logoalt Hacker News

asdfman123yesterday at 9:26 PM4 repliesview on HN

Seems like you should use an app like Signal for anything sensitive at all so you don't have to worry about megacorp ecosystems as much.


Replies

jdwithityesterday at 9:40 PM

As mingus88 said, this story is literally in response to Apple leaking messages sent through Signal. Doesn't matter if the message is securely transmitted if the operating system then keeps it lying around in plain text in a cache.

From the linked article:

> The independent news outlet reported that the FBI had been able to extract deleted Signal messages from someone’s iPhone using forensic tools, due to the fact that the content of the messages had been displayed in a notification and then stored inside a phone’s database — even after the messages were deleted inside Signal.

show 1 reply
mingus88yesterday at 9:32 PM

Nope, Signal messages were stored in the phones notification DB even after the app was deleted

https://www.404media.co/fbi-extracts-suspects-deleted-signal...

show 2 replies
ryanisnanyesterday at 9:31 PM

This is also an oversimplification. If I understand the issue correctly, the notification with the message contents was what was cashed locally and then accessed. This same vulnerability would exist with Signal if you had the notifications configured to display the full message contents. In this case, it has nothing to do with either Apple or Signal.

show 1 reply