so that's not that easy), there is no way for an attacker to make both sides show the same emoji. If they want to convince two users that they have en E2EE connection while performing a man in the middle attack, they'd have to fake their voices to each other to change what emoji sequence they each read out. That's hard, and therefore this is real, meaningful privacy.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#325

Earlier quoted context omitted.

It is widely known and confirmed by Telegram themselves that your messages are encrypted at rest by keys they possess. This is a similar process to what Dropbox, iCloud, Google Drive, and Facebook Messenger do. Your files with cloud services aren’t stored unencrypted on a hard drive - they’re encrypted, with the keys kept somewhere else by the cloud provider. This way somebody can’t walk out with a rack and access us…

How do they provide near-instant full text search on server side if the chats are "encrypted at rest"?

Encrypted at rest means the data is encrypted as stored on disk, not that they do not have access to the keys. That would be end-to-end encryption.

What Telegram claims to have done is set this up in a way that makes it very hard for a single party/state to get these keys. It's not possible to make this completely impossible (if you have a server processing user data, it will have the keys loaded at some point, and there is always some way to physically attack it), but it is possible to make it very hard (physical tamper detection on the servers, secure boot tied to machine identity credentials required to access key material, etc - it's hard, but not impossible, to make this too difficult for any nation state to bypass). We don't know how good their set-up is, but it's certainly possible to do a good job at doing what they claim to be doing.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#326

They left off one very popular messenger, SMS: * Message content: All * Subpoena: can render all message content for the last 1-7 years * 18 U.S.C 2703(d): can render all message content for the last 1-7 years * Search warrant: can render all message content for the last 1-7 years * Vague suspicion plus a small fee to the carrier: can render all message content for the last 1-7 years

Source is a few years old, but I suppose we can make another FOIA request to find out how long carriers store text messages these days - it was basically 0-5 days a decade ago: https://www.nbcnews.com/technolog/how-long-do-wireless-carri...

Idk... back in the mid 2000s my parents managed to get a transcript of all of my (minor) sister's SMS messages for a few months back (as part of a billing dispute).

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#327

Earlier quoted context omitted.

> It's (scarily) interesting that they react with actual personal attendance based purely on a very limited set of electronic information. Either their intel is better than they let on and didnt think they would be walking into an ambush or they are more stupid than we think.

Actually, I think they had no intel. You NEED intel for a judge to order a subpoena—and if a subpoena was issued, the ISP would open their firehose, and overwhelm the FBI with evidence suggesting that there’s nothing to investigate. And having visited extremist sites a handful of times—even if advertantly—is probably not going to meet the threshold for a subpoena. If the FBI visited me and casually asked about my web…

> Then again, I can’t even fathom the upside for the FBI.

The upside is power.

You yourself said as much: "If the agent was accompanied with someone from my employer, I would eagerly cart up every single device in my home and offer to carry it out to their vehicle."

You fear them. Rightly so. The FBI has incredible power, backed by the full might of corporate media. To cross them is to be crushed.

Why would they need a warrant, when Apple and Google climb over each other volunteer every scrap of your private information? Why take the time for a trial, when justice can more efficiently be served by both your employer and your union gleefully ruining you financially upon request?

People have been demanding[1] this for years. Now it's here.

[1] https://xkcd.com/1357/

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#328

Earlier quoted context omitted.

Real privacy is too burdensome for most users, so they feel just fine if the service owner promises in a stern voice that their chats are really secure . It is not necessary to provide real security, do fingerprint verification, etc if the users are already happy with the level of security they are promised.

The emoji comparison thing is mathematically solid. Assuming the clients aren't backdoored (and the Telegram client is open source, so that's not that easy), there is no way for an attacker to make both sides show the same emoji. If they want to convince two users that they have en E2EE connection while performing a man in the middle attack, they'd have to fake their voices to each other to change what emoji sequence…

Telegram can potentially perform mitm at any time and generate matching emoji images for both sides of conversation, since you can't really trust the app code to be the same they put on GitHub. If you've built it yourself, that'd reduce the risk, but nobody does that because blind trust is much more easy.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#329

Some FBI agents came to my house once and told me that my home Internet had been used to visit Islamic Extremist websites. They brought a local police office with them and a 'threat assessment' coordinator from my workplace. They asked me if my family was Muslim and wanted to know if we had been radicalized. We are not religious (at all). We do not attend church, synagogue or mosque. We are lower middle class white A…

Imagine being a muslim in such case. Trying to convince them that this can be a mix-up ( which is possible easily) won't be successful.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#330

Earlier quoted context omitted.

You deserve to be always assumed innocent until proven guilty, and you will have to be proven guilty to be found guilty, and realistically speaking, those premises are extremely technical.

You don't have to be found guilty to be punished, lookup "case load". That can keep you on probation and monitoring as long as they want to draw out the case and the whole time you are required to make monthly payments or risk going to jail.

In the US, the process IS the punishment.
Post reply on HN