Live data from Hacker News

Grand jury subpoena for Signal user data, Central District of California

signal.org

501–510 of 618 posts

Re: Grand jury subpoena for Signal user data, Central District of California

#501
post #221
post #92

Earlier quoted context omitted.

This applies on every single app, and is quite irrelevant as you already trust Apple by using their closed source device. If they want your data, they sure get it.

Unless you only contact Signal users who have verified and compiled the client themselves, you put the same kind of trust in Signal, which specify what data is logged (phone numbers are stored hashed for discovery by other users). The same may or may not be true for Apple (I have no idea) but claiming it is irrelevant as an answer to a question about whether an _Apple_ technology is encrypted, is mind boggling to me.

I mean, there is always a root for the trust. In this case, the root is Apple. Signal is one leaf below. Compromising root compromises everything.

In this case, root being the device and OS, it has unrestricted access to everything happening by your actions. The data you see on your screen is processed by the CPU, developed by Apple, controlled by kernel, coded by Apple. The can access everything they want.

Re: Grand jury subpoena for Signal user data, Central District of California

#502

It’s easy so say net win for society is privacy. But it’s important to also acknowledge it does come at a cost — there exists criminal behavior that most reasonable people would agree is bad and should be stopped that may reach a dead end with services like Signal. In formulating your statement that examining criminal behavior is a problem, you are suggesting there shouldn’t be ways to uncover crimes.

It's not a dead end with Signal. But it requires field work, as they used to do 50 years ago. Now, cops and politicians want to solve all the problems from their desk. No, sorry, my freedom is not to be sold for their convenience. You want to catch a bad guy, you get a trained investigation team that follows people, that wires their house, that interrogates neighborhood, etc. Is it more work ? Yes. Is it more dangero…

50 years ago police would obtain a suspect's phone records. This has been part of criminal investigation for as long as phones have existed.

If you have someone being blackmailed or defrauded online, what "field work" are you suggesting here?

> "cops [...] want to solve all the problems from their desk."

This literally couldn't be more wrong.

Re: Grand jury subpoena for Signal user data, Central District of California

#503

Earlier quoted context omitted.

You prevent them from gaining power by winning debates against them and demonstrating to everyone why they're wrong. I mean have you actually seen the "science" used to claim even the existence of different races? It's all misleading statistics and pseudoscience. You group a bunch of people together based on geographical origin and then observe some differences in the averages between the two groups, ignoring that th…

Individuals who dared to make anthropological, social and genetic studies on ethnic groups were retaliating upon with great anger and were banished from academic life even if the scientific methodology was sound. No one dares to do such studies anymore so we can conclude that the "good" has won.

Unless I'm misinterpreting your angle, this sounds like a blatant, hysteric mistruth. Nearly every day I see studies where social and ethnic groups are used to partition and understand the population, particularly with COVID.

https://www.cdc.gov/mmwr/volumes/70/wr/mm7015e2.htm

So it depends what you mean. If you mean there are no studies done with such partitioning aimed towards the benefit of those groups, I call that bunkum.

If you mean studies are not sponsored where the outcome is of no societal value beyond reinforcing or justifying an established hegemony or excusing discrimination, then perhaps... and good.

Re: Grand jury subpoena for Signal user data, Central District of California

#504

Earlier quoted context omitted.

> This is why there should not be a single entity that runs the network. Make it fully decentralized with economic incentives for node operators. Just make the network work based on open protocols, where anyone can run a server that interoperates with others. (Matrix.) For the non-developer end-user, they can use one of the existing servers, who in theory could charge their users. Yes, it would be hard to maintain br…

So what you are proposing is TOR but with a twist to charge connections?

Actually, what OP is proposing is federation, like e-Mail.

Some people do pay for their e-Mail providers today...

Re: Grand jury subpoena for Signal user data, Central District of California

#505

Earlier quoted context omitted.

> This is exactly the solution to that problem. I could be wrong but I was under the impression that the way end-to-end encryption worked (like what Signal claims, I thought) was it was physically impossible for them to decrypt (handover decrypted data (aka your messages) to a court of law) because the public/private keys are impossible to crack and also not known by Signal. It sounds like this isn't the case whatsoe…

It takes extra effort to design a system with this little amount of data. Note that we only have Signal's word for some of this; they could in fact log every single time that you login, which would make the amount of data sent to the FBI much larger (and could be of importance to the case, for example, if the defendant had a dedicated Signal account for the crime that they only logged into at certain times). Then the…

> they could in fact log every single time that you login, which would make the amount of data sent to the FBI much larger

I guess you mean each time you connected to their server to retrieve messages? There is no "login" step, Signal doesn't have a log in process. Presumably a typical Signal client calls several times per day.

The record they provided says connection date and despite being supplied in milliseconds since the epoch the value appears to indeed represent a whole day not a specific time. So you're correct Signal could be lying and actually store the exact moment you last connected, for whatever that's worth, and we could not prove they don't have that info.

> Most E2EE communication protocols will see (and thus potentially log) the time and destination of every message you send

Signal doesn't know who sent messages among close friends, and optionally not anybody who sent messages to a sensitive account.

Let's take the example of a message I sent to my friend Chris. I know Chris, I've sent messages to him previously and he knows me, so I'm in his contacts list. As a result by default my Signal client keeps some "Sealed Sender" tokens for Chris. When I send a message to Chris, my client uses a token it learned from a previous conversation with Chris, but Signal doesn't know who I am, just that I have a valid token for sending messages to Chris. So it stores the message, and gives it to Chris. Chris's client can determine that this is a message from me, tialaramex, but the Signal service never knew who sent the message.

If one day Chris hates me and blocks me from sending messages, his client invalidates all Sealed Sender tokens, and begins issuing new ones to his other friends so they can continue to contact him.

Re: Grand jury subpoena for Signal user data, Central District of California

#506
post #500

Earlier quoted context omitted.

Do you have any source on that?

It's not exactly a secret and any discussion of Tor's history will immediately bring it up, but sure. > For the onion router to work properly, the Navy needed to step back from running it. A cloaking system is not useful if all the cloaks say “Navy” on them. “If you have a system that’s only a Navy system, anything popping out of it is obviously from the Navy,” Syverson says. “You need to have a network that carries…

Ah - wow, dang. I believed the cover-story that Tor was a side-project of a humanitarian org in the US gov that wanted to provide people in firewalled countries a way to access the wider internet - of course, Tor does do that (just as a nice side-effect, and to be fair, the US does benefit and encourage democratic (...and neoliberal) ideals worldwide as its in their own interests to).

...it's kinda like how we were all told that the 1950s-1970s space-launches with monkeys and other animals in them were for bio-scientific experiments when they were really just cover stories for launching spy-sats and military satellites.

Re: Grand jury subpoena for Signal user data, Central District of California

#507

Earlier quoted context omitted.

That already exists, it's called the Internet

The issue is the internet doesn't provide the required service for individuals to find each other directly. We need DNS for everyone, not just the rich...er those bothering to register a name. Make it GUID based, and let people contact each other by GUID instead of phone number. Preferably add privacy enhancing encryption too so that only those with your public key could decrypt your GUID DNS entry to then find your…

LDAP could have been that service - a distributed directory. I'm not sure why it didn't become universal.

OpenLDAP's a bugger to configure, and it's much more than you need for a simple directory. But ActiveDirectory is nearly omnipresent.

Re: Grand jury subpoena for Signal user data, Central District of California

#508
post #56

Earlier quoted context omitted.

As far as I understand Signal can't just save all the data because of how the app/server are architected: They use sealed sender: https://signal.org/blog/sealed-sender/ Private contact discovery: https://signal.org/blog/private-contact-discovery/ And a "Private Group System" which is supposed to keep group membership information from the server: https://signal.org/blog/signal-private-group-system/ Though of course th…

Sealed sender only means Signal doesn't know who sent a particular message. They have to know who the recipient is so they can deliver it. Like forging the "From:" address on an email. Except in the Signal case the IP address/port of the sender is unique to the user and if the recipient responds then the link between the users is made. The private contact discovery depends on an Intel SGX hardware enclave on their se…

You said

> The E2EE in Signal only protects the actual content of messages.

> [By] (simply saving the data) Signal could get access to things like contacts and phone numbers.

And the linked blog posts show that for a few years now they've been working on limiting their own access to this kind of data --- i.e. it's not as simple as just saving it (like e.g. WhatsApp is able to and most likely doing 100% of the time to build social graphs).

Now of course all of those things are likely vulnerable to some attacks, but that's another discussion and it doesn't change the fact that Signal doesn't have immediate easy access in the way you claimed in your original comment. The fact is that there are some barriers and they'd have to put some effort into either disabling these protections or exploit flaws in them to get to the data.

Re: Grand jury subpoena for Signal user data, Central District of California

#509
post #392

Earlier quoted context omitted.

Are you aware of how easy it is to find drugs and prostitutes?

Is it? I honestly don’t know. Seriously. I’ve never been offered drugs by anyone in my life and I couldn’t tell you if someone standing on a street-corner is someone simply wanting to cross the street when the lights change or an undercover cop… or an actual prostitute. What am I supposed to be looking for? (Yes, I’m on-the-spectrum and don’t get invited to parties, so I’m not representative of everyone else’s experi…

The drug war has claimed millions of lives and drugs have never been as plentiful. There are no words in the dictionary strong enough to describe this kind of failure.

Re: Grand jury subpoena for Signal user data, Central District of California

#510

Earlier quoted context omitted.

I would go further and ask for mandatory 24/7 surveillance of elected officials for transparency and to combat corruption every time they bring up this bullshit.

In the UK the government introduced a "record of everyone's internet history" law and then exempted themselves from it. https://news.ycombinator.com/item?id=13087339

The particularly messed up thing about that and similar laws in the UK is they are made using cross party consensus
Post reply on HN