• gregorum@lemm.ee
    link
    fedilink
    English
    arrow-up
    19
    ·
    edit-2
    11 months ago

    it’s up to individual app developers to encrypt the data in their push notifications. as for the data about the notifications (the metadata stored on Apple’s/Google’s servers), that could end up being potentially useless if it were just a block of timestamped and encrypted data sitting on Apple’s or Google’s servers. Presently, that data often also includes the full notification contents, unencrypted.

    But when those companies get a court order/subpoena, they have no choice but to cooperate.

    edit: for clarity

    • towerful@programming.dev
      link
      fedilink
      English
      arrow-up
      15
      ·
      11 months ago

      The metadata is actually quite important.
      Sure, chances are it’s a “pending WhatsApp message” notification, but not the actual contents of the message.
      However, with enough metadata and by surveying traffic from WhatsApp data centers, someone could see User A accessed WhatsApps service, which generated a WhatsApp notification for User B.
      That might just be a coincidence, but with enough data and time, the probability that User A is talking to User B can be increased.
      If it also shows that Users C, D and E also get notifications at the same time, it is likely that all those users are in a group chat together.
      It’s called a timing attack.
      And perhaps it isn’t enough evidence to stand up in court, it can help build the profile of the users, and guide investigations to other possible accomplices.

      • gregorum@lemm.ee
        link
        fedilink
        English
        arrow-up
        5
        ·
        11 months ago

        I realize that sometimes metadata can be aggregated in nefarious ways. sometimes, however, it’s useless. currently, however, it contains all of the unencrypted contents of the notification itself, not just the metadata, and my point is that’s it’s better to take the step of encrypting the notifications themselves to at least protect that data.

    • zeluko@kbin.social
      link
      fedilink
      arrow-up
      3
      ·
      11 months ago

      would end up being mostly useless if it were just a block of timestamped and encrypted data sitting on Apple’s or Google’s servers

      If you are only interested in the data, sure.
      But metadata is also very powerful, specially when aggregated

      • gregorum@lemm.ee
        link
        fedilink
        English
        arrow-up
        3
        ·
        edit-2
        11 months ago

        But metadata is also very powerful, specially when aggregated

        it can be, depending on the context and what metadata you get. it can also be useless or of very limited value, even in aggregate. it’s really a roll of the dice, depending on the case. while I agree that no data access would be preferable to a little, my point is that encrypting the notification contents (a step which app devs can and should take) provides far better protection than what the cops get now, which is all.