How the FBI Extracted Deleted Signal Messages From a Defendant's iPhone
Key Points:
- Signal is an encrypted chat app using end-to-end encryption (E2EE) to protect messages, meaning only senders and recipients can read the content, though it is not foolproof against all attacks.
- The FBI recently recovered incoming Signal messages from a defendant's iPhone by accessing the device's push notification database, even after the app was deleted, highlighting a vulnerability in how iOS stores message previews.
- This issue is not unique to Signal; any app that shows message previews on the iPhone Lock Screen saves those previews in internal memory, potentially exposing sensitive information to anyone with access to the device or advanced surveillance tools.
- To mitigate this risk, Signal offers a setting to block message content from appearing in notifications, ensuring that only the fact a message was received is visible, not the sender or message details.
- Users should be aware that notifications from various apps can expose private information and take steps to limit what appears on their Lock Screen to enhance privacy.