4 ms·
How about requiring end-to-end encryption? Would that not be a better solution?
by zagrebian 3y ago
How about requiring end-to-end encryption? Would that not be a better solution?
- ynniv 3y agoThe metadata is all you need: find a few messages in an interesting e2e chat, ask Apple which accounts received push notifications at those specific times, find intersection.
- brookst 3y agoI’m not sure how E2EE would work for notifications. The ISV sends the notification but the OS displays it. I suppose some key exchange between each ISV and each device?
- keep_reading 3y agoPushover.net does it just fine. https://support.pushover.net/i46-are-messages-notifications-encrypted https://support.pushover.net/i46-are-messages-notifications-... My understanding is that Pushover encrypts the message with your device's public key (from the app) and delivers it through Apple/Google. On iOS you need a special permission from Apple to "filter" push notifications and this is the hook they use to capture and decrypt it before displaying it on your phone
- graphe 3y agoCan it hide or obscure the metadata at the time sent and received? Signal says they do that for their chats but you can also download an archive.
- keep_reading 3y agoI don't know, but I would assume not.