5 ms·
Apple and Google confirm governments spy on users through push notifications
- zer0c00ler 3y agoWhat are the reasons that makes this possible? The articles I have seen are not explaining what makes this different? What needs to be invented to get end to end security for push? I might be missing the obvious, apologies upfront.
- dmw_ng 3y agoNot least for the sake of power management, the central push provider needs to authenticate (and e.g. rate limit) notifications to a particular device. The identities of apps communicating with a particular device therefore seem to need to be known This still seems like something that could be fixed with smarter design without losing functionality.. e.g. decoupling device registrations from push channels, and treating the push channel ID a particular device is using as toxic for sharing and intermingling as other kinds of personal identifiers like phone numbers, including with the OS provider itself, or creating a unique push channel ID for every app registration, etc.
- r3trohack3r 3y agoThis is actually a bummer. P2P mobile applications cannot wake themselves up to sync with peers (short of relying on exploits). The same is true of browser service workers. The architectures I’ve explored for mobile and web based P2P apps, they’ve all needed a central trusted push notification server fallback to wake up the process so it can check for messages. Even then the APIs will fight you. Unless the fallback server syncs for you, it can only wake you up on an interval. It can’t know if there is a notification worthy event for you to sync. If you wake up the process and there are no messages from its peers that generate a notification, you “consume” some of your background notification budget. Consume too much and the system stops waking your app on push events, so you stop syncing in the background.
- wtf_srsly 3y agoThere are apps, like WhatsApp on iOS, that receive silent notifications and are started upon receiving them, allowing them to process these notifications locally (as explained in my other comment in this thread). This method enables them to bypass the need for sending clear text content through Apple's servers, upholding their end-to-end encryption. However, this practice can slightly impact battery consumption, which is probably why this specific entitlement is not freely available to all apps. It's a balance between enhanced security and a marginal increase in battery usage.
- kayson 3y agoI see power management mentioned often, but I'm not convinced. How does centralizing the push service reduce power? Why can't a developer just implement the service in the same way? (if Apple/Google let them) I self-host Gotify, which just uses a websocket for the push part, and battery consumption is only 2%/day even with the app white listed from "optimization"
- keep_reading 3y agoIt already exists for push, but most apps don't implement it and on Apple devices you need a special permission from Apple to be able to do it
- wongarsu 3y agoPush notifications are such a great way to spy on people, because so many apps send highly private information as push notification. Even if you install them on-premise, because the only well-supported battery-friendly way to send notifications is through Google's and Apple's servers. The most serious of secure messengers moved to push notifications that just cause the app to wake up and fetch the real message from the server to show as notification, but there are still plenty of apps that just send the full message as push notification.
- Jason_Protell 3y agoWhat are the most serious secure messengers?
- contact9879 3y agoSignal
- snoutie 3y agoI personally like the approach Threema has. They provide their own push serice called Threema Push[1] which is opt-in for google play store version. The push notifications for Threema do not contain any sensitve information either way.[2] They also have a libre version on F-Droid. [1]https://threema.ch/en/faq/threema_push https://threema.ch/en/faq/threema_push [2]https://threema.ch/en/faq/privacy_push https://threema.ch/en/faq/privacy_push
- orangepurple 3y agoThreema may very well be the Crypto AG of our times
- keep_reading 3y agoWhy would you say that? It's open source and has reproducible builds
- jsnell 3y agoA lot of discussion yesterday: https://news.ycombinator.com/item?id=38543155 https://news.ycombinator.com/item?id=38543155
- theknocker 3y ago[dead]
- deleted 3y ago[deleted]
- bradley13 3y ago"Because Apple and Google deliver push notification data, they can be secretly compelled by governments to hand over this information" What I don't understand is this: If the government wants to search your house, they show up at the door and show you a warrant. You can inspect the warrant - it's not secret. Granted, they're going to search your house anyway, but at least you know about it. Except in truly extraordinary circumstances, you should be informed if your government has requested access to any of your private information. This apparently goes even farther: not only have companies not been allowed to inform their customers, they haven't even been allowed to generally say that such information has ever been requested about anyone. That is seriously into dystopian territory.
- bregma 3y agoAmen. That kind of secret data collection should be reserved for profiteering capitalist oligarchs. Government is bad because it's government, but if you can generate personal wealth by exploiting others it's admirable.
- xelia 3y agoI’m not entirely sure what you’re alluding to - but yes, neither do corporations should be allowed unrestricted access to your personal data.
- Timwi 3y agoI think what they're alluding to is the unspoken implication that Apple and Google deserve admiration for coming forward about the government spying, despite the fact that they obviously spy on you, too.
- deleted 3y ago[deleted]
- chii 3y agoThe interesting thing is, the gov't cannot open your letters if it's first class mail, and may only open your letters under some well defined circumstances (https://www.rstreet.org/commentary/yes-the-government-can-open-your-mail-without-a-warrant/ https://www.rstreet.org/commentary/yes-the-government-can-op...) - it's all related to the letter being foreign, and i don't see any clause for domestic mail between US citizens being searchable warrantlessly. SO why should electronic mail not have the same rules applied?
- oneplane 3y agoOf course they do, if there's a way to get data without it being obviously illegal, it probably going to get collected. And I wouldn't be surprised if plenty of constructions like it either have a gag order or national security letter. On the other hand, there is no universal one size fits all rule that makes society better. Especially because there are plenty of very different people, both good and bad, and no rule, however well-intentioned will work out great overall. Let's hope someone at some point does come up with a better solution. In observation on why push messages: the same reason any other real-time communication is interesting, like calls, SMS, MMS, because that's enough bits being transceived, or enough of a cell location to find out where a device is, while not being long enough that you get some 'on the move' smear.
- deleted 3y ago[deleted]
- WhereIsTheTruth 3y agoThey confirm what everyone already knew, people were called "conspiracy theorists" https://www.theguardian.com/world/2013/jun/06/us-tech-giants-nsa-data https://www.theguardian.com/world/2013/jun/06/us-tech-giants... https://qz.com/1145669/googles-true-origin-partly-lies-in-cia-and-nsa-research-grants-for-mass-surveillance https://qz.com/1145669/googles-true-origin-partly-lies-in-ci...
- deleted 3y ago[deleted]
- hunters_laptop 3y ago[dead]
- wutwutwat 3y agoOne way to handle this is to send a notification with data that is meaningless, like a notification id or something, to trigger the app, which then (thanks to background app refresh, etc), pings your backend server with the id and retrieves the actual notification details. The only way to be 100% sure things are not being snooped while passing through push servers (or any third party you put your trust into), is to make the data they handle meaningless without also having access to your systems after they handle your push. Government can spy on your notification UUIDS that you send all day long, it won't do them much good though. These concerns are not unique to government. Don't trust any third party with your data. Security 101