Your Computer Isn't Yours
sneak.berlin
Your Computer Isn't Yours
1–10 of 764 posts
Re: Your Computer Isn't Yours
#2Is this substantiated somewhere? It seems like a big deal if there is any truth to it.
Re: Your Computer Isn't Yours
#3“In other news, Apple has quietly backdoored the end-to-end cryptography of iMessage.” Is this substantiated somewhere? It seems like a big deal if there is any truth to it.
- backing up your iMessages: https://support.apple.com/en-us/HT207428
- not being end to end encrypted: https://support.apple.com/en-us/HT202303
It's listed as being "encrypted in storage" and "encrypted in transit", which is a fancy way of saying "we use encrypted disks and TLS, all of which we have the keys for".
Further down on the page, they have a list of things that are end-to-end encrypted. iCloud Backups are not in that list.
It's not a secret.
Re: Your Computer Isn't Yours
#4“In other news, Apple has quietly backdoored the end-to-end cryptography of iMessage.” Is this substantiated somewhere? It seems like a big deal if there is any truth to it.
It's explained right there in the text: it's via iCloud Backup, which Apple makes no secrets about: - backing up your iMessages: https://support.apple.com/en-us/HT207428 - not being end to end encrypted: https://support.apple.com/en-us/HT202303 It's listed as being "encrypted in storage" and "encrypted in transit", which is a fancy way of saying "we use encrypted disks and TLS, all of which we have the keys for". Fur…
On the other hand it’s true that iCloud backups are not encrypted. That’s a major problem. Worse in many ways since all your private documents, tax returns etc, are in there too.
But let’s not lie about iMessage not being end to end encrypted. It certainly is.
The problem is that the end is then backed up to an unencrypted disk.
These two things are not equivalent. In one instance Apple can be compelled to provide access. In the other instance any man in the middle can intercept.
Please - there are real problems to criticize Apple for. Let’s not muddy the water with lies.
Re: Your Computer Isn't Yours
#5Earlier quoted context omitted.
It's explained right there in the text: it's via iCloud Backup, which Apple makes no secrets about: - backing up your iMessages: https://support.apple.com/en-us/HT207428 - not being end to end encrypted: https://support.apple.com/en-us/HT202303 It's listed as being "encrypted in storage" and "encrypted in transit", which is a fancy way of saying "we use encrypted disks and TLS, all of which we have the keys for". Fur…
Ok - so it’s complete bullshit. iMessage is end to end encrypted. There is no back door. The article is lying. On the other hand it’s true that iCloud backups are not encrypted. That’s a major problem. Worse in many ways since all your private documents, tax returns etc, are in there too. But let’s not lie about iMessage not being end to end encrypted. It certainly is. The problem is that the end is then backed up to…
It also backs up the device's iMessage keys, to Apple via the network, automatically, using Apple keys. That's called key escrow.
The plaintext message content backup bypasses the end-to-end encryption entirely, providing the service-in-the-middle with complete plaintext.
Apple is the only "man in the middle" for iMessage - all encrypted iMessages transit their servers (using TLS, separate from the iMessage message encryption). Apple, via software changes, has gained possession of the user's iMessage key, and the message is no longer opaque to them when relaying it, and it is not end-to-end encrypted. The party in the middle (Apple) can read all of the messages, just as if it were two different TLS sessions to each user with no encrypted payload (the way most non-e2e messaging is implemented).
Alternately, if Apple, via software changes, has caused the plaintext message content to be relayed back to Apple post-decryption, it is no longer end-to-end encrypted, as the service in the middle is no longer zero-knowledge, and has come into possession of the plaintext.
If that's not a backdoor, I don't know what is.
EDIT: (responding to comment below, throttled)
From https://support.apple.com/en-us/HT202303
> Messages in iCloud also uses end-to-end encryption. If you have iCloud Backup turned on, your backup includes a copy of the key protecting your Messages. This ensures you can recover your Messages if you lose access to iCloud Keychain and your trusted devices. When you turn off iCloud Backup, a new key is generated on your device to protect future messages and isn't stored by Apple.
So if you have "Messages in iCloud" enabled, it backs up your iMessage encryption key (Apple already has the ciphertext from the iMessage service). If you have "Messages in iCloud" disabled, it backs up the plaintext of the messages themselves from your device.
In both cases, Apple can read all of your iMessages, either because their software on your device gave them the key (iCloud Backup=on, Messages in iCloud=on), or because their software on your device gave them the plaintext (iCloud Backup=on, Messages in iCloud=off).
Re: Your Computer Isn't Yours
#6Earlier quoted context omitted.
Ok - so it’s complete bullshit. iMessage is end to end encrypted. There is no back door. The article is lying. On the other hand it’s true that iCloud backups are not encrypted. That’s a major problem. Worse in many ways since all your private documents, tax returns etc, are in there too. But let’s not lie about iMessage not being end to end encrypted. It certainly is. The problem is that the end is then backed up to…
iCloud Backup, on by default, backs up the complete plaintext iMessage history to Apple via the network, automatically, using Apple keys. It also backs up the device's iMessage keys, to Apple via the network, automatically, using Apple keys. That's called key escrow. The plaintext message content backup bypasses the end-to-end encryption entirely, providing the service-in-the-middle with complete plaintext. Apple is…
Is messages in iCloud on by default? I remember being asked.
Re: Your Computer Isn't Yours
#7Re: Your Computer Isn't Yours
#8Thanks for summarizing a bunch of changes that make me depressed about modern computing. Now Android, 'privacy apple' macOS, iOS & Windows all act in similar way. The only thing left is bad user experience linux.
I've been meaning to do this for some time anyway, due to the pervasive spyware that's embedded in most iOS apps, which Apple explicitly permits in the App Store. One travel router device should serve me for phone+tablet+laptop. I'll probably have it just do LTE+WireGuard back to a server I run, and then do all of the filtering/monitoring on the VPN server.
It sucks that it's come to this. Hopefully Apple can find their way back. I have a machine running KDE Plasma, which is worlds better than it was in years past, but still has enough rough edges compared to macOS's mirror sheen that it's annoying to use. I'm keeping my intel rMBP 16" I just got as it's likely the last machine of this quality level that will be able to run such a system.
Re: Your Computer Isn't Yours
#9Earlier quoted context omitted.
Ok - so it’s complete bullshit. iMessage is end to end encrypted. There is no back door. The article is lying. On the other hand it’s true that iCloud backups are not encrypted. That’s a major problem. Worse in many ways since all your private documents, tax returns etc, are in there too. But let’s not lie about iMessage not being end to end encrypted. It certainly is. The problem is that the end is then backed up to…
iCloud Backup, on by default, backs up the complete plaintext iMessage history to Apple via the network, automatically, using Apple keys. It also backs up the device's iMessage keys, to Apple via the network, automatically, using Apple keys. That's called key escrow. The plaintext message content backup bypasses the end-to-end encryption entirely, providing the service-in-the-middle with complete plaintext. Apple is…
Re: Your Computer Isn't Yours
#10Earlier quoted context omitted.
iCloud Backup, on by default, backs up the complete plaintext iMessage history to Apple via the network, automatically, using Apple keys. It also backs up the device's iMessage keys, to Apple via the network, automatically, using Apple keys. That's called key escrow. The plaintext message content backup bypasses the end-to-end encryption entirely, providing the service-in-the-middle with complete plaintext. Apple is…
Just turn off iCloud backup. It’s what I do.
Unless you are 100% certain that everyone you iMessage with has also done this, your conversations are still not reliably private.
Even then, Apple can silently inject additional escrowed wiretap keys into the keylist for one or both participants, although this is an active attack and can be detected by monitoring changes to the keylist for a given phone number or Apple ID provided by Apple's iMessage APIs.