• Optional@lemmy.world
    link
    fedilink
    English
    arrow-up
    62
    arrow-down
    2
    ·
    edit-2
    10 months ago

    The data is said to have been used to attempt to tie anonymous users of messaging apps to specific Apple or Google accounts.

    So it’s not about the notifications or even necessarily the data the app handles; just that there’s an apple ID or google ID they’re pinging to see who it is.

    Today’s lesson is: Never use your apple ID or (ugh) google ID for anything important. If you can not use either for anything, great, but we all know we’re not international super spies and sometimes you just want to play a card game or something. Still. If someone’s unaware that smartphones are tracking devices they should probably know that now.

    I’m amazed that Apple was prohibited from saying anything until now.

    • BearOfaTime@lemm.ee
      link
      fedilink
      English
      arrow-up
      26
      arrow-down
      1
      ·
      10 months ago

      Just because we’re not James Bond today, doesn’t mean we won’t be a person of interest tomorrow.

      That’s what’s so dangerous, especially for stuff that’s just collected for no particular reason. Look at the man who was arrested for a crime simply because he biked through the area during the right time, and his Google location history showed up in a search.

      • AVincentInSpace@pawb.social
        link
        fedilink
        English
        arrow-up
        14
        arrow-down
        2
        ·
        10 months ago

        Look at the man who texted photos of his son’s genitalia to said son’s doctor and got his entire Google account banned when his phone automatically synced them to Gdrive and the algorithm decided he was a pedophile

        • Socsa@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          3
          arrow-down
          6
          ·
          edit-2
          10 months ago

          I don’t know if that’s a great example tbh. How does Google know it’s a medically necessary picture of a child’s genitals? Just don’t do that. Don’t send anyone pictures of your kid’s junk. Or anyone’s junk for that matter, except maybe your own if you really want to. Certainly not over unencrypted channels. That seems very obvious to me. If your kid’s dick is falling off, go to the ER

          • deweydecibel@lemmy.world
            link
            fedilink
            English
            arrow-up
            13
            arrow-down
            1
            ·
            10 months ago

            You missed the point of the examples.

            They’re cases of people who did nothing wrong but none the less found themselves in trouble because they didn’t appreciate how their privacy was being invaded. You can argue about the merits of invading one’s privacy to look for child porn, but it is an invasion of privacy, and it’s one that a tremendous amount of people are complete unaware of.

            That man presumed his phone was secure, and presumed the channel to his doctor was secure. So he sent sensitive images believing the only people that would see them would be the recipient, a licensed medical professional who presumably asked for or at least expected the photos. If what he believed had been true, there’d be no story.

            He didn’t realize that his photos were synced to g-drive, and he didn’t appreciate that images backed up to a cloud are not private, and that no matter what the context, those images would trigger a response. These are all things they were ignorant of until it was too late.

            The larger point is that he is not alone. A lot of people truly don’t appreciate just how much information of theirs is out there on somebody else’s computer, and they do not have the knowledge or the imagination to know how much trouble they could be in one day.

  • noodlejetski@lemm.ee
    link
    fedilink
    English
    arrow-up
    29
    arrow-down
    1
    ·
    10 months ago

    not sure how it works on iOS, but at least on Android Signal has been taking some extra measures to avoid that. the message contents aren’t delivered over GCM, just the ping that there’s a new incoming message, which is then downloaded by Signal separately.

    • BearOfaTime@lemm.ee
      link
      fedilink
      English
      arrow-up
      8
      arrow-down
      1
      ·
      edit-2
      10 months ago

      That’s kind of how iMessage works, the Apple equivalent to GCM (Google Cloud Messaging) is called APN (or is it ANP? I always forget), and it sends a notification to the phone which then retrieves the message.

      Be interesting to hear the perspective of the developers of Bubble Mini, since they just reverse-engineering iMessage.

      https://jjtech.dev/reverse-engineering/imessage-explained/

  • LainOfTheWired@lemy.lol
    link
    fedilink
    English
    arrow-up
    17
    arrow-down
    10
    ·
    10 months ago

    Good time to switch to an open source degoogled android ROM and set up your own push notification server.

    Until people stop giving up their freedom to these companies by agreeing to legal documents they don’t even read, it’s only going to get worse.

    • solarvector@lemmy.zip
      link
      fedilink
      English
      arrow-up
      49
      ·
      10 months ago

      I agree those are good things to do.

      But… Blaming people who are being fucked over by forces generally outside their control is not really going to help their or our situation. Expecting or demanding “people” to just change is also not realistic. Even if they wanted to, time, effort, energy, knowledge, skills, and attention are all finite. This is just one important issue or source of exploitation among a sea of others.

      • Stantana@lemmy.sambands.net
        link
        fedilink
        English
        arrow-up
        3
        arrow-down
        5
        ·
        10 months ago

        But… Blaming people who are being fucked over by forces generally outside their control is not really going to help their or our situation.

        The whole premise of the comment is that it’s not outside of their control, they just chose not to be responsible for the agreements they make. If you have any better suggestions than blaming those responsible for the situation I’m willing to listen and maybe even change my mind.

        Expecting or demanding “people” to just change is also not realistic. Even if they wanted to, time, effort, energy, knowledge, skills, and attention are all finite.

        Is it more unrealistic than “we” deciding to change and find a better path forward than surrendering our digital lives to strangers? I’m able to self-host my own push server. I wasn’t born with that knowledge. I had to invest time, effort and energy to gain the knowledge and skills. If I can, so can others. I am not an extraordinary smart person.

        Still, long before one starts to self-host entire platforms like NTFY or Nextcloud Push, there’s a ton of free to use services ran by idealists rather than capitalists. Or payed options with good terms. There’s so much between just not caring and being ones own sysadmin that I don’t think “don’t have the time” is a valid excuse anymore. It’s not just push messages, it’s everything - as you point out:

        This is just one important issue or source of exploitation among a sea of others.

        Sure. And most people I offered a free Nextcloud account to said the same. And Mastodon/Friendica-accounts. And so on. It’s like a technological mass depression, we can’t do everything we need to so there’s no point doing anything at all.

        And today I’m running a custom ROM and no push services from Big Data while they’re literally getting robbed of their phonebooks by Meta.

        • grue@lemmy.world
          link
          fedilink
          English
          arrow-up
          5
          arrow-down
          1
          ·
          10 months ago

          The whole premise of the comment is that it’s not outside of their control, they just chose not to be responsible for the agreements they make.

          “If you haven’t chosen to be a subsistence farmer, every problem with Big Agriculture is entirely your fault.”

          • Stantana@lemmy.sambands.net
            link
            fedilink
            English
            arrow-up
            1
            arrow-down
            3
            ·
            10 months ago

            More like the super healthy farmer is handing out organic food for free but people rather eat at McDonalds because it’s nearly packed and that’s where most people eat.

    • iAmTheTot@kbin.social
      link
      fedilink
      arrow-up
      23
      ·
      10 months ago

      Lol you’re dreaming if you think even 0.1% of people will be interested in setting up their own server.

      • Socsa@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        4
        arrow-down
        1
        ·
        edit-2
        10 months ago

        They’re also dreaming if they think doing these things doesn’t just make them stand out, and provides them any real protection from state actors.

        The number one rule of tradecraft is to blend in. I promise that you haven’t thought of some way of using an always connected smartphone that the NSA hasn’t considered. They are probably the ones making your degoogled ROMs.

        This is hubris, plain and simple. If your goal is to hide from state actors then the best way of doing that is to be uninteresting statistical noise.

        • deadcade@lemmy.deadca.de
          link
          fedilink
          English
          arrow-up
          6
          ·
          10 months ago

          Most “standard” messaging apps (that includes signal, telegram) use the “OS provided” push service. On Android, they use firebase cloud messaging, a component of google play services.

          Degoogled Android means not having any notifications, unless the app supports UnifiedPush, runs in the background 24/7 (which drains battery), or runs in the background occasionally (which delays notifications).

          If the app runs in the background occasionaly, you can “burden” the people on the other side by being slow to respond.

          • wreckedcarzz@lemmy.world
            link
            fedilink
            English
            arrow-up
            4
            ·
            edit-2
            10 months ago

            Eh, I use a few apps that have true foss forks and thus don’t use gcm but the keep-alive method, and I didn’t notice a difference in battery when I made the switch.

            Also lol #3 isn’t exactly a “burden”, take the hint and go away people. Let me live in blissful solitude.

            • Stantana@lemmy.sambands.net
              link
              fedilink
              English
              arrow-up
              1
              ·
              10 months ago

              Pretty much my experience with pull-based notifications. I’ve even tested the same client on the same setup against both NTFY and client-pull without seeing a noticable difference in battery usage.

          • BearOfaTime@lemm.ee
            link
            fedilink
            English
            arrow-up
            1
            arrow-down
            1
            ·
            10 months ago

            Well I’d say those going the degoogle route learn about things like Unified, NLP, etc, along the way. But it is something the end user has to handle themselves, rather than it just being there in the OS.

      • kpw@kbin.social
        link
        fedilink
        arrow-up
        1
        arrow-down
        7
        ·
        10 months ago

        It’s not so difficult actually. If you already use Conversations from F-Droid you can use your XMPP address to receive push notifications for example.

        • essteeyou@lemmy.world
          link
          fedilink
          English
          arrow-up
          19
          ·
          10 months ago

          Let me just tell my dad next time he can find the Skype icon on his taskbar so I can call him.

          • LainOfTheWired@lemy.lol
            link
            fedilink
            English
            arrow-up
            1
            ·
            10 months ago

            One interesting point is that some aspects of Linux are actually really good for people who struggle to learn new things as a lot of things on Linux are very consistent, and don’t feel the need to reinvent the wheel every few years like Microsoft.

            Because anyone with older relatives or tech illiterate friends knows the fear of a looming new Windows release on having those people suddenly be asking us how to do basic things like change the WiFi network due to Microsoft changing it again.

            And for some strange reason young people somehow getting a sense of superiority due to the fact they were able to find the new menu before their parents that was perfectly good before Microsoft changed it again.

            • essteeyou@lemmy.world
              link
              fedilink
              English
              arrow-up
              1
              ·
              10 months ago

              Yeah, I was a believer of Linux on the desktop back in 2003-2005, but there’s no way I could have converted my dad.

            • BearOfaTime@lemm.ee
              link
              fedilink
              English
              arrow-up
              1
              arrow-down
              1
              ·
              10 months ago

              Which is why I don’t update machines till they die. If it works, don’t mess with it.

              I’m so tired of MS moving stuff around.

  • Brkdncr@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    6
    ·
    10 months ago

    Sounds just like the idea that governments can retrieve metadata from phone calls without much hassle.

    I’m not sure there is much you could do to get around this on iOS besides disabling push notifications in your app.

  • kpw@kbin.social
    link
    fedilink
    arrow-up
    6
    ·
    10 months ago

    How do those governments have access to this data? Is it not TLS encrypted?

    • prettybunnys@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      17
      arrow-down
      2
      ·
      10 months ago

      The article states that Apple recommends not putting any sensitive data in the payloads as well as encrypting the payloads

      This sounds a lot like a scenario where Apple informs that a mechanism used for standard mobile communication is being survived by governments not necessarily a scenario where something Apple or google are doing is inherently surveillance.

      Here it seems like the surveillance is occurring at the 3rd parties who send the push notifications.

        • BearOfaTime@lemm.ee
          link
          fedilink
          English
          arrow-up
          4
          arrow-down
          1
          ·
          10 months ago

          Right?

          First they get location data because cell towers and people not caring.

          Then they notice all these message notifications between these dozen people at this time, at this location, that happens to coincide with a protest.

          Ding, fries are done!

    • GenderNeutralBro@lemmy.sdf.org
      link
      fedilink
      English
      arrow-up
      11
      arrow-down
      1
      ·
      edit-2
      10 months ago

      Apple would be able (and perhaps required?) to provide the decrypted data. TLS is not end-to-end encryption; it’s just server-to-client. It’s useful to prevent MITM wiretapping but it is NOT useful to prevent server-side spying.

      The article quotes Apple as saying they can update their transparency report now that this is public. Doesn’t look like they have data for 2023 yet at https://www.apple.com/legal/transparency/

      I’d think Apple could make push notification content end-to-end encrypted if they so desired, but I don’t know how they could avoid having access to the vendor and user at minimum for the sake of validation and delivery.

    • ImTryingLemmy@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      10 months ago

      To turn that question around, what incentive do the corporations have to encrypt that data? Whole bunch easier to just not care.

      • AVincentInSpace@pawb.social
        link
        fedilink
        English
        arrow-up
        4
        ·
        10 months ago

        I’m more worried that Apple had data to give up at all, what with them talking big game about not doing that.

        With an Android phone I can use a deGoogled ROM and have complete knowledge and control over all data going in or out and where it’s coming from. With an iPhone, I just have to trust that Apple has my best interests at heart and takes as many steps as they are legally allowed to to prevent things like this happening. Their entire business model is dependent on people believing that that is the case, hence the high profile FBI snafu a few years back. We have just received irrefutable proof that this is not true.

        See also Signal cooperating with the FBI and giving them absolutely jack shit because by design they don’t know anything about their users.

  • gregorum@lemm.ee
    link
    fedilink
    English
    arrow-up
    4
    arrow-down
    27
    ·
    10 months ago

    While, yes, it’s fucked that Apple in Google know about this it’s not really a bother to me if the government is aware that Killers of a Flower Moon is now available on Apple TV+ for streaming, and that there were excellent black Friday deals at the Home Depot. If the government is particularly bothered my latest GrubHub delivery, that’s fine, but I don’t care that they know.