415 karma · joined November 28, 2017
Apple doesn't allow background execution for third party apps. Can't increase service revenue if you allow competition.
The reply says that he should file a radar. Radar is Apple's bug reporting platform and famously unpopular among many developers due to slow and often useless replies.
Signal, WhatsApp, iMessage and Threema seem to do just fine.
Signal's subpoenas have always left a sour taste in my mouth. I just can't believe that they are getting so few, at least some cases they'll just send the standard letter out and will try to get something. Having no list of how many they have rejected would at least increase my confidence in them a bit.
But the bigger issue is, that they data they provide is just too good to be true for the majority of users. Signal has a push token for the vast majority of accounts otherwise they wouldn't be able to send out push notifications on iOS and would waste at least some battery on devices with Google Play services installed. The subpoenas always seem to affect people who have an Android phone without Google Play services installed. In my eyes is too strange of a coincidence to be true.
Signal does at least a bad job of explaining what kind of data they keep on an average user.
But I can't see it gaining too much main stream traction any time soon. Too me it feels like WhatsApp has hit the sweet spot for people who can't get themselfes to care about security and privacy.
Fully agree on the UX but not the reliability. WhatsApp used to be famous in Switzerland for its unreliability. On big European football games and Christmas / New Year WhatsApp was regularely down for 3 hours and more.
Many governments (e.g. Germany) wanted location instead of token based tracking with central storage of location pretty much up until the point where Apple and Google said that it won't happen .
This is based on my perception of Germany tech media coverage of the issue.
Is the process actually documented anywhere? Afaik they are just saying that they are verifying a match. This could of course just be a person looking at the hash itself.
The false positive rate does not look great.
The whitepapers provided by Apple do not say what the human reviews consists of. They could just look at the hashes to make sure there isn‘t a bug in their system.
I don't know of any data from the US but in Switzerland the Federal Police pre sorts all reports from the NCEMC and around 90% are unusable [1] and cannot be acted upon. The remaining 10% are then forwarded to local authorities. There is no data I know of what the final conviction rate looks like. But from what I have gathered from local news paper these departments are usually short staffed.
I suspect that the situation is similar in the US.
[1]: https://fedpol.report/en/fedpol-in-figures/fight-against-pae...
Edit: Fix typo: persorts to pre sorts.
After hiding the standalone license this would put a lot of trust back into 1Password.
> We also show how an attacker can mount an “attacker-in-the-middle” attack on the initial key negotiation between the client and the server. This allows an attacker to impersonate the server to the client, allowing to break confidentiality and integrity of the communication. Luckily, this attack is also quite difficult to carry out, as it requires sending billions of messages to a Telegram server within minutes.
If the goal is large scale surveillance, it can be combatted fairly effectively as has been shown with e.g. kino.to and other streaming sites which have gone practivally extinct. The same would happen to websites hosting illegal apps.
If the goal is to go after real criminals this is of course useless. But EncroChat [1] has shown that at least large parts of the criminal world don't seem to have great operation security practices.