US govt pays AT&T to let cops search Americans' phone records without warrant
theregister.com
theregister.com
This is a great article to share with friends who don't understand how dangerous this is.
And you think people will be upset about the concept?
This is a poor example to use.
edit: I see lots of downvoting, but people... be realistic. The average person will only see that a rebellion could be stopped. This isn't an example which explains negative outcomes to them well.
People will give up all due to fear. Hell, people will give up all privacy to Google for beads and trinkets!
And this example shows a government being able to thrwart an actual, violent rebellion! The average Sally and Joe will think "great"!
I think you underestimate the American investment in our founding myths/stories. This is probably a bad example to convince an English person, but I imagine it would have considerable visceral appeal to an American.
"Metadata is information about information. A library’s card catalogue is an example of metadata: it contains details about the library’s books, which themselves are treasure troves of information. Metadata about a phone call can include: who called whom, what date and time the call was placed, each party’s location, and the call’s duration. ...
"Had such metadata been available to the Third Reich, it is easy to imagine that Kelly would have been flagged by encoding 3 (homosexual) on a punched card, arrested, and his death recorded by encoding 4 (execution), having been found guilty by association. There are other explanations for Kelly’s actions that, knowing the conversations’ contents, would lead to completely different interpretations."
Not sure the point of this comment.
Also, yes, check on the shadow ban ... your comment history shows a bunch of flagged/dead comments that didn't warrant it.
Agencies will throw officers under the bus at the slightest provocation to save their own asses. The easiest way is if they get caught violating policy. Officers will often work hard to find out how to not get caught/the cracks in the system, vague areas of policies, etc.
It’s always been a cat and mouse game. Same in the military, except the military doesn’t have to deal with civilian courts and shit rolls down hill more explicitly.
The courts? PUH-LEASE! Prosecutors never prosecute. Even if they go to a grand jury, they end up instructing the grand jury to pass a no-bill (i.e. not enough evidence of a crime), thus letting them was their hands and say, “Gosh! The jury didn’t indict. Can’t do anything,” when in actually grand juries indict everyone. (When I was on a federal grand jury, the AUSA told us that if we were going to pass a no-bill, to tell him so he could bring more evidence (a legitimate ask) and told us that a no-bill would result the a call to him, and his boss, from the Attorney General himself.) Then of course there’s qualified immunity and case law that is overly differential to police actions — even when they violate procedure.
It’s bullshit. Cops are completely unaccountable. They’re gangs.
https://www.ncja.org/crimeandjusticenews/fired-cops-are-rout...
Politicians have started adopting such structures too. House Speaker Mike Johnson famously has no bank account. He does, just not under his name. It would be managed by his family office.
Family offices are also an artifact of generational wealth. Plenty of famous people aren't rich enough for something that heavily staffed. Also newly wealthy will often want to be able to deal with existing friends and family on the same basis as before.
Indirectly, I've been able to observe some of the habits of someone with stratospheric levels of wealth. They had a phone number, but changed it frequently.
Now the elite use Telegram groups, Signal, and rotate SIM cards. Everybody should be doing life this way, so the telcos become dumb data pipes.
Federal law enforcement and our intelligence agencies are politically powerful organizations that pretty much do as they please and never face consequences. Even our elected officials fear them. As senator Chuck Schumer put it “Let me tell you, you take on the intelligence community, they have six ways from Sunday at getting back at you.”
I think that that's a less obvious conclusion than one might think, even though I share your more acute distrust of local than of federal law enforcement. It might seem extremely unlikely for someone inconsequential like, let's be honest, many of us here to come to the attention of a national body; but history shows that all it takes is being affiliated with a group or movement that makes the federal government nervous to become the subject of FBI scrutiny, and this likelihood is heightened the easier surveillance becomes.
Also, maybe not relevant for this discussion of AT&T, but what about "law enforcement" outside the US? My point is more broadly about the problem of verifying a request really and legally came from "law enforcement."
If my experience working with AT&T in the private sector is any indication, they would be cross referencing this sort of list when establishing new access, and I doubt this is something that can be done quickly.
> ...police chief who emails AT&T requesting emergency access to prevent a suicide?
This isn't a plausible hypothetical. If it was an emergency they would be calling through established channels and the fastest way to get access to that sort of information would likely be an emergency warrant, which is easily granted in the situation you described.
[0] https://krebsonsecurity.com/2022/03/hackers-gaining-power-of...
They've been data-mining them to create community maps and maybe even your historical location.
They've done so for decades and in the early 2000s even invented their own programming language to do it.
https://web.archive.org/web/20170129095532/https://www.wired...
This to me is the most concerning part. The government has a legal way to get that information, but belligerence to serve the rights of their citizens? That's particularly concerning, like they've forgotten who they serve and work for.
Why does someone always have to go to jail? Just stop the program. Once it’s clearly illegal you can start adding to our list of incarcerated.
Because if I do what my boss told me to do, what has been done for ages without consequence, and you’re going to pass a law putting me in jail for it, I will expend every effort to thwart it. If, on the other hand, you’re saying “stop it,” my give-a-shit factor is lower.
The broader public is indifferent about the Fourth Amendment. Polling and elections and listening to phone calls from constituents shows this. Activating a concentrated mass of political energy against yourself, in this context, is not a bright idea.
Also, it’s wild how cavalierly we’re willing to contemplate taking away someone’s freedoms in a conversation about other freedoms.
I think it shows considerable restraint, to ask for the incarceration of a handful of offenders, compared to the flagrant abuse of the rest of everybody.
It is. But that’s not how voters see it. Electorally, pushing for incarceration is a few steps behind “defund the police.”
When someone abuses power and privilege in order to take away freedoms from the powerless, the powerless wanting to take away the freedoms of the powerful is to be expected.
Even if you take this one capability away from the privileged and powerful, they will remain privileged and powerful. They've demonstrated a willingness to abuse their position to hurt others.
In contrast with removing only one capability from their arsenal, it would be better if the abusers would also be stripped of their power and privilege for having abused one of said powers and privileges.
That doesn't necessarily require incarceration, logically speaking. Sure, the wounded may feel better if it did, but the goal of policy in this situation isn't to please. But at least the individuals who violated constitutional rights are no longer trustworthy.
I’m all for firing the people and banning them from public service. I just don’t see the benefit of putting them in jail. From their perspective, what they’re doing is legal. Moreover, it’s deeply precedented.
And again, it’s a false economy. Threaten to put people in jail around a freedom that ranks low in voters’ minds and you’ll wind up with nothing.
Because we have explicit laws set up that already say this isn't an excuse. If your boss tells you to rob his neighbor, that won't save you. If your boss tells you to drive drunk you'll still get arrested for drunk driving. The agency is yours. The question is if a reasonable person would know this a violation of the fourth amendment and I'm pretty confident the answer is definitively yes. And we're talking about cops, who are trained professionals. Who are supposed to be trained in the law. They should know more than a reasonable person.
> The broader public is indifferent about the Fourth Amendment.
You're confused. The broader public is jaded. They've given up hope after decades of abuse. Losing hope is not the same as being indifferent. Even ambivalent would be a better word but I'd still say jaded. We're tired. We're exhausted. Depressed. Worn out. But not indifferent.
Besides, civilians get the "ignorantia juris non excusat" [0] principle, and the rule of law means that everybody, including government officials and law enforcement, should be held to the same standard.
[0]: https://en.wikipedia.org/wiki/Ignorantia_juris_non_excusat
Smith v. Maryland is probably the most relevant case:
> The NSA has built a surveillance network that has the capacity to reach roughly 75% of all U.S. Internet traffic.
> An internal NSA audit from May 2012 identified 2776 incidents i.e. violations of the rules or court orders for surveillance of Americans and foreign targets in the U.S. in the period from April 2011 through March 2012, while U.S. officials stressed that any mistakes are not intentional.
> The FISA Court that is supposed to provide critical oversight of the U.S. government's vast spying programs has limited ability to do so and.
> A legal opinion declassified on August 21, 2013, revealed that the NSA intercepted for three years as many as 56,000 electronic communications a year of Americans not suspected of having links to terrorism, before FISA court that oversees surveillance found the operation unconstitutional in 2011.
https://en.m.wikipedia.org/wiki/2010s_global_surveillance_di...
This part right here:
> it must trust the government to report when it improperly spies on Americans
The courts told them to watch themselves and to self incriminate if they do crimez. An honor system. Which naturally, they did not snitch on themselves to the courts, because why would they.
That is what government procurement means. Any competitive process comes before the award of the contract. After that point everyone is generally locked into a one-customer one-seller situation.
I'm certain you could, if you really put your mind to it.
Facebook, Google, etc proved that user data is lucrative. Why is it surprising when other companies want to jump on the same money-making stream?
Users don’t read terms and service agreements anymore. As long as companies include data collection and selling the data in the ToS, and customers continue to agree to it, what is the problem?
Customers can either vote with their wallet and move to a provider who respects their data, or they can push their elected politicians to make the sale of data like this illegal.
Okay, sure. But, are they compelled by law to keep 40 years’ worth of call records, and not only keep them but in an easily indexed manner?
If they aren’t, then clearly there is something going on. Those records probably aren’t that cheap to keep around, compared to not keeping them around. They’re a public company with shareholders; if it were less costly for them to get rid of the records they presumably would have already gotten rid of them, so.. what’s going on?
[1] https://www.wwnytv.com/2023/11/15/st-lawrence-county-struggl...
[2] https://www.northcountrypublicradio.org/news/story/35988/201...
I posit that it doesn't.
Personally I'm using it as an opportunity to tell my story and call out authorities by name, when my case is over.
I would like to see a country where judges don't play God or choose which families win and lose in this country. They owe every citizen respect, not just the ones with uteruses.
Our rights are but toys to them. This will not change until we start dismantling the structures of power that allow them to steal autonomy from others.
Also, a firm no thanks from me on dismantling the structures of power until we settle unambiguously on what replaces them. Again, maybe my Canadian bias, our "structures of power" are not great but typically those who want to dismantle them are advocating sheer wingnut lunacy in their stead.
There are some things, like families, that governments are simply not equipped or qualified to rule on. It doesn't concern them, they have no standing and no stake in the outcome. They are reticent to take real action and instead want people to bend to their will without having proven superiority of character, word, or deed.
Still not enough to convince me that this country is good or is capable of respecting its own documents and laws. It does what is convenient to it, no more, no less.
I will return the favor when the US inevitably pisses off another country and they invade.
Want to mistreat me? Enjoy defending yourself.
My aim in sharing that article was "how we get to a point where judges even think this is acceptable behavior/know they can usually do this kind of thing with impunity".
It just had the will to pursue those behaviors in analog.
Any E2E app that doesn't collect your phone number or any identifiable info that you can use as a standalone app on the desktop and E2EE is the only way it works (not optional or opportunistic like jabber/xmpp, whatsapp, matrix, telegram,etc...) and is developed ouside the US by a well known/reputed dev(s). Is what I recommed.
Check out wire and briar if they meet these requirements. Personally, I would not use digital media if I don't want the US gov knowing about it entirely. The solution is legislative not technical. Kind of like how you get a free TSA body massage at the airport, the people have willed it.
You could easily snoop who is messaging whom, but it's very different than knowing what is being messaged. End to end encryption would protect the second. Carrying a second phone intuitively protects the first, but in reality does not.
Signal chooses (or more accurately chose, since they’re working on eliminating it) to depend on telephone numbers for identity mapping, which was and is a reasonable design constraint given their target audience.
Who do you think their target audience is, and why do you think that this a reasonable constraint?
It's all culting around tech/crypto personalities and ignoring the obvious things that don't pass the smell test.
Explain to me why Signal is special as opposed to more popular apps made for the general population that also do E2EE? Explain to me specifically why phone numbers and mobile usage is not optional? Even after like a decade of people begging for it?
This is a lot like PGP email, the same circles of people promoted it (still do in some cases) but the government loves it because email metadata is unencrypted and tech circles insist on email dependency on every app because of the same cult mindset even though hostile middle parties love it. Everything I do in amazon, netflix, uber, slack you name it you can tell my whole life pattern just looking at email subjecte in the clear on an MTA! All because of tech sector refusal to apply critical thinking and creativity when it comes to these things.
So again I ask, if I am allowed to criticaly examine Signal: why is it special and unique that it needs phone numbers no matter what? Especially given device compromise of people you talk to is not in their threat model. e.g.: you are a source and the journalist's phone is compromised, that is exactly what governments do! If signal didn't collect phone numbers all they would see on the journalist's phone would be your nick or in-app id, but thanks to signal they can find out who the source is, and using exploit kits like pegasus this way is not uncommon! Real people are put in danger by signal.
Look at all my downvotes and tell me this is not tech sector conspiracy or at best culting after personalities.
I never said anything contrary to that.
I know that normal people are part of the intended audience - I'm interested in whether you think that Signal's target audience includes or excludes "keyring bonsai" users (which, admittedly, is an amusing and not entirely inaccurate way of describing much of the security community).
If it includes those users - then why Signal couldn't have been designed such that use of phone numbers for identification are optional (but the default)?
But for those users: you can effectively use Signal without a phone number by using a virtual number or similar for the one-time registration process. That’s clunky and not ideal, but IMO is a reasonable hurdle for “bonsai” users.
Marginal users are just as human as the rest of us. Can you show examples of how this complicates Signal's design? The idea in my head requires only marginally more complexity to serve ~hundreds of thousands of more users.
The complexity here is in crossing domains: Signal will need to decide how to communicate which “kind” of identity a user has, what that means, etc. They’ll need to decide whether to use random-but-intelligible identifiers (easy to make errors with) or allow people to configure identifies (which means storing more personal data, plus impersonation risks). And so forth.
I'm talking about users that have the understanding and desire/need to disconnect their Signal identity from their phone number. That's hundreds of thousands, minimum, if not millions.
> Signal’s intended userbase is O(humanity).
This doesn't obviously interfere with Signal's ability to create Good privacy mechanisms, e.g. disassociation between identity and phone number.
> The complexity here is in crossing domains: Signal will need to decide how to communicate which “kind” of identity a user has, what that means, etc. They’ll need to decide whether to use random-but-intelligible identifiers (easy to make errors with) or allow people to configure identifies (which means storing more personal data, plus impersonation risks)
None of these obviously "substantially complicates Signal’s design" as you claimed earlier.
> communicate which “kind” of identity a user has
Tell the user that other users either have a "phone number" identity or a "certificate" identity. Done. They're already responsible for verifying that the phone number matches the person they think it does.
> what that means
Tell users that a "certificate identity" just means that that person isn't using a phone number. And they need to be extremely careful when interacting with people using these, and absolutely should verify them using a secure channel. Or just disable these entirely until the user taps the "about signal" button in the settings menu 7 times or something.
I don't see any problems here that can't be overcome with a very modest amount of engineering. And, because it's the right thing, they should invest that effort.
What utter deception! And why i distrust signal even more! The entire world uses whatsapp which has its own identifiers as do most messaging apps. Signal deviated and went out of its way to collect the one piece of information even more identifying than your full name and address! Lol
> Contact sharing is a substantially less problematic subset of that.
HN rate limits me so please look at other comments i made on this thread about why this is decidedly more dangerous than just about any insecurity you know about. Nothing is more dangerous than false security especially when most people don't think in detail about security, they just assume signal will take care of it. I have an example about sources being revealed when a journalist's phone is compromised (many more examples).
For the general population, are you saying man in the middle attacks are of a greater risk than the other person's phone being compromised? Because if so I would strongly disagree with that and can provide sources to back that up (but save me time and look into all the pegasus pwnages and mobile stealers). In which case, in the threat model that matters most to the general polulation, signal compromised by sharing the one piece of information that is so good at identifying people it is the most popular anti-fraud identifier: phone numbers!
My trust in it is even lesser by how everyone rallies in defense of signal and downvotes any critique of it like with this thread. Be wary of crap you're not allowed to question!
I don't know about Viber, but this isn't true for WhatsApp. If someone sends you a message on WhatsApp, you can see their phone number.
Again: the overwhelming threat model is here is "two individuals that already know each other want to communicate privately." That's what Signal facilitates, and it does so pretty well given the purity compromises that need to happen to do that for non-technical users. They're not worried about leaking phone numbers, because they're already shared.
Finally: there's a good chance you being downvoted here because (1) these comments are indistinguishable from FUD, and (2) you're making claims (and now talking about examples) without citing them. I'll lead by example here: we know that the FBI can only retrieve minimal metadata from Signal[1], and various foreign intelligence services have more luck deploying malware to phones[2] than they do actually breaking anything about Signal's design. Nation state adversaries don't have trouble finding peoples' phone numbers.
[1]: https://therecord.media/fbi-document-shows-what-data-can-be-...
[2]: https://theintercept.com/2017/03/07/the-cia-didnt-break-sign...
Well there is no justification for that threat model beyond "our leader said so". Especially when they expressly fight state level censorship and interference but something as simple as someone shoulder surfing you defeats it. Threat models are for security professionals not regular people. Regular people don't model threat or assess securitu risk properly. They don't know encryption is useless if you don't authenticate. And signal's refusal to be independntly usable outside of smartphones given how much law enforcement and spies love to abuse mobile phone infrastructure leaves me to be very suspicious of their intent. Making phone numbers opt-out just makes you less discoverable at best. They have 50 million dollars and various projects no one asked for yet this is too difficult and complex? You still have't given me a reason to accept that beyond "trust me, i know".
> Finally: there's a good chance you being downvoted here because (1) these comments are indistinguishable from FUD, and (2) you're making claims (and now talking about examples) without citing them.
Disagreeing with you is FUD? What claims did i make that need citing? Please challenge me then?
For anyone who reada this thread, do you really want to use Signal given the hostility a person would get for questioning their terribly questionable choices?
> know that the FBI can only retrieve minimal metadata from Signal[1], and various foreign intelligence services have more luck deploying malware to phones[2] than they do actually breaking anything about Signal's design. Nation state adversaries don't have trouble finding peoples' phone numbers.
Do you freaking realize that you are making my point for me here? The problem is being able to connect signal messages with phone numbers. Of course they know everyone's phone numbers! But reporter A talking to source B is all they need to know because they can get access to either's phones! There are very few cases where a real life adversary cannot at some point access one party's phone over time.
If the only protection is against man in the middle attacks then signal is by far the weakest app in that category because wire, briar,etc.. i can just use them on any device.
I had advocated for signal for many years and have gotten burned by it more than any other messaging app. The worst security tools are the ones that lead you to trust them more than you should, the more cultishly supportive their supporters are the more wary of them you should be.
For the target audience of signal, imessage on an iphone is a better choice. For the real users of signals that need higher security wire and briar are better. Signal compromises on too much and then claims too much security guarantees.
Signal is no better than just using imessage or whatsapp. The terribly deceptive thing about it is that it is marketed as a super secure messaging app better than alternatives but in the most important way that matters: not crypto but metadata and plausible deniability it makes such compromises. Explain to me why signal on the desktop can't function without a mobile app?! Governments have complete control over mobile phone infrastructure and can perform targeted compromises by using signal contacts for target selection.
Do not use signal thinking it will protect you better than any other encrypted app. Governments and private partires are not out there cracking the crypto itself.
The rest of this is scattershot: what matters for the overwhelming majority of use cases is end-to-end encryption between parties that know each others' identities but aren't necessarily technically proficient enough to play key management games. This is the user story that matters for dissidents, journalists, public figures, and ordinary people: if you aren't servicing those people, then it's extremely likely that you're (1) servicing nobody at all, or (2) servicing people who treat security as a LARP rather than a practical concern.
> between parties that know each others' identities
And Signal needs to collect their identities and reveal them to each other despite the risk of one of them getting compromised?
> This is the user story that matters for dissidents, journalists, public figures, and ordinary people
When you are outed as a source, as the romantic partner of an estranged spouse, as the public figure losing an election because of an embarassing message,etc... it matters. And you have not given me a technical reason why Signal can't protect people as they expect it to. None of these people are concerned about the FBI doing a forensic investigation or wiretapping them.
> servicing people who treat security as a LARP rather than a practical concern.
Or normal people who don't know enough to think about security and threat models who simply trust you the tech savvy person recommending them Signal which will protect them, you know, the general population. Matter of fact I would bet good money most signal users don't even know you have to verify each other's codes in person for the e2ee to even mean anything other than false security!
It would be good to have a proper field guide written down, that's a little more in-depth than "leave your phone at home", weighing risks vs convenience, going into detail on what kinds of metadata you might be leaking, etc. Most of us have some rough idea but it isn't at all obvious the way we know "MD5 is broken".
AT&T did divest CNN at least, and no thanks to the US Gov't.
Frankly, I think it’s safer to assume that most (American) communications companies are involved in some level of surveillance.
Most people call that blackmail, even if it is government.
Second, it’s still a search and seizure of your records. You made the call, AT&T was only the common carrier connecting you. Regardless, of whether or not they paid to conduct the search. Now the judiciary is pretty slanted to supporting law enforcement so it will take time to play out. Often the higher courts are more apt at deciding these issues (ie less bias)
That said, there’s a tendency in the US justice system to protect the system. So we will see how it shakes out in 5 years while this makes its way through
Who said the Government blackmailed them? These companies are selling this data to every large corp asking, not just the Government. You give private corporations way too much credit here, if they can earn a buck they will sell your soul.
Furthermore, if the DOJ contracted them to build the system there would have been due diligence on the legality and process.
And I'm pretty sure that most corporations that sells your call data to other private corporations sees no issue to also sell it to the government. To them it is just another customer.
Any source for that being the case here? CPNI is partially protected, but subsets of it can be freely shared and sold by companies. Do you have a link showing the data police accesses here goes under the protected category and not just the freely available category?
Private companies can access the following according to the CPNI wikipedia, parts of it can only be shared inside the company but a very large part like location data and URLS and demographic data can be sold freely:
> Verizon shares CPNI "among our affiliates and parent companies (including Vodafone) and their subsidiaries unless you advise us not to". and states that it shares "URLs (such as search terms) of websites you visit when you use our wireless service, the location of your device ("location information"), and your use of [Application software [applications] and features" as well as other "information about your use of Verizon products and services (such as data and calling features, device type, and amount of use), as well as demographic and interest categories (such as gender, age range, sports fan, frequent diner, or pet owner)" with other non-affiliated companies
https://en.wikipedia.org/wiki/Customer_proprietary_network_i...
Here, the same pattern applies, but the scale of cooperation is staggering. “Quantity has a quality all its own,” on steroids. In the case of AT&T, their cooperation includes trillions of records and affects literally everyone who has used a phone since 1987.
The issue, according to the article, is not whether voluntary sharing of records is constitutional, but whether the public should have a right to know the details of how the system works.