This seems like a good example of that being enough metadata to be a big problem.
This seems like a good example of that being enough metadata to be a big problem.
- identify who owns the number
- compel that person to give unlocked phone
- government can read messages of _all_ people in group chat not just that person
Corollary:
Disappearing messages severely limits what can be read
It's much more likely that the government convinces one member of the group chat to turn on the other members and give up their phone numbers.
Genuinely, from outside, it seems like your government doesn't give a damn on what they are and aren't allowed to do.
The district courts will eventually back me up on this. Our country has fallen a long way, but the district courts have remained good, and my case is unlikely to be one that goes up to appellate courts, where things get much worse.
There’s an important distinction: the government doesn’t care about what it is allowed to do, but it is still limited by what it is not capable of doing. It’s important to understand that they still do have many constraints they operate under, and that we need to find and exploit those constraints as much as possible while we fight them
And if I die in jail because I won’t unlock my phone: fuck ‘em, they’ll have to actually do it.
I don’t plan on being killed by the regime, but I don’t think I would’ve survived as a German in Nazi Germany, either. I’m not putting my survival above everything else in the world.
Obama was able to get people motivated. Neither Biden nor Harris had anywhere near that motivating ability. I don't know that the Dems have anyone as motivating as Obama line up. The Dems seem to be hoping that enough people will be repulsed by the current admin to show up.
How do you explain Biden getting so many more votes than Obama even while Trump improved with black and Hispanics over past Republican candidates?
US population in 2008: 304 million
US population in 2020: 332 million
https://www.macrotrends.net/global-metrics/countries/usa/uni...
Barring enormous turnout differences, pretty much every US election gets more raw votes than the last.
Simple enough explanation… 2020 was a massive outlier.
If you forgotten, the topic is GP saying Biden didn’t motivate voters. Well, that does not seem correct.
What's weird to me is that a lot of people lost that motivation over the next four years. If they found Trump scary in 2020, they should have found him scary in 2024.
Why would Trump be so unpopular to boost Biden in 2020, then do so much better in 2024?
1. He was President at the time, and people blame the President for what's happening (COVID then, recession now). Same deal now.
2. It didn't wind up being Trump/Biden in 2024 at all.
For what office? President? Do you live in California?
By the end of his first term, the danger was hard to miss, and the attempt to remain in power after losing the election should have cemented it for everyone.
I was unhappy with Biden and Harris. I voted for them in 2020 and 2024 anyway because I understood the alternative.
I don't get it, was there anything surprising about him after his inauguration? He sure sounded dangerous on the campaign trail.
I just do not understand this sentence at all. The writing was clearly on the wall. All of the Project 2025 conversations told us exactly what was going to happen. People claiming it was not obvious at best were not paying attention at all. For anyone paying attention, it was horrifying see the election results coming in.
I just pray they run Newsom this time. Despite his "being from California" handicap, I think he should be able to easily beat Vance by simply being a handsome white man with a white family. Vance is critically flawed and will demoralize much of the far right IFF his opponent doesn't share those same weaknesses.
etc, etc. So it goes
What evidence went before a judge prior to the two latest executions in Minneapolis?
Does it really seem that far–fetched when compared to the other ICE murders?
No, not really, because in the two killings you can vaguely argue they felt threatened. Pointing a gun to someone's head and demanding the password isn't anywhere close to that. Don't get me wrong, the killings are an affront to civil liberties and should be condemned/prosecuted accordingly, but to think that ICE agents are going around and reenacting the opening scene from Inglorious Bastards shows that your worldview can't handle more nuance than "fascism? true/false".
Precisely.
There's no question that ICE is daily trampling civil liberties (esp 4th amendment).
But in both killings there is a reasonable interpretation that they feared for their lives.
Now should they have is another question. With better training, a 6v1 < 5ft engagement can easily disarm anyone with anything less than a suicide vest.
But still, we aren't at the "run around and headshot dissenters" phase.
... Did you watch the videos from multiple people filming?
Yeah, did you? Any more substantive discourse you'd like to add to the conversation?
To be clear about the word "reasonable" in my comment, it's similar to the usage of the very same word in the phrase "beyond a reasonable doubt".
The agents involved in the shootings aren't claiming that:
- the driver telepathically communicated their ill intent
- they saw Pretti transform into a Satan spawn and knew they had to put him down
They claim (unsurprisingly, to protect themselves) that they feared for their life because either a car was driving at them or they thought Pretti had another firearm. These are reasonable fears, that a reasonable person has.
That doesn't mean the agents involved are without blame. In fact, especially in Pretti's case, they constructed a pretext to began engagement with him (given that he was simply exercising his 1st amendment right just prior).
But once in the situation, a reasonable person could have feared for their lives.
Sure, all things being equal, a person on the Clapham omnibus, yada, yada.
However, specifically in this situation it is very frequently not "median people" in the mix, it is LEO-phillic wannabe (or ex) soldier types that are often exchanging encrypted chat messages about "owning the libs", "goddamn <insert ethic slur>'s" and exchange grooming notes on provoking "officer-induced jeopardy" .. how to escalate a situation into what passes for "justified homicide" or least a chance to put the boot in.
Those countries that investigate and prosecute shootings by LEO's often find such things at the root of wrongful deaths.
>That doesn't mean the agents involved are without blame. In fact, especially in Pretti's case, they constructed a pretext to began engagement with him (given that he was simply exercising his 1st amendment right just prior).
Was there anything else you would like to add as an observation?
Eventually we got used to letting the feds slide on all the good things to the point everything was just operating on slick ice, and people like Trump just pushed it to the next logical step which is to also use the post-constitutional world to his own personal advantage and for gross tyranny against the populace.
The civil rights act of 1875, which also tried to bind on private businesses, was found unconstitutional in doing so, despite coming after the 15th amendment. But by the 60s and 70s we were already in a post-constitutional society as FDRs threatening to pack the courts, the 'necessities' implemented during WWII, and the progressive era more or less ended up with SCOTUS deferring to everything as interstate commerce (most notable, in Wickard v Filburn). The 14th and 15th amendment did not change between the time the same things were found unconstitutional, then magically constitutional ~80+ years later.
The truth is, the civil rights act was seen as so important (that time around) that they bent the constitution to let it work. And now much of the most relied on pieces of legislation relied on a tortured interpretation of the constitution, making things incredibly difficult to fix, and setting the stage for people like Trump.
Signal doesn't share numbers by default and hasn't for a few years now. And you can toggle a setting to remove your number from contact discovery/lookup entirely if you are so inclined.
If you're willing to kick in doors to suppress legal rights, then having accurate information isn't necessary at all.
If your resistance plan is to chat about stuff privately, then by definition you're also not doing much resisting to you know, the door kicking.
I'm sure the Israeli spyware companies can help with that.
Although then they'd have to start burning their zero days to just go after protestors, which I doubt they're willing to do. I imagine they like to save those for bigger targets.
I’m also curious what they could get off of cloud backups. Thinking in terms of auth, keys, etc. For SMS it’s almost as good as phone access, but I am not sure for apps.
The problem with mass surveillance is the “mass” part: warrantless fishing expeditions.
But yes... it does limit what can be read. My point is it's not perfect.
Celebrite or just JTAG over bluetooth or USB. It's always been a thing but legally they are not supposed to use it. Of course laws after the NSA debacle are always followed. Pinky promise.
They technically have logs from when verification happens (as that goes through an SMS verification service) but that just documents that you have an account/when you registered. And it's unclear whether those records are available anymore since no warrants have been issued since they moved to the new username system.
And the actual profile and contact discovery infra is all designed to be actively hostile to snooping on identifiable information even with hardware access (requiring compromise of secure enclaves + multiple levels of obfuscation and cryptographic anti-extraction techniques on top).
Now, whether FBI and friends would be determined to use PII obtained in this way to that end—is a point of contention, but why take the chance?
Better yet, don't expose your PII to third parties in the first place.
Settings > Privacy > Phone Number > Who can find me by number > Nobody
I know right and that would keep you hidden from Average Joe, but not US government. The mechanism to match your account to your phone number remains in place.
That is to say: it allows a determined party to largely remain anonymous even in the face of upstream provider's compromise.
https://www.phoenixnewtimes.com/news/arizona-supreme-court-s...
"Any man who breaks a law that conscience tells him is unjust and willingly accepts the penalty by staying in jail to arouse the conscience of the community on the injustice of the law is at that moment expressing the very highest respect for the law."
-- Letter from the Birmingham Jail, MLK Jr: https://people.uncw.edu/schmidt/201Stuff/F14/B%20SophistSocr...
That's life, if you can't take that heat stay out of the kitchen. It's also why elections are a much safer and more reliable way to enact change in your country than "direct action" is except under the most dire of circumstances.
No one is arguing that people who practice civil disobedience can expect to be immune from government response.
I think it's different with illegal "penalties" like being mauled by a dog or an extrajudicial killing. While those leaders of the civil rights movement faced those risks, I don't think King is asking people to martyr themselves in that passage, but to respect the law.
In contrast to accepting punishments from unjust laws, I think there is no lawless unjust punishment you should accept.
Accepting jail over 1A protected protests only proves you're weak (not in the morally deficient way, just from a physical possibilities way) enough to be taken. No one thinks more highly of you or your 'respect for the law' for being caught and imprisoned in such case, though we might not think lesser of you, since we all understand it is often a suicide mission to resist it.
My point is about civil disobedience, not disobedience generally. The point of civil disobedience is to bring attention to unjust laws by forcing people to deal with the fact they they are imprisoning people for doing something that doesn't actually deserve prison.
Expecting to not end up in prison for engaging in civil disobedience misses the point. It's like when people go on a "hunger strike" by not eating solid foods. The point is self-sacrifice to build something better for others.
https://www.kqed.org/arts/11557246/san-francisco-hunger-stri...
If that's not what you're into -- and it's not something I'm into -- then I would suggest other forms of disobedience. Freedoms are rarely granted by asking for them.
I'm not even really sure why I'm getting so much pushback here. I've thought this administration should have been impeached and removed within a week of the inauguration in 2017. I just am not sure where all this "why won't you admit that things are so bad, and shouldn't be this way" is helpful, when Trump was democratically elected. When you have a tyranny from a majority, the parallels to MLK are very clear, and you can't expect that change with come without sacrifice.
Civil disobedience is only nice and easy when you're sect is already in power, which -- when we're talking about people who generally support liberal democracy -- it has been since probably the McCarthy Era.
It isn’t just people walking around holding signs or filming ICE. Can we please distinguish these cases?
> If two or more persons in any State or Territory, or in any place subject to the jurisdiction of the United States, conspire to overthrow, put down, or to destroy by force the Government of the United States, or to levy war against them, or to oppose by force the authority thereof, or by force to prevent, hinder, or delay the execution of any law of the United States, or by force to seize, take, or possess any property of the United States contrary to the authority thereof, they shall each be fined under this title or imprisoned not more than twenty years, or both.
A group chat coordinating use of force may be tough.
They surely can. But the point was more than the people in power don't really need Signal metadata to do that. On the lists of security concerns modern protestors need to be worrying about, Signal really just isn't very high.
The whole reason cops love ALPR data is anyone's allowed to collect it, so they don't need a warrant.
Tow trucks have ALPR cameras to find repossessions. Plenty of private options for obtaining that sort of data; you can buy your own for a couple hundred bucks. https://linovision.com/products/2-mp-deepinview-anpr-box-wit...
> This seems like a good example of that being enough metadata to be a big problem
I was not saying it's not a problem that the feds are doing this, because that's not what I was replying to.
I mean, carrying a weapon is a 2nd amendment right, but if I bring it to a protest and then start intimidating people with it, the police going after me is not "Government intimidation of the practice of constitutional rights".
Protesting is a constitution right, but if you break the law while protesting, you're fair game for prosecution.
it will be quite easy for a prosecutor to charge lots of these people.
it's been done for less, and even if the case is thrown out it can drag on for years and involve jail time before any conviction.
The real protection for the legal protesters and observers in MN is numbers. They can't arrest and control and entire populace.
The FBI is weak now compared to what it was even two years ago.
prosecutors may take their time and file charges at their leisure.
However, neither Border patrol nor ICE have been exhibiting thoughtfulness or patience, so I doubt they're playing any such long game.
https://www.amazon.com/Surveillance-Valley-Military-History-...
I live in NY now. Just today, I got a message from a close friend who also did SF->NY "I'm deleting Signal to get more space on my phone, because nobody here uses it. Find me on WhatsApp or SMS."
To a naïve audience, Signal can have a stigma "I don't do anything illegal, so why should I bother maintaining yet-another messenger whose core competency is private messaging?" Signal is reasonably mainstream, and there are still a lot of people who won't use it.
I suspect you'll have an uphill battle using something even more obscure.
Aside: I see similar attitudes when I mention I use VPN all of the time
much more closer to the $5 wrench attack
Turns out they were right.
https://signal.org/blog/phone-number-privacy-usernames/
https://signal.org/blog/sealed-sender/
https://signal.org/blog/private-contact-discovery/
There isn't really anything you can do with that information. The first value is already accessible via other methods (since the phone companies carry those records and will comply with warrants). And for pretty much anyone with signal installed that second value is going to essentially always be the day the search occurred.
And like another user mentioned, the most recent of those warrants is from the day before they moved to username based identification so it is unclear whether the same amount of data is still extractable.
Ironically enough Reddit seems to have a pretty good take on this: https://www.reddit.com/r/law/comments/1qogc2g/comment/o21aeh...
I was genuinely surprised when I went to Reddit and saw that as the most voted comment on the story.
The lookups go through a secure enclave, the system is architected to limit the number of lookups that can be done, and the system has some fairly extensive anti-exfiltration cryptographic fuckery running inside the secure enclave to further limit the extent to which accounts can be efficiently looked up.
And of course you can also remove your phone number from contact discovery (but not from the acct entirely) but I'm not sure how that interacts with lookup for subpoenas. If they use the same system that contact discovery uses, it may be an undocumented way to exclude your account from subpoena responses.
The rest of what they say however is pretty spot on. The priority for signal is privacy, not anonymity. They try to optimise anonymity when they can but they do give up a little anonymity in exchange for anti-spam and user-friendliness.
So of course the ending notes of "use a VPN, configure the settings to maximise anonymity, and maybe even get a secondary phone number to use with it" are all perfectly reasonable suggestions.
And re: defaults the default behavior on signal is that your phone number is hidden from other users but it can be used to do contact discovery. Notably though you can turn contact discovery off (albeit few people do).
>We have also worked to ensure that keeping your phone number private from the people you speak with doesn’t necessitate giving more personal information to Signal. Your username is not stored in plaintext, meaning that Signal cannot easily see or produce the usernames of given accounts.
Extremely non trivial. What I'm hearing is "security by obfuscation".
I don't really think Signal tech has anything to do with this.
As a reminder... if you don't know all the people in your encrypted group chat, you could be talking to the man.
For users who configure Briar to connect exclusively over Tor using the normal startup (e.g., for internet-based syncing) and disable Bluetooth, there is no Bluetooth involvement at all, so your Bluetooth MAC address is not exposed.
Signal does give out phone numbers when the law man comes, because they have to, and because they designed their system around this identifier.
Signal can still tell law enforcement (1) whether a phone number is registered with Signal, and (2) when that phone number signed up and (3) when it was last active. That's all, and not very concerning to me. To prevent an enumeration attack (e.g. an attacker who adds every phone number to their system contacts), you can also disable discovery my phone number.
While Session prevents that, Session lacks forward secrecy. This is very serious- it's silly to compare Session to Signal when Session is flawed in its cryptography. (Details and further reading here https://soatok.blog/2025/01/14/dont-use-session-signal-fork/ ). Session has recently claimed they will be upgrading their cryptography in V2 to be up to Signal's standard (forward secrecy and post-quantum security), but until then, I don't think it's worth considering.
I agree that Briar is better, but unfortunately, it can't run on iPhones. I'm in the United States and that excludes 59% of the general population, and about 90% of my generation. It's not at fault of the Briar project, but it's a moot point when I can't use it to talk to people I know.
The question here is NOT "if Signal didn't leak your phone number could you still get screwed?" Of course you could, no one is disputing that.
The question is "if you did everything else perfect, but use Signal could the phone number be used to screw you?" The answer is ALSO of course, but the reason why we're talking about it is that this point was made to the creator of Signal many many times over the years, and he dismissed it and his fanboys ridiculed it.
I assume because of the baseband stuff to be FCC compliant? Last I checked that meant DMA channels, etc. to access the real phone processor. All easily activated over the air.
Indeed. The only reason this is not used by customer support for more casual access, firmware upgrades and debugging is a matter of policy and the risk of mass bricking phones and as such this is not exposed to them. There are other access avenues as well including JTAG debugging over USB and Bluetooth.
FCC devices are certified / allowed to use a spectrum, but you must maintain compliance. If you're a mobile phone manufacturer you have to be certain that if a bug occurs, the devices don't start becoming wifi jammers or anything like that.
This means you need to be able to push firmware updates over the air (OTA). These must be signed to avoid just anyone to push out such an OTA.
The government has a history of compelling companies to push out signed updates.
If there's one thing we learned from Snowden is that the NSA can't break PGP, so these people who live in the world of theory have no credibility with me.
I never saw a single speck of anything I ever sent to anyone via PGP in there. They had access to my SIGAINT e-mail and my BitMessage unlocked, but I used PGP for everything on top of that.
Stay safe!
And even then, a trusted participant could not understand they're not supposed to give their private keys out or could be rubber-hosed into revealing their key pin. All sorts of ways to subvert "secure" messaging besides breaking the crypto.
I guess what I'm saying is "Strong cryptography is required, but not sufficient to ensure secure messaging."
SimpleX does better than Session because the address used to add new contacts is different from the address used with any existing contact and is independently revocable. But if that address is out there, you can receive a full queue of spam contacts before you next open the SimpleX app.
Both Session and SimpleX are trivially vulnerable to storage DoS as well.