logoalt Hacker News

FBI used iPhone notification data to retrieve deleted Signal messages

277 pointsby 01-_-today at 11:29 AM125 commentsview on HN

Comments

bharat1010today at 3:08 PM

Kind of a wake-up call that even "deleted" messages aren't really gone if the OS is caching notification previews — makes you rethink what end-to-end encryption actually protects you from.

piggggtoday at 2:48 PM

Just curious, how come at least once a month signal bugs me to turn on notifications? I said no for a reason, every single time - why does it keep asking?

Not implying anything evil but it feels a bit weird esp after this.

show 5 replies
jonpalmisctoday at 12:18 PM

Settings > Notifications > Notification Content > Show: "Name Only" or "No Name or Content"

I've had this enabled to prevent sensitive messages from appearing in full whilst showing someone something on my phone, but I guess this is an added benefit as well.

show 5 replies
chasiltoday at 12:00 PM

First, a critical setting for Signal users:

"Signal’s settings include an option that prevents the actual message content from being previewed in notifications. However, it appears the defendant did not have that setting enabled, which, in turn, seemingly allowed the system to store the content in the database."

Second, how can I see this notification history?

show 6 replies
blitzartoday at 1:04 PM

> testimony in a recent trial

Court cases are the real way to audit security.

Larping about security and complaining about companies responding to court orders only gets you so far. Its way more useful to look at what actually happens in reality.

show 4 replies
6thbittoday at 1:57 PM

So this is where we find out the one end of e2e is the phone and not the app.

Semi-related, in whatsapp reading the text in the notification doesn't mark the message as read, so the OS is kinda mitm here.

show 1 reply
1vuio0pswjnm7today at 2:38 PM

"However, it appears the defendant did not have that setting enabled, which, in turn, seemingly allowed the system to store the content in the database."

"[A]llowing the system to store the content in the database" on the phone where a third party, such as Apple or a government, can access it is the default

Only a small minority of users know about settings and how to change them. The vast majority of users do not change default settings. Apple knows this

show 2 replies
alsetmusictoday at 1:02 PM

Original article: FBI Extracts Suspect’s Deleted Signal Messages Saved in iPhone Notification Database[0]

0. https://www.404media.co/fbi-extracts-suspects-deleted-signal...

show 1 reply
kevincloudsectoday at 2:42 PM

everyone's arguing about whether apple or the government is to blame. the actual problem is the verification methods themselves. credit card, drivers license, or a pass card. three options that each create a centralized database linking your real identity to your device. age verification is just identity verification with a friendlier name.

the verification accepts other people's credit cards and IDs. so the 'age gate' doesn't even verify the person using the device, just that someone with a credit card touched it once. it's all the privacy cost of an identity check with none of the supposed child safety benefit

show 2 replies
niek_pastoday at 12:58 PM

I wonder why Apple doesn't 'just' delete the notification data associated with the app from the internal database when the user deletes the app? It seems like asking for problems to just keep old notification content around forever.

show 3 replies
chinathrowtoday at 12:22 PM

On Android, when I use WhatsApp and have notifications for groups turned off, I can still see that they arrive briefly and then get removed (the icon top left vanishes). I wonder often, if this is a way to push all group message content into an unencrypted data trace as well - for the same use case.

show 1 reply
echelon_musktoday at 1:42 PM

As an aside, I decrypted an encrypted iPhone backup using a tool from GitHub because I wanted easy access to my Voice Memo recordings.

Photos I had long deleted were still in the backup! It's quite surprising just how much is being stored by the phone.

show 1 reply
frizlabtoday at 11:48 AM

Aren’t notifications supposed to be encrypted for Signal?

show 5 replies
nottorptoday at 2:44 PM

... and I thought I'm turning off notifications for all apps just so I don't get spammed. Looks like the setting is more useful than that.

shalmanesetoday at 12:47 PM

I thought Signal didn’t show message previews by default and you had to go in and enable it? I’ve never had message previews in my Signal and I don’t remember changing anything. Maybe when they introduced the feature, you could pick but they strongly suggested it not showing?

show 1 reply
walmastoday at 2:39 PM

People also got charges in the same case for removing people from a Signal chat

lenerdenatortoday at 12:07 PM

There needs to be a bit more "group chat" control in Signal messages, wherein you could enforce certain settings for certain chats regardless of the phone settings. You could have group chats that would enforce not showing more information in the notifications, while others would still allow it.

show 1 reply
ChrisArchitecttoday at 2:18 PM

[dupe] Discussion on source: https://news.ycombinator.com/item?id=47703573

mnlstoday at 12:28 PM

People who NEED to hide their notifications from iOS have this already disabled.

They rest who "evaluate their threat models" can practice Spy-life-gymnastics by disabling it from Signal.

show 2 replies
SergeAxtoday at 1:27 PM

Probably stupid question: why won't they e2e-encrypt push notifications too? The vector is obvious and has been open since forever.

show 3 replies
i_am_proteustoday at 12:07 PM

Reminder that no end-to-end encryption arrangement can do anything before encryption, or after decryption, at the endpoints.

show 1 reply
nixosbestostoday at 1:43 PM

Um. Android has notification history also and I see no similar ability to hide notification content from the system ...

show 1 reply
dfir-labtoday at 1:03 PM

[dead]

kometoday at 12:22 PM

signal is security theater, and a very bad user experience

show 1 reply