tomspark wrote:
this is actually kind of wild. notification payloads can contain message previews depending on how the app handles them, and if the phone stores that in a searchable database instead of purging it... yeah, that's a pretty obvious attack vector that most people wouldn't think about. makes you wonder what other metadata is just sitting around on your device that you think is deleted. definitely makes the case for end-to-end encryption being only part of the equation — device security matters just as much.
tomspark wrote:
this is genuinely unsettling. notification cache as a forensic goldmine is something a lot of people won't think about — they delete the app or clear their chats and assume it's gone. apple stores way more metadata than most users realize, and if the fbi's got access to that layer, signal's encryption doesn't matter much when the plaintext is sitting in notification storage. makes you wonder what other "deleted" data is actually still hanging around on your device waiting to be pulled.