latentbrief
Back to news
General2w ago

Push Notifications: A New Frontier for Privacy Risks

EFF Deeplinks

In brief

  • Push notifications, those little alerts on your phone, can reveal a lot about you.
  • They’re so significant that Apple and Google now require court orders before sharing notification data with law enforcement.
  • However, even with this requirement, Apple has shared data on hundreds of users.
  • Additionally, forensic tools used by law enforcement can recover deleted messages from notifications, including those from secure apps like Signal.
  • The risk lies in two areas: when notifications travel through the cloud and once they reach your device.
  • On iOS or Android, notifications go through Apple or Google’s servers first.
    • These companies can see notification content, though some apps, like Signal, hide it.
  • Once on your phone, settings determine if notifications appear on your lock screen, which could be risky if your device is lost or confiscated.
  • Moreover, cleared notifications are saved in your device’s storage and might remain even after deleting the app.
  • The duration of this storage and whether data is backed up to the cloud are still unclear.
    • This means your privacy could be at risk beyond just active use of apps.
  • Stay informed about how these systems evolve to protect your data better.

Terms in this brief

forensic tools
Specialized software and techniques used by law enforcement to analyze digital devices and recover deleted data. These tools can uncover information from notifications even after they've been removed from your phone, potentially compromising privacy.
Signal
A secure messaging app designed to protect user privacy by encrypting messages so that only the sender and recipient can read them. Despite its security features, forensic tools can still recover deleted messages from it, raising concerns about privacy protection.

Read full story at EFF Deeplinks

More briefs