FBI used iPhone notification data to retrieve deleted Signal messages

01-_- 579 points 288 comments April 10, 2026
9to5mac.com · View on Hacker News

Discussion Highlights (20 comments)

frizlab

Aren’t notifications supposed to be encrypted for Signal?

etiam

Also discussed yesterday, in https://news.ycombinator.com/item?id=47703573

chasil

First, a critical setting for Signal users: "Signal’s settings include an option that prevents the actual message content from being previewed in notifications. However, it appears the defendant did not have that setting enabled, which, in turn, seemingly allowed the system to store the content in the database." Second, how can I see this notification history?

lenerdenator

There needs to be a bit more "group chat" control in Signal messages, wherein you could enforce certain settings for certain chats regardless of the phone settings. You could have group chats that would enforce not showing more information in the notifications, while others would still allow it.

i_am_proteus

Reminder that no end-to-end encryption arrangement can do anything before encryption, or after decryption, at the endpoints.

jonpalmisc

Settings > Notifications > Notification Content > Show: "Name Only" or "No Name or Content" I've had this enabled to prevent sensitive messages from appearing in full whilst showing someone something on my phone, but I guess this is an added benefit as well.

kome

signal is security theater, and a very bad user experience

chinathrow

On Android, when I use WhatsApp and have notifications for groups turned off, I can still see that they arrive briefly and then get removed (the icon top left vanishes). I wonder often, if this is a way to push all group message content into an unencrypted data trace as well - for the same use case.

mnls

People who NEED to hide their notifications from iOS have this already disabled. They rest who "evaluate their threat models" can practice Spy-life-gymnastics by disabling it from Signal.

shalmanese

I thought Signal didn’t show message previews by default and you had to go in and enable it? I’ve never had message previews in my Signal and I don’t remember changing anything. Maybe when they introduced the feature, you could pick but they strongly suggested it not showing?

niek_pas

I wonder why Apple doesn't 'just' delete the notification data associated with the app from the internal database when the user deletes the app? It seems like asking for problems to just keep old notification content around forever.

alsetmusic

Original article: FBI Extracts Suspect’s Deleted Signal Messages Saved in iPhone Notification Database[0] 0. https://www.404media.co/fbi-extracts-suspects-deleted-signal...

blitzar

> testimony in a recent trial Court cases are the real way to audit security. Larping about security and complaining about companies responding to court orders only gets you so far. Its way more useful to look at what actually happens in reality.

SergeAx

Probably stupid question: why won't they e2e-encrypt push notifications too? The vector is obvious and has been open since forever.

echelon_musk

As an aside, I decrypted an encrypted iPhone backup using a tool from GitHub because I wanted easy access to my Voice Memo recordings. Photos I had long deleted were still in the backup! It's quite surprising just how much is being stored by the phone.

nixosbestos

Um. Android has notification history also and I see no similar ability to hide notification content from the system ...

6thbit

So this is where we find out the one end of e2e is the phone and not the app. Semi-related, in whatsapp reading the text in the notification doesn't mark the message as read, so the OS is kinda mitm here.

ChrisArchitect

[dupe] Discussion on source: https://news.ycombinator.com/item?id=47703573

1vuio0pswjnm7

"However, it appears the defendant did not have that setting enabled, which, in turn, seemingly allowed the system to store the content in the database." "[A]llowing the system to store the content in the database" where a third party, such as Apple or a government, can access it is the default Only a small minority of users know about settings and how to change them. The vast majority of users do not change default settings. Apple knows this

walmas

People also got charges in the same case for removing people from a Signal chat

Semantic search powered by Rivestack pgvector
4,179 stories · 39,198 chunks indexed