Governments spying on Apple, Google users through push notifications
reuters.com
reuters.com
For context, we are sending ~35 million push notifications per month on iOS and ~67 million on Android, see more at [1]
[0]: https://developer.apple.com/documentation/bundleresources/en...
[1]: https://threadreaderapp.com/thread/1721717002946191480.html
APNS is not a "let my server wake up my app in the background whenever and however often I like" mechanism.
Defer handling other things until either your extension or your app would have run anyway and do them at that time.
Send a meaningless random ID, then do a get request to your API to get the actual content, then present it to the user.
Only a meaningless ID will transit through google/apple servers.
Honest question. I'm sure many thought about it before.
I built a finance app a few years ago that would take market data via a push notification, and then the transform extension would render it to a chart image and attach the image to the notification to avoid generating them server side.
I would pay to commission a blog post on the topic if you’re willing to write it.
Decrypting a push notification appears to be supported using 'mutable-content' with a notification service.
In fact that is the example used here: https://developer.apple.com/documentation/usernotifications/...
Zac also just let me know the other reason we need filtering is so we can properly unsubscribe users from notifications when one is received from a server they no longer are connected to.
“...for metadata related to push notifications to, for example, help tie anonymous users of messaging apps to specific Apple or Google accounts.”
So maybe more, they (or somebody) send some messages to this account they want to ID, then request the specific device identifier that received notifications for that app at all of those times?
Would obfuscating the content make much difference with respect to that category of technique?
Source code on GitHub.com/mozilla-mobile
Not saying you are obviously compromised, but the simplest explanation after this news is that maybe they relay the authorization to NSA et al, and they OK'ed your case and not theirs for some reason...
Consulted for a company who implemented access logs for law enforcement to telephone records. A friend works at ring just fetching data from the DB for the legal team after they receives pro forma requests.
And those are the regular cases since the 80s. with judges from regular courts. If there's a law those companies must follow they will implement the same systems as they had for other laws. Only that these new ones prevent them from discussing. That's the only difference. the rest is banal day to day from legal and the industry that exist to sell compliance services to them.
https://www.wyden.senate.gov/issues/secret-law
https://www.wyden.senate.gov/news/press-releases/wyden-colle...
https://www.wyden.senate.gov/news/press-releases/wyden-intro...
https://www.wyden.senate.gov/priorities/gps-act
https://www.wyden.senate.gov/news/press-releases/wyden-relea...
That's certainly a step above many of the grifters we have in government, but it's also not necessarily a good thing. People can truly believe in stuff that's harmful or flat out wrong.
It's sad we don't hear more about people like this in positions of power.
That said, I also think things happen way before the first term. It requires consent of the Party to get on the ballot and hundreds of millions of dollars, increasingly trending towards billions, to run a campaign with a chance of winning, because in a democracy it's quite self evident that the person who spends the most money, must be the better person. Results don't lie!
And on top of all of this, if you aren't shaping up to be who the Party wants, then the completely independent, free, and honest media will demonize you. And even if this doesn't destroy you in the eyes of your own supporters, it'll rile up your opponent's base enough as they race to vote (for somebody they also don't even particularly care for) because if they don't, then you might win! That cannot be allowed to happen as it would obviously be the literal end of the world.
This is why it's ever more important for social media to be controlled, lest somebody angle-shoot around the traditional path to success - the media. If somebody's gaining traction on social media, then he's saying things that disagree with the powers that be. Since he's disagreeing with the powers that be, he is spreading misinformation by definition, so he must be censored. For our safety.
I would like to ask you a serious question: do you not think it is extremely weird that so many people will at least sometimes[1] agree that "democracy" is essentially fake, but then at other times take quite literally the opposite stance...praising it, defending it, singing its virtues, etc? Granted, it is theoretically possible that each individual is 100% consistent at all times, and I am simply observing people who are on different sides of the argument, but now and then I'll check into someone's post history and find evidence that pretty soundly rules that out (subjectivity noted).
A standard response to this is something along the lines of "Oh, that's people just being X (dumb, etc)", but I do not believe that is an even remotely accurate description of what is really going on. But for even more irony: on one hand, most people tend to think democracy, governance, and all the things downstream of it (ie: their literal experience here on Earth) is a very big deal (the passionate debate over what exactly the events of January 6 "were" is a prime example), yet it is almost impossible to get anyone to engage in a highly serious conversation about just what the fuck is going on here on Planet Earth, 2023. It is as if there is some sort of a yet to be discovered phenomenon in play.
Do you think I might be crazy? I very often genuinely feel like I am living in The Truman Show.
[1] I feel like this is a crucially important detail that is rarely investigated or even contemplated.
But I think one major issue is that we're living through an obvious inflection point in history. When the US was competing against the USSR, we achieved numerous objectively incredible things. For but one example, we went from having never put a single man in orbit in 1962, to putting a man on the Moon, in 7 years! In modern times, with modern tech and knowledge, we struggle to replicate what was done 60 years ago.
And so I am exceptionally critical of our systems in modern times, but also look at them with glowing fondness at what they have achieved in the past. But socially we rarely distinguish between the two - Democracy is Democracy. And so this can appear to be cognitive dissonance when one loathes 'current democracy' yet holds dear 'classical democracy.' And I think many people also feel similarly, even if they may not actually even realize it.
But back to the inflection point, for the past ~80 years, and especially the past 30, the US has reigned relatively supreme owing to a large technological edge driving a large economic edge. But now China is equalizing technologically which is also driving their economy upward. It's already the largest in the world PPP adjusted, and will soon enough also be the largest in nominal terms as well. A country of 340 million simply will never be able to compete against a country of 1.4 billion. So they are set to become the world hegemon.
What will that mean? Well historically they've always been relatively insular, even when going through periods of great power, and I don't really expect that to change. In the early 15th century they were, by far, the greatest maritime power yet one does not find Chinese colonies in the Americas, India, Africa, or pretty much anywhere. But on the other hand, I think this change does scare many people, because what if China becomes the new US and just starts trying to put its tendrils into everything and turn everywhere into little clones of the Chinese political system?
And fear is a such a strong driver of irrationality, the same reason people continually vote for people they don't like. I think this fear tends to cause a sort of rally around the flag effect, where people can see that this flag is one they scarcely recognize, let alone truly love, yet it looks far less scary than the one they don't know at all. Drive that fear of the unknown into people, which our political types thrive at, and the people will come racing back, not entirely dissimilar to a woman in an abusive relationship.
I still feel this is not even scratching the surface, but it's at least a first effort! It's such an interesting question that one could easily write several books on the topic. And in the future, people looking back, probably will do exactly that!
I believe it is very fair to say that it is not a question of whether it is fake(!) at all (as a binary), but a question of how fake is it, and in what specific ways?
And yes, I can certainly appreciate why people would have an aversion to this, and the various other "just so" memes that are trotted out when the topic comes up, but the question remains: why is NO ONE capable of taking this topic very seriously?
Can you address that?
And while all these topics (and many more) can be encompassed by 'fake', they all are quite radically different.
Let's say an election actually was rigged - do you think that is more important than whether our "democracy" is legitimate, always?
Do you think 10% of the HN user base has the ability to discuss this question, at all, and without losing control?
I think an important point in general is that democracy is what people think it is. If people think elections are fair or a viable means to change their political fate, then they're going to act accordingly, and vice versa if they don't. So personally I think having as absurdly transparent and open a system is critical. Irregularities and oddities should be publicly emphasized across the aisle so (1) everybody can discuss things and be on the same page, and (2) they can be remedied and not repeated.
I think you hit the nail on the head here - and, it doesn't apply only to democracy, it applies to everything. It's funny, because lots of people also know this, yet do nothing about it.
> If people think elections are fair or a viable means to change their political fate, then they're going to act accordingly, and vice versa if they don't.
Where "acting accordingly" is usually ~behaving on social media in the corresponding manner.
Gosh, I wonder why it seems like humanity has little control over its fate.
It’s easy to game the system when there are only two sides to pay…
2008: https://en.wikipedia.org/wiki/Foreign_Intelligence_Surveilla...
The votes: https://www.govtrack.us/congress/votes/110-2008/s168
But this is a MUCH older issue: https://en.wikipedia.org/wiki/Room_641A
And if you don't know about Quest: https://en.wikipedia.org/wiki/Joseph_Nacchio
The entire time period of the Bush admin is a microcosm for unresolved issues of today: Voting machines, government over reach and spying, security, encryption, copyright, bad behavior by corporate entities (M$ has a cohort).
Oregon is an extremely based state. Y'all crap on PDX but the reality is that we have more freedom and less tyranny here than in any other state in the nation, and possibly in the world. PDX is "bad" because it's one of the only places in the world that hated the cops enough to actually muzzle them - and not living in fear of the boot is worth needing to deal with homeless people.
Want to smoke weed? Check (lowest prices in the world). Want to do psychedelics? (functionally legalized) Check. Want to shoot guns? (relatively lax gun laws for a blue state) Check. Want to not be spied on? As check as Ron Wyden can make it!
The tyranny of the masses is still a tyranny. I'd personally like to move to a state where all smoking, but at least weed smoking, is illegal. I really don't like second hand smoke, especially when it smells and hangs as much as weed smoke does.
In all seriousness, Utah sounds like your ideal so long as you stay outside of Salt Lake City. I'm glad to no longer be a resident
Not enough trees. Nor enough employment in my non-remoteable field.
Public smoking is a concern, but the smoke will leak even if smoked inside of a home. With edibles and inhalers I don't understand why people thought it was a good idea to legalize marijuana smoking.
> Nor do I see how having bodily autonomy is necessarily a tyranny of the masses.
Generalizing the principle of the swinging your fists near someone else's nose saying.
You do know that, right? I'm not detecting any humour markers...
You do understand that many tort suits, and outright laws, are over subjective harms, right? (trash in neighbors yards, loud sounds late at night, smells from chemical industries, etcetera) That laws such as disability protection laws exist?
Lots of people love the smell of cannabis. No one loves "trash in neighbors yards, loud sounds late at night, smells from chemical industries".
Arguing in bad faith is lame dude.
There are entire messy neighborhoods.
> loud sounds late at night
People sleep at different times of the day.
> smells from chemical industries
People who lack a sense of smell don't care.
Special pleading for marijuana smoking is also lame.
Second hand weed is harmful. https://www.uclahealth.org/news/secondhand-marijuana-smoke-w...
OP is complaining that he might get a whiff coming from his neighbors house.
> In a few states, however, public consumption is completely tolerated or allowed in licensed lounges and designated areas.
And the laws as is make it easy for people to lie to the police about exactly where they were when they were smoking the weed.
If you take one of the world's most popular pastimes that personally, and want it legislated against on that basis, I have no time for your arguments.
Like - Manhattan. Yeah, you're gonna smell cannabis in Manhattan. It doesn't matter the tiniest bit what the laws are; you're gonna smell it. It's not something to take as a personal insult, and it's wild you insist that it is.
Anyway, weren't we talking about a serious issue? Like, is this why Americans are ok with all the domestic spying - they're too worried about sniffing a reefer on the wind? Ugh.
Many popular activities are expected to be done where they do not impact others. In my local park, a man was arrested for masturbating in public, certainly a popular activity.
> It doesn't matter the tiniest bit what the laws are; you're gonna smell it.
Over the course of the last few decades, I smell it more in Manhattan and in many other places where it has been legalized. Apparently laws do matter. Not that I want any laws against it. I would just prefer that people not be assholes about it.
I did not interpret such sociopathic behavior as a "personal insult".
As for the more serious issue, I did not take the thread here. I replied to your comment, "OP is complaining that he might get a whiff coming from his neighbors house." I pointed out that one does not need to enter someone's house in order to be forced to inhale their smoke.
Wish it stopped at just the smell.
Second hand weed is harmful.
https://www.uclahealth.org/news/secondhand-marijuana-smoke-w...
https://www.lung.org/policy-advocacy/tobacco/smokefree-envir...
https://www.epa.gov/indoor-air-quality-iaq/what-can-i-do-abo...
https://no-smoke.org/secondhand-marijuana-smoke-fact-sheet/
Second hand
Cool do you have better studies? If so, please share!
I await with bated breath (due to the nasty smoke both physically and here on HN).
Whatever happened to "Trust the Science^TM" with marijuana?
When it intrudes upon the bodily autonomy of others (e.g. second hand smoke, which I am constantly facing and suffering from in the Bay Area).
You want to live in a state where all smoking is illegal?
Because you don’t like the smell of weed smoke?
How interesting.
No, not because I "don't like" it, but because the smell of weed smoke causes quality of life and health issues.
One of the biggest reasons I'm happy I moved away from my home in Oregon. The second-hand weed smoke is gross.
Your DA is determined to destroy this right by spending tax dollars appealing 114 until they find a judge who agrees with them.
When they were building the CSAM detector: "what if the government asks you to extend the detection to include other media such as political meme images?" "we would refuse".
The answer is both, which in particular means that they have to be technological. We need to prove their inability to defect with math because otherwise they can just lie about it.
What you need from the law is the right for everybody to use that kind of technology by default.
I guess now the yahoo phone doesn't sound like that bad of a joke https://www.slashgear.com/wp-content/uploads/2010/05/nokia_y...
I am legitimately surprised that more tech-heads didn't see this state-of-affairs (and all the other obvious drawbacks of The World's Most Featureful Spy Device, controlled end-to-end by a giant multinational, becoming ubiquitous in peoples back pockets) as an obvious, absolute given, right from the very start of the whole smartphone trend. Instead we all seem to have bought into it, hook-line-and-sinker.
Didn't see or didn't bite the hand that feeds?
You have to be willing to live with something less feature-rich than what you can get on the latest iPhone 27 Max Pro(TM). And you have to be gutsy enough to click an "Install some other OS" button in your web browser with your phone plugged into a USB port.
Then to extend to services, a lot of it depends on your ability to deploy your own stuff. This can involve a lot of time reading how-to guides after you've installed Linux on a machine in your house. Given how much documentation is readily available online most people with a high school diploma can probably figure it all out, but you have to be motivated enough to refuse to be helpless.
Today you can purchase a Pixel 7[|a|Pro] and flash GrapheneOS on it. There's a lot you can get from F-Droid, but if you really want Google Play Store apps, GrapheneOS does a reasonable job sandboxing it. Create a new Google account just for that installation of Google Play Store.
Never sign into anything Google, Microsoft, Apple, Facebook, Twitter/X, LinkedIn, or whatever from your phone. Or at least if you absolutely have to, use a trusted web browser in Incognito or Private Browsing Mode.
Keep location tracking disabled for everything but your favorite maps app. Put your phone in Airplane Mode when you're traveling if you don't want cell towers to capture your location info. GPS reception still works.
WG Tunnel can get you to your server when you're not on your home network. Some people swear by Tailscale, but you have to trust them with your node info.
Syncthing works for backup for a lot of people.
For private maps I've been using Organic Maps with some success. Searching for places isn't necessarily trivial, but the navigation feature has always worked well for me.
For private comms you really need it to go both ways (you and the recipient). The weak point is likely to be the recipient's environment, but at least something like Signal gives you a chance.
Something like Fastmail works for email and calendar, since they're probably not building a profile on you and selling that to advertisers. DAVx5 is free from F-Droid for calendar sync.
Kagi works really well for search. Also, they probably haven't sold out to advertisers. DuckDuckGo is another option with another set of trade-offs.
For music you can serve FLAC files via minidlnad to VLC. minidlnad was a 3-minute tweak to a config file after I apt-got it. There are tons of options here.
Explore F-Droid for stuff that might do better for privacy, like Spotube, FreeOTP, Podverse, Librara FD, Cheogram, etc. I'm not claiming that the F-Droid apps will all give you perfect privacy, but in general they're probably better than a lot of the stuff that's pushed in the Play store.
Check out e-books and audiobooks from your local library. Or copy them to your device via Syncthing after feeding your e-books through Calibre's DeDRM extension. The idea is to keep from having to context license servers from your phone.
Give up on Apple or Google Pay, credit cards, and loyalty programs if you don't want your eReceipts collected and added to your consumer profile by companies that do that sort of thing.
None of this is a surefire way to give yourself perfect privacy, but it can greatly reduce the amount of your personal information that your government and/or corporations collect on you via your mobile device.
I agree with all of this, but realistically it's not just a simple matter of being willing to live with less features - this is a significant amount of work to investigate, implement, and upkeep for someone who is techy, let alone a less technically-inclined person.
I can barely get my family to use Signal, let alone install F-Droid or learn how to configure Syncthing.
Ultimately, this does indeed come down to "if you use a big product, you're likely being spied on", but this shouldn't be the individual consumer's fault.
I feel that way too. Which is why I feel it's important to push back by at least asking every business whether they accept cash, and always using cash when they do. If they don't accept cash, I always make it a point to mention that they're paying processing fees for that transaction that they could have avoided if they accepted my cash instead. Simply raising the issue in a non-confrontational and casual way keep them thinking about it, which can lead to some of them acting on those thoughts after it happens often enough.
Simply acquiescing without any mention of cash makes one complicit in the pernicious slide toward a surveillance-infused market.
No matter what OS you put on, there's still a proprietary baseband blob with executuon permissions underneath. All of these devices are built compromised.
Also, that said, if you are personally targeted by your government for surveillance, all bets are off. I don't know how to defend against that, but a potential start would be to eliminate all electronic devices from your person and your house and then to set off a powerful EMP every time you walk through your door when coming back home.
It's refreshing that Google, the same company that makes Android, has recently called out baseband blobs for their poor security.
https://googleprojectzero.blogspot.com/2023/03/multiple-inte...
Here's some discussion on the GrapheneOS forum:
https://discuss.grapheneos.org/d/3942-baseband-vulnerabiliti...
While I'm not convinced it's causing widespread exploitation, baseband blobs are definitely a problem, and hopefully some of the advocacy that Google's Android org puts on phone vendors can get us to a better place. And maybe efforts from organizations like Librem can push us toward modems with fully OSS firmware.
Also Pinephone: https://news.ycombinator.com/item?id=36659544
Conduct yourself on your phone the way you would in public in front of friends and family. Only text/browse with stuff you'd be okay with a stranger knowing. I've operated this way for many years for the exact reason that this article highlights.
Stop being wilfully ruled by war criminals and start prosecuting their crimes.
The civil means for wresting back control over our government exists - we have to have the courage to use it. That means, prosecuting our own war criminals.
After all, it is the criminals with the most blood on their hands which want to use the tools of the state to repress the public, from which they derive their actual power, and who are the only ones with the resources to actually do something effect about the criminals getting away with it.
These rights-violating mechanisms exist to protect the criminal ruling elite only.
Seriously, to clean up our government: prosecute our war criminals. The war crimes are real, the crimes against humanity are real, the human rights violations are real. What isn't, is the general publics' stomach for the embarrassment they must experience in order to confront the fact of their own wilful rule by dyed-in-the-wool war criminals.
This discomfort at the fallacy of our own moral authority over nations considered to be 'worse human rights violators' has to be replaced with outrage at the actual human rights violations we are allowing to be committed in our name, or else we continue the slide into the abyss..
Seems like this is what is being implied:
Given:
- users with notifications enabled
- have X app installed
- targeted user(s) reside in USA
- targeted users(s) following “foo” on X app
When:
- issue FISA warrant for all smartphone users that received notifications in regards to “foo” user
Then:
- able to pull all Apple/Google accounts that match this criteria
- able to get real addresses and names
- can crosscheck names with other details to narrow down suspect
Or maybe it’s something even worse where notifications somehow leak location data
[1] https://www.washingtonpost.com/news/morning-mix/wp/2016/08/1...
So a gov finds that IP address 7.8.9.0 received one of these notifications at 12:34. They then see that 7.8.9.0 is one of ATT’s addresses. They go to ATT and learn that address was used by their customer onionisafruit at 12:34 and the device was 5ms away from tower A.
You have captured the device of some group member, and you want to investigate his associates, but you don't know who they are. So you ask Google and Apple: Make a list of all of the devices that have received a push notification sent by <list of messaging apps> where those devices have received at least 200 notifications within 50ms of a notification received by this device. (You will have to make Google or Apple share the list with the target timings with the other)
That will give you a list of everyone who is in a group chat with your target, regardless of whether or not the messages were deleted or encrypted. Now you tell Apple/Google to give all the data on those accounts. You will probably find enough in their Gmail/location history/browsing history to identify nearly all associated people without ever bothering to look at IP addresses.
This also works if you get into a chat with your target. You send some messages and then have Google/Apple identify their device via timing, then identify all their associates.
The location is always the same.
One notable corollary is, the shittier the mobile browser webapp implementation is, the more they want to push people onto their app. See: Facebook, Twitter, Reddit, etc.
Yelp is the gold standard in this regard, blithely pretending that they can't show you any photos (or is it more than a few photos? I avoid yelp on mobile so much I can't recall). It's probably the right move for them, because the photos are 99% of the reason I ever want to use Yelp. Reviews can be outright lies or simply written by people ~~with no taste~~ whose tastes are not simpatico with mine, but photos don't lie*.
* well, nowadays I guess they can
> - targeted users(s) following “foo” on X app
It seems "X app" means just any placeholder app (not the new Twitter rebrand), although I might be wrong.
Who knows? Maybe you want to retroactively look at shit peopke received and decide on new crimes.
https://en.m.wikipedia.org/wiki/Utah_Data_Center
But since PRISM was exposed ~10 years ago, they have had to resort to using FISA court to scrape data
\s
Apps notifications can trigger if you enter a "protest zone" for example then gov will know everyone who was there.
I would like to see this interaction…
The most insidious part: "Because the system actually monitors the regions, you don’t need to request always permissions for your app"
No mobile, no identification, obscure any way to uniquely be identified.
(It isn't technically a mesh, since it doesn't support multi-hop routing. Still, it is peer to peer, and doesn't require a data connection.)
[0]: https://developer.apple.com/documentation/multipeerconnectiv...
I'd love to see something with the characteristics of Find My, but open to arbitrary data transfers. The cell connectivity in my area is poor (due to monopolies not bothering to build out infrastructure, unless you believe there's no demand for network connectivity in the SF Bay Area...), and most places I drive to have guest wifi networks anyway.
I can easily imagine dropping my cell phone plan and only being available for high-latency text messages (and emergency calls to 911) when out and about.
[0] https://android-developers.googleblog.com/2018/09/notifying-...
Additionally, with a little bit of work (well, really quite a lot) the push messages can be made to hide the source. This would make it harder to distinguish a Gmail or DoorDash notification from a WhatsApp notification.
A lot of apps don’t even put much in the push messages themselves at all, they are mainly an indicator to phone home for more information.
Consequently no gov has been getting meaningful info from the content of this stuff for many years - it will all be what you can infer from observed patterns, which is a lot.
Eh, what’s a few orders of magnitude increase in notification infrastructure overhead anyway? /s
If you're trying to hide from that type of attack you need to send a fixed rate stream of messages (most of which are dummy messages, except the occasional message containing genuine content -- like number stations). Furthermore, every point in the chain also needs to avoid revealing which messages are genuine (by fetching the encrypted message from the server when it receives a genuine notification, you're giving data away).
The operator of the app could send messages at fixed intervals to make it more difficult to correlate the messages (more samples required to have confidence in the recipient). If they send dummy notifications they'd probably fall foul of Apple/Google's constraints around invisible-to-the-user notifications (I know Apple prohibits them, I assume Google does as well)
I can't see that frustrating this type of attack would be interesting to Apple/Google: it would push up power & radio bandwidth requirements for everybody pretty significantly.
However, I was actually wrong more generally because Apple does have push notification type for this, Background Updates[1] are permitted to run invisibly. They say not to try sending more than 2-3 per hour, and that "the system may throttle the delivery of background notifications if the total number becomes excessive" - which sounds like you're permitted some unspecified small number between app launches.
These notifications seem to only be able to send a single boolean flag, so it doesn't seem like an awfully viable way of implementing a fixed rate message system (especially because you'd also want to be sending messages out on that same fixed rate to frustrate analysis)
1: https://developer.apple.com/documentation/usernotifications/...
It's all about the timing (and meta-data like which app), not about the contents.
Even just E2EE on the notifications themselves would be an improvement over the current situation. It would make certain categories of data unavailable to eavesdroppers. The fact that it would not protect against 100% of all types of data/metadata exfiltration is not sufficient reason to oppose implementing it.
E.g: if I get a signal notification and the notification has no data except “event happened, call server for updates” - and then you fetch updates as a batch - doesn’t the sheer number of people making that same generic batch update call somewhat mask it?
I’m curious where Apple prohibits dummy notifications, by the way - I used them for a financial app I worked on a few years back and never got dinged for it.
But as others have pointed out, just having the timestamp and target of the notifications already tells a lot.
Consider:
1. A phone call in which Mrs. Smith talks to a receptionist to set an appointment with a doctor for 9:30 next Wednesday.
Vs.
2. Knowing that Mrs. Smith called an abortion clinic.
#2 seems like a bigger violation of privacy. Metadata is the real data.
you'd still have to look up who the doctor they called is from the metadata; it's still info but absolutely not more informative than the real data
so this line of thought makes no sense, and glenn greenwald should be looked at very skeptically in general, he sounds smart but when you look at his logic closer it breaks down
You're assuming these things are mentioned. "Hi, I'd like to book/confirm an appointment with Dr. Jones." doesn't leak information about "abortion".
Yes, these things obviously depend on what information is transmitted. The point, however, is that metadata more reliably transmits sensitive information than does "the data".
yes it does.. just look up who dr jones is; is the metadata going to say "this lady is getting an abortion" ?
1. The conversation may or may not contain information pertaining to an abortion.
2. The metadata (namely: "it's an abortion clinic") inherently contains such information.
The point is that metadata is usually the more interesting data.
no it doesn't, it'll contain a phone number to a clinic, then you'll have to look up what kind of clinic it is
you're telling me the receptionist answering the phone at the clinic won't mention the name of the clinic when someone calls?
and stick to objective points and don't fault me by calling it nitpicking because your argument falls apart when basic critical thinking is applied to it
It can simultaneously be true that metadata contains less information than real data and that metadata is still dangerous. But when one is known for breathless hyperbole, should we be surprised when that’s what we get?
They’re not just a “doozy” they’re downright fascist authoritarian. Even the positive positives are infringements.
Someone pointed out that, while being watched is creepy, the real damning information on people actually comes from being listened to.
[0]: https://www.nybooks.com/online/2014/05/10/we-kill-people-bas...
The most promising starting point is probably at the state level.
But yeah, I'm not going to let threat of death keep me from plowing forward. Embracing death is part of death practice. I'm still going to move forward playfully and through harm reduction.
(Now I expect to get in trouble here because I mentioned a third party, that is fine with me.)
I think you've read the government's self promotional material, and believe it - that it's trying to do the best for its citizens, keep people safe, etc as opposed to seeing it for what it is, which is a mafia exploration racket that keeps it's major beneficiaries out of public view.
> In this case, the federal government prohibited us from sharing any information," the company said in a statement. "Now that this method has become public we are updating our transparency reporting to detail these kinds of requests.
What is the point of transparency reports if they don't include major vectors of government surveillance?
IMO such gag orders shouldn't be legal when applied to dragnet surveillance. If you want to gag a company from notifying an individual they're being surveilled (with a warrant), then fine. But gagging a company from disclosing untargeted or semi-targeted surveillance, especially if it involves American citizens, seems like it should be unconstitutional on free speech grounds.
I wish it didn't cost a lot of money and years of your life to beat these over-reaches.
https://www.aclu.org/documents/constitution-100-mile-border-...
As far as "reasonable suspicion" goes, I'm increasingly unwilling to support the right of law enforcement to independently, without oversight, determine what is "reasonable".
[0] https://www.nationalreview.com/2018/02/border-patrol-warrant...
> [CBP officers] demanded proof of citizenship from the passengers
> CBP officers boarded a bus in Bangor, Maine
None of those are searches, they are temporary detentions with strong legal basis and case law going back to Terry. To wit:
> most people have no idea that they can refuse to be searched at a roadblock or bus boarding
Ignorance of the law != warrantless searches. Arm yourself with knowledge, just as the Founding Fathers intended.
I frankly don't care what's legal or not at this point. The surveillance and police state has gotten out of control, and needs to be rolled back. If we constantly just accept past precedent as dictating our future, our rights will be chipped away one by one.
I don't want to live in a society where I can be stopped and asked for identification by law enforcement at any time. Most Americans don't, that's why we still don't have a proper national ID. I consider that to be a warrantless search regardless of what the law currently says.
> Arm yourself with knowledge, just as the Founding Fathers intended.
I find that most people who pretend to speak for "the Founding Fathers" are extremely ignorant of the actual motivations of these people who lived 200 years ago. I won't pretend to speak for them, but I will note that I strongly suspect that the smugglers and tax evaders who signed the Declaration of Independence would probably not be in favor of the ever-growing police state we have today.
Regardless, what they wanted is immaterial—they set up this country for us, and presumably expected us to lead it after their deaths.
Oh, but you should - your freedom may depend on it.
> police state has gotten out of control, and needs to be rolled back
Maybe, but this is the world we presently find ourselves living in, and we can either choose to become empowered with knowledge about it, or throw a hyperbolic tantrum and wish for the moon.
> I don't want to live in a society where I can be stopped and asked for identification by law enforcement at any time.
You don't, at least not in the US. If you took more time to care about the laws you decry, you would know there is no such requirement, unless you have been suspected of a crime by a lawful sworn agent of the state. Which is a reasonable compromise in a society.
> smugglers and tax evaders who signed the Declaration of Independence ... would probably not be in favor of the ever-growing police state we have today
I agree. Those individuals knew well what an unchecked government can do, and took many reasonable precautions to safeguard against such infringements and tyranny. They were of course imperfect in their implementation, but the principals they set forth (freedom of speech, defense, religion, &c.) formed a radically different society to anywhere else on the planet today. Which is why I'm always puzzled when people disregard their hard work to take some agency's word and propaganda at face value, rather than consulting the original tenets which founded this great country.
They generally ask. If you refuse, you are now suspected of a crime. If you refuse again… well, I hope you like the back of a squad car.
Source: went for a walk in my own neighborhood at 3am.
If you took the time to read the article I sent you, you would know that CBP asserts that it has the right to get onto any bus at any time and demand to see proof of citizenship for anyone on board.
You can wave the book at me all day long, but what actually matters is how the law is implemented in practice, and it's pretty clear that law enforcement does, in fact, claim the right to stop anyone at any time and ask for ID.
> Border Patrol, nevertheless, cannot pull anyone over without “reasonable suspicion” of an immigration violation or crime (reasonable suspicion is more than just a “hunch”). Similarly, Border Patrol cannot search vehicles in the 100-mile zone without a warrant or “probable cause” (a reasonable belief, based on the circumstances, that an immigration violation or crime has likely occurred).
In practice, the evidence gathered by unlawful searches is going to be discarded in a court of law. Other wise said, there is no carving in penal law for "100 miles " from the border.
I don't understand how you reach this conclusion.
> In practice, the evidence gathered by unlawful searches is going to be discarded in a court of law
Yes, of course. What I'm talking about is the threshold for when evidence is considered "unlawful".
The "reasonable suspicion" threshold is intentionally an extremely low bar. Low enough that it's barely a meaningful threshold. In practice, it's incredible easy for any officer to make up some articulable suspicion for pretty much anything.
Maybe. Probably? But this isn't always the critical question.
Sometimes, "You May Beat the Rap, But You Can't Beat The Ride" is the problem.
Poor school kiddos. :( Anyway, if you prefer text, click the transcript. I recommend listening though, if you have time!
I looked it up though. This was 30 years ago. The court issued Border Patrol an injunction and protected students from discimination. A perfect example of the legal system acting justly and prudently, which only supports my argument that unbridled searches within 100 miles of the border is hyperbole only.
Hey we would like to bring suit because the government says we can't talk about them doing X. Oh no, that would be talking about doing X!!
https://aspe.hhs.gov/sites/default/files/documents/e4a791060...
How about the NSA spying on congress?
https://www.theguardian.com/world/2014/jan/04/nsa-spying-ber...
How about the ATF making up laws?
https://nclalegal.org/2019/09/atf-admits-it-lacked-authority...
The only teeth congress has with these bureaucracies is the power of the purse.
Not true. Congress can make laws defining what those agencies are and are not allowed to do.
It's certainly not a perfect system, but it's successfully done all the time.
>Not true. Congress can make laws defining what those agencies are and are not allowed to do.
>And if the agencies go outside the bounds of those laws like some currently do?
>Then those who are victimized take it to court.
Right, the court isn't congress. My point was the only teeth congress has in regards to the bureaucracies is the power of the purse.
>successfully done all the time.
It depends on how you define successfully. I mean they employ people, is that good enough? Do you think they would be more or less effective with a 20% haircut? I don't really know, but members congress probably don't either. Plus, it's bad politics to cut jobs come election time, right? Seems like a perverse incentive for the people charged overseeing the bureaucracies.
Congress can create new criminal/civil remedies and then create an office tasked just with enforcing them.
https://nyc.streetsblog.org/2020/07/17/fridays-headlines-blu...
Perhaps we just go with rock solid transparency laws...
> That rule didn't come from the people who wrote the law.
But lawmakers can write a law to address that.
The fact this rarely happens is more due to people not actually knowing the law and typically wanting to avoid potential conflict.
The term "unelected bureaucrats" applies to people like...I dunno, the director of the NIH and field office managers. Heck, even a police captain is an "unelected bureaucrat". Sheesh.
See also the California senators, which have at this point been unilaterally appointed by Gavin rather than elected by the people. If that wasn’t bad enough, he appointed this latest one based on a personal promise made to put a Black woman in the seat, in exchange for some union to aid in his personal election campaign.
If anyone cared about civics, separation of power, or indeed democracy itself, there’d be rioting in the streets.
As for your alleged lesson in civics, the actual matter is covered by the 17th amendment to the constitution, which states:
> When vacancies happen in the representation of any State in the Senate, the executive authority of such State shall issue writs of election to fill such vacancies: Provided, That the legislature of any State may empower the executive thereof to make temporary appointments until the people fill the vacancies by election as the legislature may direct.
- U.S. Cons. amend. XVII § 2, emphasis mine
So then the question is how has the CA legislature directed the executive thereof to make temporary appointments? The answer to that lies in the California Code:
> If a vacancy occurs in the representation of this state in the Senate of the United States, the Governor may appoint and commission an elector of this state who possesses the qualifications for the office to temporarily fill the vacancy until a person is elected at a statewide general election...
- Cal. Elec. Code § 10720, emphasis mine
So we're left with a very simple question: Was Laphonza Butler an elector of the state of CA at the time she was appointed to fill the vacancy by Gavin? If not, Gavin was operating outside his authority as granted by the CA Legislature, and accordingly in volition of the 17th amendment to the US Constitution.
And the answer to that is very simple, a resounding "No":
> Butler is a longtime California resident but now lives in Maryland. She owns a home in California also. The governor’s office said she would re-register to vote in California soon.
- https://www.sfchronicle.com/politics/article/laphonza-butler..., emphasis mine
The feels.
I think companies publishing whatever they can is a good thing. We would be worse off if they took the attitude of if we can't publish everything we might as well publish nothing.
But this is also a great reminder that there's a bunch of things they can't publish -- so "transparency reports" are of extremely limited value. Their greatest value is encouraging people to have a false sense of security.
How many times did those of us who knew all of this to be a farce warned about this?
I see you have not read the Patriot Act, an Orwellian double-speak of a title if there ever was one.
Is there any data on how often they're surveilling people without warrants vs with warrants?
This seems like important info to know.
But won’t someone think of the children!?
Uniting and Strengthening American by Providing Appropriate Tools Required to Intercept and Obstruct Terrorism.
It really is one of the best double-speak bill titles ever.
If you actually take a second to listen to Matt Gaetz, for example, you might be surprised to learn his (rather principled) positions are much closer to those of AOC than to President Orange, at least in some dimensions. He wants to require single-issue bills, and to completely eliminate FISA-702. Ironically, it seems like FISA will be reauthorized as part of an omnibus spending bill...
Support from members here and there is nice but in reality for the 20 years I’ve been paying attention has resulted in nothing.
That is until a government asks them to do things behind the scenes.
Why isn't there key exchange happening at the time of enrollment? Why is it something apps have to manually do? We moved the web to https everywhere for a reason, why are apps behind the web in privacy?
Potentially stupid question - how is iMessage encrypted end to end if the notifications aren't?
- why not identify them?
Why would it matter if they "do intel business" with the US, EU, UK, etc. ?
/s
I just want the equivalent of debian, but on mobile. I understand I'll have to give up a bunch of apps, but honestly I think its worth it. As soon as its possible I'd like off this ride.
They exist in the frustrating spot of “I want to like them, but I can’t trust the purchase based off of everyone I know who tried getting burned, so now I’ll just look at a Pinephone because it’s easier”.
There are a few alternatives, more can be found but this is a selection of the most prominent offerings.
/e/OS: https://e.foundation/e-os/
GrapheneOS: https://grapheneos.org/
LineageOS: https://lineageos.org/
CalyxOS: https://calyxos.org/
PostmarketOS (based on Alpine Linux rather than Android, and what's used in Pinephones): https://postmarketos.org/ (for some reason the site is currently down)
Of course, your data will still be in the hands of app vendors unless you choose your apps wisely.
You should also block analytics on the network level (using firewall apps or alternative means) because these days developers like to send analytics events for every button pressed, all associated with your phone's unique identifier. If the government can use push notifications for tracking, imagine the tracking they can do through Firebase Analytics or one of its many data hoarding alternatives.
You're suggesting a deviation from the norm (99.99% of users) by installing a custom operating system (which they will now also be on the hook to secure and update regularly) by developers with nothing to lose.
This will greatly increase scrutiny on you, or colloquially speaking definitely put you on a watch list, the opposite of what is allegedly desired. Rather, accept the plain fact electronic communications are subject to government surveillance and adjust your threat model accordingly. Don't try to fight the bear with a flyswatter.
"Custom" ROMs also get OTA updates, so keeping up to date is as easy as it is on a vendor spyware ROM. In fact, you will usually get updates from the community well beyond when vendors stop support.
https://www.linuxjournal.com/content/nsa-linux-journal-extre...
But they totally can't figure out you use a custom OS built to resist surveillance. Go figure!
Which still leaves you in a large enough group that it's not practical to deploy full-press individualized surveillance against all of them. A group which contains a fairly large number of people who're doing it just to piss off the spies, and an even larger number of people who happen to be of no interest to you as a particular spy deciding where to apply your resources.
As for mass surveillance of that group, that can happen, but there still aren't such good, cheap choke points to use. The cost per bit of actionable information is still relatively high even if the group is relatively rich in targets.
> by installing a custom operating system (which they will now also be on the hook to secure and update regularly)
... as opposed to the stock operating system, which may very well not get updated at all.
I get constant updates for GrapheneOS. And they're automatic.
> by developers with nothing to lose.
What the hell does that mean? They have reputations on the line, much more so than the faceless people doing the OS work inside the vendors. Some of them depend on this for their livelihoods.
Assuming no advances in technology obscured from public view, of course.
> Some of them depend on this for their livelihoods.
You sort of answered your own question there. Consider whether foreign nationals writing software in near destitute are susceptible to MICE, in relation to Bay Area millionaires.
Every last one of us is being constantly surveilled by the government. If there is any kind of "list" individuals can get on at this point, it's reserved for a very small number of people who are ignored or whose data is excluded.
Governments view legibility of their constituencies as a feature, not a bug. They want to be able to query the population like a database in order to manage it better. This is exactly like a product manager at a tech company who wants to know whether a certain feature is being used, and asks for more instrumentation in the next release of the product if needed. Over time the product (the population) becomes better and better instrumented.
Of course, the other side of the coin of better legibility is worse privacy. Their feature is your bug.
Are there ways to circumvent or mitigate what's happening? For you, personally, sure. You can turn on all the buried options, add VPNs, proxies, additional profiles/accounts, etc. And for a while it will work.
But you're defeating legibility by doing that, so you're fighting against a very strong opposing force. Over time, the bugs that reduce legibility coverage will be fixed. The options will go away, VPNs will be banned or at least instrumented well enough to nullify their utility, COPPA and porn age-verification laws will extend to make multiple or anonymous identities impractical, and so on. And the few of us who do manage to go online fully anonymously might as well be wearing a "CRIMINAL" hat, because the public will have been trained that only bad actors want privacy, but not to worry if they themselves have nothing to hide.
You can see this already happening with financial transactions. Try to conduct a significant low-legibility transaction (in other words, buy something big with cash). Your bank will ask why you want to withdraw $20,000. Cops might seize the cash, legally and without probable cause, while you're driving to the seller. And when the seller deposits the cash, the bank might file a SAR. This is all working as designed. You're being punished for adding friction to legibility.
Even on HN, where you think people would be ahead of the curve, the PR campaign against financial privacy and censorship resistance is winning. Mention The Digital Currency That Shall Not Be Named, and suddenly the Four Horsemen of the Infocalypse are in control. Why HNers are pro-VPN but anti-Bitcoin, when both stand for privacy and censorship resistance at the price of reduced legibility, is beyond me.
The battle to fight is not just protecting your own privacy. It's protecting your right to protect your privacy without being ipso facto declared a criminal for doing so. Turn on all the options, hold Bitcoin, use VPNs, pay with cash, delete cookies, etc. But above all, be an ordinary, conscientious, law-abiding citizen. Render unto Caesar what is Caesar's. Be average. Be unremarkable. Privacy should be the default. Not unsavory, not for those with something to hide. Just the default.
> Why HNers are pro-VPN but anti-Bitcoin, when both stand for privacy and censorship resistance at the price of reduced legibility, is beyond me.
neither vpn nor btc are "for privacy and censorship resistance". Maybe in some dystopian neoliberal every-man-is-an-island way. I think you were thinking about "overlay networks (tor et al) and communal economies" maybe? Those would fit with the rest of the claims.
but again, you are correct on the concepts. I would only add that corporations and gov are not that separate as you think. They have that power because they must have that power. capital will flow. rentiers will get paid. and those rentiers either have connections or they are the inteligence agencies. Do you think cesar could just fire the praetorian guard?
These platforms are so opaque and completely controlled by US corporations (so we know they are beholden to NSLs etc). If you care about your data and privacy, the best suggestion is to avoid phone platforms completely for anything important.
Btw, here's the telegram team complaining about the change: https://github.com/Telegram-FOSS-Team/Telegram-FOSS/blob/mas...
Facebook abused this a bunch. https://www.theguardian.com/technology/2016/feb/01/uninstall...
And you can simply offer more battery controls, rather than general not overridable rules
It's more problematic that some Android "skins" tend to kill background applications at random https://dontkillmyapp.com/, but at least, one cannot squarely blame Google for that one...
The "battery life" argument that that they constantly use is also a very poor excuse. Even when Conversations (the Jabber client) didn't use push notifications at all and would just listen on noisy XMPP sockets, it still had about the lowesst power consumption of all Android messaging programs, lower than Google's own push notifications client app (play services).
Certainly I might imagine that if all 1,000 adware apps your average Android user installs all needed to be wired and listening to a socket in order to receive the latest offers (all in the legitimate interest of the user, of course) you might literally run out of memory. But even then there are many solutions (such as inetd like services) that do not require centralizing everything into Google.
...I'm not even clear on what they're complaining about (the page github links to seems to have been changed, it describes the current state rather than what happened in 8), because this was actually a thing as far back as Android 2: you had to have one of those notifications up to prevent Android from killing your service.
Additionally, Alarms and Broadcast Listeners were seriously crippled which made common workarounds much harder.
Not to mention that people might prefer to use some more battery in exchange for more privacy
It’s possible that a better interface could be developed but it wouldn’t help privacy unless the implementers were in different legal jurisdictions: the same government which can subpoena or NSL Apple or Google could’ve asked e.g. Urban Airship for the same details. There’s also a challenge in that each implementation is a chance to make mistakes or fail to deliver promised privacy protections, and someone in a country which isn’t the United States might have stronger privacy laws but is also a legitimate NSA target. This kind of problem just doesn’t have simple solutions.
Before the platform notifications every single app kept their own connections open; allowing (completely) third part notification platforms would have a small or non-existent impact
I’m not sure this is true: a small company is less likely to have the legal resources or confidence to stand up for their customers’ rights. I’m sure you could find examples going either way at either size.
Being in a different country helps but only if the company has sufficient security to even notice if the NSA decides to take advantage of them being outside of the US. I would bet Apple and Google have that level of expertise but not everyone else.
https://github.com/Telegram-FOSS-Team/Telegram-FOSS/blob/mas...
I doubt it solves much but I like to think of it as a little poke in the eye.
I'm not sure if it only covers (for example) the unified notification service on Android or whether Apple and Google know of notifications that don't make use of that API. It's not clear from the article.
Apple open complies with all data requests from government agencies and law enforcement. It is not a hard process for law enforcement to get someone’s iCloud data with a warrant.
https://www.apple.com/privacy/government-information-request...
If you have deeper access to the OS, then fingerprint unlock or FaceID also seem important for positive identification prior to, for example, a Predator strike.
- Michael Hayden
https://en.wikipedia.org/wiki/SMS#Silent_SMS
Plus, you can always ask the carriers to which tower(s) a phone is connected and simply triangulate from there, without sending any (user) data to the phone.
"Phone call for XYZ", "SMS for XYZ", "Establish TCP connection to XYZ". Every single device that hears this has to decode the message to the point that it can say "Nope, this isn't for me. Ignore". You've got billions of devices online at once, doing things that require messages to be sent to them. The network has to find a way to broadcast these messages to the tiniest geographic area that it possibly can, or else the whole thing breaks down. So yes, there are plenty of completely normal, standard ways that the network can make your phone say "I'm over here" without anything showing up on your screen.
(I worked at Motorola in infrastructure tech for many years)
Amusingly and sadly, the law was called PATRIOT as a normal "give a bad law a Good name", but over time "patriot" has become synonym for "traitor" in common use.
Reminds me of the Eufy issue where they said everything was encrypted except for push notification images.
Hard to pick the most appropriate Orwellian quote. "All tyrannies rule through fraud and force, but once the fraud is exposed they must rely exclusively on force." ~ George Orwell
If we held a poll, what percentage of privacy-loving HN parents don’t have tracking on their kids phone? 5%? 10%?
You get the illusion of choice but you get the same government spying on you in either case.
With Apple/Google you get the comfortable padded jail cell with 24/7 guards to protect - and monitor you; the digital equivalent of having a police officer live with you. You can't go outside of the walled garden and you're told this is for good reason.
Without them, you're totally on your own; you better be prepared and know how to defend yourself. No one will care about your security and privacy. But don't for a second think you're not still under the all-seeing eye of panopticon surveillance, and possibly additional scrutiny therein.
Anyway, these "trees" were effectively user behavior across all our products. I was shocked that simply knowing *when* (to within a second or two) a person did two or more things, you could narrow it down to *one single person* out of hundreds of millions.
Assuming Signal sends push notifications of some sort, as most messaging services do, that would make them vulnerable to the metadata-level attacks described in this thread.
What kind of "out-of-band" are you thinking of that would mitigate this issue?
I dunno how it would work, maybe something like a third-party push? Why does everything have to be channeled through central service? A service like Signal could operate its own push channel.
On iOS in particular background modes are finicky and you cannot generally have an continuously poll notifications in the background. Further, if every app did this battery drain would be significant.
I.e, the push notification itself contains little to nothing in terms of data/metadata.
You can also of course decrypt a notification by shipping an extension to do so, and maybe Signal does - it’s been awhile since I poked around it. I’d just be surprised if the Signal team didn’t analyze the issue to death and find the gaps.
If the question to Apple or Google is "who received a notification from Signal at 17:15 UTC?" then even if the notification is “hey, something happened, call the service and check for updates”, you've got your answer.
i.e. the app sends its push token to its back end, together with a "use by" date. The server sends a push by that time, even if there is nothing to send. In the case of receiving such a "nothing happened" push, the app gets a new token, and informs the back end server.
The constraint there is how frequently Apple / Google will allow pushes, and how well the respective central server can scale to sending all of those dummy notifications.
The cost for the mobile being extra data use, and extra battery from the forced wake ups. So it may have to be a configurable option in the app.
So do Apple / Google allow at least one notification per hour?
e.g: If the question to Apple or Google is "who received a notification from Signal at 17:15 UTC?", then that could very well be a million people.
https://blog.davidlibeau.fr/push-notifications-are-a-privacy...
Thus, we wind up in the following situation: the US govt could ask Apple for a list of people who got notifications at X/y/z time to try and tie it to someone who sent at those times, but Signal is so large and widely used that it'd be finding a needle in a haystack (and that's probably putting it lightly).
The news from this article is concerning, no doubt... but I'm not particularly worried about Signal is all.
Here's a Signal dev talking about it on the Signal-Android GitHub: https://github.com/signalapp/Signal-Android/issues/12961#iss...
And similarly for Signal-iOS: https://github.com/signalapp/Signal-iOS/issues/962#issuecomm...
You can slow this down by making data explicitly built to be impossible to read in transit (eg e2e) and then deleting or never saving it, but the fact that data flows through multiple stops means each transition is an opportunity for third party observation
This is deterministic and is built into the structure of data production transport and consumption. This is part of the infrastructure and cannot be extricated
[1] SoK: Metadata-Protecting Communication Systems, Sajin Sasy and Ian Goldberg, Cryptology ePrint Archive, Paper 2023/313, https://eprint.iacr.org/2023/313.pdf
1. The app registers a push token with their backend. This can happen without granting notification permissions, and without notifying the user. So the backend is free to start sending push messages immediately after registration, which is typically done on the first app launch.
2. The controls available in Android's per-app notification settings have nothing to do with push messaging. These allow the user to limit or change how the app displays notifications, regardless of the reason the app is displaying them. Some apps have additional options to disable push messages, but that preference must be communicated to the app's backend to prevent the backend from sending pushes in the first place. Some apps may consider Android's notification settings to determine this preference, but it's extra work to do so.
The concepts of "push messaging" and "notifications" are often used interchangeably, but at least on Android these are separate systems that are tied together with client code. The push messages may also contain notification data, and the official FCM client will display these automatically, so this confusion is understandable.
Its a band-aid, but its something.
Obviously there will be people who choose to be mostly evil regardless of what everyone else is doing, but society trying not to be evil in general is still the best case scenario.
Our laws were not designed for a society with perfect surveillance.
What examples are you proposing? If you count speeding, sure I guess.
These are the ones I can brainstorm in 30 seconds.
If the government could enforce every law on the books with perfect accuracy and with 100% effectiveness, it would be intolerably oppressive.
Laws are written often with the expectation that enforcement will not be perfect, that between impracticality and officer discretion, that such laws will be a net positive without being silly.
We are coming up on a time of government surveillance and data analysis technology (AI) that we will not be able to escape the panopticon. Laws or enforcement will have to adapt.
[1] https://history.stackexchange.com/questions/23785/what-did-r...
You have to randomly leave your phone at home for criminal and non-criminal things. That way, there's a plausible alibi that your phone was at home or on you at the time of the crime.
These things are troubling now. In the post AGI world these are much more difficult problems because the data becomes training for purposes far beyond anything that could be foreseen in the data collection questions.
When the government asks citizens for information it's usually for a specific purpose and can only be used for that purpose. When so-called "tech" companies collect information, it is for any purpose. They might assure users that "the information is only used to improve the software or service". What limits does this create, if any. How dow we verify that the company is not using our information in ways that compromise our interests if we are not allowed to learn how the company is using the information. Imagine if the government assured people that the information it collects "will only be used to improve the government".
Not every computer is a national security threat or even a common criminal, i.e., a person that the government has some need to spy on. That's not who I am referring to in this comment. These so-called "tech" companies spy on everyone. And they don't just want to know about one thing, for one purpose, they want to know everything for any purpose.
Eg. Parallel construction, FISA, etc etc.
But also, you're whispering right in that if Google and Apple are able to do this, then is that "laundered" spying, I'm that various law enforcement and government agencies can buy this information?
> "In this case, the federal government prohibited us from sharing any information," the company said in a statement. "Now that this method has become public we are updating our transparency reporting to detail these kinds of requests."
If Apple knew about this why wouldn't they limit their exposure to this user data?
> No, Joust does not sell any user data.
extraordinary claims require extraordinary evidence
For example; Cloud storage? Streaming music? Online note-taking?
Should the more technically-inclined, but average, person start looking at taking more and more of these things off-line given the state of mass surveillance going on and the crazy push towards all things AI?
Outside of that kind of thing, we're probably yelling everything out loud to anyone who wants to listen.
But is there some sort of sensitive info that these governments are trying to glean? Or is it more so they can build info maps and communication maps on targets?
Depending on specifics, it seems it would be possible to do this cleverly, so the app still thinks it's connected, but just never receives these messages.
I'm not an expert on this, it just seems a plausible possibility. Best effort response to your question! :)
It's conceivable that connectivity checks flow to other servers than delivery traffic, and these are passed-through. Although addressing your more general critique of the "flurry" (good word! :)), requires noting that accomplishing this capability would involve compromising the app's servers. Such backdoors are again not outside the realm of possibility in the given threat model.
Do you see any possibilities for interference in the push interception capability described?
Apple needs to know your Apple ID to send you an APNS payload. Now your anonymous chat profile is tied to your real Apple ID. Busted.
E.g: if I get a push notification that is simply “you have a new event, poll the server”, and then I poll the server for (encrypted) batch updates, where exactly do you see the leak that ties an anonymous profile to an Apple ID? Given a large enough service, that same generic batch update endpoint would be getting hammered and I have to think it would effectively be camouflaged to a degree.
Granted, not every app is going to use this design - but if or when done properly I don’t see that much of an issue here.
(I am open to being wrong, mind you)
If the government has access to telco resources (I think it's safe to assume that they can and do), then they can line up the timing of a chat message with the push notifications it triggers.
If we are chatting and the government doesn't know who I am, it will only be a matter of time before the number and timing of the push notifications I receive line up in a unique way to the messages you sent me. That would work for every member of the group.
Apple could bundle up multiple push notifications to obfuscate it a bit, but it would hurt real-time communications and wouldn't be that strong of a mitigation anyway.
Oh look! The US end-running constitutional protections again via 5+Eye proxy governments. Who could ever have guessed.
[0] still bad though and they should stop.
They know you rang a phone sex line at 2:24 am and spoke for 18 minutes. But they don't know what you talked about.
They know you called the suicide prevention hotline from the Golden Gate Bridge. But the topic of the call remains a secret.
They know you got an email from an HIV testing service, then called your doctor, then visited an HIV support group website in the same hour. But they don't know what was in the email or what you talked about on the phone.
They know you received an email from a digital rights activist group with the subject line “Let’s Tell Congress: Stop SESTA/FOSTA” and then called your elected representative immediately after. But the content of those communications remains safe from government intrusion.
They know you called a gynecologist, spoke for a half hour, and then called the local abortion clinic’s number later that day."They know you got a push from McDonalds at 11am"
"They know you got a Slack message at 2pm"
All metadata is not created equal.
You're using the internet afterall which isn't your network- it's someone else's! When you send a packet there is a header w/ information required for routing. Some call this the "outside of the envelope" if using the mail analogy. We can pass the buck by using a VPN but this also adds a VPN org that we need to trust. On the other hand, it's not your network! Why do you think you have a right to absolute secrecy and anonymity on someone else's network?
What's funded by tracking as much as possible is the current perverse part of internet, it definitely wasn't always like that and doesn't need to be.
I hope that that perspective comes from someone that hasn't lived anything before Facebook.
Being aware of the tracking and risks means people can make efforts to reduce the tracking, but it's almost becoming impossible to use the internet if you don't AGREE to the tracking in many cases, such as websites that won't risk GDPR violations and chooses to deny access to people blocking cookies entirely.
People who remember the old internet want it back, people who grew up with social media don't know what they're missing, and there's not much we can do to convince people to care about changing the DNA of the internet so that it's no longer perversely gobbling up all data.
In the US, the courts just decided there's no right to privacy (despite what the 4th amendment says) as part of rolling back Roe v. Wade.
So, the path forward is to vote in legislators that respect basic human rights, followed by court packing (or just impeaching the judges that have been publicly accepting bribes and failing to recuse themselves on cases where they have a clear conflict of interest).
Since the above is supported by way more than 50% of the US population, the main obstacles are gerrymandering and ending the currently common practice of appointing blatently corrupt judges to state supreme courts (and also restoring recently stripped powers to state governors, since they're elected via simple majority).
People are generally keeping themselves monitored as they use the internet. It's a panopticon with more steps. So it's no surprise governments are using the plaintext of anything they can find to track people.
And if people don't care about that because they are more focused on their pet political issue, it will never change, and silently get worse.
Apple Confirms Governments Using Push Notifications to Surveil Users (macrumors.com)
At the core most technologies have been deeply rooted by intelligence agencies.
And why aren't push notifications E2EE?
Looking at my own phone right now, it just got a push notification that my wife has arrived at home. That could be useful if you wanted to track my wife.
> And why aren't push notifications E2EE?
That's a great question. And I hope the answer is "we're on it, they will be E2EE in the next release."
1. Generate a local key pair per app (never uploaded to Apple). 2. Each app can request their public key from iOS (or provided with (void) application:(UIApplication )application didRegisterForRemoteNotificationsWithDeviceToken:(NSData )deviceToken andPublickKey: (NSData *)publicKey;). 3. App uploads token + public key to their own server. 4. Server encrypts notification payload with the public key before sending to APNS. 5. Apple forwards encrypted payload to device. 6. Device uses the bundle name to look up the local private key and uses it to decrypt the payload.
It is a Weird Nerd Thing to believe that old laws can't apply to new computer thing.
It feels so liberating to be spied upon by "democracies allied to the United States." vs. others.
LOL.
Corporations showing me better-targeted ads is the least of my troubles.
If you have any contemporary examples of the way the government has used the same information, in a way that’s been more widely destructive, I would be curious to know more.
Yep. Treating the two as distinct makes no sense. Corporate dragnet surveillance collecting forever-datasets isn't meaningfully different from the government doing the same thing, directly. People who fear government power ought to support outlawing corporate collection of the same types of things they don't want government collecting.
Granted that's relying on the government to prevent corporations from doing things in order to limit... the government (and, incidentally and IMO beneficially, also the corporations themselves). However, that's the only effective mechanism we've got—and the basis of all the other mechanisms we have available, ultimately, short of violence and strikes and such—and I think it's implausible that, even assuming a great deal of bad-faith behavior, such a move wouldn't significantly curb this activity.
Right now they just write fat checks to Google, Apple, Amazon and the telcos and badda bing, badda boom it's done.
Do we not agree that corporate America and other special interest groups essentially control Washington via lobbying and corruption?
Do we not agree that a US citizen has (nominally) more leverage over their government than over an unaccountable private collective?
I mean, we are half a century deep into this Reaganite "your government is your enemy" experiment.
For the record I agree with the grandparent post's question: at least, gov is _supposed_ to be controlled by the citizenry through elections, corporations are not. I can have ("should have") visibility into what the government is doing, corporations can hide (and do hide) as much real information as they can and there's no way for me to get to it.
Whether it's naive of me to think so or not is not what is being discussed here.
I’ll take power being consolidated in a democratically elected government over a privately controlled corporation any day of the week.
Let’s put the spotlight on the stuff that isn’t democratically controlled, and subject to much more limited oversight.
I think it would be wrong to ignore either. Especially since most of the data the government gets is from corporations.
> Corporations showing me better-targeted ads is the least of my troubles.
You're right about that. That data sure isn't only used for ads. Companies use it to decide what services you're allowed to get and under what terms. The policies a company tells you they have are different from the polices they tell others they have. Companies use it to set prices so that what you pay can be different from what your neighbor does for the same goods/services. Companies even use that data to determine how long to keep you on hold when you call them.
Employers use it to make hiring decisions. Landlords use it to decide who to rent to. It's sold to universities who use it to decide which students to accept or reject. It's sold to scammers who use it to select their victims. Extremists use it to target and harass their enemies. Lawyers use it in courtrooms as evidence in criminal cases and custody battles. Insurance companies use it to raise rates and deny claims.
The data companies are collecting about will cost you again and again in more and more aspects of your life. Ads are absolutely the least of your troubles.
"declining to hire, insure, or loan to you" and "declining to admit your kids into school|sports program|internship"
So, whether the world has changed enough to justify it, people still do care and when adequately informed about some magistrate furiously eavesdropping on private matters, people universally recognize this is antisocial bizarre conduct.
[1] https://theintercept.com/2019/10/10/fbi-nsa-mass-surveillanc...
People absolutely care about their privacy. If you don't believe me try going outside and following someone in public with a video camera. They'll scream at you about how horrible and illegal what you're doing is. They'll probably call the police on you. Upset as they are, they ignore the fact that they've been being filmed from the moment they stepped outside and have in fact been being extensively tracked and recorded even while they were still inside their homes.
People don't understand the extent that their privacy is being violated. It's mostly out of sight/out of mind. They also don't understand the impact the data they give up has on their daily lives. They aren't allowed to know when or how much that data costs them. The moment they are confronted with the reality of the situation, they suddenly care very much about their privacy. Mostly they feel powerless against the invasion of their privacy.
I don't agree with everything he said but the information was well presented and enjoyable.
E2EE for chats (Matrix, Signal, or XMPP) is pretty solid I think. More shaky, Tor/reputable VPNs or some combo for browsing. FOSS ROMs for phones (Graphene), or Librum/PinePhone if you can deal with not always having a working phone.
It's not a great situation, but it's not hopeless!
But what the 14th amendment says is that people and their property are protected against searches by the government wherever there is a “reasonable expectation of privacy.” That and some combination of other details imply a right to privacy, but its mot very explicit and clearly limited. In light of this, the Supreme Court has actually ruled quite favorably In practice, the Supreme Court has actually ruled pretty favorably towards a right to privacy, considering whats actually in the constitution.
> X. The powers not delegated to the United States by the Constitution, nor prohibited by it to the States, are reserved to the States respectively, or to the people.
Operating a surveillance apparatus isn't an enumerated power of the federal government. The courts screwed up by reading its enumerated powers so unreasonably broadly that this even came up.
The GOP is trying to create an apartheid state where minority rural areas dictate the laws for the majorities that live in urban areas while they extract resources from those areas.
They know this is incredibly unpopular, so they don't even pretend they're trying to get the majority of the vote in most places. Instead, they've been trying to set vote thresholds to > 60% for ballot measures and stripping authority from all elected offices that aren't subject to gerrymandering.
In May 2017, Wyden co-sponsored the Israel Anti-Boycott Act, Senate Bill 720, which made it a federal crime, punishable by a maximum sentence of 20 years imprisonment,[88] for Americans to encourage or participate in boycotts against Israel and Israeli settlements in the occupied Palestinian territories if protesting actions by the Israeli government. The bill would make it legal for U.S. states to refuse to do business with contractors that engage in boycotts against Israel.[89] https://en.wikipedia.org/wiki/Ron_Wyden#Israel
It's similar to what economists say about not pulling all your eggs in the same basket.
I must add that "good politics" are all about compromise.
In my somewhat grim perspective the best outcome of good politics means none of the constitutents are happy and none are desperately angry.
politics are all about the completely bland and boring averaging
but I come from a land of historically terrible, awful politicians and leaders
These would seem to contravene the First Amendment.
... you won't be left with many allies.
Foreign governments can’t force government contractors to comply with boycotts. This bill AFAIK simply closes the loophole of Palestine not technically being a foreign government.
Congress has been in a state of deadlock for too long to pass any actual laws, so this type of performative theater ahead of midterm elections is what passes for statesmanship.
I think it's a bad law and he's making a big mistake. I'm still a fan though.
> The act does not apply to contracts worth less than $1,000, or to companies that offer to provide the goods or services for at least 20 percent less than the lowest price quoted by a business that has complied with the certification requirement.
So, a contractor if free to boycott as long as they cost the taxpayer a little bit less.
... Also, as sibling commenters pointed out, anti-BDS gag laws are everywhere in this country, and have yet to be struck down.
their letter: https://content.govdelivery.com/attachments/IACIO/2023/12/04...
Yet it is the US government who revealed it: "In a letter to the Department of Justice, Senator Ron Wyden said foreign officials were demanding the data from Alphabet's (GOOGL.O) Google and Apple (AAPL.O). Although details were sparse, the letter lays out yet another path by which governments can track smartphones." - https://www.reuters.com/technology/cybersecurity/governments...
Less "the government" and more "a member of government", the same member who has revealed and demanded accountability when discovering domestic government overreach.
We should choose our congress critters carefully.
[1] https://en.wikipedia.org/wiki/James_Clapper#Testimony_to_Con...
Repeatedly Congress has shown that it's checks and balances have more power than others. If Congress picks the supreme court and there are multiple ways for a massed power to keep it's power then nobody else has any real power. The US system is actually rather poorly designed in that form.
Agreed 100% and sadly, quite rare. I'm not going to start naming names, because that would devolve this into a political conversation about the parties. That isn't this. I suspect most people know who the criminals are. Now to see if they care.
The problem with corruption is scale, when you have too large of an institution, it's easier to hide intent. I don't see how you can police that by voting when so much of what goes on is not easily seen.
For every persons that gets voted in to do the right thing, there are 4 others who are doing the wrong thing.
*And/or other Five Eyes members.
Nothing has materially changed since then, technically, politically, legally, or even culturally. Yet people still believe for-profit corporations have their best interests in mind, thanks to clever marketing and groupthink, clutching to "encrypted apps" and empty "we value your privacy" double-speak: neither will defend you.
There is no privacy on proprietary closed source platforms - it is simply infeasible; it is trying to squeeze blood from a stone. I know this truth will likely trigger and upset people with their $1,000+ iPhones, MacBooks and other iToys, and this sunk cost fallacy is really pathetic to witness in grown adults.
My first thought is that this is looking like an especially fun (for the rest of us) popcorn session where someone in one government is shocked to discover that other governments pull the same stunts that they think should be reserved for "our people"… but then I looked up Senator Ron Wyden's Wikipedia page and he seems to be genuinely opposed to such shenanigans from everyone including the US.
So, good for him.