this post was submitted on 07 Dec 2023
160 points (90.0% liked)
Technology
59366 readers
5328 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related content.
- Be excellent to each another!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, to ask if your bot can be added please contact us.
- Check for duplicates before posting, duplicates may be removed
Approved Bots
founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Oof that's bad.
Although it should be noted that in well designed apps this should only be metadata. The push notification should just tell the phone that "content is available", which will power up the CPU, launch the app in the background, download your actual message/etc, decrypt it, and finally put a notification on the lock screen.
Metadata is obviously useful to law enforcement, but unless the app is really poorly written they shouldn't be getting your actual notification alerts. Those should be E2EE and therefore can't be disclosed.
Unfortunately the notification system does allow messages to be sent without encryption. Perhaps they should remove that feature.