Code from the FBI’s Anom encrypted messaging app
1–10 of 107 posts
Re: Code from the FBI’s Anom encrypted messaging app
#2Lots of "secure" messaging apps do this for intel and surveillance and not just the white hats.
Other areas that "secure" messaging apps have holes in is the anti-spam/moderation systems that need to view messages and in the clients themselves who have access to the unencrypted content. This is also taking place in other client apps as well: VPN, password managers, extensions, wallets, even build systems and more. Many like VPNs have logs sent elsewhere but deleted locally -- access to entire machine and all network access. People are way too trusting of "secure" systems/apps that are very common today based on trust.
All of these apps/systems would pass code checks, reviews, security inspections and essentially be encrypted/"secure" though a copy is sent off to another area for review. At runtime the leak is in the direction of the data.
Re: Code from the FBI’s Anom encrypted messaging app
#3What other services might be run, controlled, or surveilled by the US investigative authorities?
What other services might have operators that can be extorted or blackmailed by those same authorities, due to the fact that US-based data aggregators (FAANG et al) have extensive information about the lifestyles, behaviors, habits, and travel of billions of people worldwide?
We already know Apple has preserved a backdoor in the end-to-end cryptography of iMessage at the FBI's behest, as reported by Reuters. WhatsApp has always had the same backdoor (unencrypted backups to cloud services). The largest services are all unsafe for privacy.
What about the medium-sized ones?
Re: Code from the FBI’s Anom encrypted messaging app
#4> Last year, the FBI and its international partners announced Operation Trojan Shield, in which the FBI secretly ran an encrypted phone company called Anom for years and used it to hoover up tens of millions of messages from Anom users. What other services might be run, controlled, or surveilled by the US investigative authorities? What other services might have operators that can be extorted or blackmailed by those…
All closed source software
Re: Code from the FBI’s Anom encrypted messaging app
#5> Last year, the FBI and its international partners announced Operation Trojan Shield, in which the FBI secretly ran an encrypted phone company called Anom for years and used it to hoover up tens of millions of messages from Anom users. What other services might be run, controlled, or surveilled by the US investigative authorities? What other services might have operators that can be extorted or blackmailed by those…
I try to use medium sized services that are based in other countries. I figure if their government has insisted on backdoors it is less directly impactful than if my government does.
I don't really have anything to hide anyway so if my assumptions/approach is wrong then worst case they find out about the concert I'm talking about going to. I grew up thinking encryption and technology were going to free us though, and have found reality to be quite the opposite -- so I try to cover my tracks out of spite I guess.
Re: Code from the FBI’s Anom encrypted messaging app
#6> The code shows that the messages were secretly duplicated and sent to a “ghost” contact that was hidden from the users’ contact lists. Lots of "secure" messaging apps do this for intel and surveillance and not just the white hats. Other areas that "secure" messaging apps have holes in is the anti-spam/moderation systems that need to view messages and in the clients themselves who have access to the unencrypted cont…
Re: Code from the FBI’s Anom encrypted messaging app
#7> Last year, the FBI and its international partners announced Operation Trojan Shield, in which the FBI secretly ran an encrypted phone company called Anom for years and used it to hoover up tens of millions of messages from Anom users. What other services might be run, controlled, or surveilled by the US investigative authorities? What other services might have operators that can be extorted or blackmailed by those…
I don't agree with your characterization of that as a "backdoor" and I think that dilutes the term dangerously. There is no need to use Apple's backup at all, iDevices can still be backed up to your own computer same as always. I do think it's a real problem and one of the real clear cases where Apple's lockdown is anti-user, it should be possible to direct convenient automatic backup at any service one wishes using standard APIs. But it's not any kind of backdoor in iMessage, in the same way it's not a backdoor in Signal or whatever else you might choose to run. Or would be a backdoor if you decided to do unencrypted backups to your own NAS because you decided under your threat model that physical attacks there were less of a risk/value then losing data due to losing keys or something. It's an entirely orthogonal system to the encryption of the messengers themselves. It's not a "backdoor" in a communications system, any communications system, if someone chooses to keep logs unprotected elsewhere. Lack of E2EE in the most convenient wireless backups is a flaw in the general iOS ecosystem, not iMessage specifically.
Re: Code from the FBI’s Anom encrypted messaging app
#8If you're going to take apart JVM bytecode, you're better off using Recafe or Quiltflower.
Re: Code from the FBI’s Anom encrypted messaging app
#9> Last year, the FBI and its international partners announced Operation Trojan Shield, in which the FBI secretly ran an encrypted phone company called Anom for years and used it to hoover up tens of millions of messages from Anom users. What other services might be run, controlled, or surveilled by the US investigative authorities? What other services might have operators that can be extorted or blackmailed by those…
Consider the story of Crypto AG, the most enduring and therefore successful example of this sort of exploit; crucial for putting it in place was that the founder happened to be friends since 20 years with a highly placed chief in the NSA and that's just not a scalable model. It also required convincing an independent, world renowned, crypto expert to completely compromise their work and serve as the authority that kept lesser experts from questioning the cooked algorithm, also not a terribly scalable thing.
Re: Code from the FBI’s Anom encrypted messaging app
#10> Last year, the FBI and its international partners announced Operation Trojan Shield, in which the FBI secretly ran an encrypted phone company called Anom for years and used it to hoover up tens of millions of messages from Anom users. What other services might be run, controlled, or surveilled by the US investigative authorities? What other services might have operators that can be extorted or blackmailed by those…
Any service that is marketed to you as privacy- or security-as-a-service, or software sold as privacy- or security-enhancing, is virtually guaranteed to be secretly working against the interests of its users. You can't buy security or privacy in the form of software or services, because privacy and security are a set of good practices, not a product. People who think they can buy a "privacy phone" are just marks who are being conned by various organizations.