How encrypted communications apps failed to protect Michael Cohen
fastcompany.com
fastcompany.com
[About Cohen] > It’s unclear if the FBI actually broke through any layers of encryption to get the data
[About Manafort] > Paul Manafort, himself found ... Those messages appeared to have been found through Manafort’s Apple iCloud account.
"It’s unclear if the FBI actually broke through any layers of encryption to get the data. It’s possible that Cohen, who apparently at times taped conversations, stored the conversation logs in a less-than-secure way."
We can consider the article a reminder that secure communication tools are not enough for full privacy. One also needs a privacy aware behavior to take advantage of such tools: don't record/backup these conversations, delete the history from your app, have strong passwords, etc.
"Secure communications app" != "Secure communications"
Reminds me of.. « Yes your database was encrypted but the key was stored in a file on the server adjacent. »
Case in point, all of my messages in Signal are locked behind a password phrase, which I have to re-enter every time the phone restarts or the app gets updated. I figured it was iron-clad. Until I discovered that the whole password-protected message vault is entirely optional (must've been one of those things I toggled years ago and never looked back). My girlfriend, of course, uses Signal but does not have that turned on, so if they really wanted a record of our communications, all they'd have to do is subpoena her phone instead of mine.
If you want to be secure against a possible prosecution you really need to hire an expert to setup your devices and teach you how to use them securely. And you also need to think about physical security.