Question for security nerds:
With the recent revelations about governments spying on push notifications, doesn’t that circumvent Signal’s “sealed sender” feature?
If you can spy on APNS traffic, then you can easily see who is messaging whom. Right?
Question for security nerds:
With the recent revelations about governments spying on push notifications, doesn’t that circumvent Signal’s “sealed sender” feature?
If you can spy on APNS traffic, then you can easily see who is messaging whom. Right?
@jsq Hi Jesse!
Before talking about Sealed Sender specifically, it's worth calling out that Signal does not send any push content other than a flag that says: “Connect to the Web Socket” and retrieve some messages”. The content is then fetched and decrypted in a Notification Service Extension and then displayed as a local notification to the user.
https://github.com/signalapp/Signal-iOS/blob/b1027b670ea145073b12e5fb5c281a2facd3b61b/SignalNSE/NotificationService.swift#L105
APNS therefore never sees, even the Sealed Sender-encrypted ciphertexts, of the incoming messages.
@fj @jsq But they can see who is talking to whom, right? (The metadata the NSA and CIA use to kill people, according to General Michael Hayden.)
076萌SNS is a social network, courtesy of 076. It runs on GNU social, version 2.0.2-beta0, available under the GNU Affero General Public License.
All 076萌SNS content and data are available under the Creative Commons Attribution 3.0 license.