6 ms·
> The code shows that the messages were secretly duplicated and sent to a “ghost” contact that was hidden from the users’ contact lists. Lots of "secure" messa
by drawkbox 4y ago
> The code shows that the messages were secretly duplicated and sent to a “ghost” contact that was hidden from the users’ contact lists.
Lots of "secure" messaging apps do this for intel and surveillance and not just the white hats.
Other areas that "secure" messaging apps have holes in is the anti-spam/moderation systems that need to view messages and in the clients themselves who have access to the unencrypted content. This is also taking place in other client apps as well: VPN, password managers, extensions, wallets, even build systems and more. Many like VPNs have logs sent elsewhere but deleted locally -- access to entire machine and all network access. People are way too trusting of "secure" systems/apps that are very common today based on trust.
All of these apps/systems would pass code checks, reviews, security inspections and essentially be encrypted/"secure" though a copy is sent off to another area for review. At runtime the leak is in the direction of the data.
- mavhc 4y agoMatrix treats all chats as chatrooms, even 2 people chats. This is promoted as a simplification, but maybe it's a security problem. If a protocol only allows 2 people to chat, harder to exfiltrate the messages
- jeroenhd 4y agoEncrypted chats need device/key verification/permission before the receiver can see any message contents. Even if Matrix were to limit chats by protocol, a malicious sysadmin could probably fake a cross-signed device if they had access to the client like this. I don't think this is actually a problem, a chat room is as good a representation as anything.
- Arathorn 4y agoAs the sibling implies: it doesn’t matter if the conversation is limited to 2 users - it’d just shift the attack adding a ghost device to one of those users, which is equivalent (and arguably more subtle) than adding a 3rd user to the conversation.
- dmix 4y ago> Lots of "secure" messaging apps do this for intel and surveillance and not just the white hats. It's how Apple would do iMessage intercepts for the FBI.
- criddell 4y agoI wonder if Messages will be available at all in lockdown mode? If Apple can be compelled to build in surveillance (and it's not clear to me that they can be), then it really should be.
- selykg 4y agoI think they indicated it will be, for example, they indicated that link previews would not be available, if I recall correctly.
- gabagool 4y agoIn a word, yes. > Messages: Most message attachment types other than images are blocked. Some features, like link previews, are disabled. https://www.apple.com/newsroom/2022/07/apple-expands-commitment-to-protect-users-from-mercenary-spyware/ https://www.apple.com/newsroom/2022/07/apple-expands-commitm...
- londons_explore 4y agoLockdown mode protects against bad snoopers, not good snoopers...
- nojito 4y agoYou can't really do this in iMessage.
- vorpalhex 4y agoWhat makes you think that?
- 4y ago
- richbell 4y ago> Lots of "secure" messaging apps do this for intel and surveillance and not just the white hats. Lots of VPNs, too! "We don't keep any logs! We just pipe a direct feed to the government so they can keep logs!"
- l33t2328 4y agoDo you have any examples?
- richbell 4y agoUnfortunately Google is failing me right now. There was a case within the last few years where someone was convicted because their VPN provider was sharing raw traffic (not logs) with the government. If anyone knows what I'm referring to, please chime in. But given the existence of Room 641A[0], and other extra-judicial mass surveillance, I am confident in my assertion. Moreover, the explosion of VPN companies with large marketing budgets over the past few years has always made me suspicious. [0] https://en.m.wikipedia.org/wiki/Room_641A https://en.m.wikipedia.org/wiki/Room_641A
- mike00632 4y agoYou're probably thinking of the big story from January of this year: https://www.pcmag.com/news/nordvpn-actually-we-do-comply-with-law-enforcement-data-requests https://www.pcmag.com/news/nordvpn-actually-we-do-comply-wit... NordVPN says they don't collect logs, but then it came out that they send information to law enforcement. So the big question is what information is being sent to law enforcement. Despite what NordVPN maintains, it seems like they do keep incriminating data about their users.
- Terry_Roll 4y agoMaybe the vast majority of big companies listed on stock markets work for the govt, and the price of a CEO or board member keeping quiet is the income and wealth gained from these stock market listed entities?
- SheinhardtWigCo 4y agoAll E2EE does is keep the general herd of users safe from malicious insiders and script kiddies. It's valuable but doesn't make these apps worthy of the catch-all "secure" descriptor. For anyone worth targeting, there are so many options available to actors with moderate resources. They will pwn your OS with an RCE exploit; or interfere the next time you update that "E2EE" app via Google or Apple's servers; or your laptop will take a few seconds longer to reappear at airport security; etc. Marketing messengers as "secure" because they use some derivative of the Double Ratchet is like your bank saying your funds are secure because their website uses TLS.
- oceanplexian 4y agoYou also have to keep in mind that spreading FUD about secure messaging apps can be a type of manipulation, in some cases planted by the FBI. If you don't have confidence in say, iMessage, which is pretty secure, you might instead go for a "secure" messaging app that's actually a plant (Like Anom).
- asdff 4y agoI would be bewildered if the FBI doesn't have a back door into every messaging app allowed on american cell phones. That being said there is one chat app that cannot be easily broken by the FBI: Pictochat on the nintendo DS. You would need an FBI agent with a nintendo DS searching for chat rooms in physical proximity to the communicators.
- mjreacher 4y agoI'm not sure if this is 100% serious but if it is, how could the FBI having a backdoor into every messaging app fit in with the relative ineffectiveness of the FBI?[0] If they truly did have the ability to spy on any messaging app without issue then you would expect them to have far more success than they actually do. For comparison, a quick Google search says China has a 99.9% conviction rate. Remember security and intelligence agencies also want people to think they are some omnipotent and omniscient entity that you cannot escape from, even though we know this is far from true[1][2]. [0]: https://time.com/magazine/us/5264136/may-14th-2018-vol-191-no-18-u-s/ https://time.com/magazine/us/5264136/may-14th-2018-vol-191-n... [1]: https://www.nytimes.com/2017/05/20/world/asia/china-cia-spies-espionage.html https://www.nytimes.com/2017/05/20/world/asia/china-cia-spie... [2]: https://www.nytimes.com/2021/10/05/us/politics/cia-informants-killed-captured.html https://www.nytimes.com/2021/10/05/us/politics/cia-informant...
- danso 4y agoThis is kind of a nitpick, but U.S. prosecutors also boast 99+% conviction rates. Note that conviction rate is not necessarily indicative of a systems effectiveness (or lack of fairness). Prosecutors only pursue charges in very few cases, and very few of those cases go to trial https://www.pewresearch.org/fact-tank/2019/06/11/only-2-of-federal-criminal-defendants-go-to-trial-and-most-who-do-are-found-guilty/ https://www.pewresearch.org/fact-tank/2019/06/11/only-2-of-f...
- legalcorrection 4y ago>Lots of "secure" messaging apps do this for intel and surveillance and not just the white hats. That's a broad claim. Do you have specific examples?
- londons_explore 4y agoHow could it be done better? I imagine for example, the protocol could be opensource and documented, and then the app-maker could be a different company than the server-owner. The server-owner need not be trustworthy as long as the protocol is sufficiently reviewed. The app-maker still needs to be trusted, but you can at least constrain the app to only communicating with the one allowed server and having no other network access. Perhaps the server owner could also make a webpage showing all the people you have communicated with... That way a malicious client couldn't send your data astray.
- asdff 4y agoI don't know why radicals can't go back to physical written works and spoken word. No surveillance from someone sitting in a cubical 1000 miles a way at least. Suddenly the agency needs to spend a lot more money and effort to physically infiltrate your group and intercept written communication. It's worked for thousands of years, and the internet has not made it obsolete contrary to popular belief.
- go_elmo 4y agoStill easier to do it digitally and e.g. physically exchange digital encryption keys?
- sweetbitter 4y agoYes lol. You can share your AES key physically and write/edit an application that encrypts with that. You could share one time pads, or other preshared secrets for techniques like winnowing and chaffing and whatnot. Always amusing that these guys always opt for trust in some bizarre app.
- more_corn 4y agoAnom wouldn’t pass a security review. Certainly not a successful decompile. Certainly not code review.