• MrSoup@lemmy.zip
    link
    fedilink
    English
    arrow-up
    20
    ·
    edit-2
    6 hours ago

    If you turn off notification history on Android, should be enough to avoid such “attacks”. Hiding sensitive content inside notifications only hides it in the lock screen. If your OS keeps a clear log of them, it’s useless.

    Edit: didn’t know Signal actually has settings to hide their own notifications. I was thinking about Android’s “hide sensitive content” setting.

    • 4am@lemmy.zip
      link
      fedilink
      English
      arrow-up
      25
      arrow-down
      2
      ·
      6 hours ago

      Notifications go through FireBase Cloud Messaging (FCM) on Android. They bounce off a Google server. Even from local, on-device apps.

      Same with iOS.

      They can read and store every one of them, and you don’t control the encryption keys.

      • CorrectAlias@piefed.blahaj.zone
        link
        fedilink
        English
        arrow-up
        4
        ·
        2 hours ago

        Signal only sends a “new message, retrieve the rest from Signal” ping to your phone through Firebase. It doesn’t contain message details, just that you have a new message.

      • Björn@swg-empire.de
        link
        fedilink
        English
        arrow-up
        18
        ·
        6 hours ago

        But they only instruct Signal to wake up and download whatever is waiting. They don’t contain the message contents.

        • bearboiblake@pawb.social
          link
          fedilink
          English
          arrow-up
          10
          arrow-down
          1
          ·
          edit-2
          6 hours ago

          If you don’t use Google Play Services, you don’t get push notifications, so yes. Libre reimplementations of Google Play Services such as Gapps etc. or alternative push notification providers do not circumvent this issue, except possibly self-hosted push notification providers. This approach is really rare though and limited generally to very few apps.

          • Semperverus@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            5 hours ago

            Is this true if you don’t have Google Play Services but the person you’re messaging does? Is one person cutting GPS out enough?

            • bearboiblake@pawb.social
              link
              fedilink
              English
              arrow-up
              3
              ·
              5 hours ago

              The message you send them would probably go through as a push notification to them, but the message they send you wouldn’t.

    • bearboiblake@pawb.social
      link
      fedilink
      English
      arrow-up
      1
      ·
      5 hours ago

      I’m actually talking about sensitive data on Google/Apple hosted servers, as well as on the phone itself!