Live data from Hacker News

Grand jury subpoena for Signal user data

whispersystems.org

51–60 of 258 posts

Re: Grand jury subpoena for Signal user data

#51
post #11

Earlier quoted context omitted.

Only because they don't store it. They are able to choose to store it at any point; we can only rely on their honesty (and lack of compulsion). It's better to have a protocol in which there isn't any significant metadata to choose to store. I don't distrust them today, but I have no way of knowing what their future behaviour will be. I'd prefer not to have to trust.

Is this something OWS could be subpoena'd for? Or something that the government would just subpoena Google for? (I mean, given a phone number, can't you identify someone's Google Play account anyway? That sounds more useful.)

> Is this something OWS could be subpoena'd for?

Not by subpoena alone, but in theory a court order could order them to modify their software (server or client) to collect data. They could fight that court order, and in particular it seems like they'd have a good case on the grounds that such an order would destroy their entire business, but legally a court could at least attempt to issue such an order.

Re: Grand jury subpoena for Signal user data

#52
post #5

It'd be better, of course, if we didn't rely on Signal not storing all that metadata and instead used a protocol which made it impossible for anyone to be in a position to choose whether or not to store it. Unfortunately, the protocols that enable truly traffic–analysis-resistant messaging (I believe the Pynchon Gate[1] is currently the best-of-breed) tend to have increased latency and consume greatly-increased bandw…

Can someone explain how people are imagining protocols that do not to create / store metadata? This seems like something fundamentally impossible on a packet-switched network. After all, the data has a source and a destination, and goes through the infrastructure that's tappable (and in big part already tapped) by a state-level actor.

About the only thing that comes to my mind would be a digital equivalent to broadcasting a radio signal - a protocol, under which everyone receives all communication that's done over that protocol, but each person can only decrypt the part that's addressed to them directly. This would reduce the metadata to "who's broadcasting", without revealing the listener.

EDIT: Some back-of-the-napkin calculations on such broadcast protocol:

I took a look on my today's communication with my SO; rounding somewhat up, it would be ~100 messages of on average 50 characters, going in both directions. That gives, using 2 bytes for character and multiplying by 1.5 to account for protocol-related padding:

- 15000 bytes / user / day of a single conversation

Say this protocol has 1M user, that gives us:

(50 * 100 * 2 * 1.5 * 1000000) / (100010001000)

15 GB of data, spread over the whole day.

Seems manageable; especially if one would be to bucket it by e.g. hour by default, or less, if client is active and streaming data continously. Definitely a mobile bandwidth killer, though.

Re: Grand jury subpoena for Signal user data

#53
post #5

It'd be better, of course, if we didn't rely on Signal not storing all that metadata and instead used a protocol which made it impossible for anyone to be in a position to choose whether or not to store it. Unfortunately, the protocols that enable truly traffic–analysis-resistant messaging (I believe the Pynchon Gate[1] is currently the best-of-breed) tend to have increased latency and consume greatly-increased bandw…

What about Vuvuzela? Haven't thoroughly examined it, but it focuses on metadata-privary and -relative- scalability. web: https://vuvuzela.io/ repo: https://github.com/davidlazar/vuvuzela paper: https://davidlazar.org/papers/vuvuzela.pdf slides: https://davidlazar.org/slides/vuvuzela-sosp2015.pdf

Paper conclusion says the cost of running Vuvuzela is pretty high per month, so you would need a benevolent millionaire to make it happen.

As for signal what every prosecutor wants is metadata to show the court that user A was in communication with user B. The actual contents of the messages aren't important especially in a conspiracy case and user B is an informant, their word against yours plus metadata showing you communicating is good enough.

Besides forcing Signal to keep this metadata in the future, I wonder if they can just obtain it themselves by watching all traffic on their federated servers and timing it to discover communication networks.

Re: Grand jury subpoena for Signal user data

#54
post #5

It'd be better, of course, if we didn't rely on Signal not storing all that metadata and instead used a protocol which made it impossible for anyone to be in a position to choose whether or not to store it. Unfortunately, the protocols that enable truly traffic–analysis-resistant messaging (I believe the Pynchon Gate[1] is currently the best-of-breed) tend to have increased latency and consume greatly-increased bandw…

Can someone explain how people are imagining protocols that do not to create / store metadata? This seems like something fundamentally impossible on a packet-switched network. After all, the data has a source and a destination, and goes through the infrastructure that's tappable (and in big part already tapped) by a state-level actor. About the only thing that comes to my mind would be a digital equivalent to broadca…

A blockchain, of sorts...

Re: Grand jury subpoena for Signal user data

#55
post #9

Earlier quoted context omitted.

They would also be able to figure out what phone numbers it was communicating with, at what times and how often - they do the routing. We're relying on them not to store that metadata, which is the problem.

How would they be able to do that? Can you quote where in the article you got that and how that would happen? "Notably, things we don't have stored include anything about a user's contacts (such as the contacts themselves, a hash of the contacts, any other derivative contact information), anything about a user's groups (such as how many groups a user is in, which groups a user is in, the membership lists of a user's…

> If they don't store the contacts, or even a hash of the contact, how can you figure out who was talking to who?

Think of it like email. The body is encrypted, the subject is encrypted, any attachments are encrypted, but in order for them to route the message to the correct destination every message you send still has a "To:" field - their server still decides who to send the notification to.

They don't need to read the contacts or anything of the sort - they just read the "To:" field.

Re: Grand jury subpoena for Signal user data

#56
post #11
post #8

Earlier quoted context omitted.

What metadata? All they were able to produce was whether or not a phone number was associated with Signal at all , and the last time that phone number's account pinged the Signal service for any reason . They produced virtually no metadata to the investigation.

Only because they don't store it. They are able to choose to store it at any point; we can only rely on their honesty (and lack of compulsion). It's better to have a protocol in which there isn't any significant metadata to choose to store. I don't distrust them today, but I have no way of knowing what their future behaviour will be. I'd prefer not to have to trust.

Who owns Open Whisper Systems? I know Twitter bought WhisperSys, and with it Textsecure and Redphone though unsure who currently owns Open WhisperSys and it's products Signal (I assume Twitter does). Twitter is also rumoured for sale with Microsoft looking at aquiring it, so the future of Signal not keeping this metadata depends on who aquires it.

Re: Grand jury subpoena for Signal user data

#57

Earlier quoted context omitted.

Yeah, but I'm kind of tired of having to fight my own government every step of the way. I'd prefer a political solution at this point.

To me, the big question is what a trustworthy political solution would look like. I see this desire raised a lot, in contexts from HN to Valley-mocking pieces on how encryption is no substitute for advocacy. I completely understand the instinct, but every incarnation of it seems to struggle with the same question. Namely: how do you know when you've won? Restrictions against collecting data on US citizens didn't prod…

You never win. To use a controversial example: Who thinks abortion rights people "won" with Roe v Wade? Their opponents have been relentlessly chipping away at that "victory" ever since. When you make something a political issue, you are guaranteeing that it cannot be won with any kind of finality.

Re: Grand jury subpoena for Signal user data

#58
post #5

It'd be better, of course, if we didn't rely on Signal not storing all that metadata and instead used a protocol which made it impossible for anyone to be in a position to choose whether or not to store it. Unfortunately, the protocols that enable truly traffic–analysis-resistant messaging (I believe the Pynchon Gate[1] is currently the best-of-breed) tend to have increased latency and consume greatly-increased bandw…

What about Vuvuzela? Haven't thoroughly examined it, but it focuses on metadata-privary and -relative- scalability. web: https://vuvuzela.io/ repo: https://github.com/davidlazar/vuvuzela paper: https://davidlazar.org/papers/vuvuzela.pdf slides: https://davidlazar.org/slides/vuvuzela-sosp2015.pdf

Obfuscation is one approach, but it typically gets cracked pretty quickly or gets bogged down in trying to improve SNR.

Re: Grand jury subpoena for Signal user data

#59
post #53

Earlier quoted context omitted.

What about Vuvuzela? Haven't thoroughly examined it, but it focuses on metadata-privary and -relative- scalability. web: https://vuvuzela.io/ repo: https://github.com/davidlazar/vuvuzela paper: https://davidlazar.org/papers/vuvuzela.pdf slides: https://davidlazar.org/slides/vuvuzela-sosp2015.pdf

Paper conclusion says the cost of running Vuvuzela is pretty high per month, so you would need a benevolent millionaire to make it happen. As for signal what every prosecutor wants is metadata to show the court that user A was in communication with user B. The actual contents of the messages aren't important especially in a conspiracy case and user B is an informant, their word against yours plus metadata showing you…

The cost of running Vuvuzela is dominated by bandwidth, and the paper used AWS prices to estimate the cost; purchasing IP transit directly would lead to about an order of magnitude reduction in costs (still non-trivial, of course).

Re: Grand jury subpoena for Signal user data

#60
So, when is it going to be considered misconduct for Dana Boente and the (not so) honorable Theresa Buchanan to tack on gag orders for no good reason? How do we change that? Calling our representatives in Congress won't help. Signing petitions is laughable. I'm at a loss for how to change this as a regular citizen.
Post reply on HN