Hacker Newsnew | past | comments | ask | show | jobs | submit | itsthecourier's commentslogin

Push-to-Sync. We observed 8 apps employ a push-to-sync strat- egy to prevent privacy leakage to Google via FCM. In this mitigation strategy, apps send an empty (or almost empty) push notification to FCM. Some apps, such as Signal, send a push notification with no data (aside from the fields that Google sets; see Figure 4). Other apps may send an identifier (including, in some cases, a phone num- ber). This push notification tells the app to query the app server for data, the data is retrieved securely by the app, and then a push notification is populated on the client side with the unencrypted data. In these cases, the only metadata that FCM receives is that the user received some message or messages, and when that push noti- fication was issued. Achieving this requires sending an additional network request to the app server to fetch the data and keeping track of identifiers used to correlate the push notification received on the user device with the message on the app server.


Is that not still incredibly vulnerable to timing attacks?


Maybe I’m mis-interpreting what you mean, but without a notification when a message is sent, what would you correlate a message-received notification with?


saw an xpeng playing music outside the car, not inside, for beach parties

and, this is not a joke, truly: the seat gave me a massage.


just got an etron because my partner wanted a xpeng, guy is super happy in that xpeng and I gotta say, he's right


Etron is Audi?


great analysis


I was reading about Porsche this week on reddit. lots of complaints about Taycans.

always have been a fan of Porsche.

hope they find the way forward


feel the same, but I moved up. create full products and profit from them. you have a great taste if you know what's behind


it must be done



good examples


I use it on a 10 years codebase, needs to explain where to get context but successfully works 90% of time


the longest case I know is a guy in big crypto who after a fallout was taking care of a zombie company for about a year and half, full pay, practically 1 or 2 hours of work some of the weeks


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: