FBI using push notification tokens to identify anonymous users
washingtonpost.com
washingtonpost.com
And you might be thinking that people shouldn't have to worry about all these details, so they're unnecessary in a news article for general consumption. Except focusing on details is exactly what the article is encouraging with its target of "push notifications", but its description of the mechanism isn't specific or actionable. Cue endless folk security advice to "disable push notifications" with no recognition of their specific info leaking properties.
Personally if I was going to maintain a persistent online nym actively posting evidence of things against most everyone's morals and generally antagonistic to law enforcement, I would use TOR and an operating system that wasn't designed by a surveillance company rather than thinking that some commercial off the shelf app made me invincible. Then again how is this really different than back in the day when people would ignore that IP addresses could identify them. It was great fun to go into pedophile IRC channels, paste a bunch of real names pulled off of poorly configured terminal servers, and watch the panicked disconnects.
FBI orders an "anonymous" messaging service to give them the Google and Apple push tokens that the service created and stored on its backend for some pseudonymous user when that user first registered through a smartphone app.
Then the FBI goes to Google and Apple and orders them to hand over the gmail or iCloud ID associated with that push token.
Which implies there are only 2 workarounds:
* for a user - use a burner phone with a burner Gmail/iCloud ID and all forms of sync and cloud backups disabled
* for privacy-focused messaging services - do not generate push tokens without an explicit user request. Tell the users about the privacy risk. And if a user opts into push notifications, frequently delete existing tokens, purge them from all logs and backups, and generate new ones.
The third (or really first) workaround is to use a personal computer with libre operating system rather than one designed by a surveillance company. Then you can skip this dynamic where entire OS subsystems have been designed around users being plainly identified.
I don't remember ever having to turn on one of those things. I have to do the exact opposite and go into the settings of almost all apps and disable notifications. This is not even related to privacy, as much as annoyance as all the apps want you to be "engaged", from chat pings (which are sometimes essential), to pushing ads through.
As a very basic user of a smartphone (Android) with relatively few apps, please ELIF how do I determine the current permissions for such notifications on my phone, in case I want to turn them off.
I have a couple of apps that are out there, right now, that use the Apple iOS notifications system (I write native Swift apps).
One of the apps, is the end-user one. That does not subscribe to external notifications. I only use the notifications system to badge the app icon, if there are things that need to be addressed. The badge is only affected, when the app is being run.
The other app, is an admin dashboard for that app (It uses a server-based system to manage user accounts). That subscribes to APNS, so we get alerted, when new signup requests come in.
The end-user app has a notifications panel in the Settings app, and you can specify that it not badge the app icon, but that makes no difference, in terms of privacy, because nothing is ever sent to the server.
The dashboard app actually registers the device ID, when registering for push notifications. Apple is probably aware of the device ID, and likely uses it, internally for stuff, but as an app developer, I only care about it, when one of the dashboard users signs up for push notifications. In that case, I store the ID into my own database, and use it to send push notifications to the device.
I suppose there may be some built-in OS services, that use APNS behind the scenes, but I'm not aware of them.
But Apple knows where all its devices are, and how to reach them (which is why it's a bad idea to buy a stolen iPhone). APNS is just an exposed SDK, to piggyback on it. I don't think there's any way to avoid them knowing where your phone is, unless you choose to use a [non-Apple] system that doesn't have any of those types of services.
I use GrapheneOS, so I don't have any google play services running, but for the apps where I need notifications I use https://unifiedpush.org/ (only a few apps implement it) and I host my own https://ntfy.sh server.
If you have a smartphone you are being tracked. If you don't you're being tracked as a NACK which raises alarms. Four people in an elevator with three phones means those get additional scrutiny.
count? I am having trouble believing this.
Signals and lack of signals are the same thing when tracking or locating.
I can see this being hard and time consuming the first time around, but I’m sure now it’s just routine.
This process is used all the time. Facebook/ Meta has an easy law enforcement portal that does the same thing (same for Snapchat, etc).
If anything they would use parallel construction and setup pretend documentation on old school investigation… they would want to hide that all these crimes are essentially solved via easy to access phone data.
https://www.apple.com/legal/privacy/gle-inforequest.pdf
https://www.facebook.com/records/login/?wtsid=rdr_0brcIrz9z5...
> said an investigation had revealed that the Justice Department had prohibited Apple and Google from discussing the technique.
That could complicate having a discussion about the problem.
Also, guessing from the quote that, even if a platform vendor wanted to fix this privacy&security problem, they'd be asked or compelled not to.
(Side note: Occasionally, you see an epic bug report or support thread with lots of people incredulous about why something isn't being fixed, and the vendor is silent. I usually guess that the inaction and silence is due to corporate triage, misalignment, or dysfunction, and that no one has the guts/decency to respond to all the people. The quote above suggests that the true explanation for silence by the platform vendor on a particular bug/support ticket could actually be that the paranoid conspiracy theorists guessed correctly.)
A blatant 1st amendment violation.
I currently use two phones with notifications turned off for Snapchat. However, the notification settings get reset if I use it on my other device. I don't use Snapchat altogether, but the other day, they sent me an SMS mentioning that I have a few unread messages. So scummy and so stupid!