苹果修复一个允许联邦调查局读取已删除Signal消息的漏洞。
Apple Fixes Bug That Allowed FBI To Read Deleted Signal Messages

原始链接: https://www.zerohedge.com/technology/apple-fixes-bug-allowed-fbi-read-deleted-signal-messages

苹果公司最近修补了一个安全漏洞,该漏洞允许联邦调查局访问iPhone上已删除的Signal消息,即使启用了阅后即焚功能。该漏洞存在于iOS推送通知数据库中,该数据库在删除消息和卸载应用程序后仍会保留消息的缓存预览。 此事通过与FBI案件相关的法庭文件曝光,404 Media报道称,该机构能够提取这些消息。Signal确认苹果的修复解决了该问题,强调虽然他们的应用程序使用端到端加密,但设备层面的漏洞仍然可能损害数据安全。 这凸显了仅依靠加密的局限性,并引发了对操作系统安全影响消息隐私的担忧。Telegram的创始人提出了一种解决方案:完全消除通知预览,以确保完全的隐私。苹果的更新现已发布,旨在防止未来访问已删除的消息数据。

相关文章

原文

Authored by Brian Quarmby via CoinTelegraph.com,

Tech giant Apple has fixed a security flaw that had allowed the FBI to access a Signal user’s deleted messages through their phone’s push notification database, despite the app being deleted and messages being set to disappear.

In a security advisory released on Wednesday, Apple said it had fixed a bug that allowed “notifications marked for deletion” to be “unexpectedly retained on the device.”

In an X post on Wednesday, Signal said the update fixed the issue that made a user’s messages retrievable by law enforcement.

"Apple's advisory confirmed that the bugs that allowed this to happen have been fixed in the latest iOS release," Signal said.

Signal uses end-to-end encryption to secure messages between its users. The bug is a reminder that messaging encryption may not be enough to keep data protected when using certain devices or operating systems.

Apple’s notes on the security patch. Source: Apple

This security flaw was first highlighted by independent technology news website 404 Media, which reported on April 9 that documents recently unsealed in Texas federal court related to an FBI case over an attack on the Prairieland ICE Detention Facility last July.

The court proceedings showed that the FBI was able to forensically extract a defendant's Signal messages from the iPhone's notification database, which contained cached, readable previews of incoming Signal messages even after disappearing messages were enabled and the app was deleted.

Following the 404 Media report, Signal President Meredith Whittaker called on Apple to quickly fix the issue, noting in an April 14 X post that "notifications for deleted messages shouldn't remain in any OS notification database."

Pavel Durov, the co-founder of competing privacy messaging app Telegram, also commented on the report, arguing in an April 14 Telegram post that the only way to truly stay safe was for the app to "force an absence of notification previews" on both ends of a conversation.

联系我们 contact @ memedata.com