Financial Times journo's private messages quoted to her at China visa renewal
twitter.com
twitter.com
The FT uses a modern(ish) communication stack. Gapps and slack throughout. So if this ia a work feed, then that raises interesting issues. However I suspect this is based on her private devices.
For certain journalist there is a "secure room" (well its not a room yet, that comes later) with isolated throwawy hardware for viewing potentially insteresting files. But I don't shes not part of that team.
And chances are there are some security researchers who wouldn't mind diverting those devices from the trash...
(My curiosity honestly probably stems from the fact that I'm always on the lookout for unorthodox ways to upgrade my own _very_ old tech)
While not throwaway hardware, the company I work for destroys hard drives and other persistent memory devices before discarding computers. If the persistent memory device cannot be easily and reliably destroyed, the whole device is.
I bet journalists with sensitive information are far more thorough.
destruction is rather fun actually, after wiping, memory/disk is removed and taken apart manually. lots of magnets to play with.
I'm not a journo. More importantly the browser I was using didn't have a working spell check. This all compounds the obvious, which is; I can't spell for shit, and my proof reading is also notably weak.
https://www.forbes.com/sites/erikkain/2013/12/29/report-nsa-... https://www.theverge.com/2013/12/29/5253226/nsa-cia-fbi-lapt... https://en.wikipedia.org/wiki/Postal_interception https://books.google.com/books?id=2OZgDQAAQBAJ&pg=PA97&lpg=P... http://www.nytimes.com/2013/07/04/us/monitoring-of-snail-mai... http://www.pucl.org/from-archives/81july/mail.htm https://www.theguardian.com/commentisfree/henryporter/2010/m...
Regardless of what your expectations are, it's not private. Just because you expect something to be private does not mean that it actually is.
What security agencies have done is scan and collect all envelope info (metadata) which was ruled to be not private (makes sense) but with powerful enough cameras, lights, and enhancement software that most letters sent in standard envelopes can leak their contents.
Not when you have all of congress (minus a very select very few) wagging their tails and eager to please you it's not.
My "I just sent an interesting PM and it probably won't disappear but just in case it does this is a canary message" stayed, and the interesting message actually did disappear. The chat bubble remained, the message content was gone (so the bubble was tiny).
Feel really really stupid I believed "nah, it won't disappear" enough not to screenshot both messages beforehand >.<
TIL that day that the imgur moderators (that, like all unpaid moderator situations, have a reasonable amount of drama associated with them) have access to PMs. Nice.
An IRC network owned by PrivateInternetAccess, Snoonet, also applies censoring filters to your private messages, and redirecte them to volunteer moderators in case you should use words that they consider worthy of censoring ("to prevent spam", of course)
I think that says everything one needs to know when even companies that claim to focus on privacy do this.
It’s gotten to the point where if a message I send touches the internet in any way I consider its privacy compromised.
https://www.theverge.com/2018/2/1/16721230/wechat-china-app-...
Fix the key persistence problem on mobile, stop encouraging people to reinstall new keys every 2 weeks.
It takes two to keep a conversation secret, and if one of them is unable to do so (e.g. has their papers and devices seized/searched), then no channel can be secure. OTR algorithms won't help you if one endpoint is compromised and its message history revealed, so switching to another app will help for some threats but not this (quite common) one.
I.e. plausible denial is essentially based on the hope that the opponent will follow some high standard about what constitutes evidence/proof and what is the level of plausibility. In a good legal/political environment you don't really need plausible deniability that much, and in a bad legal/political environment plausible deniability won't save you from harm; your plausible denials can simply be ignored.
E.g. in the Signal standard "plausible denial" means that the message might have been spoofed by your recipient as it involves a shared secret that's not solely available to you - but it's not particularly likely (without extra evidence, motivation, etc) and not really that plausible. A good lawyer in USA might succeed using it as an argument to prevent a conviction, but any totalitarian regime will simply disbelieve it and declare it not sufficiently plausible; they are not really looking for solid proof of wrongdoing, hints of wrongdoing are good enough.
No. Signal is GPLv3.
They don't allow third parties to distribute modified binaries that connect to their servers. You can argue if that is a good idea, but don't misrepresent the situation.
The whole spirit of GPL and FOSS is to be able to examine the source, modify it, and distribute it freely. It’s a form of DRM to restrict who can and cannot distribute the Signal binary.
Maybe this is an unpopular opinion, but IMO the fact that Facebook "trust" it means that I have a lot of reserve about using it myself.
(if that's the rule anyway - I couldn't find confirmation for that)
Hence why Moxie doesn't think federation is practical with an evolving communications protocol.
[1] https://matrix.org [2] https://riot.im
[1]: https://cointelegraph.com/news/skype-wechat-snapchat-thrashe...
https://www.theguardian.com/world/2018/jan/31/this-is-over-p...
"....he saw that by surveilling my private messages and not on my public feed...."
The question to ask is: why are you as a foreign-based journalist working with/for the Communist Party of China in the first place? Why are they cooperating with you at all?
2. Ensure your journalism is helping to improve the world and not enabling oppression.
I mean, I think it's true, solely based on the things I know about China's surveillance... But it does not mean we should just take this tweet as a fact...
For example, it could be the author PM'd another journalist about an event, and the 3rd party then posted it publicly. Or they just ratted her out to the feds. Who knows?
How do we know that she is a person?
How do we know that China is a country?
How do we know what a tweet is?
You're right. There are many assumptions we can make here. Can you say why you chose that particular point of abstraction?