Code from the FBI’s Anom encrypted messaging app
vice.com
vice.com
Lots of "secure" messaging apps do this for intel and surveillance and not just the white hats.
Other areas that "secure" messaging apps have holes in is the anti-spam/moderation systems that need to view messages and in the clients themselves who have access to the unencrypted content. This is also taking place in other client apps as well: VPN, password managers, extensions, wallets, even build systems and more. Many like VPNs have logs sent elsewhere but deleted locally -- access to entire machine and all network access. People are way too trusting of "secure" systems/apps that are very common today based on trust.
All of these apps/systems would pass code checks, reviews, security inspections and essentially be encrypted/"secure" though a copy is sent off to another area for review. At runtime the leak is in the direction of the data.
Even if Matrix were to limit chats by protocol, a malicious sysadmin could probably fake a cross-signed device if they had access to the client like this. I don't think this is actually a problem, a chat room is as good a representation as anything.
It's how Apple would do iMessage intercepts for the FBI.
> Messages: Most message attachment types other than images are blocked. Some features, like link previews, are disabled.
https://www.apple.com/newsroom/2022/07/apple-expands-commitm...
But based on some googling Apple hasn't provided this capability, at least to the FBI (they claimed it would require modifying the iMessage key server, so we have to trust them on that they haven't done that yet), mostly because they don't need to - the iCloud backups are usually enough for pen-register intercepts. A leaked FBI's document backs this claim up:
https://www.rollingstone.com/politics/politics-features/what...
That's what I just said, it still doesn't mean the feds would be dumb enough to make visible changes the destination contacts
Lots of VPNs, too!
"We don't keep any logs! We just pipe a direct feed to the government so they can keep logs!"
But given the existence of Room 641A[0], and other extra-judicial mass surveillance, I am confident in my assertion. Moreover, the explosion of VPN companies with large marketing budgets over the past few years has always made me suspicious.
https://www.pcmag.com/news/nordvpn-actually-we-do-comply-wit...
NordVPN says they don't collect logs, but then it came out that they send information to law enforcement. So the big question is what information is being sent to law enforcement. Despite what NordVPN maintains, it seems like they do keep incriminating data about their users.
You don't mean sharing raw traffic as in forwarding actual requests, I wouldn't think?
And if someone thinks the first option is not realistic - this is how almost every ISP in Russia works (search for SORM-2 and SORM-3 for more detail, typically traffic is mirrored at ISP's border gateway(s)). Sure, Russia or China wouldn't be great examples, but the point is that it's technically possible, even at scale, and all the real problems are in the meatspace (legal enforcement or coercion).
The usual method is either to use a splitter or switch configuration to mirror traffic to another interface, attached to a machine running packet capture/analysis tools.
Think of it as just monitoring vehicle movements on a road network which cross borders, you cant see the contents of the vehicle, but you can see where they are heading back and forth multiple times, and thus work out what they are upto, even if the destination is a cloud server!
The article also shows that the network carriers, land line and mobile network carriers many of which are stock market listed dont monitor the networks to protect their users, thus do they fail in their duty of care? I think many victims of crime could have a case, it wouldnt be hard to spot whats going on for them, in much the same way the postal service can tell whats going on when people deliver drugs through the postal system, or supermarket loyalty card schemes can highlight changes in their customers which can indicate health issues. The lawyers and judges probably wouldnt be able to understand it, in much the same way people cant understand quantum physics, so is there a case to bring?
Everyone gives away metadata, if you know what to look for, the crime is the current setup of society benefits a privileged few!
https://thenextweb.com/news/purevpns-non-existent-logs-used-...
These guys just actually logged certain data when they said they didnt
As a rule, if a VPN is hosted in Europe/North America, you need to assume that they log.
edit: my source is from this talk at BalCCon, unfortunately the video is not available. https://2k19.balccon.org/events/278.html
Unfortunate that talk is not publicly available.
For anyone worth targeting, there are so many options available to actors with moderate resources. They will pwn your OS with an RCE exploit; or interfere the next time you update that "E2EE" app via Google or Apple's servers; or your laptop will take a few seconds longer to reappear at airport security; etc.
Marketing messengers as "secure" because they use some derivative of the Double Ratchet is like your bank saying your funds are secure because their website uses TLS.
If you don't have confidence in say, iMessage, which is pretty secure, you might instead go for a "secure" messaging app that's actually a plant (Like Anom).
[0]: https://time.com/magazine/us/5264136/may-14th-2018-vol-191-n...
[1]: https://www.nytimes.com/2017/05/20/world/asia/china-cia-spie...
[2]: https://www.nytimes.com/2021/10/05/us/politics/cia-informant...
https://www.pewresearch.org/fact-tank/2019/06/11/only-2-of-f...
That's a broad claim. Do you have specific examples?
I imagine for example, the protocol could be opensource and documented, and then the app-maker could be a different company than the server-owner.
The server-owner need not be trustworthy as long as the protocol is sufficiently reviewed.
The app-maker still needs to be trusted, but you can at least constrain the app to only communicating with the one allowed server and having no other network access.
Perhaps the server owner could also make a webpage showing all the people you have communicated with... That way a malicious client couldn't send your data astray.
[…]
> For this new analysis of the code, a source provided a copy of the Anom APK as a standalone file which Motherboard then decompiled.
This doesn't add up. The code snippets they show are decompiled obfuscated Java. But compilation->decompilation wouldn't have preserved comments from the original source code.
Sometimes Java decompilers spit out chunks of code they don't understand as commented-out sections for manual analysis. Maybe Motherboard is misinterpreting this output? And, yeah, decompiled Java is gonna be messy, especially if the compiled code was obfuscated, as looks to be the case here.
There aren't laser fields. There's a directory and concierge. A full back-catalogue. A social network.
Most importantly, the viewing experience is consistent across all media, your media viewer of choice, without the need for a constant internet connection. Just like it used to be.
I don't encourage rampant piracy, but I certainly understand when some people don't have the luxury of purchasing an unlocked blu-ray ripper and storing old blu-rays in order to get the same viewing experience.
Another good example is old games like NOLF which are entirely unplayable today without piracy. Pirated releases often contain much smaller download sizes as well as patches to enhance or correct the experience.
Pirating won't convince companies to change, so I vote with my wallet by trying to avoid purchasing media which has unacceptable licensing terms or pervasive DRM, and purchasing any media which I think integrates my values. I also only purchase on platforms which prize discoverability, such as GOG or Steam, while avoiding locked-down platforms like Origin or Epic Games store.
Maybe the strategy is just "get the win now, and tomorrow's another day." A lot of people seem to think it's a bad idea to use some technique that will motivate a counter-technique , like that counter-technique can be prevented by not using the technique (it comes up a lot when sanctions are discussed). However that's flawed assumption. Sometimes sitting on a technique will mean it becomes obsolete before you can realize advantage from it, and it's actually smarter to try capture that advantage while you still can.
Also, if organized crime stops trusting apps and goes back offline for communication, it could become far less efficient/effective, which would be a win for law enforcement.
Also, a sucker is born every minute. Maybe the Mob will shy away from encrypted apps due to institutional memory, but some upstart criminal orgs without that memory may still adopt "FBI 'Encrypted' Messenger 2.0."
Tomorrow they'll think of a carrier pigeon spy.
Organized crime is smart but even smart people can be dumb. They were dumb for trusting a random app and not using in-house or at least looking at the source code in the first place.
And as someone else noted, if they just decide to go completely online that’s going to be much harder
If you're going to take apart JVM bytecode, you're better off using Recafe or Quiltflower.
Any idea whether any of these two decompilers work with Dalvik bytecode?
https://github.com/ricochet-im/ricochet
Every user is their own Tor onion service, so you get E2E encryption and no centralized servers. The whole thing hinges on the security of Tor itself which is probably a safe enough bet.
The problem though is that you’re still trusting the code. Nothing stops self hosted from rotting on you unless you look and read the code yourself.
Lots of people are using it (and probably more every day), but there are also some quite vocal haters. Of course it has its share of problems (availability of non-Electron clients and different servers among then), but many of them constantly improve as the ecosystem grows.
Matrix is similar in many ways, and certainly younger, but also has a vastly different design at the protocol layer. It's more akin to a distributed JSON database/log, while XMPP is more focused on message routing and synchronization. Therefore each has different strengths/weaknesses for different use cases.
Despite these differences, both protocols indeed have IM apps and a whole lot of other software built on top of them.
What other services might be run, controlled, or surveilled by the US investigative authorities?
What other services might have operators that can be extorted or blackmailed by those same authorities, due to the fact that US-based data aggregators (FAANG et al) have extensive information about the lifestyles, behaviors, habits, and travel of billions of people worldwide?
We already know Apple has preserved a backdoor in the end-to-end cryptography of iMessage at the FBI's behest, as reported by Reuters. WhatsApp has always had the same backdoor (unencrypted backups to cloud services). The largest services are all unsafe for privacy.
What about the medium-sized ones?
All closed source software
I try to use medium sized services that are based in other countries. I figure if their government has insisted on backdoors it is less directly impactful than if my government does.
I don't really have anything to hide anyway so if my assumptions/approach is wrong then worst case they find out about the concert I'm talking about going to. I grew up thinking encryption and technology were going to free us though, and have found reality to be quite the opposite -- so I try to cover my tracks out of spite I guess.
I don't agree with your characterization of that as a "backdoor" and I think that dilutes the term dangerously. There is no need to use Apple's backup at all, iDevices can still be backed up to your own computer same as always. I do think it's a real problem and one of the real clear cases where Apple's lockdown is anti-user, it should be possible to direct convenient automatic backup at any service one wishes using standard APIs. But it's not any kind of backdoor in iMessage, in the same way it's not a backdoor in Signal or whatever else you might choose to run. Or would be a backdoor if you decided to do unencrypted backups to your own NAS because you decided under your threat model that physical attacks there were less of a risk/value then losing data due to losing keys or something. It's an entirely orthogonal system to the encryption of the messengers themselves. It's not a "backdoor" in a communications system, any communications system, if someone chooses to keep logs unprotected elsewhere. Lack of E2EE in the most convenient wireless backups is a flaw in the general iOS ecosystem, not iMessage specifically.
Let’s not even talk about Chinese users, as apparently Apple bending over to store all their data in CCP data centers doesn’t count.
Tough to disagree.
I feel like that paragraph would lose most people because it's a long chain of connections. It's hard to do a TL;DR but here, I'll try:
Basically "If you message someone in China, Apple sees to it that your identity and content is handed to the Chinese government."
I don't know this for a fact. But as far as I can tell (and they aren't saying anything) this is exactly what is going on.
>a) on by default
I've never seen it on by default, it's a toggle. I can't find anything to support this assertion, and Apple's docs seem to indicate too it must be turned on [1]. How would it even be possible for this to work? Apple only gives you 5GB by default, and backups absolutely count against the quota.
>and b) isn’t clearly marked as being readable to Apple
As I linked they do clearly convey that. If you think it should be some extra warning dialog on enabling it, maybe that's a criticism, but there's certainly no standard around that across software industry-wide including on computers. Whether something is E2EE or not is usually something those that care need to look up. Maybe that should change. But no, it's not a "backdoor in practice".
>Let’s not even talk about Chinese users, as apparently Apple bending over to store all their data in CCP data centers doesn’t count.
No let's not, and no it doesn't here. That's a case with a lot more complexity then tends to come out on HN where instead people like you use it as a lazy bit of whataboutism. Apple is in the wrong there, and the US for allowing/encouraging it as well, but not for the same reasons as with the FBI and the path away from it is very different and harder as well. They deserve major blame in both cases, but why they deserve blame differs, and that matters.
----
0: https://support.apple.com/en-us/HT202303
1: https://support.apple.com/guide/iphone/back-up-iphone-iph3ec...
You seem to be unfamiliar with the concept of iOS storage classes. The iOS security overview pdf from Apple will explain better than I can.
> I've never seen it on by default, it's a toggle.
I set up dozens of iOS devices per year. Logging into even the App Store (after declining to log in during initial setup) silently enables iCloud, and iCloud Backup. It is on by default and most users are never once presented with the toggle. You can accidentally enable it just by installing an app.
https://www.wired.com/2015/09/apple-fighting-privacy-imessag...
So if you make a software package that monitors for "FBI iPhones" being added to your account, and make that available on github for other people to use, and have it send results back to a big web dashboard, then both the FBI and Apple would have to immediately stop for fear of being caught.
Such a package could be on Mac, where you have easy root access, because the e2e keys of chats has to be visible to all clients, not just iPhones.
Remember you only have to find one convincing case of Apple/FBI adding a phone to a users account without consent, and Apples privacy conscious reputation is ruined.
Even if you disable iCloud Backup, Apple can still read all of your iMessages.
They'll be in the (on by default) iCloud Backups of everyone you chat with.
It is absolutely a backdoor: https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...
You may not be aware that Signal endpoint keys are of a device-local storage class that are excluded from backups of any kind, and consequently they do not leave the device. iMessage endpoint keys are backed up to Apple, effectively without encryption.
There is no step you can take that will easily compromise your Signal endpoint keys to a second party. Simply logging in to an iPhone (required to install apps!) will configure your device to escrow your iMessage keys to Apple.
That's a backdoor any way you slice it.
Consider the story of Crypto AG, the most enduring and therefore successful example of this sort of exploit; crucial for putting it in place was that the founder happened to be friends since 20 years with a highly placed chief in the NSA and that's just not a scalable model. It also required convincing an independent, world renowned, crypto expert to completely compromise their work and serve as the authority that kept lesser experts from questioning the cooked algorithm, also not a terribly scalable thing.
Any service that is marketed to you as privacy- or security-as-a-service, or software sold as privacy- or security-enhancing, is virtually guaranteed to be secretly working against the interests of its users. You can't buy security or privacy in the form of software or services, because privacy and security are a set of good practices, not a product. People who think they can buy a "privacy phone" are just marks who are being conned by various organizations.
Do you have any source at all to back a claim like that?
The government doesn’t have the resources to compromise every online service. There’s money on the line for entities like proton.
If you are seeking out a way to hide information, you are part of a market that is signalling you have something worth hiding (to you, at minimum). As a bad analogy, it's a bit like putting up a sign in front of your house that says "We went on vacation, but the door is locked!"... basically, begging to be exploited.
Short of regular, independent audits, you are mostly reduced to guessing who to trust, and even then (as demonstrated by Lavabit) the trustworthiness of the actor isn't always the only relevant factor.
No one is saying that they can't, somebody is saying that they are, but not in that customer's best interest.
-----
edit: with parallel construction, there are absolutely no drawbacks to narking on your users, assuming that the way you do it is an obvious possibility that you just minimize or ridicule the likelihood of.
e.g. "Everybody knows that they can use Method A to break your encryption, but that would be company suicide! Do you seriously think they're stupid enough to do that!? They even made the client open source to be open about what they can or can't do."
rather than
"Guys, I just noticed a process running on my phone that isn't supposed to be there."
Which is what we've been taught to watch out for.
If you are willing to spend 6+ digits, there are absolutely good solid privacy products/services you can get. These folks aren't catering to individuals or street criminals, though.
I agree, if you're a person with a serious targeted privacy threat, and you think there's a magic bullet, you're kidding yourself. Any serious data privacy solution is going to involve a ton of associated meatspace solutions beyond buying one SKU and calling it done.
But, yes, largely correct.
"Initially the device offered strong DES encryption, but this was replaced in 1984 by an NSA-supplied alternative algorithm."
"The NSA bought 12,000 DES-based PX-1000 units, along with 50 PXP-40 printers and 20,000 ROMs that had already been produced, for the total sum of NLG 16.6 million (EUR 7.5 million)."
More boringly, and more simply, they hire people who work at Apple, Google, and so forth to exfiltrate data, create constant new bugs that will at some point be called a 0 day, and it goes on and on.