Grand jury subpoena for Signal user data, Central District of California
signal.org
signal.org
Why would you expect them to understand how Signal works? A lawyer does not and cannot become a subject matter expert for every aspect of a case they undertake.
A lawyer's job is to investigate every possible avenue for evidence to support their case. They're going to ask Signal for everything imaginable and have legal recourse if they discover at a later date that Signal withheld information.
A lawyer with a complete understanding of how Signal works and intimate knowledge of it would still send the same subpoena and expect the same response. They would never say "Oh Signal? That's a dead end, don't bother."
[0] I assume. I don’t do steel.
I really hope the lawyer I’m hiring is at least a subject matter expert on the specific laws around the subject. Then a simple google search would explain how this data isn’t available.
> Subpoenas are the only mechanism by which prosecutors are able to test the waters to confirm/deny whether they can demand production of this data
I think many people fail to appreciate the importance of setting a precedent in the courts. Maybe this is because our legislators have been shirking responsibility for decades and pushing what should be their work off onto the executive and judicial branches, but regardless this is where we are today: If a demand like this is not challenged in court then nobody knows whether it's legal or not. *This is the process by which we learn whether Signal's implementation is allowed in our country.* It may seem clear to you what the right answer should be, but until its tested it's not clear to our government.
Except that written law is the whole story.
(Precedential court decisions are, after all, not transmitted as oral history.)
"pure" versions of either don't work - it's more like a spectrum. Unfortunately moving to more legislative emphasis than case law only works if you have an efficient legislative process to update. If that's too adversarial, you get the worst of both worlds.
There’s no precedential issue here. Law enforcement can and routinely do demand such data, and in the case of other services they receive it. The only news here is that Signal can’t produce much of it because they don’t have it.
Signal is in fact complying with the subpoena. They’re not challenging anything in court.
They deal specifically with crimes that involve international transport. So this is human trafficking, drug smuggling, money mules, etc.
To be honest the rest of it is just standard "we have some phone numbers" boilerplate. Same thing was probably sent to Facebook, Twitter, etc. with the hopes that someone was dumb enough to login and check their messages from a burner phone.
Edit: Rereading it, this is a grand jury. They likely already know the who, what, why, and how. Signal's response will go to support other evidence that they may have recovered from cell phones or cell network. Grand juries historically result in a 95%+ chance of indictment so this isn't a fishing expedition.
You’re also just speculating about the nature of the crime, but saying it confidently, like, oh, this is definitely true. You don’t know.
† Americans didn't invent them, but they did keep them after everybody else went "Wait, this is a terrible idea" and abolished the Grand Jury.
• High public interest in the case;
• The fact that a preliminary hearing would take more time than a grand jury hearing;
• The necessity for calling children or timid witnesses who would be subject to cross‑examination at a preliminary hearing;
• The ability to test a witness before a jury;
• Where the secrecy of the grand jury may allow defendants to be charged and taken into custody before they can pose potential danger to a witness' safety or flee from the jurisdiction;
• Where the identity of undercover agents needs to be protected;
• The existence of a weak or doubtful case which the district attorney wishes to test;
• The opportunity to involve the community in case screening; and
• Whether the case involves malfeasance in office.
https://www.pooleshaffery.com/news/2014/december/a-crash-cou...
I wonder how other common law systems handle this (not a lawyer, am genuinely asking).
The jury that hears the evidence in a trial is referred to as the petit jury (small jury). It is convened for a single case.
The grand jury is a standing body (also supposed to be drawn from the populace, and with definite tenure) which hears preliminary evidence and in theory decides whether there is enough of a case that an actual trial would be warranted. It can issue subpoenas (as in this situation).
The rest of the US system is weird. At the federal level the people who judge the cases are a whole branch who do pretty much nothing but that. The actual bringing of the cases is the responsibility of the executive. Oh, various departments of the executive have their own "courts" too that rule with no juries. There is no constitutional reason why this whole apparatus could not be part of the judicial branch but I've not seen any interest in that happening. Actually the executive's courts are pretty clearly not constitutional but they have survived enough challenges that they are simply the way they are.
At the state level the same system is roughly followed but in most, or perhaps all states, the attorneys general (who oversee all prosecutions) and Supreme Court judges are elected. Sheriffs too, which in some states are important police, and even some chiefs of police. You might think that this direct election would reduce the chance of corruption but of course it seems to run the opposite way. The longstanding American distaste for competence is the strongest force against a trained, standing set of people to do things.
They are Constitutional, they just perform Article II executive functions and are established under Article I powers of Congress; despite being called “courts”, they do not exercise any part of the Constitutional judicial power. (Hence, why they are described as “Article I courts” as opposed to the “Article III courts”.)
HSI is a fairly narrowly scoped law enforcement agency. I've dealt with multiple agents over there, and at one point considered joining when I wanted to get out of computers. But feel free to call the press office and ask if you don't want to believe a random on the internet.
The legal aphorism has long been attributed to Sol Wachtler, former chief judge of New York’s Court of Appeals, based on a piece that appeared in the New York Daily News in January 1985. Mr. Wachtler told the paper that the state should scrap the grand jury system for bringing criminal indictments. The piece summarized his view, with brief quotes: “district attorneys now have so much influence on grand juries that ‘by and large’ they could get them to ‘indict a ham sandwich.’”
Mr. Wachtler became even more firmly linked to the saying two years later, when Tom Wolfe, a classmate of the judge at Washington and Lee University, credited him with the “ham sandwich” line in “The Bonfire of the Vanities.”
From https://www.wsj.com/articles/indict-a-ham-sandwich-remains-o....
I remember hearing it on Law and Order!
Is this automatically assumed to be a good thing? If so, why?
So Signal is being used for human trafficking? And they are deliberately making it easy to do that kind of activity on Signal without law enforcement knowing? Sounds like the app stores should ban them and AWS should kick them off.
I disagree with the above sentiment, but I think end to end encryption apps will be treated like that in the near future.
Also the founder of signal is very well connected to the Silicon Valley who’s who.
I currently think the main benefit of juries is to educate the public on how screwed up the whole process is. It was a waste of time in terms of protecting anyone involved, but brought my trust in the criminal judicial system to an all time low.
> Grand juries historically result in a 95%+ chance of indictment so this isn't a fishing expedition.
There were cases presented to us which did not result in any indictment vote as new information was discovered or persons involved made deals with the prosecutors. The prosecutors didn't have us vote on things they weren't sure about, but that doesn't mean they never made mistakes.
Gaming out the subpoena, Signal does not have this user information because it does not exist, but it does have server locations, 3rd party service providers relationships, and staff who can all be dragged into the process and system, where they can be charged with other arbitrary process crimes to put pressure on them.
It's a mistake to interpret any official action as a serial, single point transactional request. Like mice, if you think you see one, you have, and it's guaranteed there are many more behind it. Given where they have used the action to draw your attention, where in relief is the second part of the pinch or funnel they are creating?
If the legal system wants to destroy you, they can and do. Signal has antagonized them, and the current political climate is all about getting rid of any resistance to official powers and their unofficial private arms. Politically, there is ample incentive to take out Signal and cause users to switch to more amenable apps from friendly platform companies. They may even be able to compel friendly app stores to patch apps before they are distributed.
To me, this subpoena looks like the Cellebrite takedown was analogous to injuring a cop, where the response will likely be disproportionate and even extra-legal, because it is about maintaining public perception and belief.
It's actually comforting to believe your adversary is so powerful that the only thing keeping you safe is their failure to notice you. Because that leaves you with only one reasonable course of action: don't rock the boat.
The reality, however is far more troubling: Even great powers have blind spots, weaknesses and limitations. Though it's not easy, their power can be contested. Which implies that refusing to rock the boat is just laziness or cowardice.
I totally lack the skills necessary in this case, but that’s my preference.
Google's apk signing changes comes to mind.
I know they are very much against decentralisation (technially), but in order to keep the service going even in that case it would probably make sense to create dozens or hundreds of legal entities. I know it sounds like a joke, but I know for sure in real estate or meatpacking businesses you have people register companies like "Joes Sausages #1", "Joes Sausages #2", ... "#400" - mainly to get around labor laws but also to make it complicated to determine ownership.
And don't underestimate how utterly dependent our governments are on the online industries - it is todays equivalent of the railroad, and getting control of the railroads was one of the important milestones in the october revolution.
Long story short, I don't think it is quite so one-sided, and I'm going to grab some popcorn...
Legal systems are peopled by people. Just like other systems. Unlike many other systems, the American legal system is in fact highly distributed—so it's hard to say things like "The System is out to destroy you"; individual agents of that "system" might have different, misaligned, or antagonistic goals.
Much of this is by design.
Of course, even when not by design, the local, state, and federal agencies, elected officials, and judiciaries which make up "the government" comprise a massive, federated, distributed organization, far more complex, and far less centrally administered, than the most chaotic FAANG company.
So if you think Microsoft can't turn their product strategy on a dime, well, the US government isn't capable of reacting to the Cellebrite blog post this quickly (even if this subpoena didn't precede that post, as someone else pointed out).
(As an aside, while I'm not a lawyer, the question on "interstate wiring" seems rather obviously to suggest that the investigators are pursuing a theory of federal criminal charges that require the messaging to cross state lines. Getting Signal to say "yes, this is interstate" might just be something they need to convince a grand jury the theory applies.)
What if there's a misconfigured logging server that has information that can be used to identify users? Well then that's now going to be given to the government and if Signal tries to turn it off they'll be liable for destruction of evidence.
The actual employees of Signal know internal details of if something is poorly implemented and leaks useful information or not. If the government rattles the cage hard enough, they think they might find someone within it that will give up that information.
A judge could in theory respond with 'orly, hand over source code'. What the judge could not do is say 'ok, source code shows you're telling the truth, but you should change it to record the information the prosecutor wants.' Only the legislative branch could do that.
Judging by how the the crypto wars played out the last few times, the "Four Horsemen of the Infocalypse" will be trotted out again soon, and probably with the addition of a new predictable character trope.
On a very macro level, tech humiliates intellectuals, politicians and other courtiers, or those who aspire to be them, and this motive is what makes forecasting a crackdown sparked by something like the Cellebrite pillorying seem reasonable.
That's literally how the justice system works in every case. For some reason it was designed this way.
How do you explain the 9th circuit court and their decisions around gun control while being scolded by SCOTUS for not following proper process? The legal system is highly politicized these days, and if your not on the “correct” side, it most definitely is out to get you. California turned a bunch of law abiding citizens into felons overnight after abiding by a law written by said government.
What if there is no conspiracy and this is basically marketing for signal to say “look. We have no data to share. Take our word for it under threat of perjury”
To George Floyd witness: "So you had something called a mobile device right? And a mobile device is capable of taking pictures right? And you used the mobile device to use that capability right? And your eyes were able to see things besides the phone right?"
No shit Sherlock, have you never used Facebook and seen the glaring ads? A 15-year old could figure that out. Oh and yeah phones take pictures and people have eyes that can move. Just play the damn video. Yes, play the video, not "publish the exhibit". They really do sound pretty stupid to me.
The legal system is not about truth. It's about corraling 12 fish out of water to your way of seeing things. Throw the judges/lawyers a curveball with something like jury nullification and see how quick things get nasty.
There a very good reasons for it even if it isn’t maximally entertaining viewing.
I'm sure everyone would agree that people have eyes and phones and that a phone can take pictures. Why is that a fact claim? Just show the pictures. And then ask real questions, like "what do you see" "oh look someone's knee on someone's neck". I hate inefficiency.
Every single one of those questions is establishing a fact in the record without which the opposing counsel would potentially have grounds to object to the presentation of the pictures. You can’t just show pictures without an explanation through facts themselves introduced as evidence, whether by testimony or otherwise, unless freely stipulated by the opposing party, of what the evidence is, where it came from, and why it is relevant.
Again, yeah, it makes crappy theater. The rules are about due process for the parties in a case, not keeping the proceedings engaging for an audience.
"Humans have legs right?"
"And how many legs do you have?"
"And legs can be used for locomotion right?"
"And you used those legs to translate your body to the location of the mobile phone right?"
"Oh yeah, you have a body, right? I forgot to ask"
"And there are these appendages called arms right?"
"How many arms do you have?"
> It originally included a broad gag order that would have prevented us from publishing this notice, but the ACLU represented us in quickly and successfully securing our ability to publish the transcripts below.
This subpoena says:
> you are asked not to disclose the existence of nature of the subpoena
But the post doesn't mention that at all. I wonder how much effort they had to spend, if any, to be able to publish this this time.
[1] https://signal.org/bigbrother/eastern-virginia-grand-jury/
I suspect it might not. I don't know why this additional information wasn't quoted by the parent comment.
Indefinite gag orders aren't a good thing, but if there is an investigation and knowledge of that investigation can interfere with it then I can see why they would be "asked" not to publish it.
These asks should have time limits though, just like security disclosure. The only valid reason to keep it under covers would be just that: because it could interfere with an ongoing investigation.
Asking to not disclose inquiries while an investigation is ongoing, or "withing 12 months due to an ongoing criminal investigation" would have better optics.
The lawyers at DOJ know what they are doing (notwithstanding the history or fact that signal will respond with little information): The subpoena has a request for interstate wire to help them quash future motions to dismiss on jurisdictional grounds.
Whatever statute they're looking to charge will have an element of federal jurisdiction attached and interstate wire works great even if there are other ways. It's easy to ask, so they'll ask for it all.
U.S. jurisdiction is complicated.
Fed jurisdiction extends in weird ways.
Or if that will disrupt Signal services. The central, non-distributed architecture is always a big concern against Signal.
There is a lot of very good point in this talk by Moxie, it's a bit long, but worth it.
I also learned a lot about why Signal does what it does.
I highly recommend this video to everybody, no matter your background or current work role.
Smartphones in their current form cannot have secure messaging.
What about self-hosted matrix/element, used from the browser?
https://developer.sony.com/develop/open-devices/
furthermore Sony provides blobs to enable full feature sets of the cameras and even the 120Hz refresh options that Sony doesn't enable with stock firmware / Android. This gets you notch free real UHD (but not DCI) 4K 120HZ HDR screens and the same performance as a Galaxy S10 for ~$150 | XZ Premium / the XZ Premium 2 model adds a 12MP monochrome camera and wireless charging for a bit more... up to the first Xperia 1 models are supported including dual SIM SKUs. I'm seriously thinking of going back to either of these from the iPhone 11 Pro Max 512GB I'm typing this on, because the PDF reading experience (even in 2K standard resolution) of the Sony was a unique experience of being able to read full page papers set Euro A4 and 8pt and less text and no problems for my 6th decade eyes.
if you're in the UK, www.aaisp.net is a isp that hasn't reached the statutory customer base numbers to require keeping the extensive and extremely detailed records of communications UK laws require. The company is privately owned by a PhD and Reverend and the people recognise you by voice if you establish a relationship needing the contact. Andrews and Arnold they can fulfil our compliance with encrypted call recordings by email and ability to configure your landline numbering plan over cellular for PBX equivalence. (I dunno if it's helpful but if you do speak with Phil Boddy I think he'll be willing to confirm that John K isn't a commission agent only a impressed customer about to resurface with new business because there's nobody else short of starting your own MVNO..
Incidentally in Europe only Andorra has cellular operators who don't spill location metadata with every SMS.
this story involves Vodafone Greece deleting potentially vital call records evidence of a assassin of a minister : https://en.m.wikipedia.org/wiki/Greek_wiretapping_case_2004%...
I can't find it (on my phone) but the fuller story is that due to high licensing costs of traditional (not vRAN) basestation equipment features, common practice in Europe retains virtually no call records evidence / data and overwrites everything on cycles only long enough for billing.
if anyone is interested in the public spectrum of 5G applications and the acquisition of test sites in London, my lock down research got as far as only needing to be formalised and pursued. I have put much more interesting details in my profile concerning this because I am as serious as I'm probably crazy but at the lowest utility I'm trying to find London interest in getting quality time with some installed, legal, vRAN systems and possess the necessary means and certifiability.
what gets me about the Huawei affair is how much straightforward argument there is to drop this monoclonal monopoly supplier in preference for massively more flexible and capable equipment from a plethora of suppliers who need to be made to do bake offs again like we used to (I remember reading 3Com white papers proudly reporting successful bake offs and recognising that that company was going places..) I mean Joe Public understands the arguments that matter to common sense and national security simply follows with unavoidable obviousness. Microsoft and Huawei were the only phone manufacturers who provided user defeat switches to 2G and hence the stingray intercept vulns. Both also made surprisingly good hardware, or could do. I'm old enough to worry about reds under the bed but I think it is positively the most amazing thing how given today's sensitivity to ecological impact of industry waste that we cannot require the reuse of the tools and process equipment created for closed product lines. Of course I understand the tax write off and the trade secrets concerns. But the incredible cost of manufacturing today surely has to force us to deliver mothballed factories to people who have ability to use them. At the very least I would use my day to be dictator to enforce the auction of all such manufacturing facilities.
I just decided against cutting my diversion into factory and product design recycling because I think far too much of the irresponsible attitude towards security comes out of the assumption that everything is going to be forklift upgraded every 2 years. This is precisely what is happening with cellular networking. The very same thing is opening the door to China to try and drive through standards and protocols that suit China for 6G and next generation Internet. Samsung basically just ignore the existence of every phone after 2 years from launch. Not from the day you purchase your Samsung phone. From the product launch date you have 2 years of maybe possibly a few updates and patches. There is no way that anyone would have tolerated this 40 years ago. Why now? I'm concerned that there's a more serious systematic failure of the human cognitive capability.
Now I'm wondering what it takes to get a phone contract in Andorra.
Unless you also ensure proper certificate pining, if someone can get a court order for any accepted CA to give them a valid certificate for your domain you won't notice a thing while that someone gets your browser to run any code and e.g. dump keys, certificates or messages.
There is a clever way of doing this, using a bookmarklet, a dataURI, and SRI, but the UX isn't great.[0] If something like Hashlinks[1] were supported by browsers, though, this could work quite nicely.
Certificate transparency logs make it possible to notice. I'm not 100% sure, but I think all major browsers require certificates to be logged at this point; and there are several services that you can list your domain and get notified when a certificate is issued.
You (or your users) may still be MITMed with the rogue cert without notice in the browser, though.
None of the browsers require by policy that certificates be logged. What this means is that the existence of a certificate which wasn't logged is not by itself a misissuance. Whereas for example the Apple 398 day rule is a policy rule, so a certificate which breaks the rule not only won't work in Safari, but it is also a misissuance and your whole CA might get distrusted by Apple.
However, all the major browsers except Firefox require that certificates they are shown which purport to have been issued after a mandate are presented with SCTs. We'll discuss what that means below. For Chrome that mandate begins after 30 April 2018, which means it doesn't catch certificates issued in a small window of time when certificate lifetimes up to 39 months were still allowed at the start of 2018, the last of these certificates would expire at the end of next month, May 2021.
In practice no public CA was selling unlogged certificates intended for web servers by the point the mandate triggers, it would have been a needless business risk to sail so close to the wind, so chances are no certificates in this category exist today.
Signed Certificate Timestamps are issued by the log, they are like "proof of posting" when you send a letter. The log warrants that any certificates for which it has issued SCTs will appear within the Maximum Merge Delay (for public CT logs this is 24 hours).
That might seem like a long time, but it's a do-or-die promise. Logs which experience a problem making them unable to show a consistent log with the corresponding certificate within 24 hours are disqualified and you need to start over, because without such a rule obviously you can smuggle anything into an outage.
Google and Safari's policy (I don't know the Edge policy) dictates two or more SCTs, at least one to be from a log controlled by Google. So this gives Google the handy property that they don't need to trust any combination of third parties, you must show all certificates to Google itself.
1) You don't get push notifications on most mobile OSes
2) Mobile users have poor control over their browser (if any.)
And I'm not sure what you're referring to by "control", but Firefox on Android allows you to install addons and use about:config (Chromium can't do the former and doesn't have an equivalent for the latter, even on desktop).
I do wish we had kept from the existing desktop OS ecosystem.
Apple's update schedule is a lot better in this regard for me (iPhone SE still gets iOS 14 FROM 2016)
The clients are open source, presumably you can compile and install the client from source to avoid a bad update being pushed.
As I understand it if you take this code, and the binary blobs of the code that does stuff like video calls, you can verify that's what is inside your Play Store APK.
Now, if you're a tinfoil hat wearer obviously you can consider that maybe the video call code secretly reads your messages and sends them to the FBI, or indeed that the Android OS just ignores this APK and when you install it you get something else entirely anyway.
But it sure looks like the source code is in fact for the app you get.
https://transparency.dev/application/add-tamper-checking-to-...
> [...] because the data is transmitted peer-to-peer or relayed through a third-party server [...]
Attachment A, Section 2C
Each entity could have their own public key (also hardcoded into the client), and the client could pick one at random and then bootstrap you up to the entire P2P network, where it would find the other hardcoded identities (or N out of M of them) to confirm you were seeing the whole network.
Probably is that all of those techniques, are still centralized.
I suppose you could argue that the list itself is centralized, if there is only one list, but if the protocol is an open standard then different clients could ship with different lists.
Would you say that the web PKI is "centralized" because most browsers agree on which CAs to trust?
This trades two different privacy risks, would you prefer that a hypothetical adversary who has successfully seized control of Signal can see which IP addresses are communicating or would you prefer if people you accept realtime calls from or make calls to learn your IP address?
You get to pick which you prefer in the Signal app preferences. [Edited to add: Specifically, if either of you insists on having Signal relay the traffic, then that's what has to happen, otherwise it is peer-to-peer.]
As with anything else involving IP addresses, you could choose to go via Tor, with all the consequences of that.
Okay boys, take all these servers because evidence is hiding on them and these lefty pinkos aren't helping us find it. Let's get them back to the lab to find out what that evidence is.
2) The social connection graph is easy to extract when people communicate often
3) The more data is captured, the more likely it is to find suspicious coincidences that are actually false positives
4) Not everybody lives in a healthy and safe society
Please consider recommending Briar or similar onion-routed messengers instead of Signal, Matrix, XMPP
In [1], Signal mention that traffic correlation via timing attacks and IP addresses are a work-in-progress as far as their metadata protection goes. They also claim that they do not store IP addresses, or at least they are not set up to do so. I guess they can be forced to record some of these, if need be.
I am not deeply concerned about the metadata Signal could possibly collect if compelled to (although it is unclear what exactly they can collect) because it is likely best-in-class among encrypted messengers anyway. I suppose it is likely that even if Signal were forced to lie or undergo a gag, the chance of whistle-blowing would be much higher given that they are a donations based nonprofit that probably employ more young-ish people with strong principles, as opposed to employees who need a stable job and have families to look after.
That’s it."
Signal offers a "registration lock" for the phone number used to register the account, so that another user cannot register using the same number (i.e. reusing VLNs and similar). If "that's it", then where is the phone number (or its hash) associated with the account stored in order to facilitate the lock?
I wondered originally if this would help disambiguate accounts, perhaps if two numbers last logged in at the same timestamp one could guess that they were on the same device or something, but this doesn't look possible.
Is this an elegant way to notify those six users?
For example, last number last connected on Sep 13, 2020 (they're just dates, no time info stored), while the account was created on July 7th, 2020 at 16:15:37. Knowing the number's without Internet access for over half a year, person in question is probably unable to compare the creation date and time to the SMS received from Signal.
Are they connected?
Signal gets this subpoena on the 29th March, and the reply by ACLU is on the 12th April.
Signal's founder and CEO, Moxie Marlinspike, hacked Cellebrite and the story surfaced this week.
Was it retaliation? Was it just because the subpoena made him wonder? Or is there something else causing Moxie to lash out at Cellebrite about now? Or was it all chance?
Doubtful there's any connection between the two.
[1] - https://securityboulevard.com/2020/12/signal-app-crypto-crac...
Based only on this post and the Cellebrite hack, Signal appears overconfident, taken with their own press clippings, and making enemies. That's not behavior that leads to good security: Paranoid, worried about the next vulnerability, and utilizing excellent risk management to prevent conflict are what I would look for. How does it help their millions of users when Signal provokes a leading forensics firm and the U.S. DoJ?
Could you imagine a security team at a company doing this, making problems for the company? It would be absurd. Maybe Signal feels they need the publicity.
The Cellebrite hack is not a shocking thing, similar demonstrations have been done for other digital forensics, IDS/IPS systems, and others over the last 20 years (longer?).
This notion that directly, and clearly calling out your adversaries deficiencies is unprofessional or a risk is kind of asinine, whether it's another business like Cellebrite, or ongoing government overreach in support of mass surveillance, or specific cases of investigation.
Failing to call them out leaves room for to imply agreement with their tactics and practices.
I don't see Signal's recent blog post as trying to pressure Cellebrite to improve their security. And the fact that other people do something isn't evidence of good judgment - other people can be stupid, and your circumstances are your own. Moxy doesn't work for possibly the most well-resourced security organization in the world (maybe outside the NSA), and he's not some independent hacker: he has a company, a product, and the privacy of millions of people that he has taken responsibility for - it's like having kids: you don't get to think of just yourself anymore, ever.
> asinine
At least you take your own advice.
I worry that Congress with just make them liable if they are requested to produce location data and are unable to do so, for example.
Signal, just follow the law and quit acting so happy whenever your software helps a criminal get away with criming. It's not a good look.
In fact I'd argue that anyone who is not a criminal is probably quite a boring and uninteresting person.
Traffic is probably one of the easiest examples where disobeying the law makes a ton of sense multiple times per day/week.
I would not want any entity to be able to track my history of these kinds of felonies committed multiple times per week (not related to Signal though, but keeping track in general).
And don't get me started on drugs. Crime has gone down a lot by decriminalizing marijuana for example. "Crime".
Software that allows the possibility of cops spying on you is antithetical to "privacy and good software"
I am amazed that Signal claims to be private while requiring all chat participants to expose their government-regulated phone number often tied to the legal identity.
Such strange and probably necessary legal language...
And in other jurisdictions, only the correspondence would be inaccessible. Furthermore, there would be no need to contact Signal because you can get that information just from their phone number.
Just in case anyone is still wondering why there are users who still complain about Signal linking accounts to phone numbers.
The cover letter from DHS says they need to warn the agent before disclosure. Presumably they did that.
I wonder how they'd like it if you sent them files literally named
FILE001.PAGE001.*.TIF
(the rest of the specified file format structure notwithstanding)It's very important to follow the instructions exactly when you are legally compelled to do something!
A: "Because you specified an extension, not a file format."
It will continue until Signal agrees to become part of the surveillance state or goes broke and goes away.
Either or it shows how tone deaf the state is when it comes to modern technologies.
For about 24 hours no messages could be sent, resulting in a 401 unauthorized error from the server side.
Telia is the former state-owned Swedish ISP that is now only half state-owned I believe.
They have a bad rep already for sending out extortion letters to torrent users and are almost assumed to be monitoring all user traffic for the police.
No explanation of the event has been provided by anyone. Users have done some basic troubleshooting but couldn't really establish much. I personally would love to see what those 401 errors looked like on the Signal server side. What exactly were these clients sending that was unauthorized on the server side? I guess we'll never know, hopefully it wasn't even stored.
That's almost never the ISPs doing, they are being strong armed by IP owners.
It is entirely possible that somebody at Signal fat-fingered an IP address block, e.g. some kiddie is spewing 10Gb/s of traffic from 10.2/16 to Signal, but a Signal person blocks 10.20/16 [addresses example only] and only a week later when investigating "Why are we still eating 10Gb/s of spew?" do they realise they typo'd the number.
https://textsecure-service.whispersystems.org/v1/config
HTTPS is HTTP protocol spoken over a TLS encrypted channel.
When these Telia users weren't able to use the Signal Desktop software, this fetch failed, with a 401 error which is the HTTP error code for Unauthorised.