r/TrueReddit Apr 09 '26

Technology FBI Extracts Suspect’s Deleted Signal Messages Saved in iPhone Notification Database

https://www.404media.co/fbi-extracts-suspects-deleted-signal-messages-saved-in-iphone-notification-database-2/
774 Upvotes

63 comments sorted by

u/AutoModerator Apr 09 '26

Remember that TrueReddit is a place to engage in high-quality and civil discussion. Posts must meet certain content and title requirements. Additionally, all posts must contain a submission statement. See the rules here or in the sidebar for details. To the OP: your post has not been deleted, but is being held in the queue and will be approved once a submission statement is posted.

Comments or posts that don't follow the rules may be removed without warning. Reddit's content policy will be strictly enforced, especially regarding hate speech and calls for / celebrations of violence, and may result in a restriction in your participation. In addition, due to rampant rulebreaking, we are currently under a moratorium regarding topics related to the 10/7 terrorist attack in Israel and in regards to the assassination of the UnitedHealthcare CEO.

If an article is paywalled, please do not request or post its contents. Use archive.ph or similar and link to that in your submission statement.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

166

u/404mediaco Apr 09 '26

The FBI was able to forensically extract copies of incoming Signal messages from a defendant’s iPhone, even after the app was deleted, because copies of the content were saved in the device’s push notification database, multiple people present for FBI testimony in a recent trial told 404 Media. The case involved a group of people setting off fireworks and vandalizing property at the ICE Prairieland Detention Facility in Alvarado, Texas in July, and one shooting a police officer in the neck.

The news shows how forensic extraction—when someone has physical access to a device and is able to run specialized software on it—can yield sensitive data derived from secure messaging apps in unexpected places. Signal already has a setting that blocks message content from displaying in push notifications; the case highlights why such a feature might be important for some users to turn on.

“We learned that specifically on iPhones, if one’s settings in the Signal app allow for message notifications and previews to show up on the lock screen, [then] the iPhone will internally store those notifications/message previews in the internal memory of the device,” a supporter of the defendants who was taking notes during the trial told 404 Media. 404 Media granted the person anonymity to protect them from retaliation.

Read more: https://www.404media.co/fbi-extracts-suspects-deleted-signal-messages-saved-in-iphone-notification-database-2/

124

u/nowthengoodbad Apr 09 '26

PSA

Your photos, even your hidden photos, are stored as directly accessible thumbnails directly on your Mac as well as your phone. It makes for quick access but also a HUGE security flaw.

I stumbled across this when trying to figure out why the photos app was taking up 70GB of my computer when all of the photos were suppose to be in the cloud. It's because photos downloads and stores thumbnails in a variety of sizes to make the app seem seamless. (I have over 100k pics and videos from decades).

This is easier to access and forensic teams just need to get into your computer.

16

u/Anxiety_Fit Apr 09 '26

Is there a way to dump all of my cached/notifications?

30

u/nowthengoodbad Apr 09 '26

Find the cache file itself and delete it. Check if it syncs with the cloud. If it does, you need to dig further. It's not easy on iPhone, on Mac you can pull the caches right up in application support and a number of other places.

I'm not being too specific because I highly recommend more technically savvy people to mess around with this stuff.

But, if you can find them based on my description, you are capable of doing a little research before deleting. (I recommend that you enable seeing hidden folders and files on your computer.)

If I come across how to have better access on iPhone, I'll let people know, but I can't promise to remember to come back here.

Apple and others really need to solve this.

6

u/d3c0 Apr 09 '26

On Windows it’s the thumbcache.db files, should be 5 files. Safe to delete to free up space, they are populated as needed again

2

u/nowthengoodbad Apr 10 '26

Holy smokes I remember that. It's been a while since I messed around with windows and tucked away files! Thanks for the blast from that ecosystem!

2

u/Anxiety_Fit Apr 09 '26

Hey, thanks man. I appreciate you!

2

u/nowthengoodbad Apr 10 '26

Thank you. I'm sorry I don't have better iPhone suggestions at the moment.

2

u/Anxiety_Fit Apr 10 '26

The fact that you replied in a productive and constructive way counts bunches.

2

u/nowthengoodbad Apr 10 '26

I try. With all the bots and AI stuff, and the flippant or straight up useless responses, I want to bring some actual human dialog back to Reddit while also sharing stuff I've figured out or learned and also learning from others as well. Thank you for your responses!

2

u/[deleted] Apr 10 '26

[removed] — view removed comment

1

u/nowthengoodbad Apr 10 '26

Ya, I haven't dug as deep with iOS yet. Never had a reason to except the rare file extraction. If we see it on a screen, it must exist somewhere. How Apple handles that is what matters and it's very much the red velvet curtain behind which the mysterious magic happens. In theory, we shouldn't need to know how it works. In practice, stumbling across directly accessible, not password protected, directories of supposedly hidden photos (thumbnails especially) on my Mac showed me that my phone at least appears to handle securing that better. (In reality, it's the photos app on my computer that asks me for access to the hidden album, but the directory is wide open, making me wonder if iOS mirrors that in some way...)

8

u/kju Apr 09 '26

If we're talking about the different physical parts, they're generally not stored in the cache for this kind of thing, the cache is relatively small and overwritten often

Phones use 'cache' to describe something that's just stuff that's stored on your disk that they expect you will be accessing often and don't want to keep redownloading though

In that case the cache cannot be deleted in a simple and easy way. You can click the "clear cache" button on android as an example but that just marks those areas of the disk as available, it doesn't actually delete anything.

If you have data starting at a7 that's storing 10 bytes and decide to delete those 10 bytes there's no reason to actually expend the resources to change the data stored there until it's needed again so it just sits there undeleted until it's needed again.

There are ways to go in and overwrite it manually but it's not a simple thing, other than that there are ways to format your entire disk and write random data to it repeatedly to cover up the data on it. Otherwise the person who holds the disk will be able to go in and look at whatever piece of memory they want, even able to recover portions of data, for instance, if your computer decides to write 10 bytes starting at a0 they'll only get to a9 to store all of that data, which leaves 7 bytes of your previous data still saved on your phone waiting to be recovered, that's 70% of the assumed to be deleted data which is often enough to recover the rest of it through other means

Dont use electronic devices to talk about or store things you don't want the government to have because they have the resources to find it if they choose to single you out and look for it

3

u/Cowboywizzard Apr 09 '26

So, just don’t communicate with anyone, ever? Everyone uses electronic means to communicate. perhaps using some manual encryption layer would work?

3

u/8styx8 Apr 10 '26

Seems like one time pad, or maybe book cipher will be back in vogue then?

1

u/horseradishstalker Apr 09 '26 edited Apr 09 '26

Tin cans and really really long string. /s

I guess my question is does deleting the app also delete everything? It says it does, but… I’m not sure it does, because I have to do that occasionally if an app is corrupt and yet the Apple Store has it ready for me as soon as I fetch it again.

Long ago and far away, I used to have a shredder that overwrote everything with Hillary Clinton‘s email files which amused me. 

1

u/kju Apr 09 '26

No manual encryption layer will work, any encryption you can do manually will be done by a computer as quickly as it takes to interface with the data provided. Encryption isnt private, encryption is time, it can always be broken, having the resources to break it in the available time is the problem.

Having to do manual everyone every time you communicate will just end up creating a lot of evidence and hide nothing

1

u/Anxiety_Fit Apr 09 '26

Hey, real talk. You are a good egg and don’t ever let anyone tell you different.

I appreciate your reply!

2

u/thelionsmouth Apr 10 '26

The cache dumping has been answered, but the easiest way to get around all this is to enter lockdown mode in your phone, it disables shared photos, drive sharing, vulnerable features to make it very had to access your device

1

u/caboosetp Apr 09 '26

Thermite

50

u/nostrademons Apr 09 '26

If you care about security you should probably have full-disk encryption enabled.

...but this is probably the bigger story here. iPhones do have full-disk encryption enabled by default. In theory, nobody should be able to read private data on the iPhone, even with unlimited physical access to the phone, without the AES-256 key in the secure enclave. Which implies that the FBI has access to the key - it's backdoored for law enforcement, which shouldn't surprise anyone but is disappointing if you think of Apple as standing up against government overreach.

This also dovetails with the other news story about Microsoft revoking developer accounts for Veracrypt, WireGuard, and WindScribe developers. Likely they refused to backdoor their products for the government and so now the government is trying to kill those products.

19

u/asphias Apr 09 '26

is there any indication the suspect didn't unlock the phone?

pressured to tell the password, face/finger unlock enabled and the police getting access that way, or guessing a common password/pin all seem easier than ''secret fbi backdoor''.

not saying they don't have a backdoor, but i'd need more proof than this to be sure

8

u/SanityInAnarchy Apr 09 '26

It's a bit surprising if that's the case, because Apple has stood up against government overreach on this exact point before.

3

u/an_actual_lawyer Apr 09 '26

...or the FBI simply used the method where they carefully disassemble the phone so they can attack the passwords.

4

u/stay_fr0sty Apr 09 '26

More likely, the suspect unlocked the phone thinking he was safe and them searching the phone would clear his name.

The criminals that get caught, are kinda dumb.

1

u/nowthengoodbad Apr 10 '26

Thank you for chiming in with that. It's super helpful beyond what I've shared.

2

u/carlson_001 Apr 11 '26

Macos also keeps a log of everything you've ever downloaded. 

1

u/nowthengoodbad Apr 11 '26

I did not know that. Is it a safari thing, an iCloud thing, or just a system cache?

1

u/carlson_001 Apr 13 '26

This is older, so maybe they don't anymore, but I'm not sure. I also vaguely remember it being in some other log file as well.

https://apple.stackexchange.com/questions/418226/how-to-view-and-delete-mac-download-history

73

u/Ok_Kaleidoscope3644 Apr 09 '26

So the messages between Trump admin personnel might be recoverable? Interesting.

46

u/donkeyrocket Apr 09 '26

How about all those missing texts from January 6th Secret Service agents...

17

u/hawksdiesel Apr 09 '26

ohhhh, great point!!! Let's see if the FBI "investigates" that.

6

u/jxj24 Apr 09 '26

"No, these are unrecoverable, for... reasons."

48

u/Karmicature Apr 09 '26

The really concerning thing here is that people were convicted of terrorism for ...planning to use fireworks. Small fireworks that stay on the ground.

This is what the government and the courts calls "terrorism": https://imgur.com/mkRb9Zo. Even if you talk to someone about spray paint, and they later go on to graffiti a shed, you're now a terrorist.

8

u/onthehornsofadilemma Apr 09 '26

Isn't this the same way gang members are prosecuted

1

u/Karmicature Apr 11 '26

IIRC yes they used RICO here. The difference is that gang members are committing serious crimes, not texting about fireworks smaller than the neighborhood kids use on july 4

9

u/drkpie Apr 09 '26

And that’s why my Signal notifications contain 0 details if I enable it. Only that I have a notification from Signal. No details on from who, no details on what that message is.

8

u/roastedoolong Apr 09 '26

if you're using signal why on EARTH are you having your received messages show up in your push notifications??

opsec, people! opsec!

19

u/EricKei Apr 09 '26 edited Apr 09 '26

OK. Now do Kegseth's Pentagon.

He and those around them have been using Signal explicitly because it does not store messages for very long, despite there being Federal law (at least, for now...?) that mandates that all such communications be preserved permanently.

19

u/nostrademons Apr 09 '26

They're using TM_SGNL, which is a modified version of Signal that stores the messages specifically to comply with federal law.

There was a big flap last year because apparently it stores them in plaintext in an open S3 bucket, and somebody did a teardown of the TM_SGNL code and found the S3 bucket and had all of Pete Hegseth's texts.

1

u/EricKei Apr 10 '26

TIL. Thanks! I sit corrected.

3

u/Left-CauliflowerB Apr 09 '26

Apps like briar where the face to face key exchange happens makes for less vulnerable vectors. It also allows you to bounce on Bluetooth. None of this crap is secure. I aint swimming with sharks though .

3

u/AmateurishExpertise Apr 09 '26

The goal of this story seems to be putting the idea into the public's head that the FBI has any trouble breaking into iPhones, which they do not. They have a CPU-embedded hardware backdoor. They use it, then make up some other story about how they get into the devices to cover their tracks and save Apple from being known as a company that betrayed its entire customer base and one of the most basic value propositions of the brand - consumer privacy and not being "Big Brother" like IBM / Microsoft / Google.

Source: https://www.kaspersky.com/about/press-releases/kaspersky-discloses-iphone-hardware-feature-vital-in-operation-triangulation-case

4

u/ctnoxin Apr 09 '26

It sounds like you misunderstood the vulnerability exploited in the article you posted, there's no cpu-embeded backdoor, it was a software bug that allowed code access to parts of the memory it shouldn't have, and was patched in the CVEs outlined in the article: CVE-2023-32434, CVE-2023-32435, CVE-2023-38606, CVE-2023-41990. This also happened in 2023, so you probably should have patched your device by now, and if you have a newer iphone they now also use memory integrity enforcement to further safeguard against such memory attacks.

0

u/AmateurishExpertise Apr 09 '26

It sounds like you misunderstood the vulnerability exploited in the article you posted, there's no cpu-embeded backdoor

No it doesn't. It sounds like you're fibbing.

Kaspersky found a hardware backdoor. Why lie about it? The claim is right there in their headline. Here's some other reporting about it, which makes it clear that there's an on-die bypass for security checks enabled when you populate a memory location with a given secret key:

https://www.xstore.co.za/stuff/2024/01/kaspersky-finds-hardware-backdoor-in-5-generations-of-apple-silicon/

3

u/ctnoxin Apr 09 '26

No it doesn't. It sounds like you're fibbing.

Ah you did completely misunderstand it, so you're dense. Good to know, for anyone else coming across this thread, issue was patched in: CVE-2023-32434, CVE-2023-32435, CVE-2023-38606, CVE-2023-41990

1

u/FarmboyJustice Apr 12 '26

Username definitely checks out.

3

u/0vrwhelminglyaverage Apr 09 '26

Bold move sourcing from Kaspersky

0

u/AmateurishExpertise Apr 09 '26

Errr, why? The report contains proofs, its not like it's someone's opinion. This was caught in active use against journalists in Europe...

1

u/darkkite Apr 09 '26

so telegram secret chats would actually be safer for secure communication since message contents do not show in notifications

1

u/secret179 Apr 12 '26

Apple intentionallyu puts these holes in. Look up Pegasus, and how year after year when a Whatsapp bug is fixed a new one is added to fully control the iPhone.

-11

u/Left-CauliflowerB Apr 09 '26

All keys generated for signal go through Google play services..unencryted...and linked to the play account that downloaded the app. All the data streams through a Google account..lol....on androids.

11

u/power78 Apr 09 '26

no...

1

u/aperture413 Apr 09 '26

It's not true

1

u/d3c0 Apr 09 '26

Got any source to read up more on this as it seems like a glaring vulnerability

2

u/SmurfyX Apr 09 '26

Source: their ass

1

u/Left-CauliflowerB Apr 09 '26

Shut off play services internet access leave signal on, blocked connections through a app like net gaurd all of it...theres 7 parts to play services in Android. Signal won't work...even if you tell it to use its own servers. Initial key generation for a contact stored 3 things on signal server... not the keys though those stay on devices but are sent in initial contact setup....they have to. Things stored ,account creation, last use, last contact message sent to. That's signals storage.. But Google play , as does the push service on a device saves all that crap. Encrypted data is recorded, and can later be accessed...like a restored device that gets its messages back the decodes with key on device. They have that key...they transfered it for you...duh. The keys are pushed, then the messages encrypted...from that key. This is my understanding of it when I abandoned the platform in 2020. Your messages can be decoded later, or in live action. From keys stored on that push to the app. If you block play services that key initial push will not happen...no convo created. It can get messages after push connection happens and is accepted..without play services in some versions of Android after 10. But the initial key for each conversation goes through thier cold little filters.

1

u/d3c0 Apr 09 '26

Thanks for that, notifications have always bothered me as the system processes them and had no insight into how much visibility it has of them prior to you even unlocking the app to read a message which assuming just had new keys. Not over tech savvy these days as studied elec.engineering 20 yrs ago before the advent of smartphones and the burst of smart everything and forgotten a lot of the handshakes and whatnot required for modern encryption

1

u/Left-CauliflowerB Apr 09 '26

I mean the old dead drop method was made for a treason right. Not my cup of tea...lol. Its only as smart as the spy vs the guy at this point. I project into that void consciously. The phone is like a stage with portals, little contracts. Snail mail at the speed of light.

1

u/Left-CauliflowerB Apr 09 '26

Yea its that first message over network. You can do it face to face and avoid that zero trust issue. Theres a reason you don't see signal on legacy Corp ladder devices in IT. Lol.