news.volyx.in

FBI used iPhone notification data to retrieve deleted Signal messages (9to5mac.com)

635 points by 01-_- · 143 days ago · 307 comments on HN

Article summary

The FBI was able to recover deleted Signal messages from an iPhone by extracting data stored in the device's notification database, even after the Signal app had been removed. This was possible because the defendant had not enabled the setting to prevent message content from being previewed in notifications. As a result, the iPhone stored the notification content in its internal memory, allowing the FBI to access it. Apple has since released an update to address the issue.

Main themes

  • Signal security
  • iPhone notification storage
  • FBI data retrieval
  • End-to-end encryption
  • Notification privacy
  • iOS security updates

What commenters say

  • The default setting in Signal to show notification previews on the lock screen is insecure and should be changed to prioritize security over convenience.
  • The issue is not with Signal, but with the way iOS stores notification data, which can be accessed even after an app is deleted.
  • Users who prioritize security should disable notification previews or use alternative messaging apps that do not store sensitive data in notifications.
  • The fact that iOS stores notification content in an unencrypted form is a significant security vulnerability that can be exploited by law enforcement or other actors.
  • Signal's end-to-end encryption is effective, but it does not protect against data being stored in plaintext on the device, such as in notification previews.
  • The responsibility for securing notification data lies with the user, who should take steps to protect their data by adjusting their settings and using secure messaging apps.
  • The issue highlights the need for more transparency and control over how notification data is stored and accessed on mobile devices.
  • The default settings in Signal and iOS prioritize convenience over security, which can put users at risk of having their data accessed by unauthorized parties.