• bearboiblake [he/him]@pawb.social
    link
    fedilink
    English
    arrow-up
    1
    ·
    24 days ago

    It always bears repeating, push notifications are not private, neither for Android, GrapheneOS, nor iOS, even if you use end-to-end encryption. If you are privacy conscious, you should either use settings to hide sensitive data from push notifications or turn them off altogether.

    • MrSoup@lemmy.zip
      link
      fedilink
      English
      arrow-up
      1
      ·
      edit-2
      24 days ago

      If you turn off notification history on Android, should be enough to avoid such “attacks”. Hiding sensitive content inside notifications only hides it in the lock screen. If your OS keeps a clear log of them, it’s useless.

      Edit: didn’t know Signal actually has settings to hide their own notifications. I was thinking about Android’s “hide sensitive content” setting.

      • 4am@lemmy.zip
        link
        fedilink
        English
        arrow-up
        1
        ·
        24 days ago

        Notifications go through FireBase Cloud Messaging (FCM) on Android. They bounce off a Google server. Even from local, on-device apps.

        Same with iOS.

        They can read and store every one of them, and you don’t control the encryption keys.

        • Björn@swg-empire.de
          link
          fedilink
          English
          arrow-up
          1
          ·
          24 days ago

          But they only instruct Signal to wake up and download whatever is waiting. They don’t contain the message contents.