惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
DataBreaches.Net
N
Netflix TechBlog - Medium
P
Proofpoint News Feed
D
Docker
J
Java Code Geeks
L
LangChain Blog
Microsoft Security Blog
Microsoft Security Blog
The GitHub Blog
The GitHub Blog
I
InfoQ
Stack Overflow Blog
Stack Overflow Blog
云风的 BLOG
云风的 BLOG
Engineering at Meta
Engineering at Meta
MongoDB | Blog
MongoDB | Blog
月光博客
月光博客
T
Tailwind CSS Blog
M
MIT News - Artificial intelligence
Blog — PlanetScale
Blog — PlanetScale
Google DeepMind News
Google DeepMind News
腾讯CDC
罗磊的独立博客
U
Unit 42
爱范儿
爱范儿
Vercel News
Vercel News
MyScale Blog
MyScale Blog

WIRED

‘Avatar: Aang, The Last Airbender’ Leaked Online. Some Fans Say Paramount Deserves the Fallout NASA Wants to Put Nuclear Reactors on the Moon AI Could Democratize One of Tech's Most Valuable Resources Microsoft Surface PCs Are Getting Big Price Hikes, and the Cheaper Models Are Going Away Why Amazon Is Buying Globalstar—and What It Means for Your iPhone The US Government Will Ask Data Centers How Much Power They Use MAGA Is Starting to Look Beyond Trump Allbirds Is Pivoting to AI Compute. Sure, Why Not Best Smart Smoke Detector (and Why You Still Need a Dumb One) 12 Best Standing Desks of 2026, Tested and Reviewed Best Wi-Fi Routers of 2026 for Working, Gaming, and Streaming Best GoPro Camera (2026): Compact, Budget, Accessories The Caves That Could Help Us Find, or Become, Aliens AI Slop Is Making the Internet Fake-Happy The Deepfake Nudes Crisis in Schools Is Much Worse Than You Thought In the Wake of Anthropic’s Mythos, OpenAI Has a New Cybersecurity Model—and Strategy Telegram Is Still Hosting a Sanctioned $21 Billion Crypto Scammer Black Market The FCC Has a Fast Lane for Complaints About Trump’s Media Critics Top iRestore Deals for Hair Growth and LED Therapy Devices Meta Is Warned That Facial Recognition Glasses Will Arm Sexual Predators You Should Be More Freaked Out by Shingles BYD’s Fastest-Charging Car in the World Is Astonishing—in Good and Bad Ways The 4 Best Water Filter Pitchers (2026): PFAS, Microplastics The Internet's Most Powerful Archiving Tool Is in Peril The Dumbest Hack of the Year Exposed a Very Real Problem AI Agents Are Coming for Your Dating Life ‘The Audacity’ Is the Broligarchy Takedown You Were Waiting For Why Is It So Hard to Fix an Electric Bike? (2026) Best 2-in-1 Laptops (2026): Microsoft, Lenovo, and the iPad There’s a Secret Ingredient to Making Luxury Ice at Home
Your Phone Notifications Reveal More Than You Realize. He...
David Nield · 2026-04-29 · via WIRED

You may have spotted the recent case of the US Federal Bureau of Investigation pulling Signal messages from a defendant's iPhone, even though the messages were set to disappear automatically, and the Signal app itself had been deleted from the phone.

The trick used by law enforcement? Previews of each incoming Signal message were logged in the notification database kept by iOS. Even though Signal had deleted the conversations, and Signal itself was deleted, this database was still available to the FBI's forensics teams.

There is some good news: Apple has pushed out an iOS 26.4.2 update that makes sure notification logs are properly cleaned up after the notifications have expired. Make sure your iPhone is updated (via General > Software Update) and you should be protected against this type of intrusion.

Still, the events are concerning for anyone interested in protecting their own privacy. And even though Apple has improved iOS’s housekeeping, there are steps you can take to further minimize your risk in similar circumstances.

What Did the FBI Do?

Unsurprisingly, the FBI is reluctant to provide step-by-step instructions for how it breaks into smartphones and extracts data. Nevertheless, through reporting by 404 Media and analysis from experts such as cybersecurity specialist Andrea Fortuna, we can make some educated guesses about what happened.

What seems clear is that the forensics team didn't break Signal's encryption, or hack into any Signal database, but focused its attention on the database of notifications logged by iOS. It's notable that the FBI could only extract incoming messages rather than outgoing ones, because messages being sent out from a device wouldn't show up in a notification.

Given that Apple keeps iOS pretty tightly locked down, it seems likely that the analyzed iPhone was unlocked, or at least in an After First Unlock (AFU) state. When a phone reboots and first presents the lock screen, that's a Before First Unlock (BFU) state—but when you subsequently lock and unlock your phone through the day, that's AFU.

Image may contain Text

Even though an app's messages may be gone, its notifications aren't.Photograph: David Nield

Both states show the lock screen and keep your phone protected from unwelcome visitors, but BFU comes with some extra security and encryption measures. It's one of the reasons Android phones now auto-reboot if they haven't been used for three days—because that very first unlock screen after a restart is slightly more secure.

Your friends and family—and probably most of the people likely to steal your phone—will be stumped by both AFU and BFU. But for the advanced hacking tools most probably used by the FBI, BFU presents more of a challenge. We don't know for sure based on the information that's public, but the chances are that the iPhone in this case was in an AFU state or unlocked entirely.

The 404 Media report mentions that the FBI had both physical access to the iPhone and “specialized software” to run on it, so this isn't a hack you're going to be hit by often. However, there are ways to make sure your message history can never be recovered.

How Can You Protect Yourself?

As the Electronic Frontier Foundation notes, we don't know much about the notification logs stored by iOS or Android. One key question is whether or not these logs are backed up to the cloud, which may mean they can be requested by law enforcement. (In the US, both Apple and Google need a judge's order before they'll agree to this.)

There's no setting on your phone to wipe these notification logs or to stop them from being created and updated, short of completely resetting your handset. That will clear everything off it, notification logs and all—but it's probably not something you want to have to do every day. The recent iOS security update also takes steps to more effectively clear the logs of notifications that have been marked for deletion.

An easier fix is to stop message content from appearing in notifications, so it never gets logged at all. In Signal you can do this by tapping your profile picture (top left), then choosing Notifications and Show to hide the message contents. Other apps are rather hit and miss on this feature—WhatsApp offers something similar, for example, but only on iOS (pick Notifications > Show preview from the You tab).

Image may contain Text

You can cut out message content from Signal notifications.

Photograph: David Nield

Another step you can take is to restrict notifications at the system level. From iOS Settings, pick Notifications, then an app, and disable Show Previews. From Android Settings, choose Notifications > Notifications on lock screen > Show sensitive content. Both iOS and Android also let you block notifications entirely for individual apps.

If you're prepared to live with fewer informative notifications, or fewer notifications in general, you should be safer. However, the details remain murky as to what a phone's internal notification log might record, even if these pop-ups aren't being shown to the user. It's possible we'll see some more changes in this regard in future versions of iOS—and some changes to Android too—in the light of this high-profile case.

In general, reboot your phone often, limit notifications where possible, and maybe even leave your phone at home in some higher-risk situations. Just remember that you can only protect one half of the conversations you have, so you're going to need to pass this advice on to the people you communicate with to make sure the other half is covered too.