Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. Let me get this straight...

Let me get this straight...

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
60 Indlæg 23 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • avuko@infosec.exchangeA avuko@infosec.exchange

    @Beachbum @wdormann if you do not want to be tracked/traced/placed, don’t bring a mobile phone in any way tied to you or your previous locations.

    I worked in telco for years, trust me on this one.

    The problem here was different: people who thought they were communicating privately, had their messages (or those that ended up in Apple’s notifications database on the iPhone) accessible to law enforcement. Even after (taking precautions like) deleting the app.

    beachbum@mastodon.sdf.orgB This user is from outside of this forum
    beachbum@mastodon.sdf.orgB This user is from outside of this forum
    beachbum@mastodon.sdf.org
    wrote sidst redigeret af
    #17

    @avuko @wdormann That’s partly why I’m asking because I disable notifications as soon as I purchase a phone. Locating my phone is important because I misplace it a lot. My location services it’s also always off.
    I have a degree in IT, but it goes back to 2006 and so much has changed since then and honestly, I only keep up through what I read here on Mastodon. I thought doing these things would secure my privacy.

    1 Reply Last reply
    0
    • avuko@infosec.exchangeA avuko@infosec.exchange

      @Beachbum @wdormann if you do not want to be tracked/traced/placed, don’t bring a mobile phone in any way tied to you or your previous locations.

      I worked in telco for years, trust me on this one.

      The problem here was different: people who thought they were communicating privately, had their messages (or those that ended up in Apple’s notifications database on the iPhone) accessible to law enforcement. Even after (taking precautions like) deleting the app.

      beachbum@mastodon.sdf.orgB This user is from outside of this forum
      beachbum@mastodon.sdf.orgB This user is from outside of this forum
      beachbum@mastodon.sdf.org
      wrote sidst redigeret af
      #18

      @avuko @wdormann I was rather shocked that this could even be possible yet actually occurring.

      1 Reply Last reply
      0
      • wdormann@infosec.exchangeW wdormann@infosec.exchange

        Let me get this straight...

        The default setting for Signal on an iPhone allows law enforcement to see the content of all incoming messages, even after the app has been deleted? 🤔

        https://www.404media.co/fbi-extracts-suspects-deleted-signal-messages-saved-in-iphone-notification-database-2/

        prism@infosec.exchangeP This user is from outside of this forum
        prism@infosec.exchangeP This user is from outside of this forum
        prism@infosec.exchange
        wrote sidst redigeret af
        #19

        @wdormann The default setting is that you get notified when you receive a message, because most people want those.

        wdormann@infosec.exchangeW 1 Reply Last reply
        0
        • wdormann@infosec.exchangeW wdormann@infosec.exchange

          Let me get this straight...

          The default setting for Signal on an iPhone allows law enforcement to see the content of all incoming messages, even after the app has been deleted? 🤔

          https://www.404media.co/fbi-extracts-suspects-deleted-signal-messages-saved-in-iphone-notification-database-2/

          craignicol@glasgow.socialC This user is from outside of this forum
          craignicol@glasgow.socialC This user is from outside of this forum
          craignicol@glasgow.social
          wrote sidst redigeret af
          #20

          @wdormann @mastodonmigration eh what?

          On Android it just shows "you have a new message". Was this an Apple or a Signal decision?

          erwinrossen@mas.toE 1 Reply Last reply
          0
          • wdormann@infosec.exchangeW wdormann@infosec.exchange

            Let me get this straight...

            The default setting for Signal on an iPhone allows law enforcement to see the content of all incoming messages, even after the app has been deleted? 🤔

            https://www.404media.co/fbi-extracts-suspects-deleted-signal-messages-saved-in-iphone-notification-database-2/

            lennybacon@infosec.exchangeL This user is from outside of this forum
            lennybacon@infosec.exchangeL This user is from outside of this forum
            lennybacon@infosec.exchange
            wrote sidst redigeret af
            #21

            @wdormann Looks different here. But it’s Most probably the „Preview“ -Thing that causes Information to leak (to the OS which persists it unsecure)

            wdormann@infosec.exchangeW 1 Reply Last reply
            0
            • lennybacon@infosec.exchangeL lennybacon@infosec.exchange

              @wdormann Looks different here. But it’s Most probably the „Preview“ -Thing that causes Information to leak (to the OS which persists it unsecure)

              wdormann@infosec.exchangeW This user is from outside of this forum
              wdormann@infosec.exchangeW This user is from outside of this forum
              wdormann@infosec.exchange
              wrote sidst redigeret af
              #22

              @lennybacon
              The screenshot I shared is from the Signal app itself, in Settings.

              Not iPhone-wide settings.

              lennybacon@infosec.exchangeL 1 Reply Last reply
              0
              • prism@infosec.exchangeP prism@infosec.exchange

                @wdormann The default setting is that you get notified when you receive a message, because most people want those.

                wdormann@infosec.exchangeW This user is from outside of this forum
                wdormann@infosec.exchangeW This user is from outside of this forum
                wdormann@infosec.exchange
                wrote sidst redigeret af
                #23

                @prism
                The default setting is that you get notified with the message contents

                rolfbly@mastodon.socialR 1 Reply Last reply
                0
                • tdpsk@sueden.socialT tdpsk@sueden.social

                  @wdormann @Mer__edith I was unaware notifications on iOS were stored in an on-device database even after they had been dismissed. That seems like an inefficient waste of storage - does anybody have a link to some Apple docs providing context about this database?

                  wdormann@infosec.exchangeW This user is from outside of this forum
                  wdormann@infosec.exchangeW This user is from outside of this forum
                  wdormann@infosec.exchange
                  wrote sidst redigeret af
                  #24

                  @tdpsk @Mer__edith
                  The problem is that such content is not included in unencrypted backups. So we mortals can't even confirm this, as we don't have access to full-device exploit tools such as Cellebrite.

                  tdpsk@sueden.socialT 1 Reply Last reply
                  0
                  • grammasaurus@mastodon.socialG grammasaurus@mastodon.social

                    @omnicore @wdormann @signalapp What I got from the article is what you said here: the weakness is in iPhone’s default behavior.

                    wdormann@infosec.exchangeW This user is from outside of this forum
                    wdormann@infosec.exchangeW This user is from outside of this forum
                    wdormann@infosec.exchange
                    wrote sidst redigeret af
                    #25

                    @grammasaurus @omnicore @signalapp

                    The screenshot I shared is from the Signal app itself, which chooses to include the message content in notifications.

                    So I'd say that both are at fault.

                    grammasaurus@mastodon.socialG 1 Reply Last reply
                    0
                    • wdormann@infosec.exchangeW wdormann@infosec.exchange

                      Let me get this straight...

                      The default setting for Signal on an iPhone allows law enforcement to see the content of all incoming messages, even after the app has been deleted? 🤔

                      https://www.404media.co/fbi-extracts-suspects-deleted-signal-messages-saved-in-iphone-notification-database-2/

                      thomasareed@infosec.exchangeT This user is from outside of this forum
                      thomasareed@infosec.exchangeT This user is from outside of this forum
                      thomasareed@infosec.exchange
                      wrote sidst redigeret af
                      #26

                      @wdormann @Viss It’s been a while since I installed Signal, but I have a vague memory that it may have reminded me to change that setting the first time I ran it.

                      wdormann@infosec.exchangeW 1 Reply Last reply
                      0
                      • cppguy@infosec.spaceC cppguy@infosec.space

                        @avuko @wdormann

                        Oh, but it's even worse than that. From TFA:

                        Authorities have turned to push notifications more broadly as an investigative strategy too; in June 404 Media reported Apple gave governments data on thousands of push notifications. Those were legal demands made to Apple, while the Prairieland case was about data from a device authorities had physical access to.

                        This suggests that your #notifications are sent home to #Apple. Why is that necessary?

                        I have further questions:

                        • Why, and for whose benefit, were notifications stored on the phone after the #Signal app had been removed? They were useless to the other of the phone.
                        • How much of this vulnerability is shared with Android phones?
                        wdormann@infosec.exchangeW This user is from outside of this forum
                        wdormann@infosec.exchangeW This user is from outside of this forum
                        wdormann@infosec.exchange
                        wrote sidst redigeret af
                        #27

                        @CppGuy @avuko

                        Apple gave governments data on thousands of push notifications

                        Is open to wide interpretation. Did they give information about thousands of push notifications? (i.e. metadata) (e.g. the App that sent the notification and the timestamp, and potentially account info tied to the request)

                        If they gave the actual notification content, then that's a whole other scandalous animal. Extraordinary claims require extraordinary evidence, and whatnot.

                        1 Reply Last reply
                        0
                        • wdormann@infosec.exchangeW wdormann@infosec.exchange

                          Let me get this straight...

                          The default setting for Signal on an iPhone allows law enforcement to see the content of all incoming messages, even after the app has been deleted? 🤔

                          https://www.404media.co/fbi-extracts-suspects-deleted-signal-messages-saved-in-iphone-notification-database-2/

                          lazarus7@infosec.exchangeL This user is from outside of this forum
                          lazarus7@infosec.exchangeL This user is from outside of this forum
                          lazarus7@infosec.exchange
                          wrote sidst redigeret af
                          #28

                          @wdormann switching my friends and family to signal was made easier because of settings like this. It behaves like a normal messaging app. None of them have a threat model that has them thinking of device seizure by law enforcement.

                          1 Reply Last reply
                          0
                          • thomasareed@infosec.exchangeT thomasareed@infosec.exchange

                            @wdormann @Viss It’s been a while since I installed Signal, but I have a vague memory that it may have reminded me to change that setting the first time I ran it.

                            wdormann@infosec.exchangeW This user is from outside of this forum
                            wdormann@infosec.exchangeW This user is from outside of this forum
                            wdormann@infosec.exchange
                            wrote sidst redigeret af
                            #29

                            @thomasareed @Viss
                            I don't believe you, as that setting (my screenshot) is within the Signal app itself.

                            As such, if they wanted a different default value, they would have just released the software with the preferred setting.

                            thomasareed@infosec.exchangeT 1 Reply Last reply
                            0
                            • wdormann@infosec.exchangeW wdormann@infosec.exchange

                              @thomasareed @Viss
                              I don't believe you, as that setting (my screenshot) is within the Signal app itself.

                              As such, if they wanted a different default value, they would have just released the software with the preferred setting.

                              thomasareed@infosec.exchangeT This user is from outside of this forum
                              thomasareed@infosec.exchangeT This user is from outside of this forum
                              thomasareed@infosec.exchange
                              wrote sidst redigeret af
                              #30

                              @wdormann @Viss Okay, whatever. “I don’t believe you” is a pretty rude response, as it implies I’m lying and that nothing changed in the years since I installed it. I do distinctly remember some kind of warning about Signal notifications from somewhere, though, so this is most definitely NOT new news.

                              1 Reply Last reply
                              0
                              • wdormann@infosec.exchangeW wdormann@infosec.exchange

                                @lennybacon
                                The screenshot I shared is from the Signal app itself, in Settings.

                                Not iPhone-wide settings.

                                lennybacon@infosec.exchangeL This user is from outside of this forum
                                lennybacon@infosec.exchangeL This user is from outside of this forum
                                lennybacon@infosec.exchange
                                wrote sidst redigeret af
                                #31

                                @wdormann Thanks. Looks the same in the app to me.

                                Probably the same but configured from the opposite side of things.

                                1 Reply Last reply
                                0
                                • wdormann@infosec.exchangeW wdormann@infosec.exchange

                                  @prism
                                  The default setting is that you get notified with the message contents

                                  rolfbly@mastodon.socialR This user is from outside of this forum
                                  rolfbly@mastodon.socialR This user is from outside of this forum
                                  rolfbly@mastodon.social
                                  wrote sidst redigeret af
                                  #32

                                  @wdormann @prism

                                  fwiw, I just checked on Android. Notification history goes back only 24 hours. Message + sender visible.

                                  1 Reply Last reply
                                  0
                                  • wdormann@infosec.exchangeW wdormann@infosec.exchange

                                    @Mer__edith
                                    Can we get a comment on this?

                                    1) The default Signal setting to show message contents in push notifications seems... bad, assuming this article is accurate.
                                    2) Does changing the in-Signal-app setting for Notification Content indeed prevent notifications from being stored anywhere, which by default contains incoming message bodies.

                                    wdormann@infosec.exchangeW This user is from outside of this forum
                                    wdormann@infosec.exchangeW This user is from outside of this forum
                                    wdormann@infosec.exchange
                                    wrote sidst redigeret af
                                    #33

                                    @Mer__edith
                                    On the macOS side of things, we have confirmation that Signal notification contents get stored, even for disappearing messages

                                    iOS sadly offers less visibility into what's going on. But the FBI probably appreciates that it's happening there too.

                                    The default notification setting for Signal (on both iOS and macOS) ensures that potentially sensitive information leaks out of the Signal app. This is unfortunate.

                                    wdormann@infosec.exchangeW 1 Reply Last reply
                                    0
                                    • wdormann@infosec.exchangeW wdormann@infosec.exchange

                                      @Mer__edith
                                      Can we get a comment on this?

                                      1) The default Signal setting to show message contents in push notifications seems... bad, assuming this article is accurate.
                                      2) Does changing the in-Signal-app setting for Notification Content indeed prevent notifications from being stored anywhere, which by default contains incoming message bodies.

                                      jason@logoff.websiteJ This user is from outside of this forum
                                      jason@logoff.websiteJ This user is from outside of this forum
                                      jason@logoff.website
                                      wrote sidst redigeret af
                                      #34

                                      @wdormann @Mer__edith it should probably be changed but you also have to weigh this against how many people would try Signal, see that it lacks message previews, and go back to SMS.

                                      1 Reply Last reply
                                      0
                                      • craignicol@glasgow.socialC craignicol@glasgow.social

                                        @wdormann @mastodonmigration eh what?

                                        On Android it just shows "you have a new message". Was this an Apple or a Signal decision?

                                        erwinrossen@mas.toE This user is from outside of this forum
                                        erwinrossen@mas.toE This user is from outside of this forum
                                        erwinrossen@mas.to
                                        wrote sidst redigeret af
                                        #35

                                        @craignicol @wdormann @mastodonmigration On my Android it did show Name and message completely. Not sure if I have changed that setting myself in the past 8 years that I have been using Signal, or whether that is/was the default.

                                        craignicol@glasgow.socialC 1 Reply Last reply
                                        0
                                        • erwinrossen@mas.toE erwinrossen@mas.to

                                          @craignicol @wdormann @mastodonmigration On my Android it did show Name and message completely. Not sure if I have changed that setting myself in the past 8 years that I have been using Signal, or whether that is/was the default.

                                          craignicol@glasgow.socialC This user is from outside of this forum
                                          craignicol@glasgow.socialC This user is from outside of this forum
                                          craignicol@glasgow.social
                                          wrote sidst redigeret af
                                          #36

                                          @erwinrossen @wdormann @mastodonmigration hmm. Entirely possible the default has changed

                                          1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper