• MarmaladeMermaid@lemm.ee
    link
    fedilink
    English
    arrow-up
    3
    arrow-down
    8
    ·
    10 months ago

    The only push notifications I get are from post mates.

    What other, more sensitive information would they be collecting this way?

    • PM_Your_Nudes_Please@lemmy.world
      link
      fedilink
      English
      arrow-up
      11
      ·
      10 months ago

      Pretty much any app that has message details in the notification. For instance, if I get a comment response on Lemmy, my app sends a push notification. If that notification contains details about the message, the government would supposedly be able to read that data.

      Secure messaging apps have moved away from including message info specifically for this reason. For instance, Signal only sends a notification that you received a message. The push notification doesn’t say who the message was from, or what the message said.

      But when Snapchat tells you that a specific friend is typing/has sent a message, the government could conceivably see that and connect you to that person. Maybe not a huge deal if it’s just a friend with nothing to hide. But we all know that “you have nothing to hide so you have nothing to fear” is a horrible excuse. Because it could land you on a list if that friend is a dealer, or becomes radicalized in the future, or has family who has ties to illegal activity, or any number of other things that the government may want to start watching them for.

      • brbposting@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        4
        ·
        10 months ago

        …Signal only sends a notification that you received a message.

        Signal on iOS shows previews by default. It even reads messages over AirPods as they come in.

        iOS must be doing something special here, right? They can’t be sending message contents through the same route as push notification metadata, or it would be breaking end-to-end encryption… right?

        • NotMyOldRedditName@lemmy.world
          link
          fedilink
          English
          arrow-up
          4
          ·
          10 months ago

          Correct, messages aren’t E2E encrypted if the push has the data.

          If there’s any reason to preserve privacy the push only has an identifier of the message to be downloaded on the device. When it comes in, the device downloads it and then if you’ve allowed it, will show it on a notification

      • MarmaladeMermaid@lemm.ee
        link
        fedilink
        English
        arrow-up
        3
        ·
        10 months ago

        Oh, got it. I turn all those off to avoid being bothered. Post mates is only on so I don’t miss it if “the driver is trying to contact” me.

        Does this apply to when I get a text or voice message on my iPhone? There is a message preview before clicking on it.