Grand jury subpoena for Signal user data, Central District of California
signal.org
signal.org
I actually believe that law enforcement has the legal right to subpoena information, with a judge's consent, while investigating criminal activity. This is exactly the solution to that problem. These platforms should want to know as little about you as possible.
The problem is abuse of that system.
Let's be clear There is no reason to assume that this type of thing is constrained to "just the type" the government can have their arm forced into admitting to.
> "... In a democratic country governed by the rule of law, indiscriminate spying on individuals cannot be allowed except with sufficient statutory safeguards, by following the procedure established by law under the Constitution ...
> We had made it clear to the learned Solicitor General on many occasions that we would not push the Respondent-Union of India to provide any information that may affect the national security concerns of the country. However, despite the repeated assurances and opportunities given, ultimately the Respondent-Union of India has placed on record what they call a "limited affidavit", which does not shed any light on their stand or provide any clarity as to the facts of the matter at hand.
> However, this does not mean that the State gets a free pass every time the spectre of "national security" is raised. National security cannot be the bugbear that the judiciary shies away from, by virtue of its mere mentioning. Although this Court should be circumspect in encroaching the domain of national security, no omnibus prohibition can be called for against judicial review.
> The Respondent-Union of India must necessarily plead and prove the facts which indicate that the information sought must be kept secret as their divulgence would affect national security concerns. They must justify the stand that they take before a Court. The mere invocation of national security by the State does not render the Court a mute spectator"
> ... We are not interested in knowing matters related to security or defence. We are only concerned to know whether Govt has used any method other than admissible under law ..."
Source: Supreme Court Constitutes Independent Expert Committee To Probe Pegasus Snooping Allegations - https://web.archive.org/web/20211029130706/https://www.livel...
For iOS users, that will be a death knell.
You press the only non-"give up" button at each stage and you're done.
Remember that Fortnite succeeded in convincing people to do this by the millions. It's not hard.
Somewhat. And sometimes. And when the high-security-site for installing a high-security-tool is asking you to do a thing, it's quite a bit psychologically different than e.g. a reddit post saying "install this apk and approve all prompts: http://www.5z8.info/hack-outlook_w2f7vj_dogfights"
Come to think of it, that'd be the perfect place to go to demand a wiretap - at least one such popular "LY" service already exists.
I'm still shaking my head at what many regular users will agree to..
I’ve been watching _The Wire_ and Idris Elba’s character sounds like a good overlap, but he feels very unusual (in fiction)--and definitely too careful about OpSec to use that kind of service.
More generally, there’s a lot of anecdotic evidence between problematic behaviour and low-level spelling details: one that is apparently better documented now is a correlation between insurance fraud and whether you capitalise properly the name of your employer on registration form.
If they had developers in, say, France, who would need to accept changes made somewhere else then a single country could not force such secret modifications.
Of course an app is actually a binary, so there must be a way to verify that code + compilation = the published binary.
The Internet may interpret censorship as damage and route around it, but spy agencies interpret laws as inconveniences and ignore them.
As access closes in one place (i.e application layer), they will just get closer to the source (i.e operating system or supply chain)
Same goes for music and video - we won't be legally allowed to hear and watch non-DRM-playable devices as the speakers and displays will be rented not owned by corporations.
We have almost arrived at the Rental Economy, where we dont own anything and are at the behest of corporations. It's modern serfdom
The more I think about it, the more I am convinced they could do this, but they would rather not because it's much harder, since it requires a special warrant with high evidence thresholds for each user. This reinforces the claim that what they really want is an ability to get any messaging data without a warrant, but they don't want to say so.
I could be wrong but I was under the impression that the way end-to-end encryption worked (like what Signal claims, I thought) was it was physically impossible for them to decrypt (handover decrypted data (aka your messages) to a court of law) because the public/private keys are impossible to crack and also not known by Signal.
It sounds like this isn't the case whatsoever.
I don't really understand modern chat apps that talk about encryption. By no means am I a pro on the subject so I apologize in advance but... if you really don't want ANYBODY EVER snooping on your data network wise (unless they are holding one of the devices and reading the screen after it has been unlocked via passcode/biometric, etc.), can't you just tell your friend a key and exchange it offline and then communicate freely with no middleman? Or even, with a middleman... that is just transporting your data and doesn't know your agreed upon shared secret or keys.
How could a subpoena ever work against this kind of data?
Then there's IPs. If you log IPs along with when someone connects, then an IP can often be tracked to a WiFi router, which then pins your location.
Most E2EE communication protocols will see (and thus potentially log) the time and destination of every message you send. If two people have been accused of conspiring to commit a crime, this could be material in forming the case. They may also store your contact list, but a sufficiently long list of messages sent will practically determine your contact list anyways.
Even just the time of messages could be important; if someone interviewed claimed to be in the shower at a certain time, but there were logs of a message being sent at that time, that's probably enough for an obstruction of justice charge to stick.
I guess you mean each time you connected to their server to retrieve messages? There is no "login" step, Signal doesn't have a log in process. Presumably a typical Signal client calls several times per day.
The record they provided says connection date and despite being supplied in milliseconds since the epoch the value appears to indeed represent a whole day not a specific time. So you're correct Signal could be lying and actually store the exact moment you last connected, for whatever that's worth, and we could not prove they don't have that info.
> Most E2EE communication protocols will see (and thus potentially log) the time and destination of every message you send
Signal doesn't know who sent messages among close friends, and optionally not anybody who sent messages to a sensitive account.
Let's take the example of a message I sent to my friend Chris. I know Chris, I've sent messages to him previously and he knows me, so I'm in his contacts list. As a result by default my Signal client keeps some "Sealed Sender" tokens for Chris. When I send a message to Chris, my client uses a token it learned from a previous conversation with Chris, but Signal doesn't know who I am, just that I have a valid token for sending messages to Chris. So it stores the message, and gives it to Chris. Chris's client can determine that this is a message from me, tialaramex, but the Signal service never knew who sent the message.
If one day Chris hates me and blocks me from sending messages, his client invalidates all Sealed Sender tokens, and begins issuing new ones to his other friends so they can continue to contact him.
I am aware of this, and I had split my comment into "extra things Signal could log" and "Extra things most other E2EE services could log" but somehow lost the divider between the two during editing.
Also, "Impossible" is not the right term. "Extraordinarily expensive" is a better one. And yes, anyone can share public keys with each other offline and have end-to-end encrypted communication without help from a service. But advertising companies and the govt are not incentivized to make that practice convenient, and people typically do what is most convenient.
Issue a subpoenas for something they know they can't architecturally fulfill? I would imagine the government will get mad and shut them down, no?
can't you just tell your friend a key and exchange it offline and then communicate freely with no middleman
Yes, keywords are pubkey, fingerprint, diffie hellman. It’s easy to use, just run:
openssl genrsa -des3 -out private.pem 2048
to generate a key pair, then export pubkey via: openssl rsa -in private.pem -outform PEM -pubout -out public.pem
Once you have you exchanged pubkeys and checked fingerprints offline, simply create a new secret key: openssl rand -base64 32 > key.bin
and encrypt that new key and also your message with it: openssl rsautl -encrypt -inkey id_rsa.pub.pem -pubin -in key.bin -out key.bin.enc
openssl enc -aes-256-cbc -salt -in message.txt -out message.enc -pass file:./key.bin
Now just send .enc files over the wire. It is trivial to decrypt at their side, even my grandma can do that. She usually leaves raw files in her downloads folder though, but it’s easy to remove them via local crontab job.I read a good short story on the subject recently, "The Truth of Fact, the Truth of Feeling": https://en.wikipedia.org/wiki/The_Truth_of_Fact,_the_Truth_o...
PS: I didn’t notice the attachement. Yup, that’s _exactly_ what they send. Curious whether the suspect could recognise their creation date and know that they are being investigated that way--and whether that exposes Signal.
While you might forgive someone working for interior ministries, this is an automatism towards fearful stupidity. Benefits don't play are role here, it is exclusively about any potential security benefit, doesn't matter how small.
Sadly signal is based on phone numbers which I dislike, but other messengers should take note here.
It's probably fine here, but if you store it in binary, you should probably parse it into something human-readable.
It's the final dash on the icing of "politely F yourself". Compliant and accurate but "let me burn up a little bit _your_ time" (pun).
Made me smile.
Does anybody know if Apple's notifications are E2EE? I doubt that gov't doesn't have access to the push notifications...
> [...] never include sensitive data or data that can be retrieved by other means in your payload. Instead, use notifications to alert the user to new information or as a signal that your app has data waiting for it.
https://developer.apple.com/library/archive/documentation/Ne...
https://developer.apple.com/documentation/usernotifications/...
Edit: wow people were fast to reply…
The same may or may not be true for Apple (I have no idea) but claiming it is irrelevant as an answer to a question about whether an _Apple_ technology is encrypted, is mind boggling to me.
In this case, root being the device and OS, it has unrestricted access to everything happening by your actions. The data you see on your screen is processed by the CPU, developed by Apple, controlled by kernel, coded by Apple. The can access everything they want.
Good grief, why would you do that? Just send a notification that data is ready and the when the app wakes, go get the remainder of the data from signal servers.
https://developer.apple.com/documentation/usernotifications/...
The E2EE in Signal only protects the actual content of messages. In the case where Signal takes an assertive action, and the users are not paying any attention to their "safety numbers" (probably the most common case) they could in theory get message content with a MITM attack.
With an less assertive action (simply saving the data) Signal could get access to things like contacts and phone numbers.
Tutanota and Protonmail have both been forced in the past to take assertive actions to retain data as a result of legal warrants. Does American law even allow such warrants? If not then perhaps the USA is underrated as a place to base privacy oriented services.
https://www.legislation.gov.uk/ukpga/2016/25/section/87/enac...
Ctrl+f for "generation"
Basically can the UK government compel you under the threat of criminal prosecution?
Noncompliance with a data retention notice lands you in court, but it's a civil matter, not criminal - though if you then ignore an order of the court, you could be facing some jail time and/or a fine for contempt of court. https://www.legislation.gov.uk/ukpga/2016/25/section/95/
Regarding compliance costs, there's a vague provision in the IPA for contribution to your expenditure: https://www.legislation.gov.uk/ukpga/2016/25/section/249 A little more detail, although not much, can be found in the accompanying Communications Data Code of Practice
I am a lawyer, but I am not YOUR lawyer.
They use sealed sender: https://signal.org/blog/sealed-sender/
Private contact discovery: https://signal.org/blog/private-contact-discovery/
And a "Private Group System" which is supposed to keep group membership information from the server: https://signal.org/blog/signal-private-group-system/
Though of course they could still push malicious updates.
The private contact discovery depends on an Intel SGX hardware enclave on their server. Which is good in this case as it implies more work to bypass it but where is the ultimate trust here? Intel? Did Signal ever get this working?
In general Signal can just see what IP address/port picks up a particular user's pre-keys if they want to know who is talking to who.
> The E2EE in Signal only protects the actual content of messages.
> [By] (simply saving the data) Signal could get access to things like contacts and phone numbers.
And the linked blog posts show that for a few years now they've been working on limiting their own access to this kind of data --- i.e. it's not as simple as just saving it (like e.g. WhatsApp is able to and most likely doing 100% of the time to build social graphs).
Now of course all of those things are likely vulnerable to some attacks, but that's another discussion and it doesn't change the fact that Signal doesn't have immediate easy access in the way you claimed in your original comment. The fact is that there are some barriers and they'd have to put some effort into either disabling these protections or exploit flaws in them to get to the data.
I did not at all mean to imply that. The assertive action that Signal would have to take might involve actual work. The question is if they could be forced to do that work by the authorities of the country they operate from. I doubt that the amount of work would really factor into the legal stuff.
Signal of course might of already done the work as part of some cooperation with a national signals organization or simply because someone felt bored and contrary, but they could not admit that if they want to preserve the value of the information gathered.
The E2EE encryption part is in the end the only provable aspect of Signal Messenger. The leakage of meta information is inherent when one entity controls all the infrastructure.
Even worse - American laws allow the US government agencies to actually access the servers directly (or even add other servers or routers) in the data centre of the service provider, and the service provider is legally obliged to not tell anyone about it!
The Congressional response should be, "Do you have no other way of investigating these criminals?" "Could you not put an officer out to surveille them?", "Have you not seen the misuse that law enforcement has engaged in, with such capabilities? From petty revenge to stalking lovers who rejected them. Will you consent to mandatory surveillance of all law enforcement officers that is recorded and stored in a civil controlled repository so that officer conduct may be reviewed at any time?"
They won't say that of course. But they should.
I very much suspect that who is elected has nearly zero effect on spying programs.
- Senator Chuck Schumer
And blackmail is only one tool in the toolbelt. Bribery comes long before that. Anybody with too much integrity is quickly removed from office or worse.
Ive tried to explain to some progressives why AOC and the squad have turned their backs on them with this, but for many their schoolhouse rock propagandized brains refuse to admit its as bad as it is.
It only gets worse the more we aquiesce to increases in censorship and surveillance (which I like to remind people is in the hands of the executive branch, further eroding the checks and balances system).
I could be missing something, but I did a quick search and all I see is news about them scrapping their once-encrypted backups at the request of the FBI.
And the reason for the huge backlack, is that this stop gap will actually make it easier for them to request more afterwards, because the infrastructure, the proof of concept, will already be there and running. And it will cross to other providers: "see Apple does it, so clearly it's Signal that's being protective of criminals, we should impose them to do the same thing Apple did with no issue".
The arguments about slippery slopes and potential surveillance weren't as interesting to me as the opposing argument: that a very high level of privacy (not even an absolute level) carries consequences for a specific segment of society by the intrinsic nature of what is kept private, and in the name of protecting that segment of society, the tradeoff is not worth it.
There is also the idea that data on a hard drive can be as damaging to human livelihood as physical contraband, to the point that the vast majority of the world's legal systems, not just those of the U.S., have decided that the data should not exist under any circumstances. CSAM is one of the few classes of digital data that compels the creation of scanning systems for such data on a scale that isn't driven by political ideology, propaganda or similar. It's difficult to imagine how Apple would be obliged and driven enough to implement such a system out in the open and in the name of the public good if the publicly announced reasoning was to scan any other class of data (assuming that Apple can be trusted, at least).
I simply disagree with the notion that I should be controlled and monitored by a third party just because someone else might do something evil.
We should always remember that power corrupts and definitions of evil change almost on a whim.
I don't know why we accept the same things when we're talking about digital privacy.
Here the problem is when you go down the ballot and reach the judges, schoolboard, and other offices where most people have no idea who the candidates are and many just vote randomly.
In Arizona there was a campaign that unseated an incumbent schoolboard member by a rival candidate whose last name, if some letters were transposed, was a famous local figure. The funny last name guy won.
So go ahead and vote, but please leave blank or skip over any of the candidates that you haven't researched. Don't vote randomly - some people are trying to have a real election.
It leads to abominations of platform planks, but in our race to the bottom as least you get close to what you think you want.
And that's for hyper-partisan issues! I'm not sure there's any truly influential political group that would strongly oppose this. Thinking it's just the politicians who are unaware and/or disagree with the tech-minded is a mistake. The populace is less on our side re: surveillance than we'd hope.
If that happens, hopefully usage of p2p messaging apps like Briar or Status will gain more traction and usage.
Complying with such a request is going out of business.
"Could you not put an officer out to surveille them?",
Your argument kind of falls on itself there --> We can surveil them in person, but not digitally?
Why?
I think the tech crowd has this wrong.
The issue - as you have indicated - is not 'By What Means To Surveil'.
The issues are: Legitimacy, Proportionality, Oversight.
Messages, tech, sign language, in person, phones or messaging pigeons, the issue remains the same:
Is there a legitimate reason for access?
Is the intervention proportional to the probability of cause, the ostensible crime, the risk to other citizens and the public good?
Is there authoritative Judicial oversight of the surveillance, and, is there sufficient Congressional oversight of the legality of the program?
Those are the questions.
Should police be able to tap Signal (or anything else) for data on anyone they want, for whatever they want, willy nilly without a Warrant or oversight?
Definitely not.
Should Apple be scanning content for crimes?
Probably not, but that's slightly more complicated.
Should the police be able to access the Signal messages of someone they apprehended at a murder scene wherein other suspects fled the scene, and are therefore likely the suspects accomplices?
Likely yes. Or at lest, most people would agree with it both in the pragmatic sense, and also the Constitutional sense.
Should the FBI be able to, with special permission of a Federal Judge, watch all cell tower transactions in 5x5 mile grid grid, while there's a literal manhunt on for literal terrorists during a literal state of emergency?
Probably yes again, it's hard because the proportionality and tactics are rare and unique.
The technology is a secondary issue.
Because, before the internet, when surveillance was a lot of work, this prevented the abuse that is mass surveillance.
Only now do we see how much democracy relied on this natural limitation of state power for civil rights. It was never just the need for warrants that maintained civil rights. Remember the Verizon FISA court order authorized surveillance of millions, and that was just one order of hundreds.
Power corrupts. State power should be sufficient, but minimal. Being allowed to do physical surveillance only is sufficient to reduce crime rates to the point where most people can safely neglect that crime exists at all, and it is less power because it does not scale.
You mention proportionality yourself. Proportionality means that something is not done if the same objective (finding a given murderer) can be achieved in a less rights-infringing way. Proportionality at the policy level, means that a surveillance power may not exist, if its objective (such as safety from murder, i.e. low rates of murder, high chance of finding murderers etc.) can be achieved without the power or with a power that is less likely to be abused or that infringes rights of suspects less. (I admit this is somewhat of an editorialization; the technical meaning of proportionality is in [1]. To be clear the existing legal proportionality principle does not try to directly minimize power; but it does usually present an obstacle whenever new powers are created by law)
Limiting power is simpler and less error-prone than allowing power and adding control structures like warrant requirements for the power. It is thus better, if the outcome is the same.
---
[1] https://en.wikipedia.org/wiki/Proportionality_(law)#European...
> Likely yes. Or at le[a]st, most people would agree with it both in the pragmatic sense, and also the Constitutional sense.
Sure, but that is not the question. The question is: should Signal be forced to implement its software in a way that allows the police to access its messages?
Likewise, everyone also agrees that in person surveillance is in general legitimate, but that doesn't mean that we all agree that the government should be able dictate burdensome measures on third parties to make it easier to perform this surveillance: say require that the friends of the suspect keep notes on his whereabouts. Changing its architecture would cost Signal a lot of money and good will, and the suspect would probably not be very happy that his friends ratted him out as well.
They are not willing or able to do that for whatever reason, but the ability exists.
I agree the technology used is a secondary issue, but Law Enforcement got lazy when they were able to wire-tap phones willy nilly whenever they wanted. They need to get un-lazy again. They can do all they want to do without needing un-encrypted traffic, un-encrypted traffic just makes them not have to work as hard.
I'm fine with them having to work harder instead of them getting to see all the communications they could ever dream of.
Are they though? First it's "only" to catch the super-terrorists. Then it's only to catch the murderers. Then it's for VIP missing person cases. Then it's petty crime. Then it's for political opponents. Then nobody dares ask anymore about "legitimacy, proportionality, oversight."
When those in power grant themselves more power, the onus is on them to prove they can't abuse that power. Of course, the way power works is they have that choice and we don't.
Are you confusing S44 with S60 Stop and Search?
I believe under those circumstances, the police should be able to apply to a judge for a warrant, and if probable cause is found and a warrant is issued, attempt to access the Signal messages of such a person. A requirement that they succeed has technological implications; Signal, the device, or both would have to contain a backdoor, or use security measures that are not very effective.
I am an absolutist on this question; I don't think governments should have the authority to mandate backdoors in products or services even if doing so would result in the prosecution of many criminals who otherwise go unpunished. For those who want to balance the government's interest in prosecuting criminals against secure and private communications, the question I would ask is: how often do investigations or prosecutions fail because it was impossible to access encrypted data with a court order? A precise answer might be difficult since the content of the encrypted data is unknowable, but an upper bound could be established by assuming such encrypted data is always incriminating.
Make it fully decentralized with economic incentives for node operators.
some projects trying to do this now are Status, Session, Sylo
Silos are the reason that platforms get centralized in the first place: people generally enjoy using the same X as their peers, so they can communicate in a single platform.
We need DNS for everyone, not just the rich...er those bothering to register a name.
Make it GUID based, and let people contact each other by GUID instead of phone number.
Preferably add privacy enhancing encryption too so that only those with your public key could decrypt your GUID DNS entry to then find your IPv6 address.
Or something smarter than that probably.
DNS already exists as a point of centralised control. Service Providers already have to log IP vs user accounts.
don't see how extending DNS for the masses could make things any worse.
As a sibling comment points out though, who pays to run it?
OpenLDAP's a bugger to configure, and it's much more than you need for a simple directory. But ActiveDirectory is nearly omnipresent.
I'd say the big problem at the moment is that people are not used to paying for service. Lots of stuff related to naming is very cheap. But if you require it to be free, then you will get bad incentives like trying to build a silo and fill that silo with ads.
That way, users ARE paying for it. And honestly, it is a fundamental internet service, just not in the way most people think of.
I’ve never been offered drugs by anyone in my life and I couldn’t tell you if someone standing on a street-corner is someone simply wanting to cross the street when the lights change or an undercover cop… or an actual prostitute. What am I supposed to be looking for?
(Yes, I’m on-the-spectrum and don’t get invited to parties, so I’m not representative of everyone else’s experience, but I am being sincere in my anecdote)
In reality most people aren’t going to (or rather, shouldn’t try to) seek out drug dealers and prostitutes on the street. For the former it’s more likely someone will “know a guy who knows a guy”, or maybe use the dark web. For the latter there are websites and classifieds, you just need to know the right terminology, etc (from what I’ve gathered, I have no personal experience...)
So yeah, it’s underground, but not that underground.
Going downtown around 1am on a Sunday morning should get you the full package, at least in most European cities. City parks, albeit edgy and dangerous, are an almost sure bet.
Dealers usually ask you if all is fine and you need help with anything, prostitutes clues are usually attitude and attire, plus they often work in groups. A good undercover cop will be unrecognisable, for obvious reasons (they have to copy criminal behaviour to be successful).
Providers have a harder time than their customers (longer jail time and higher fines) hence the secrecy which makes it diffocult to spott them.
When in doubt assume it's not a professional, if they are they will make it obvious.
Trafficking underage girls is obviously a crime against another human being, it's not a victimless crime like drugs and should be punished.
If you're killing yourself with unhealthy eating in private, it's on you. Despicable choice for sure, and it sucks if a bad environment drove you down this road - but that's on you: don't make me pay for your healthcare.
We just need someone to step up and collect the data.
(Analogously, this is why law enforcement professionals and the like have been moving to the term "child sexual abuse material" instead of "child pornography": the problem with it is not that it's pornography, it's that it's sexual abuse.)
It is not only entirely possible to fight the crime of trafficking people and forcing them to do certain acts without criminalizing those acts, it is in fact significantly more effective. Imagine, for instance, if Abraham Lincoln had tried to eliminate slavery by declaring that picking cotton was illegal. Not only would it not have addressed the problem, it would have made the problem worse - slaves are in no position to refuse to do an act because it's illegal, and a fugitive slave would be liable for the crimes they committed as a slave.
Prostitution does not have victims. Forcing someone into prostitution has a victim - the unwilling prostitute. This is a crime committed by the trafficker against the prostitute, not a crime committed by the prostitute against the client (or even vice versa).
Again, take the example I gave of slavery. The analogous argument to yours is to claim that cotton picking is not victimless. Obviously there were victims in the antebellum south. But to say that cotton picking is the crime is to miss the point entirely and to hurt the victims of the actual crime. Cotton picking is victimless, unless you think cotton feels pain. Forcing someone to pick cotton is a crime.
STDs are not a crime*. They are a potential downside of sexual activity of all kinds. We are comfortable with all sorts of activities having potential injurious downsides which are not criminal. You can get a concussion playing football, but that doesn't mean giving someone a concussion in the course of playing football (as opposed to because you specifically set out to attack them, of course) is a crime, and it certainly doesn't mean that playing football itself ought to be criminalized. If someone claimed that the only way to stop football concussions was to criminalize the game, we would find that position laughable or at least dangerously authoritarian.
Robberies and killings are a crime, and they can be prosecuted in their own sake. Robberies and killings also happen in, say, banks; we don't say that this is a reason to make banking illegal.
In fact, it is because banking is legal that police and regulated armed guards can be at banks and stand by as legitimate, victimless banking transactions happen, and that a bank under attack can call for the police and know that they will not get shut down. Going back to the example of the fugitive slave - a slave who knows he's been forced into illegal actions is unlikely to seek his freedom and is quite likely to seek the effective protection of his master, preventing him from accessing the liberty due to him in a just society. Similarly, people participating in the victimless crimes of the sex or drug industry generally have little recourse to the justice system. Robberies and killings (and mistreatment of prostitutes) happens because criminals know that their victims do not have the same ability to pursue justice as the general public does. Fully legalizing these industries is the only plausible first step to solving this problem.
* I should probably say that they should not be a crime. Some jurisdictions have such laws, and they are widely recognized to be both unjust and ineffective, e.g., https://en.wikipedia.org/wiki/Criminal_transmission_of_HIV_i...
Concentration of money will cause unscrupulous people to gather.
Realistically, legalization doesn’t end these issues.
> For the onion router to work properly, the Navy needed to step back from running it. A cloaking system is not useful if all the cloaks say “Navy” on them. “If you have a system that’s only a Navy system, anything popping out of it is obviously from the Navy,” Syverson says. “You need to have a network that carries traffic for other people as well.” Tor Project was incorporated as a nonprofit in 2006 to manage operations. [0]
[0] https://www.bloomberg.com/news/articles/2014-01-23/tor-anony...
...it's kinda like how we were all told that the 1950s-1970s space-launches with monkeys and other animals in them were for bio-scientific experiments when they were really just cover stories for launching spy-sats and military satellites.
To be clear, they encourage democratic ideals where/if it's in their own interests to. There are plenty of places where they encourage non-democratic ideals as well (or directly fund their own coups to put usually military leaders they like in power).
I wouldn't trust Tor to solely protect my identity since there might be ways to attack it. But it can be an useful asset in a "pipeline" designed to protect one's identity.
Well, that would explain why the nodes don't get shut-down when the local police come knocking...
Still, that must require some very awkward conversations when ethics committees or even departmental budgets are approved - not to mention inviting consternation from the general-public who really don't approve of their tax-money being used to knowingly facilitate dark-net activities, especially horrific child abuse, ugh. (I'm a utilitarian myself, but personally I'd pull the plug on it: surely there are better ways for embedded agents to exchange information? What about digital-steganography, and concealable satellite comms hardware?)
Just make the network work based on open protocols, where anyone can run a server that interoperates with others. (Matrix.)
For the non-developer end-user, they can use one of the existing servers, who in theory could charge their users.
Yes, it would be hard to maintain branding cohesion, and the product/service would lose to a centralized service. However, transitioning to heterogenous social/messaging landscape (from current oligopolies) could make smaller services like that competitive.
IMO it’s not clear we should treat a legal/political issue with technical workarounds, it doesn’t seem sustainable.
Some people do pay for their e-Mail providers today...
In a network like Status or Session, you don’t need to know and don’t care who runs the node you happen to be using at a given moment.
In a network like Status or Session, you don’t need to know and don’t care who runs the node you happen to be using at a given moment.
Isn't registering an account necessary to avoid impersonating? how does Status ensure a stable user ID?
Everyone gets a random super long number for an ID. Your friends can assign your name when they add you as a contact (just like phone numbers). And then you can also get a globally recognizable name like ENS domains if you want to pay a little. It’s like a vanity plate on a car.
Not to mention that you don’t actually own your accounts unless you run the server yourself.
> The only information Signal maintains that is encompassed by thesubpoena for any particular user account, identified through a phone number, is the time of account creation and the date of the account’s last connection to Signal servers. That is all. [2]
> [2] see e.g. https://signal.org/bigbrother
And those people who help you draft patents for your computer-related inventions? Also lawyers.
I think this should be implemented regardless. But the danger is they can easily say "sure; your turn". Some in law enforcement may even genuinely want to do that for its own sake.
I think that's a totally orthogonal thing to violating citizens' privacy and shouldn't be considered as leverage or a counterargument.
It won't help them but will still do a lot of damage. And they wonder why people don't trust a single word they say. Poor representatives...
Why are the previous subpoenas Signal Messenger LLC has refused not sufficient for this purpose?
In addition, I’d wager lots of politicians use it now for obvious reason’s.
Ergo that won’t happen. That being said, can’t blame DoJ for trying though.
As they say, “Put your money where your mouth is.”
Some people think the ACLU should fight specifically for such organizations to make a point that everyone, even hateful bigots, have the same rights.
Personally? I'm on the fence. On the one hand, given limited resources & all else being equal in two cases, why not choose the group of people who are nicer? On the other hand, if you choose the hateful group & set a precedent that even the most hateful people have the same set of rights as others, it's close to irrefutable in future cases with nicer people that they get those rights too.
Historically, the ACLU is one of the most well known organizations to defend free speech regardless of label. They should not create such a gaping vulnerability in their strategy.
Don't announce to the world that any case involving the word "crypto" will not be defended. Or the words "carpentry", "space", or "elephant". The issue should be free speech, not miscellaneous labels.
I think "failing to support" in the grandparent comment is too weak for some. This is Glenn Greenwald on a recent ACLU amicus brief[1]:
>> This is the first time, at least to my knowledge, that ACLU is explicitly arguing in court that the First Amendment's free speech clause has been interpreted *too broadly* by courts, and are advocating *a more restrictive view* of what free speech means.
I'm not sure about that case in particular, but on your question of
> why not choose the group of people who are nicer?
I'd say the grim batman ACLU of my alternate-history fanfic cares more about precedent than it does about defendants.
1: https://twitter.com/ggreenwald/status/1449739621563346944
>> Mr. Cross spoke in opposition to Policy 8040 at a school board meeting, and refused to comply with the provision...
>> While the teachers may disagree with the policy, they do not have the right to violate it in their capacity as K-12 teachers in the Loudoun County school system.
The brief was unclear about whether the teacher refused to comply in the meeting or in another circumstance, and I don't care enough to check sorry.
FWIW, I'm mostly in favour of at-will employment, and think that they should be able to suspend or get rid of him for any reason. And I'm in favour of school choice, and think that if the views of parents and teachers would be better reflected if the government weren't involved. And I'm a cynic, and believe that the only reason anyone's talking about a Virginia school is the governor's race, and it's all just entertainment for people living elsewhere.
On the one hand there's the teachers' free speech rights, freedom from compelled speech. On the other hand are the students' civil rights protecting against discrimination.
The ACLU in that situation has decided the later should prevail over the former when it pertains to government workers & their speech while on-the-job.
What if a white teacher spoke to the only black student in the room using his own version of AVE, and used his usual English for the rest of the class?
I don't know the answer, but I can understand the ACLU seeing a case where rights come into conflict and choosing a result that seems more just.
If your concern is specifically the ACLU's disagreement with recent Supreme Courts on the intended scope of Second Amendment rights, the EFF isn't going to address that either since it's out of scope for their mission. But that's in no way relevant to what Signal had to deal with here, an area in which I think ACLU and EFF are pretty well aligned.
The comments about the ACLU probably aren't about the second amendment. That's never been the ACLU's thing. It's probably about the recent backing away from the 1st amendment which has historically been the ACLU's domain.
NYT link covering the topic: https://www.nytimes.com/2021/06/06/us/aclu-free-speech.html
Archive.org link in case you can't view the NYT link: https://web.archive.org/web/20211027082703/https://www.nytim...
https://www.aclu.org/news/lgbtq-rights/the-coordinated-attac...
Here's a recent NYT article discussing this change in the organization: https://www.nytimes.com/2021/06/06/us/aclu-free-speech.html
And sadly, the word 'nazi' has lost all of it's meaning in the last years, and has gone from swastika carrying Hitler supporters to someone who doesn't want illegals working below minimum wage to take his job.
I live in a small european country, and literally every foreign worker is lowering the wages of all the local workers - because why offer higher pay to get a local, if you can get some cheap foreigner to do it at minimum wage? And i'm talking about legal workers... if you take in account illegals, that are willing to work below minimum wage, the situation gets even shittier for locals.
https://lawandcrime.com/first-amendment/aclu-backs-n-j-woman...
[1] http://www.bayareaintactivists.org/sites/default/files/aclu_...
[2] https://www.aclunc.org/news/aclu-urges-court-invalidate-sf-c...
In 1978, the ACLU successfully defended the right of neo-Nazis to march in the predominantly Jewish town of Skokie, Illinois. This action reflected their commitment to free speech, regardless of how offensive the speech might be. The movie "Skokie" and documentary "Mighty Ira" are based on this event-- I highly recommend them because this is an important piece of U.S. history.
In contrast, the modern ACLU has backed away from this stance. A leaked ACLU memo[1] says that before they take a free speech case, they will consider the "context of the proposed speech; the potential effect on marginalized communities; the extent to which the speech may assist in advancing the goals of white supremacists or others whose views are contrary to our values; and the structural and power inequalities in the community in which the speech will occur."
[1] https://reason.com/2018/06/21/aclu-leaked-memo-free-speech/
I understand citizens need the right to voice their opinion without fear of government repression; but citizens shouldn't believe they have the right to insult and behave antisocially to other citizens.
Any kind of white supremacist behavior is not something to be treasured as freedom, because that enables their harmful behavior against other citizens.
At the same time, I’m under no obligation as a private citizen to tolerate their odious speech. This even includes in business settings… At an old company I once asked our CEO to take down “sponsored content” from our home feed that was promoted by a group on the SPLC hate group list (for comparison we also regularly took down ISIS material.)
Civil order that it is a crime to breach. So you could get slapped with one on "balance of probabilities" while becoming criminalised for something fairly arbitrary like entering an area or being drunk. I seem to recall somebody was given an ASBO forbidding them from having noisy sex - which they subsequently did and then faced criminal sanction.
Yes we should tolerate the speech of white supremacists and other hateful characters, because the alternative is to see reasonable statements lumped in with them. Where we should draw a clear and sharp line is at violence.
"It is better that ten guilty persons escape than that one innocent suffer." - William Blackstone
"I disapprove of what you say, but I will defend to the death your right to say it" - Evelyn Beatrice Hall
I mean have you actually seen the "science" used to claim even the existence of different races? It's all misleading statistics and pseudoscience. You group a bunch of people together based on geographical origin and then observe some differences in the averages between the two groups, ignoring that the differences within each "race" are larger than the differences between "races," and that the lines are being drawn arbitrarily, and that even the measured averages could be different as a result of environment or culture rather than genetics.
There is no way for a Nazi to win that on the facts because the facts are against them. Which is why they have so little actual support. There are probably more trolls pretending to be Nazis than there are actual Nazis.
They're used as the boogeyman specifically because there is such widespread agreement that they're wrong.
If you want to understand the terror of total state censorship practiced "the first time", then look to Lenin specifically and communism more generally.
Alternately, one can argue this climate of fear and systematic repression was present during the French revolution, but not localized to the entire state.
Once you start studying groups by linguistic origin (not "race") things become much clearer since people historically didn't really move around that much, and genetic markers are quite visible (a la 23andMe). I don't think you need to be a Nazi or a troll to be interested in any of this.
1. https://openpsychologyjournal.com/contents/volumes/V3/TOPSYJ...
And it's a completely arbitrary line. If Swedes are on average taller than Austrians, are they different "races" then? It's balderdash. There are genes that affect height and whatever else, but they're widely distributed throughout all "races."
Edit: To your point about group taxonomy, usually precision is only available to a level where genetic markers are present and distinct. This in turn comes from groups not interbreeding. For instance, using 23andMe's taxonomy, Sweden belongs to the "Scandinavian" group and Austria belongs to the "French & German" group:
https://customercare.23andme.com/hc/en-us/articles/212169298...
Edit: Also to assert that, given two random people on opposite ends of the height spectrum, it's much more likely that they are distantly related than closely related (controlling for sex) because (controlling for nutrition) height is a heritable trait.
But we already know that, by and large. It's genetics. And the thing we know about genes is that they align very poorly with "races".
It's like grouping animals by color. Then you discover that brown animals are bigger than red animals, because bears are brown and bears are big whereas cardinals are red and cardinals are small. But sparrows are brown. Using the logic of "race" we put the sparrows in the same category as the brown bears. The black bears go in with the black housecats. The red housecats are with the cardinals.
The fact that you can find statistically significant differences between the color groupings doesn't mean you're not doing something preposterous.
The thing about groupings like this is that they only exist in the statistics.
If you take two populations of otherwise identical people and then isolate them from each other, they'll diverge over time. Maybe the land is different, or the weather, and some genes are better adapted to one place or the other so they become more common there.
That's just averages. Originally 50% of the combined population had trait A. Over time, it becomes the case that 30% of the first population has it and 60% of the second population. You can measure the difference in the average. But the people in the first population who have the trait are the same as the people in the second population who have the trait. It just happens to be the case that that trait is better adapted to the place where the second population lives. If you want to talk about something, talk about people who have the trait or don't, rather than where their ancestors lived.
> When we're talking about IQ, asking "why is does it differ across identifiable groups of people?" seems to be a very controversial question to ask or attempt to answer, often getting you lumped in with the Nazis, which was my original point.
Oh, absolutely. And if that's true, it's true whether you want to hear it or not.
The salient point is that the Nazis are still wrong even if it is. Because it's all still just averages. If there is some gene that makes you smarter and 55% of "white people" have it and 45% of "black people" have it and as a result the averages are different, the conclusion obviously isn't that all white people are smarter than all black people, so Nazis are still wrong.
There is also no concrete proof that that's the case rather than the disparity being a result of nurture rather than nature. It's legitimately hard to separate them out even when it's not as politically charged as this.
You could say that about any grouping of people whatsoever.
> If you want to talk about something, talk about people who have the trait or don't, rather than where their ancestors lived.
But clearly where there ancestors lives is a major factor in identifying the likelihood that a person will have a particular trait. And all of this matters because people have gotten it into their heads that every cultural/ethnic group should be equally represented in every field. When you point out that, for the above reasons, this is just as absurd in executive leadership as it is in basketball, they call you a racist/Nazi.
The same objection is raised when people ask "Why are Ashkenazi Jews disproportionately rich/powerful/successful?" or "Why are African Americans disproportionately not?" and you point to the IQ data. In fact you're a racist for even thinking to study this in more detail. This is why I'll never trust anyone to decide what is and isn't an offensive thing to say.
> The salient point is that the Nazis are still wrong even if it is.
It depends on what you mean "wrong". They're clearly morally wrong for murdering and sterilizing millions of people. They're not however wrong that eugenics programs are just as effective in humans as any other animals. And there's more than one way to do eugenics. Why not, for instance, as a matter of public health, simply incentivize people with desirable traits to produce more offspring?
> It's legitimately hard to separate them out even when it's not as politically charged as this.
I agree. Like most things it seems to be genetic predisposition in combination with environmental factors.
By these logic every form of life it's the same since all evolved from the same unicellular organisms.
And yet my cat doesn't have leaves while my plant I keep in the pot doesn't meow.
What about "ethnic groups"? https://en.m.wikipedia.org/wiki/Pygmy_peoples
>It's like grouping animals by color. Then you discover that brown animals are bigger than red animals, because bears are brown and bears are big whereas cardinals are red and cardinals are small.
Are the grizzlies the same with pandas?
And there are two trees with different height from the same species. Both make the same kind of fruits.
Valable also for German Shepherd and Golden Retriever.
>If Swedes are on average taller than Austrians, are they different "races" then?
But Swedes can be still considered a different ethnic group than Austrians. Does the exact terminology matters? Various groups of people have both differences and also things in common. So what?
"We are what we pretend to be." --- Kurt Vonnegut
And to the extent that it is true, it implies that we should stop using Nazis as the boogeyman. Because trolls are going to use whatever will get a rise out of people. Best not have it be this that they summon up.
That is true enough for most, but not all.
https://en.m.wikipedia.org/wiki/Daniel_Gonzalez_(spree_kille...
Daniel clearly could not separate the Freddy mask from fiction and made it a tragic reality.
No one dares to do such studies anymore so we can conclude that the "good" has won.
https://www.cdc.gov/mmwr/volumes/70/wr/mm7015e2.htm
So it depends what you mean. If you mean there are no studies done with such partitioning aimed towards the benefit of those groups, I call that bunkum.
If you mean studies are not sponsored where the outcome is of no societal value beyond reinforcing or justifying an established hegemony or excusing discrimination, then perhaps... and good.
>no societal value beyond reinforcing or justifying an established hegemony or excusing discrimination Researchers might have hypotheses they want to test, and any hypothesis that's not "good" is not explored. Because 1. real identities and careers are affected 2. collected data isn't good enough for journals
"A lie can travel around the world and back again while the truth is lacing up its boots."
It doesn't matter how solid your facts are if people are listening to vox pops of people who back their own internal beliefs.
> There is no way for a Nazi to win that on the facts because the facts are against them. Which is why they have so little actual support.
They don't need support, they just need an echo chamber to be encouraged. Pop onto stormfront and try convince a handful of posters there and see how far you get.
> There are probably more trolls pretending to be Nazis than there are actual Nazis.
If x% (where x is some suitably small number) of a group are the only ones who truly believe it, and the rest are just trolls, then increasing the population size leads to both more trolls and more Nazis. It also doesn't matter to anyone whether the person spewing vitriol is actually a Nazi or a troll when the abuse is directed at them.
> Pop onto stormfront and try convince a handful of posters there and see how far you get.
I've actually done this - it's far easier than you make it seem. I haven't really started collecting metrics on success, but that's kinda what we're missing - messengers who construct a pyramid of truthy statements and go back up the chain to whoever convinced THEM to a particular viewpoint when they find resistance to change from the opposite side. We're missing tech that incentivizes such behavior.
Of course this requires that everyone has a set for themselves a threshold for when they would change their mind about a topic - which I find is far more prevalent among US conservatives (at least online, as they behave to me), than when you try to establish the same among US liberals. Of course, ignoring the obvious field that doesn't have a threshold by design - supremacist religion.
My working theory is that supremacist religionists who converted out of it simply replaced it with liberal ideas (and were being supremacist about those), while there are both religionists and non-religionists among the conservatives.
IF we fixed THAT problem (with new technology, an early one is https://www.kialo.com/tour, but it's not good enough), we can have what you want.
Right now, we're effectively the same tech level as the 1900s (perhaps in a more dangerous way) w.r.t finding truth or the "right" arguments
People like you need to stop saying things like "I understand citizens need the right to voice their opinion without fear of government repression" because this is exactly the opposite of what you want. You want views that you consider objectionable to be subject to government repression. You don't have to qualify it, just admit it.
The reason people oppose restrictions on freedom of speech are fairly obvious to anyone who has thought about the question for more than 5 minutes. The moment you start deciding which speech is and isn't legal, you have now established a mechanism to censor. Ban 'hate speech', those who define the term now control the boundaries of allowable speech, and you can guarantee bad actors will seek those powers and abuse them.
TL;DR: The government must not censor freedom, and citizens should not support acts of oppressions disguised as civil rights.
I'm sure you heard about the Golden Rule, as long as you follow it you should be allowed to express yourself.
But inciting on harmful behavior against white people is somehow the right thing to do?
I believe all people should be treated against the same set of rules.
There are many in the US: https://en.wikipedia.org/wiki/Category:Civil_rights_organiza...
I usually never express it but this kind of stuff makes me proud of being an American. We need to double down on CR non-partisanly and non-negotiably.
It's also bad that cops pull people over arbitrarily, but that's not the part in the EFF's bailiwick, and there are other solutions than putting ALPR cameras everywhere.
What are these solutions?
For context, speed cameras have been very effective at reducing traffic deaths in cities- https://patch.com/new-york/new-york-city/camera-zones-curbed...
Also, I think it's a bit of a weird argument to say that ALPR is alright for paying highway/tunnel/bridge tolls but not for speed cameras.
I aspire to not hand them AWS dollars one day, but Aurora has been an amazing product for my business.
(Only EFF is really for this particular issue though)
Fighting against due process: https://www.nbcnews.com/news/us-news/see-you-court-aclu-sues...
claiming there's no men: https://twitter.com/ACLU/status/1196877415810813955
and this: https://twitter.com/ACLU/status/1199725066302308354
Telling families to discuss pronouns: https://twitter.com/ACLU/status/1250795126584217602
and this: https://twitter.com/ACLU/status/1453779768063766529
I'm all for defending freedom of expression, religion, speech, etc. But this is weighing into topics that aren't really about freedom and in some cases they're actively fighting against freedom. AKA it's become way more political and one sided.
I think there's an argument to be made for the ACLU becoming increasingly performative, with catchy Twitter slogans edging out the real work, but this isn't it.
People feeling uncomfortable with their bodies and performing mutilation is sad. Some people remove their feet as a kinda fetish. Trans people try to look like something else to make themselves feel normal (evidence is that’s not super effective, but that’s beside the point).
The main issue isn’t that. People can do what they want in my opinion. It’s the compelled speech that the ACLU is promoting. “You have to use someone’s pronouns” is the exact opposite of free speech. It’s about as authoritarian a position as you can take. Imo pronouns are even more insidious because (a) they can change by the day and (b) you rarely use someone’s pronouns with said person, so other people have to “enforce” the proper pronoun use.
No, civil liberties has nothing to do with people using someone’s pronouns. It has to do with the freedom to say what you want to say, not compel others. ACLU is now on the side of compelled speech.
This isn't me policing your speech, by the way, saying that you shouldn't say something isn't the same as saying you shouldn't be able to say something.
Is the ACLU actively trying to force you to use specific pronouns, or is that just something they say because it's good social media optics?
that's probably the least worthy of the ones in the list. https://en.wikipedia.org/wiki/User:Guy_Macon/Wikipedia_has_C...
1634169600000 (unix millis)
Thursday, October 14, 2021 12:00:00 AM
Well done. I immediately thought that having a millisecond granularity of last connection time could be used to roughly correlate who contacted whom, depending on what the "connected" event is considered.Couldn't they easily use the phone number associated with the Signal account to find the target's name? Even if the account uses a pre-paid SIM without a credit card attached, the telco could still reveal the location of the device and probably its IMEI, which could be used to find other SIMs associated with it.
I think Signal should stop pretending they're an anonymous service when their identity is based on phone numbers.
What do you mean? They already have the telephone number. It is listed in the subpoena. All Signal is doing is confirming that this phone number has a Signal account - sure, it's not perfect, but I don't really see your point. They don't need Signal to be able to do any of the things you listed.
This means they minimize the information that is in the clear and do this quite well.
Now to your specific concern about the phone number. Signal only has your phone number and sign up time. This means that for someone to request your information, they’ll pretty much need that already. If you look at the subpoena you’ll see that the FBI is asking for data associated with the persons name or phone number. Name is something Signal doesn’t have. You’re right that it’s trivial to get with the phone number (and the FBI has obviously done this), but they must necessarily have this information to even request data from Signal.
In other words, Signal doesn’t provide a means of leaking your name. What using a phone number identifier does do is allow someone to go from name to phone number to Signal request, though that Signal request with turn up very little data.
https://www.aclu.org/ https://signal.org/
Nothing is free, support these folks.
Account created: 1606866784432 (unix millis)
That's Tue Dec 01 2020 23:53:04 UTC, consider this a heads up if that's when you started using signal.There are very many ways to encrypt messaging data by sharing public keys. There are also several decentralized, federated encrypted messenger apps. They are great options for folks, but frankly aren’t as easy to use or feature rich and thus not as widely used.
-Ultimately this issue isn't that big of a deal to law enforcement. In 99% of cases they can just get the defendant's cell phone and look at his unencrypted messages in the Signal and Whatsapp applications directly.
-I think in theory if a lot of platforms start doing end to end encryption globally, then things could get a little more interesting. But as far as I know for a lot of tech stacks (like ones more complex than simple messaging) that's difficult to do.
please stop asking for mandatory phone number to register and use Signal.
This raises privacy concerns and negates all the end-to-end encryption goodness you're offering.
I find it really interesting that Bill Binney says, despite years of me hearing the opposite, that we shoild all be rolling our own crypto because its a form of decentralization. The more time goes on, the more I think hes onto something.
The main problem I see is this: a future where only the hackers have privacy, and everyone else apathetically accepts their servitude and abuse. Furthermore, to maintain that privacy, hackers will have to be extremely selective in their friends, due to the invasive nature of the privacy violations from those around us, unbeknownst to them.
Matrix is pretty good.
I run a Matrix instance on my own hardware for my extended family. I suppose that I could be served with a subpoena/warrant for the data, but the contents of any voice or video calls mediated through my Matrix server wouldn't be preserved.
Likewise, any private chats on the server would remain encrypted and I wouldn't be able to decrypt them even if I wanted to do so.
Since the instance isn't federated, and access is only available through invitation, only those who have access know about.
As such, I'd say that private chats and voice/video calls through my Matrix instance are pretty secure.
Identifying users is one thing, reading their message is another. People can still deny and not answer questions.
What matters is the messages being encrypted, identifying users is already being made possible through other means.
So yeah, using a phone number is good enough, in my view.
There is no perfect security, there is only "good enough" security.
Not to mention that phone numbers are more secure, in my view, than other sorts of digital communications, and are not always monitored in all countries.
Certainly saying "I know that Janis and Nate talked on this day this many times / for this long" and "Janis and Nate had a detailed conversation covering lemons and lye" have two different levels of private information revelation; and E2E protects against the latter but not necessarily the former, so why does it negate _all_ the goodness?
It literally does not. Source: the OP
Using a phone number means that an agency can ask Signal if you have a Signal account, but they can’t access any other info about you.
Solid impenetrable encryption from a neutral and privacy obsessed country. All a careful front for the CIA. The encryption was solid as far as I know but they the CIA had a back door.
If there was a backdoor into the system somehow, it would be perfect to have stories such as the above to recruit criminals or even foreign intelligence to adopt it.
As far as I know Signal is 100% legit and deliveres what they promise. and I use it myself.
https://www.washingtonpost.com/graphics/2020/world/national-...
https://www.theguardian.com/us-news/2020/feb/11/crypto-ag-ci...
The account creation date is basically equivalent to the phone number and would allow the owner of the account to know a subpoena was requested for them.
Most "donate" pages do not allow for "donor-advised funds (DAF)." They assume you're giving it with your before-tax money and presumably taking a tax deduction for it.
In a DAF, which your financial institution surely offers, you can donate appreciated assets, e.g. your FAANG stock, and take the entire amount as a tax deduction. So if your 10 shares of Facebook (excuse me, "Meta") stock are at 322, you can take a deduction of $32,200 this year.
What's the catch? That money's gone, and you can't get it back. You can only "advise" your DAF to give it to a 501(c)(3) organization, which Signal is. There are no time limits.
The good part, though, is you can probably have your DAF give the money anonymously, so the charity can't bug you every time they're having a fund drive.
Like, let's say your intent is to donate $10k to some charity, out of the goodness of your heart and/or as a tax write off. You don't have that in cash, but do in stock.
You could liquidate $10k of stock, pay capital gains on it (if it appreciated since acquisition), then donate it. So you're out the capital gains tax.
The method you describe seems more efficient, since you don't need to sell; you simply transfer ownership of the asset.
Or is there still capital gains to be paid?
I wonder if billionaires are setting up charities as trusts for their kids, then "donating their shares to charity?"
Billionaires have access to much fancier schemes than this, and I won't even attempt to describe all those. But yeah, I imagine "donating their shares without capital gains taxes" figures into them.
I just noticed you said "trusts for their kids" -- that's something different. If the children can access it, it's not a DAF. But trusts are much more complicated, and someone who understands them (which I don't) can hold forth here.
In your example above, let's say the person purchased those 10 Meta shares for $38 each at the IPO and they're worth $322 each now. That's $3220 in proceeds and a $2840 capital gain.
The taxes on this depend on income level and state of residence, but let's say they're in CA making $300K/year. They'll pay 20% federal capital gains tax + 3.8% net investment tax + 10.3% CA income tax, or $968 in taxes, and they're left with $2252.
On the other hand if they donate the shares to a charity (or DAF), they get a tax deduction for the appreciated amount ($3220), which can be taken against 35% federal income tax + 10.3% CA income tax = $1459.
So in the scenario where they just sell the shares, the proceeds after taking taxes into account are:
Donor $2252
Charity $0
And in the scenario where they donate the shares, they are: Donor $1459
Charity $3220
In other words, for an effective cost to the donor of $793, the charity gets $3220.If you donate to a DAF, it's 100% gone to charity, *someday."
(Also, DAFs allow claiming the deduction during high-income years and deferring distribution to charities over a longer period of time.)
https://www.bloomberg.com/features/how-billionaires-pass-wea...
DAFs are a convenient way to gift appreciated stock (which is already a nice tax gift to the charitable wealthy), but fundamentally not a vehicle for passing money to your heirs.
Your article is about GRATs, which should be illegal.
Also, the annual stock deduction limit is capped at 30% or so of income.
So that money goes to charity, but what charities? You won't be here, obviously. When you're looking into this, see if your DAF administrator allows a "successor trustee." If not, that institution itself (Schwab, Vanguard, whatever) will disburse it.
If they do, you can pick someone whose values you trust to be the successor & disburse the money. (Probably someone younger than you!) You should ask them, or else they'll get a real surprising phone call right after you die.
I thought the ACLU was more of a protection against smaller entities who didn't have funding/legal firepower?
The important thing is minimizing the data that is collected, period. Otherwise you’re just obscuring the data storage.
I can choose to use a server outside the US. I can choose to run a server in my basement and still talk to all my contacts. You simply do not have this freedom with Signal. Finally, I do not have to trust anyone about what (meta-)data is collected.
An out of the US host is easier for them actually. Say hello to NSA exploits without a warrant!
Have you looked to see what metadata something like Matrix collects? How federation and contact lists work on that server?
Edit: What raised my eyebrow is that the subpoena specifically asks for that. Why?
Additionally, Signal's encryption scheme gives their messages the "forward secrecy" property which means that acquiring key material at some point in the future does not allow you to decrypt any previous messages. Any encrypted messages that they could provide would be useless.
For more, check out their really interesting doc on the double ratchet algorithm that they use!:
The government is funded by its Citizens.
I remember a time when spying on EVERYONE was a bad thing.
There's also no mention of TLS termination in the Signal-Server repository on GitHub, or TLS between the Redis cluster in use. If FBI or NSA has compromised the AWS VPC, then all of this network traffic would be in the clear to be picked up behind the load balancer(s).
The Account DynamoDB table [2] also seems to indicate more information is tied to the phone number in cleartext than what is indicated by the response?
[0]: https://github.com/signalapp/Signal-Server/blob/14f5271c2012...
[1]: https://github.com/signalapp/Signal-Server/blob/14f5271c2012...
[2]: https://github.com/signalapp/Signal-Server/blob/14f5271c2012...
The DB table looks like signal creates UUIDs to represent users and devices. This isn’t really sensitive information but really just how you can see and revoke devices associated with your account. Maybe I’m misreading something tough. Do you have any reason to believe otherwise?
Note that disabling iCloud Backup won't help you, as it's turned on by default and everyone else you iMessage with will be leaking your conversation plaintext to Apple for you.
Disable iMessage. Use Signal exclusively.
* if you use Messages in iCloud, iCloud Backup instead backs up the cross-device sync key instead of the iMessages themselves, which means Apple gets your iMessages in real time as they sync between your iCloud devices, instead of once per day
https://mobile.reuters.com/article/amp/idUSKBN1ZK1CT is why fake pro-privacy Apple will never be able to run a story like Signal has here today.
> Why, on any planet, would law enforcement issue a warrant to get user data from a company that doesn't have any user data?
Signal erases that kind of information but I'm pretty sure that user must have had some messages delivered to them while signal was processing the subpoena. So pretenting they don't know anything else is just wrong IMO.
If you have a phone number, a zero-click NSO spyware would provide full control over target device.
* FBI could get user’s data from Apple if it’s an iPhone (considering that iOS is closed source), or force a malicious update to user through so many ways (including by pushing a bad update or manipulating safety numbers in signal).
So why asking a messaging app that everyone knows doesn’t have the requested information?
See https://en.wikipedia.org/wiki/FBI–Apple_encryption_dispute
This threat is why there need to be checks on the power of the state to conduct searches, one of which is privacy technology like encrypted communication networks.
They've only gotten used to going after the intermediary, and it feels uncomfortable for them to have this power removed and reset back to the mean.
When encryption and secure messaging is outlawed, only outlaws will have and use it.
Freedom is won in the courts and the legislature, not in the code (although tech is as useful tool for keeping government implantations in check).
(I still use and donate to Signal, but have a healthy understanding of its limits)
Freedom is won through weapons. Encryption is a potent weapon, it can defeat states, militaries. Before computers, it used to be a military tool. It must be democratized, the whole world must use it.
They don't necessarily need to outlaw it. They may just throw up enough hurdles that it doesn't become a major success. Developing a communication system that is secure, featureful and convenient to use for the general population is not a trivial task. A large effort that can be undermined.
E.g. if they only require logging from communication service providers but not from application developers then this would force a decentralized solution. If they lean on payment providers it might get difficult to charge for phone apps or get donations.
The software could continue to legally exist but see little adoption. Which is enough to enable surveillance.
Even if Signal operators can't provide them metadata, maybe they found ways to snoop on traffic.
> Last connection date: 1634169600000 (unix millis)
> Account created: 1606866784432 (unix millis)
Impressively small amount of information. I wonder Account Created needs to be stored?
> Account created: 1606866784432 (unix millis)
This response of the user information they have is hilarious.
Thu 14 Oct 2021 12:00:00 AM UTC
Do they round?
https://www.legifrance.gouv.fr/jorf/id/JORFTEXT000023646013
On the books since 2011. Upheld in a recent decision of France's supreme court despite what some thought to be quite clearly contrary EU caselaw (which takes precedence over national law, roughly speaking) https://www.nextinpact.com/article/45613/comment-conseil-det...
https://threatpost.com/protonmail-log-ip-address-french-acti...
From that article: “The internet is generally not anonymous, and if you are breaking Swiss law, a law-abiding company such as ProtonMail can be legally compelled to log your IP address.”
They must keep this data hot because they can send "this specific person in your phonebook just installed signal" messages.
https://www.aclu.org/ https://signal.org/donate/
Nothing is free, support these folks.
Now don't pull any sketchy shit like Mobilecoin without being transparent.
What are you arguing for? Visible transaction histories that can be used to jail you?
doing a lot of work here. To what degree is that simply anti-governmental sentiment rather than an honest evaluation of the agencies in question?
Say you'd be living in a narco neighborhood in Mexico were cartels regularly shoot civilians up in private wars, have you considered how badly institutions could do in comparison?
But I’d say that we should work to make it impossible for mass surveillance to exist, full stop.
Police should have to do real actual detective work to implicate people in a crime.
That's reasonable.
https://www.lawtechnologytoday.org/2019/08/can-police-force-...
And that's a good thing.
Now, cops and politicians want to solve all the problems from their desk.
No, sorry, my freedom is not to be sold for their convenience.
You want to catch a bad guy, you get a trained investigation team that follows people, that wires their house, that interrogates neighborhood, etc.
Is it more work ? Yes. Is it more dangerous ? Hell, yes.
But don't say you can't catch criminals because of Signal. What you can't do, is click on a button to spy on people. It's a good thing.
This mantra is just an excuse to chew off chunks of democracy.
There's a subpoena in this process that you're glossing over. You can argue that's too easy or too secretive or something, and that's more than fair, but it's not just 'clicking a button'.
Do you have a source for that?
If you have a subpoena to open a safe, and you realize that you have no tools that are strong enough to open that safe, you don't suddenly blame safes. You don't tell banks they should stop using safes. You don't ask them to create weaker safes robbers can break into.
You try another route.
A subpoena is fair. Asking signal to preemptively not encrypt the data in case we need it later is not.
Those are the tip of the iceberg.
If there is an automated way to get this data, the agencies will do it, and then retroactively generate the paperwork to make it look ok in court if they feel it’s worth their time.
If structurally there is no privacy except some friction with generating paperwork, then we already have solid evidence here in the US in modern times that you defacto have no privacy.
[citation needed]
Further:
Wiretapping is illegal without a warrant. I believe the spirit of the law there implied that wiretapping of [previous, historical conversations] was _always_ illegal, since a wiretap could only be tracking future conversations by its very nature.
The nature of communication has changed, such that all conversations theoretically have a permanent, historical record, despite the intention of those conversations to not have that historical record. It's called "instant messaging", after all, not "perpetual letter writing". It's meant to be an analogue to talking directly with one another.
The path we've gone down where everyone uses a third party to communicate with each other, and that that third party could theoretically record and retain all communications back and forth in perpetuity does not change the _intent_ of the laws as they were written.
The laws were to protect everyone from unreasonable review of their historical actions.
Perhaps you remember that story - I've completely forgotten the source and am having trouble finding it - about the person taken in the night and thrown in front of a judge. He asked what his crimes were, and the judge said "that's what we're here to find out", as they were going to go through everything he'd ever done to find something to charge him with.
edit: another instance would be Lavrentiy Beria, a police chief under Stalin (https://www.oxfordeagle.com/2018/05/09/show-me-the-man-and-i...)
"Show me the man, I'll show you the crime."
That's nothing new, either.
"If you give me six lines written by the hand of the most honest of men, I will find something in them which will hang him." -- Attributed (possibly apocryphal) to Cardinal Richelieu (1585-1642).
I don't disagree that overly broad laws are a problem in non-totalitarian countries, but I think that regimes like Stalin's are a special case.
Because my privacy and that of most others who are decent, law-abiding citizens is more important than not making police do their jobs.
How do you think police caught people before apps like Signal? With real police work. Perhaps if they had to spend more time doing that, they wouldn't have time to beat and kill as many unarmed civilians.
If you have someone being blackmailed or defrauded online, what "field work" are you suggesting here?
> "cops [...] want to solve all the problems from their desk."
This literally couldn't be more wrong.
What argument do you have that less encryption is the preferred solution?
Meanwhile Encrochat's non-encryption ended up allowing a multinational set of drug cartels to be taken down.
It's not difficult to come up with such examples.
I (obviously) have no idea about the details of that situation, but since a violent crime can't be committed over the internet via a chat app, there ought to be physical evidence of that crime, no?
If there's some sort of conspiracy element to that, I can see how chat logs might be useful.
But attempting to require folks to provide information they don't have (as is the case here) is a fruitless endeavor.
What solution would you suggest? Get rid of encryption? Force providers to collect the contents of their users' computers and phones?
While, as I said, I sympathize with your family members (and you), such an outcome doesn't justify taking away everyone's privacy.
Especially since the vast majority of people are decent, law-abiding folks.
I get that your experiences and the pain they've caused won't allow you to see things differently, but privacy is important, and I for one, won't give mine up without a fight.
You have added that last line yourself, and it appears to suggest that you would prefer all of humanity be constantly surveilled in case it may catch more criminals.
E2E does not require a valid reason. Its only change as far as law enforcement is concerned is to stop monitoring when they do have a valid reason. (Which I think most people feel is as acceptable trade-off.)
Not only did I not say such a thing (I even said it was easy to argue that encryption is a net win), it’s not something I believe, especially when you put it in such extreme terms. But encryption brings a cost, one that shouldn’t be ignored.
Most people here are taking extreme arguments — assuming everything is about mass surveillance and crimes are more often than not victimless. This ignores the reality that real crimes are regularly happening that most reasonable people would wish to stop, and when you add friction to that, it means there are many cases were justice will not be served.
The privacy/security trade-off is vastly overstated.
Regardless, there are far more ordinary crimes being committed than terrorism.
Would YOU be happy spending trillions of dollars with no way to see if it was accomplishing anything, while clear negative effects were also occurring?
But when the authorities transgress once too many, the public in general will switch to services that properly defends their privacy.
We can consider this a game-theoretic outcome of abusing the trust of the public. The consequence will eventually be that properly henious criminals will have better tools for not getting caught.
Privacy with end-to-end encryption keeps everyone's communications safe. Criminals, politicians, people working for government contractors, and everyone else. This means criminals can get away with more things. It also means that politicians and surveillance governments have a harder time monitoring regular people or their government challengers.
Who exactly said this? It's rather the other way around: flagrantly examining and being able to examine non-criminal behaviour at a whim is a problem. The excuse of potentially being able to spot criminal behaviour is not enough.
Absolutely. The other side of that coin is that people are not required to keep (or in this case, even gather) information in a way that allows the government to obtain it.
I'd also point out that this isn't about information that could prove a crime. It's about the government demanding information from a third party about unknown persons and the contents of their personal effects.
Given that Signal doesn't collect or have access to such information[0]:
"...this subpoena requested a wide variety of information we don’t have, including the target’s name, address, correspondence, contacts, groups, calls."
It's not possible to provide it. Are you claiming that Signal should be required to gather such information solely for the benefit of the police?
As the Fourth Amendment[1] to the US Constitution says, in part:
"...and no Warrants shall issue, but upon probable cause, supported by Oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized"
And since the subpoena was asking for Signal to identify the subject (their name), such a demand is clearly outside the bounds of the Fourth Amendment.
I'll say it again: Whether a judge (in this case, it was a grand jury and not a judge, but why split hairs?) agrees or not, Signal can't provide information it does not possess.
I suppose a law could be passed requiring them to collect such information as was demanded, but it's hard to see how that would be defensible on any grounds.
[0] https://signal.org/bigbrother/cd-california-grand-jury/
[1] https://en.wikipedia.org/wiki/Fourth_Amendment_to_the_United...
First they came for the socialists, and I did not speak out, because I was not a socialist. Then they came for the trade unionists, and I did not speak out, because I was not a trade unionist. Then they came for the Jews, and I did not speak out, because I was not a Jew. Then they came for me, and there was no one left to speak for me.
Now is the time to speak out. By the time you want to protest and push back, it could be too late.
But it can make your life a lot more inconvenient.
Until all of that changes I am not interested in giving them more ammo.
Well, the other bar is "the justice system follows its own rules." That's reasonable enough to ask, isn't it?
Your statement is carefully crafted to sidestep this with the wording, "...there exists criminal behavior that most reasonable people would agree is bad and should be stopped that may reach a dead end with services like Signal...", ignoring that the crime of abuse of power is far greater than any crime that could be prevented when it'd granted.
There will always be "some people" that think this way. But more certainly such powers will be abused by those entrusted with them.
Absolutely.
>In formulating your statement that examining criminal behavior is a problem, you are suggesting there shouldn’t be ways to uncover crimes.
I didn't get that at all. Before Signal and other encrypted apps, folks who didn't want to be spied upon would meet in person, in private places or write messages in code.
That didn't stop the police from bringing down many criminals, such as Al Capone, the New York Mafia and many others, did it? Nope, it didn't.
What you seem to be advocating is that everyone's privacy should be forfeited so police can get information without doing, you know, police work.
I'm all for bringing criminals (especially violent ones) to justice. But I'm not willing to give up my privacy so that police can spend their time eating donuts instead of their jobs.
Feel free to disagree, but I'm going to keep using Signal and be glad of it -- not because I'm involved in criminal activity, but because I value my privacy.
The world isn’t black and white.
I assume you're referring to this sentence in my comment:
What you seem to be advocating is that everyone's
privacy should be forfeited so police can get
information without doing, you know, police work.
Note that I said seem. Which, in this context, means that's what I understood you to be saying. Thank you for clarifying.What's more, I'm not attacking anything or anyone. Rather, I'm expositing my views WRT encrypted communications and police work.
That you interpreted the expression of my views as an attack says more about you than about me, IMHO.
What is the "strawman" you appear to believe that I've set up and then attempted to knock down?
Any backdoor - any! - will result in your data being exposed, sooner or later. Your Signal messages could then be exposed in a data breach on the dark web for all to see.
It is not worth it to risk everyone's privacy to allow for the chance at easily prosecuting a small number of crimes. Remember - you're not preventing crime this way, just allowing for easy evidence capture. There are viable alternative ways of investigating crimes, as others here have said. There are not viable alternative ways of protecting our data.