Grand jury subpoena for Signal user data
whispersystems.org
whispersystems.org
I don't really know what the solution is, but I'm very uneasy about the central point of failure Open Whisper Systems is. Moxie's previous points about the difficulty of upgrading a federated protocol[2] are correct, but I think that despite the difficulty it's important to do.
[1] http://freehaven.net/anonbib/cache/sassaman:wpes2005.pdf
[2] https://whispersystems.org/blog/the-ecosystem-is-moving/
I believe Whisper doesn't want this data. I can even trust that they would never collect it of their own volition. But it's irrelevant if they can simply be compelled to collect it, or even worse, someone within their organization can be compelled to secretly collect it and may even do a better job at this secret collection than Mayer's lackies at Yahoo!.
"Notably, things we don't have stored include anything about a user's contacts (such as the contacts themselves, a hash of the contacts, any other derivative contact information), anything about a user's groups (such as how many groups a user is in, which groups a user is in, the membership lists of a user's groups), or any records of who a user has been communicating with."
If they don't store the contacts, or even a hash of the contact, how can you figure out who was talking to who?
1. "the contacts, or even a hash of the contact" are being not stored by choice rather than by necessity.
2. If OWS chose to start storing these metadata in the future, they could.
3. A protocol where the metadata could not be stored intrinsically would be preferable.
Think of it like email. The body is encrypted, the subject is encrypted, any attachments are encrypted, but in order for them to route the message to the correct destination every message you send still has a "To:" field - their server still decides who to send the notification to.
They don't need to read the contacts or anything of the sort - they just read the "To:" field.
I don't distrust them today, but I have no way of knowing what their future behaviour will be. I'd prefer not to have to trust.
(I mean, given a phone number, can't you identify someone's Google Play account anyway? That sounds more useful.)
Not by subpoena alone, but in theory a court order could order them to modify their software (server or client) to collect data. They could fight that court order, and in particular it seems like they'd have a good case on the grounds that such an order would destroy their entire business, but legally a court could at least attempt to issue such an order.
http://www.globalresearch.ca/leaked-documents-expose-secret-...
The interesting part is in this table from the TS/ECI leaks from Core Secrets:
https://theintercept.com/document/2014/10/10/eci-whipgenie-c...
Notice how the lower levels of secrecy talk about how the companies cooperate or are partners. Then, you hit TS/COMINT and TS/ECI to find additional detail:
"the fact that FBI provides assistance with compelled and cooperative partnerships associated with WHIPGENIE"
"details of FBI assistance with compelled and cooperative partnerships with WHIPGENIE"
So, it's a backdooring program with major U.S. companies that the FBI "compels" assistance with for those that don't willingly cooperate. I have no idea what that entails but it works. It might work better on smaller firm with less resources but also maybe less as I think damaging income stream matters to greedy CEO's at public firms more. So, who knows.
Personally, I think they're pulling a variation of Escobars silver or lead policy. You take generous bribes to do what they want or you take generous donations of lead. In this case, legal fines or imprisonment rather than actual lead.
Yeah, I wish he went with another name, too. Not only is Open Whisper Systems making it more confusing, but it's also quite a mouthful.
web: https://vuvuzela.io/
repo: https://github.com/davidlazar/vuvuzela
As for signal what every prosecutor wants is metadata to show the court that user A was in communication with user B. The actual contents of the messages aren't important especially in a conspiracy case and user B is an informant, their word against yours plus metadata showing you communicating is good enough.
Besides forcing Signal to keep this metadata in the future, I wonder if they can just obtain it themselves by watching all traffic on their federated servers and timing it to discover communication networks.
It's really easy to underestimate how big of a ripoff EC2 bandwidth pricing is.
Is this 1 gigabit of accumulated traffic, or sustained bandwidth guaranteed for an entire month?
1 TiB of accumulated bandwidth at DigitalOcean costs me $5/month. I am unaware of what sustained rates are given that tier of pricing, however.
On the expensive end you'd be looking at around $600 for such at $NOT_AMAZON, and on the cheap end you'd get it for "free" because a plenty of hosts have excess bandwidth.
DO doesn't separately charge for BW or enforce any limitations AFAIK.
A strong political regime and support for privacy. Strong technical tools for enforcing those political goals.
The fact no one has done anything major about any of the other surveillance state BS is proof enough of that.
In any case, there are still the negative economic consequence which important alone, but also affect politics.
http://www.cnn.com/2016/06/15/politics/donald-trump-muslims-...
> Trump doubles down on calls for mosque surveillance
http://thehill.com/blogs/ballot-box/presidential-races/26167...
> Trump said Tuesday that he would be "fine" with restoring provisions of the Patriot Act to allow for the bulk data collection, something candidates such as former Florida Gov. Jeb Bush have also called for that was banned with the passage of the USA Freedom Act, which Cruz supported.
Well I don't think I'm going to agree given the only person who made it to the GE is a guy who supports surveillance.
TBH it probably wouldn't require that much Orwellian apparatus; you just make the software slightly harder to use than it already is today, and network effects basically ensure that only people who are really interested in communications without government interception (who the government is presumably interested in) are using it. Then you can start doing endpoint attacks, deanonymization via compromised downloads, etc.
The government's -- and I don't mean just the U.S.'s, but most large governments', I think -- ideal for Internet communications is something similar to the telephone network circa 1975. They're fine with privacy between one individual and another (i.e. keeping your conversations private from your neighbors), but they aren't going to be satisfied with any technology that prevents wiretaps by state-controlled apparatus.
I am not exactly bullish on the ability of technology or technologists to resist this, over the long run. Unless there is a widespread and overwhelming realization on the part of individuals that governments shouldn't have this ability, and I don't think that consensus exists even in the liberal West if you frame the question even moderately advantageously to the government, then they will get it. There will always be pockets of noncompliance, and an ensuing cat-and-mouse game, but the steady state will likely be one that deters mainstream usage.
And if we really are seeing the end of Anglo-American geopolitical dominance in favor of countries whose political systems emphasize stability and harmony over individual rights and dissent, then it becomes very difficult to see that consensus ever manifesting itself at a meaningful global level.
RSA Net Income (2011-2015): 426M 320M -306M -115M 79M
Verizon Net same period: 2.4B 875M 11.5B 9.63B 17.88B
ATT Net same period: 3.94B 7.26B 18.25B 6.22B 13.35B
RSA took quite a hit but it could be market as well. I don't know what it's status was pre-Snowden but much of hit comes during year of the leaks. Revenue dropped a billion or two with profits turning to losses but rebounding into $75 million in 2015. Verizon and ATT are doing great. Other companies that are managed profitably that cooperate tightly with Washington are Microsoft, IBM, Google, and Oracle. Their net incomes are in the billions.
So, I think the market data indicates you're wrong even in the worst scenario for working with the surveillance state. Also, the more lock-in the business has, the better it does despite any evil choice it makes. Rule of thumb.
IANAL though, so I digress.
When the Securities Exchange Commission decides that something is a security, it retroactively applies the civil and criminal compliance back to 1934 because it was always a security. I mean, you can argue it in front of a judge if you want, but thats how they established jurisdiction.
Same goes for discretionary tax law at the IRS
or any regulatory agency
I agree its a problem, but if you live your life under your version of reality it is easy to get railroaded in the dragnet
New Regulation -> Future Date -> Ex post facto claims don't happen.
That is the process my original comment intended to imply.
If you are a vast major bank and don't like the SEC you can try not being allowed in the doors of the private buildings of the NYSE, LSE etc.
They have the power not of law but of losing billions
That's not a retroactive application of the law. If they are correct in their interpretation of the law, it was already the law. If they are incorrect, the courts will not allow it (whether the enforcement concerns acts before or after the determination by the SEC.)
The ATF is particularly notorious for this.
Yes, and if that conflicts with what the courts believe the law has always meant, those decisions won't survive contact with the legal system. An ex post facto law is a law creating (or enhancing) criminal penalties for acts that exist before the law is passed. Changing administration interpretations are like changing prosecutorial priorities (and the former comes with a lot more notice and specificity than the latter) -- they only have effect so long as they are within the bounds of what the courts will accept was covered by the law when it was passed.
https://en.wikipedia.org/wiki/Chevron_U.S.A.,_Inc._v._Natura....
Detailed analysis with appropriate links:
https://www.schneier.com/blog/archives/2014/11/the_return_of...
Note: I could be really misreading the material due to not being a lawyer or pouring through regs all the time. I think it says all this stuff is still 5A002 (munition) outside the exemptions they compromised on.
Being provably secure is great, but this is a tall order -- there are always conditions to satisfy (solution is secure if A, B and C and governments and other attackers might invalidate those by a tap point, decree, a court action, etc.).
In America, we have had those, and it hasn't helped. We have a First Amendment and a Second Amendment, and yet we have campaign-finance restrictions and gun control.
Political decisions simply don't stand. It's terribly sad.
Consumers aren't interested in buying a "UWB mesh hub" or some such, which wouldn't appear to do anything but drain batteries. But they might, for example, buy a car stereo or security system that uses a wireless device to deliver specific features, and which also happens to help saturate the city with a p2p mesh network.
Likewise with cryptocurrency, most people are not interested in the hassle for some intangible privacy benefit. But a lot of people might be interested in a crypto video game currency that can be easily traded, even between games. Or perhaps a currency-like mechanism to implement quotas on the mesh.
"Mathematical security" can be politically banned, is banned in many parts of the world. You only have the option to use mathematical security because other people have been doing the politics for you.
I see this desire raised a lot, in contexts from HN to Valley-mocking pieces on how encryption is no substitute for advocacy. I completely understand the instinct, but every incarnation of it seems to struggle with the same question. Namely: how do you know when you've won?
Restrictions against collecting data on US citizens didn't produce the expected results. Testimony to Congress didn't accurately depict what's collected, even in secret. In the early days, the existence of these agencies was classified to help go around restrictions on existing agencies. Years ago, back in the Puzzle Palace days, the DoJ cited systematic criminality but concluded that they were unable to prosecute it.
So... what does winning look like? What regulation, what testimony, what promise could possibly convince people that a solution had been reached, even for the moment?
Roe v Wade was a clear and unambiguous advance for abortion rights, and the battle lines are now arrayed somewhere different than they were before Roe. The fight isn't over, but it's fairly clear who holds what.
I'm talking about even knowing when you've made progress. If a federal directive came through tomorrow expansively forbidding the NSA from collecting data on US citizens, privacy advocates wouldn't even hope that bulk surveillance of citizens would stop. They know better, because it basically happened, and the definitions of words got rearranged until the program could continue unabated.
Political issues aren't settled until they fade into consensus belief, but it's usually possible to make progress and then defend it. On surveillance and privacy, there's no law or court decision or whistleblower or even prosecution that can guarantee things aren't continuing exactly the way you didn't want them to.
Similarly when it comes to security, privacy, and anonymity the best defense is to arm yourself with mathematical security.And to enshrine our right to those defenses in law. A subpoena only works if there is information that can be handed over in the first place. If strong and private encryption is made illegal then the best defense is still to use that technology clandestinely.
fallacy [1]
>I feel x
isn't an argument. for example: I feel safer with a gun.
fallacy [2]
> ... when every private citizen I interact with carries a gun.
Having the right to carry a gun or the right to encryption does not imply everyone will/must carry one or use it at all times.
With encryption criminals around you can plan attacks, steal your identity, and trade child pornography without fear of the prying eyes of law enforcement ever being able to discover the evidence. That would probably make a large number of other people 'feel' unsafe as well. feeling a certain way isn't an argument.
I 'feel' safer with the right to carry a gun. I can feel safer when everyone has a gun. Therefore morninj's argument does in fact also apply to guns.
Anyone can feel a certain way about anything, which is why it is invalid when trying to construct a logically sound objective argument.
A subjective premise can not lead us all to an objective conclusion.
I feel (part of) the reason your society is in political gridlock is because everyone keeps looking for that mythical "objective" proof that ensures a 100% victory for their side. But that's just another unicorn.
Here are some examples of how both a gun and encryption can be used for the same end goal.
X can secure a financial transaction
X can stop a thief from obtaining my credit card information
X can stop someone from forcibly obtaining my identity
X can stop an attacker from obtaining private data stored in my home.
The only thing I've been able to think of that applies to encryption and does not apply to a gun is:
Encryption can verify that a message actually came from me by decrypting it using my public key.
This is objectively true for encryption and objectively false for a firearm. Also a firearm doesn't really help with anything on the internet except maybe a shady craigslist transaction in a dark parking lot. But I meant to imply that a realistic and suitable physical analogy can be applied.
People will use force to take advantage of your moral stand against violence and make you comply to things you do not agree to.
We both abhor violence. The difference is I refuse to be victimized by it.
Citation needed.
https://www.nraila.org/articles/20150708/radical-anti-gun-gr...
http://www.naturalnews.com/047378_murder_sprees_armed_citize...
http://www.wsbtv.com/news/local/gwinnett-county/video-shows-...
"Best" might be hard to argue but it can be easily shown that you are better off having one when you need to defend yourself.
There's still rule of law, and the executive mostly listens to what the judiciary tells it to do. For all its flaws, some of our institutions work pretty well compared to most places. I cannot think of another country where judges are able to overtake heads of states in substantial policy outcomes.
The infamous one: in its early days, the NSA was ordered to stop surveillance of US citizens. It went before the Church Committee and testified that the relevant sites had been closed for more than a year. This was a lie, bottom to top. The sites were actively operating as those words were spoken, and they weren't closed down until whistleblower James Bamford exposed the lie. https://theintercept.com/2014/10/02/the-nsa-and-me/
There's a list a mile long of similar stories. Court decisions, executive orders, and acts of Congress have bounced off these agencies without result.
I'd like to see examples, but I agree that you're not wrong in general. The agencies do respond to court decisions sometimes. My point is that when legal compliance is a coin flip and there's no way to check for results, you can't be sure that legal decision has changed anything at all.
There, the "opponents" are a subset of society that have a legitimate right to not to agree with the decision and they are acting within the public framework of our governance to overturn a decision.
Here, the "opponents" of strict privacy rights are spooks and crooks in government and international corporations. It is entirely a differnet matter.
Established inherent rights -- specifically the rights of free speech, freedom of assembly, and protection from unreasonable search and seizures -- need to be protected in context of new capabilities afforded by modern communication, surveillance, and data retention technologies.
Corporations will not pull a dissenting "Roe vs Wade" that would challenge citizen rights. Just let them try that.
Overreaching elements and sub-systems of the government can try and present cases where our (updated) rights present obstacles to their performances of their legitimate legally mandated activities. And there is ample precedence for oversight for such matters.
A technological cold war with government and industry on the technological field is not a realistic option. First of all, it is politically useless since that approach implies that the constitutional framework and our entire system is in effect broken. Second, the "mathematical" bit in the secure and private mediated communication systems is the only element where one could possibly argue for parity in terms of the contending parties' capabilities. Why pick a losing fight when there remains the constitutional field where we have the upper hand, by definition.
[edit: minor cleanup]
But you also set up the infrastructure to fight the good fight forever. Which is what it takes to make democracy work, and work well.
Because everything important is a political issue, whether you want it to be or not. The Superconducting Supercollider, which was as clear a piece of pure science as you could imagine, was killed by politics. End to end encryption could be too.
Honestly, a major reason we are in this mess now is that for decades Silicon Valley has avoided politics and tried to pretend that the federal government does not exist. Now that it can't be ignored anymore, the tech industry does not have any of the civic institutions needed to build broad public support for its issues.
It's a bit more complicated here, though, since so much of this activity is clandestine. We can't know what rules they may be breaking (unintentionally or otherwise).
What about human slavery?
At this point, winning looks like the people responsible for abusing their power and overstepping their constitutional authority going to jail. And for a long time.
As long as the only consequence of illegal activity that violates the constitutional rights of citizens is being told to stop, there will be continued efforts to chip away and push the envelope for what they can get away with. If it were made apparent that there are personal consequences above and beyond the scope of their jobs, perhaps some of the people in those jobs would more carefully consider the constitutionality of their actions.
What's scary, is some people seem to want that stuff - as long as it's not them getting taken away and thrown in a cell.
Think democracy. We have to fight for democracy over and over, and we have a technical solution in the form of an election process that's designed to make tampering hard and in the form of institutions controlling each other for a good reason. There is no political solution to the risk of putting all your trust in a single person, aka a dictatorship, there is only a technical solution, and that is democracy: A system of government that avoids the single point of failure at great cost.
We are creating absurd amounts of information compared to before. Just because US Gov could access the measly amount of info that was generated before doesn't mean that they should be able to access the crazy amounts created now. It is from a very narrow perspective that anyone can call this a "fundemental weakening of government". Compared to before the internet, they're still drowning in insane amounts of data.
We can also add that if they can access some things, they will manipulate their way into accessing more things. Which means that reducing privacy and security is just optimization for them. And that will have costs beyond the US Government's own doing.
Sure, the current law climate seems to be that they can access it. But that climate was created with pushes from LE agencies and ignorant politicians. You may argue that that has always been the case, but clearly there's increasing demand for this to be decided democratically. So US Gov "giving up" this "right" might be the thing that democracy wants.
Yeah both of these are a pretty large problem for a messaging service designed to replace SMS on phones. Really anything other than a forum or email replacements will have a very hard time getting adopted if they have too much latency.
About the only thing that comes to my mind would be a digital equivalent to broadcasting a radio signal - a protocol, under which everyone receives all communication that's done over that protocol, but each person can only decrypt the part that's addressed to them directly. This would reduce the metadata to "who's broadcasting", without revealing the listener.
EDIT: Some back-of-the-napkin calculations on such broadcast protocol:
I took a look on my today's communication with my SO; rounding somewhat up, it would be ~100 messages of on average 50 characters, going in both directions. That gives, using 2 bytes for character and multiplying by 1.5 to account for protocol-related padding:
- 15000 bytes / user / day of a single conversation
Say this protocol has 1M user, that gives us:
(50 * 100 * 2 * 1.5 * 1000000) / (100010001000)
15 GB of data, spread over the whole day.
Seems manageable; especially if one would be to bucket it by e.g. hour by default, or less, if client is active and streaming data continously. Definitely a mobile bandwidth killer, though.
In most cases a DHT is far simpler. But naturally some nodes can be evil and log metadata. This is just a risk, but it also exists in block chains. Furthermore DHT's are lower latency then block-chains.
Blockchains aren't a magic fix all solution for network consistency/privacy models. Outside of currency transactions it is a horrible distributed system model.
Blockchains address that problem too.
Consistency (every read receives the most recent write or an error): Not True for block chains. All reads are dirty. The further back in time you go the higher the probability the read isn't dirty.
Availability (every request receives a response, without guarantee that it contains the most recent version of the information): 100% true.
Partition tolerance (the system continues to operate despite arbitrary partitioning due to network failures): Yes the system will continue to function. But you can suffer data loss when the partition is healed.
Still not perfectly metadata proof, but it carries a lot less metadata than peer-to-peer messages.
And yes, mobile bandwidth is a killer.
By combining such techniques, it's possible to be much much better than naive broadcast, and also possible to use a client/server architecture so that low bandwidth endpoints can participate.
Have a look at systems such as Dissent and Riffle.
It deals with the metadata leaks by using Tor. Every user runs a Tor hidden service, and the users identity is the address of that service. So no single point in the chain can tell who is talking to whom, without having to resort to a broadcast protocol like you describe.
I'm still looking for an option that is basically Richochet+Signal+Burner.
That would be an ideal app IMO.
One recent project that validates this is from ACM SOSP'15 titled "Vuvuzela: scalable private messaging resistant to traffic analysis"[1] (open-access URL):
> Vuvuzela has a linear cost in the number of clients, and experiments show that it can achieve a throughput of 68,000 messages per second for 1 million users with a 37-second end-to-end latency on commodity servers.
> Vuvuzela works by routing user messages through a chain of servers, as shown in Figure 1, where each of the servers adds cover traffic to mask the communication patterns of users.
Similar to the P2P project Bitmessage[2] where clients receive and forward traffic not related to themselves.
There were some comments on HN discussing FreeNet and how it similarly forwards traffic unrelated to an individual client, but which has led to conviction by police, unfortunately.
Just for using it? That's crazy! Do you have a source?
1 - http://www.thedickinsonpress.com/news/north-dakota/3885239-p...
> Just for using it? That's crazy! Do you have a source?
Hm, I admit fault, hastily writing the above reply. I do not have sources for actual convictions, so what I wrote is not validated.
s/has led to/may risk/
Source[1] that I read prior to my comment, which is under the thread[2] "Suspect jailed indefinitely for refusing to decrypt hard drives". The discussion was along the lines of, if you have encrypted data, and the state "knows" it has illegal content, your not decrypting it makes you liable for it. Thus the extrapolation to use of Freenet, which forwards encrypted content from others, and is heavily littered with CP[3], according to HN commenters.[1] https://news.ycombinator.com/item?id=11590880
Then they could ask Apple or Google to turn over any cloud data they have for that phone.
Do you know both how long the investigation would be under for? Do you know the timing?
Stating there's no good reason is not true - it's quite possible that a gag order is issued to protect the investigation, including identification of suspects, the number of suspects (at least two in this case), change of behavior (e.g. switch from Signal to smoke signals, fax, or just lay low for a while), etc.
What happens when two days after a terrorist attack, OWS publishes a subpoena for the first time? I for one welcome that they go through the official channels to get the redacted version approved. Let's not botch investigations for the sake of pitchforking the "everything should be public" slogans.
Outside the usual "let's ask for more than we're legally entitled" shtick, there's nothing particularly alarming about this subpoena; it was narrowly focused on two phone numbers, for which only one was a Signal user.
It's good on OWS to fight so hard for transparency.
It's volatile data exchanged between the clients only, but not centrally stored anywhere (contrary to all other secure chat systems out there). The FBI has probably no idea how Signal works, what is stored and what not.
Even a grand-jury subpoena has no chance to produce more data. But maybe they can force them to re-implement Signal with a government backdoor (because it's a police state after all), and that's what Open Whisper Systems is really objecting to? Or just logging the metadata? (Which btw. duckduckgo does, even if it slows down their webserver by at least 20%).
Or did they just try to mess with the FBI lawyers?
However, even this requires an understanding government that isn't willing to poison the well in order to get to the target. A government that justifies dragnet (and whose agencies allegedly buy and sit on a stash of zero days) isn't something I'd trust to be bothered by the idea of leaving many people vulnerable in order to catch one bad guy.
I know it sounds trite but technology will not provide a full solution here. We need a lot of lobbying and a lot of PR to have any chance. Co-ordination will be very challenging when our goals very so wildly. But I guess we need to ask ourselves where we stand on this issue. Given we have difficulty getting almost half of the people to even bother registering and showing up to vote, this is an uphill task.
Trust in binaries is a harder problem, but reproducible builds is probably an important part of it. If several separate entities vouches for the binary, you have reason to believe what you run corresponds to be published source code.
They don't have access to group message membership directly. A group appears as a bunch of one to one messages between the participants, so they might still be able to infer it.
Or is that what they called PRISM? Legal route splitting at the endpoint, i.e. legally declared as such by the secret FISA court, because there's oversight...
The court can compel a business (or individual) to lie about that sort of thing.
source for this?
I believe the GP is echoing zeverb's sentiment, that it would be preferable if OWS (Signal) could not even be ordered to collect such data.
The thing I don't understand about the GP's post is "but someone else could be storing it". I would expect the entire message (including headers / metadata) to be encrypted in transit, with a pinned key, so that only OWS has access to the routing metadata. Please correct me if I'm wrong.
Check the metadata portion. One thing to note, this isn't surprising at all. All of the centralized IM servers can do this and, usually more. The alternatives that try to minimize or obfuscate metadata are far from market-ready.
Remember LavaMail? This is pretty much what happened to them.
I'm curious what type of metadata Facebook would have from the signal integrations with Whatsapp and Messenger. Is there more, less, or same? Has anyone looked in to this?
Whatsapp and Facebook, meanwhile, are sharing data to improve ads - surely they share much more than that with LE.
Signal is the best shot we have at widespread, usable private communications at this point. It's about time we get around to supporting it. Be pragmatic.
A serious question though, how do gag orders work? How do I notify an attorney?
I note that the documents use a proportional width font, and there's been previous research into using the width of blacked-out sections of redacted documents along with information about the font to work out possible character combinations that fit appropriately...
We know freedom loving software engineers after decades of posturing have long folded and left Snowden holding the baby.
We also know companies here are either closely linked to intelligence agencies or bending over backwards.
We know the executive branch is in the middle of a full blown identity crisis of whether they are the good guys or bad guys of the world. Closesly followed by a legal system that has developed a third world regime like affinity for blanket gag orders and rubber stamping with 100% approval rates. This is a bit like tasking the fox to protect the hens.
What stops a goverment friendly company from acquiring whispersystems, or whisper itself being some sort of a release valve operation?
My bet is on December. My hedge is that I counted wrong.
Edit: I counted wrong. <digit><digit><space>[April,March] works just as well.
in the eyes of LE... they have metadata that you spoke with suspected individual :)
If you meant to imply they could abuse this capability to get a warrant, I'll be concerned about it when they have any trouble getting warrants.
- 100+ years of business telecommunications without significant strong encryption. - Robust wiretapping and law enforcement access laws and practices that mean there is NO place or piece of information within US sovereign territory that is inaccessible to an authorized agent of the state. - they have the expectation of total control. Hell, beat cops can shoot you over minor "comply or die" orders. - Crypto isn't about your email or even evidence in a particular case, it is about the completeness and totality of their authority. - States around the world routinely decimate their populations in civil wars and massacres to ensure the same people remain in power. From the LE perspective, anyone who threatens the sovereignty of the state is a terrist they would complete for the opportunity to shoot.
Hackers don't get it. If the crypto debate ever gets real, you cannot imagine how real it will get.
The way I'm reading/understanding this is that they have the encrypted messages, but don't specify whether they are stored. However, since the messages are encrypted, they don't have the message contents/that information. Concluding, they may have all the messages saved, albeit in an encrypted format and with minimal metadata.
Did I come to the right conclusion? Or does Signal not store the encrypted message data either?
It'd be difficult to delete metadata about a message, but still keep the content. And they are claiming to not retain message metadata.
The clients you have are Signal, WhatsApp, Messenger and Allo. (all that run the Signal protocol currently)
Wire is one of those which is E2E by default and uses the similar algorithm as Signal.
Moxie's link shows her campaign is in fact relying on the service.
Bottom line, just because Hilary's campaign is using Signal, it doesn't mean that in the future her administration won't gag them or make legislation available in order to use them so spy on their own citizens.