A warrant showing the U.S. government is monitoring push notifications
404media.co
404media.co
Maybe it’s time to actually enforce this and remove the ability for arbitrary content to be sent?
Of course, depending on the app, it coupd be possible to correlate even E2E-encryped push notifications with other data on that app's backend server etc. But beyond specific apps is there a generic vulnerability here?
The payload of Signal's push notifications should have roughly the same length every time as they are only used to wake up the app. The time I receive a push notification doesn't depend on me, but on when my contacts send messages. (Yes, you could use this to narrow down someone's time zone but not much more than that. Plus there are a million other ways to determine the time zone.)
I now have enough information to either blackmail you further or end your career.
But they wouldn't need to analyze push notifications for that, they could simply ask Google/Apple who installed a given app.
Time of day that you're awake/active, the frequency of message push notifications vs your travel patterns when you might be expected to be offline, weekday vs weekend message traffic volumes per day, traffic volumes on holidays, all these sorts of things are valuable metadata for an NSA-like organization.
But the push notifications I receive through Signal don't tell you any of those things?
Threema doesn't send the message in the notification either, per the link.
Disabling push notifications would help, especially if you disable notifications through individually app settings first. That should make sure an app doesn't continue trying to send notifications entirely, if you just disable notifications globally Apple or Google may still see notifications that they just don't route to your device.
If you really want better protection, use GrapheneOS or a similar de-Googled android device and don't install any Google services. That's the best way to still have a modern smartphone with limited risk that Apple or Google is somehow tracking most use.
Personally I see Graphene as a lesser of two evils compared to the guaranteed spying of Apple and Google for anyone that can't avoid having a smartphone all together.
If the application in question has the ability to disable notifications inside the application itself, that should work.
Practically, this means you use your cell phone for phone calls (the metadata is public, and I assume anyone who wants to listen in can already do so), and for SMS/MMS messages (see above, except I don't think the contents are quite as protected as voice).
You disable location services, you don't install anything of any interest on your "daily carry" phone, and you regularly shut it down for periods of time to build the expectation that your device is regularly offline. Let it run out of battery. Cultivate the "senile old senior" approach to using your phone. Leave it behind.
And then carry a small laptop, preferably running Qubes, for "everything else," and either use Tor or your own VPN infrastructure (ideally shared with friends) for access.
... and start cultivating ways of life that are offline first, that don't rely on consumer electronics (or the upstream companies) to behave as anything other than the data-grubbing, data-selling sorts they've reliably proven to be.
Yeah. It sucks. The past 20 years of consumer electronics turn out to have been rotten on the vine, actively working against your own interests, comically insecure (so even if they're not just streaming your data off to whoever pays/demands, it's not hard to extract), etc.
I don't have any better answers. I've been trying for about the last 5 years to figure out a solution, and I just can't come up with anything reasonable that still involves using consumer electronics for much more than toy uses. Apple looked better for a while, but then lost their head with the on-device CSAM scanning stuff and, while I like it, Lockdown is a simple admission that they cannot build secure software against nation-state level adversaries. Plus, most of their updates are "Oh, yeah, so, update this now, we have reason to believe [solid proof and won't say it, usually...] that this fixes things under active exploit." But, hey, we've got MeMojis and such now!
We have built too much complexity into our systems (see all the uarch vulns that are fundamentally a result of chasing performance over everything) to understand, to reason about, and we can't fix the problems of complexity with yet more complexity (as the last 5 years of papers demonstrate, often to comedic effect, about how the uarch vuln mitigations open up this other channel). And the software isn't any better.
I don't see the path forward other than simply opting out, and building systems that no longer rely on vulnerable pocket computers that leak literally everything you're doing to whoever might care.
I have it on my personal server, configuration is easy and the app is available on degoogled phones and works perfectly.
Just look at the doc on Github, most professional software don't have such a well done doc.
I also love ntfy for its general handiness.
That said, MollySocket is a pretty neat hack that I had never heard of until now. I'll keep it in mind for a future use.
So now they go the official way. They already know exactly where to look and what to look for and what to ask for.
Illegally obtained evidence can't be used, so they must build the story using only legal means, which can be difficult and take longer or not possible at all sometimes.
That rule been so undermined in so many respects that is has little effect.
When the government illegally spies on the public it goes in knowing that it has to cover for its actions.
The evidence rules tend to only catch genuine errors where they failed to do the required parallel construction or set things up for the inevitable discovery doctrine because the unlawful search was inadvertent rather than intentional.
In the US, a particular form is evidence laundering, where one police officer obtains evidence via means that are in violation of the Fourth Amendment's protection against unreasonable searches and seizures, and then passes it on to another officer, who builds on it and gets it accepted by the court under the good-faith exception as applied to the second officer. This practice gained support after the Supreme Court's 2009 Herring v. United States decision.
See also the sibling about Fruit of the Poisonous Tree, the principle of law that Parallel Construction has rendered moot.
reminds me of algebra equation solving encountering square root of -1, then naming it an introduced variable “i”, rather than being stuck, and moving on, in hopes “i” vanishes later in the set of equations being solved or simplified.
Has this happened - probably. Does it happen a lot - probably not. But none of that matters - the uncertainty is enough to build a whole online community that believes hard.
https://en.wikipedia.org/wiki/Parallel_construction
AGAB
All Governements Are Bastards
It's possible to E2EE push notifications, but you need custom application logic.
Send the push without content, or with just an identifier, and then have the app go get that message from the database and show it.
A lot of apps clearly do notifications separately from content though: you'll get a notification, but when you tap on it, the content has to load.
The problem comes with sifting through the data, but now that you have tireless AI doing that work for tired humans, who's to say what they actually don't see.
Years back I was touring a local datacenter that was more than a bit quirky, but their offer was basically that they had fiber loops into the main carrier hotel a few blocks away. This was useful because the guy than ran the carrier hotel wouldn't even return your email unless you were from BigCo.
But anyhow, walking around he pointed out one cage and said something like "And that's the NSA's cage, we don't ask what they do haw haw." At the time I mostly thought he was just exaggerating or joking around. But later after revelations of the scale of bulk collection I had to wonder if it really was true and simply banally that much in the open.
The ECHELON report revelations were packaged into a formal (boring) European Parliament report. Meanwhile Edward Snowden had the counter-cultural packaging of a cool dissident hacker.
Snowden did his leak way later in 2013.
VPN providers that are run by reputable people/orgs and make security promises are liable to lawsuits and criminal prosecution if they sniff your traffic or sell info about you, unlike ISPs complying with gov requests/partnerships and who want another revenue stream by selling your info to the highest bidder with no specific privacy guarantees.
Stasi was limited by that the whole of DDR can't work at Stasi.
Instead of the government joining in on the fun, maybe it would be good to e.g. close down Google (split up the spy and search parts, which essentially is closing down Google since they have relatively nothing without the spying).
Tangentially, J. Edgar Hoover was politically opposed to feminism, and COINTELPRO had a massive secret police action against feminists and feminist groups in the 1970s. Some of us want these issues hashed out at the ballot box, not by some giant secret political police force.
SMH
Study history.
The US Gov kept a record of all the metadata of every letter sent through the USPS?
> Since 2001, the Postal Service has been effectively conducting mail covers on all American postal mail as part of the Mail Isolation Control and Tracking program.[1]
https://en.m.wikipedia.org/wiki/Mail_Isolation_Control_and_T...
It's surprising because the government doesn't exactly talk about it a lot. Thus, most people who don't follow security issues don't hear about it very often. It's not like the government advertises these activities with billboards and TV spots. The reason they don't is because this broad interpretation of their responsibilities makes them look pretty bad without having a long discussion with a lot of context. As it is, people might just ask them to stop reading their emails. So, if the people doing it don't talk about it, why would you be surprised that other people don't know it's happening? It sounds like you're saying "I'm surprised that not everybody pays careful attention to the specific domains I pay attention to", but remember that it takes all kinds of people to make the world go round.
Is it warranted (figuratively, not literally) in this instance? Perhaps. But nonetheless, it re-opens the conversation about the wider implications about warrantless searches.
Right, but!
That's what the conversation would be about, without a long discussion and a lot of context. That's why we don't have the conversation: it's too hard, and people would just say "stop listening to my phone calls, you government perverts". And because we don't have that conversation, it's a surprise when things like this come up.
They might not talk about it but one agency or another has been consuming all digital traffic since at least the late 90s.
https://en.wikipedia.org/wiki/Carnivore_%28software%29?wprov...