Earlier quoted context omitted.
If you're killing yourself with drugs in private, it's on you. Despicable choice for sure, and it sucks if a bad environment drove you down this road - but that's on you: don't make me pay for your healthcare. Trafficking underage girls is obviously a crime against another human being, it's not a victimless crime like drugs and should be punished.
Should this not also apply to unhealthy eating? How do you feel about: If you're killing yourself with unhealthy eating in private, it's on you. Despicable choice for sure, and it sucks if a bad environment drove you down this road - but that's on you: don't make me pay for your healthcare.
Grand jury subpoena for Signal user data, Central District of California
591–600 of 618 posts
Re: Grand jury subpoena for Signal user data, Central District of California
#592Earlier quoted context omitted.
For supporting "this" very specifically, ACLU (in the form of their 501(c)(3) foundation) is directly involved as legal counsel to Signal, so donating to EFF would be less relevant to "this" than donating to either Signal (also a non-profit) or to the ACLU Foundation. But, sure, the EFF is also a good organization. If your concern is specifically the ACLU's disagreement with recent Supreme Courts on the intended scop…
> If your concern is specifically the ACLU's disagreement with recent Supreme Courts on the intended scope of Second Amendment rights, the EFF isn't going to address that either since it's out of scope for their mission. But that's in no way relevant to what Signal had to deal with here, an area in which I think ACLU and EFF are pretty well aligned. The comments about the ACLU probably aren't about the second amendme…
https://www.aclu.org/news/lgbtq-rights/the-coordinated-attac...
Re: Grand jury subpoena for Signal user data, Central District of California
#593Related: does anyone know why the Signal-Server code allows for toggling request logging? [0] If this allows for logging raw HTTP(S) requests server-side, presumably this could be grabbing the passwords generated and held on each device used for authentication [1]? There's also no mention of TLS termination in the Signal-Server repository on GitHub, or TLS between the Redis cluster in use. If FBI or NSA has compromis…
The HTTP request does not have the users private keys. That never leaves your phone. The DB table looks like signal creates UUIDs to represent users and devices. This isn’t really sensitive information but really just how you can see and revoke devices associated with your account. Maybe I’m misreading something tough. Do you have any reason to believe otherwise?
However, if the password (generated on each linked device) used for authentication is compromised, presumably it could be used to generate different keys altogether for an account. If the device password is compromised, then it seems feasible (but difficult) for some sort of attack be to be pulled off that could eventually lead to the compromise of messaging itself, or adding of another (shadow) linked device.
The subpoena explicitly asks for:
>Online Behaviors: Including device data, site interactions, and cookies if available
>Activity Log: Including logs of click-stream data if available
I would think device data would include things such as the number of devices associated with the phone number, which appear to be stored in the clear in the table, regardless of whether or not it is sensitive. Looking at the Device DynamoDB table, which is linked to the phone number, you'd also have things like the associated auth token + salt, GCM / APN IDs, public prekeys, etc. AWS DynamoDB is potentially going to have request logs for these requests as well, using the UUIDs, to associate finer-grained access timestamps. That may be useful for this case.
It seems odd not to be using TLS within the VPC and storing these seemingly insensitive values encrypted within DynamoDB / SQS / etc. Doing so would ensure that compromise of the hosting provider is irrelevant. Why not terminate TLS on the Signal server itself, behind the load balancer? Why not use TLS for communications between the Signal server and the Redis cluster it uses? Why not encrypt phone numbers before storing them in DynamoDB?
Re: Grand jury subpoena for Signal user data, Central District of California
#594Earlier quoted context omitted.
From the descriptions you gave, I did not expect most of those links to end up being "The ACLU harmlessly addresses a trans issue in passing." I think there's an argument to be made for the ACLU becoming increasingly performative, with catchy Twitter slogans edging out the real work, but this isn't it.
There is no “harmlessly addressing” the trans issue. People feeling uncomfortable with their bodies and performing mutilation is sad. Some people remove their feet as a kinda fetish. Trans people try to look like something else to make themselves feel normal (evidence is that’s not super effective, but that’s beside the point). The main issue isn’t that. People can do what they want in my opinion. It’s the compelled…
This isn't me policing your speech, by the way, saying that you shouldn't say something isn't the same as saying you shouldn't be able to say something.
Is the ACLU actively trying to force you to use specific pronouns, or is that just something they say because it's good social media optics?
Re: Grand jury subpoena for Signal user data, Central District of California
#595Earlier quoted context omitted.
you purposely ignored the biggest name? or is matrix not as popular as I thought?
Matrix system sucks because the servers are branded with domain names and the server operators have total ownership of your account. In a network like Status or Session, you don’t need to know and don’t care who runs the node you happen to be using at a given moment.
Isn't registering an account necessary to avoid impersonating? how does Status ensure a stable user ID?
Re: Grand jury subpoena for Signal user data, Central District of California
#596Earlier quoted context omitted.
No one is suggesting it should be impossible to uncover crimes. But I’d say that we should work to make it impossible for mass surveillance to exist, full stop. Police should have to do real actual detective work to implicate people in a crime.
Why is obtaining phone records not "real actual detective work"?
Re: Grand jury subpoena for Signal user data, Central District of California
#597Earlier quoted context omitted.
You weren't talking about legal workers, you were specifically talking about, this is an exact quote, "illegals working below minimum wage". That's what I was responding to. If you also have issues with people "from some shithole country" employed, working, and paid fully in accordance with your own country's laws and regulations, that's a different discussion, in that case the employers and employees are all doing w…
Yes, and in the secon post I was talking about both legal and illegal, and both of them destroy the labour market for the locals.... and in both cases, opponents to imigration (legal economic or illegal) are branded as nazis.
Re: Grand jury subpoena for Signal user data, Central District of California
#598Earlier quoted context omitted.
Asking people to not be transphobic threatens your free speech rights? Way to take something not even remotely about you and get offended by it.
Perhaps it’s offensive to the other side being forced to accept someone born the opposite sex as exactly equivalent? Perhaps it has nothing to do with judging them or their lifestyle? Perhaps by the same logic they shouldn’t care about grouping themselves forcibly into a group their offending at least some of the members of?
Re: Grand jury subpoena for Signal user data, Central District of California
#599Earlier quoted context omitted.
Federated servers are still servers. It’s nothing for the FBI to subpoena any server you’ve connected to and then any server that server connected to, etc. The important thing is minimizing the data that is collected, period. Otherwise you’re just obscuring the data storage.
> It’s nothing for the FBI to subpoena any server you’ve connected to I can choose to use a server outside the US. I can choose to run a server in my basement and still talk to all my contacts. You simply do not have this freedom with Signal. Finally, I do not have to trust anyone about what (meta-)data is collected.
An out of the US host is easier for them actually. Say hello to NSA exploits without a warrant!
Have you looked to see what metadata something like Matrix collects? How federation and contact lists work on that server?
Re: Grand jury subpoena for Signal user data, Central District of California
#600While I applaud Signal's response I expect this entire event (subpoena and response) will be provided as one of the exhibits to congress by the Department of Justice to justify their request that it be unlawful to provide such services. The DoJ will say, "See, here is this horrible crime we are investigating and because this company chose to make it impossible for law enforcement, with a warrant and a subpoena to get…
Pretty sure the military recommends their troops use signal for civilian communication when abroad. In addition, I’d wager lots of politicians use it now for obvious reason’s. Ergo that won’t happen. That being said, can’t blame DoJ for trying though.