Live data from Hacker News

Your Computer Isn't Yours

sneak.berlin

1–10 of 764 posts

Re: Your Computer Isn't Yours

#2
“In other news, Apple has quietly backdoored the end-to-end cryptography of iMessage.”

Is this substantiated somewhere? It seems like a big deal if there is any truth to it.

Re: Your Computer Isn't Yours

#3
post #2

“In other news, Apple has quietly backdoored the end-to-end cryptography of iMessage.” Is this substantiated somewhere? It seems like a big deal if there is any truth to it.

It's explained right there in the text: it's via iCloud Backup, which Apple makes no secrets about:

- backing up your iMessages: https://support.apple.com/en-us/HT207428

- not being end to end encrypted: https://support.apple.com/en-us/HT202303

It's listed as being "encrypted in storage" and "encrypted in transit", which is a fancy way of saying "we use encrypted disks and TLS, all of which we have the keys for".

Further down on the page, they have a list of things that are end-to-end encrypted. iCloud Backups are not in that list.

It's not a secret.

Re: Your Computer Isn't Yours

#4
post #3
post #2

“In other news, Apple has quietly backdoored the end-to-end cryptography of iMessage.” Is this substantiated somewhere? It seems like a big deal if there is any truth to it.

It's explained right there in the text: it's via iCloud Backup, which Apple makes no secrets about: - backing up your iMessages: https://support.apple.com/en-us/HT207428 - not being end to end encrypted: https://support.apple.com/en-us/HT202303 It's listed as being "encrypted in storage" and "encrypted in transit", which is a fancy way of saying "we use encrypted disks and TLS, all of which we have the keys for". Fur…

Ok - so it’s complete bullshit. iMessage is end to end encrypted. There is no back door. The article is lying.

On the other hand it’s true that iCloud backups are not encrypted. That’s a major problem. Worse in many ways since all your private documents, tax returns etc, are in there too.

But let’s not lie about iMessage not being end to end encrypted. It certainly is.

The problem is that the end is then backed up to an unencrypted disk.

These two things are not equivalent. In one instance Apple can be compelled to provide access. In the other instance any man in the middle can intercept.

Please - there are real problems to criticize Apple for. Let’s not muddy the water with lies.

Re: Your Computer Isn't Yours

#5
post #4
post #3

Earlier quoted context omitted.

It's explained right there in the text: it's via iCloud Backup, which Apple makes no secrets about: - backing up your iMessages: https://support.apple.com/en-us/HT207428 - not being end to end encrypted: https://support.apple.com/en-us/HT202303 It's listed as being "encrypted in storage" and "encrypted in transit", which is a fancy way of saying "we use encrypted disks and TLS, all of which we have the keys for". Fur…

Ok - so it’s complete bullshit. iMessage is end to end encrypted. There is no back door. The article is lying. On the other hand it’s true that iCloud backups are not encrypted. That’s a major problem. Worse in many ways since all your private documents, tax returns etc, are in there too. But let’s not lie about iMessage not being end to end encrypted. It certainly is. The problem is that the end is then backed up to…

iCloud Backup, on by default, backs up the complete plaintext iMessage history to Apple via the network, automatically, using Apple keys.

It also backs up the device's iMessage keys, to Apple via the network, automatically, using Apple keys. That's called key escrow.

The plaintext message content backup bypasses the end-to-end encryption entirely, providing the service-in-the-middle with complete plaintext.

Apple is the only "man in the middle" for iMessage - all encrypted iMessages transit their servers (using TLS, separate from the iMessage message encryption). Apple, via software changes, has gained possession of the user's iMessage key, and the message is no longer opaque to them when relaying it, and it is not end-to-end encrypted. The party in the middle (Apple) can read all of the messages, just as if it were two different TLS sessions to each user with no encrypted payload (the way most non-e2e messaging is implemented).

Alternately, if Apple, via software changes, has caused the plaintext message content to be relayed back to Apple post-decryption, it is no longer end-to-end encrypted, as the service in the middle is no longer zero-knowledge, and has come into possession of the plaintext.

If that's not a backdoor, I don't know what is.

EDIT: (responding to comment below, throttled)

From https://support.apple.com/en-us/HT202303

> Messages in iCloud also uses end-to-end encryption. If you have iCloud Backup turned on, your backup includes a copy of the key protecting your Messages. This ensures you can recover your Messages if you lose access to iCloud Keychain and your trusted devices. When you turn off iCloud Backup, a new key is generated on your device to protect future messages and isn't stored by Apple.

So if you have "Messages in iCloud" enabled, it backs up your iMessage encryption key (Apple already has the ciphertext from the iMessage service). If you have "Messages in iCloud" disabled, it backs up the plaintext of the messages themselves from your device.

In both cases, Apple can read all of your iMessages, either because their software on your device gave them the key (iCloud Backup=on, Messages in iCloud=on), or because their software on your device gave them the plaintext (iCloud Backup=on, Messages in iCloud=off).

Re: Your Computer Isn't Yours

#6
post #5
post #4

Earlier quoted context omitted.

Ok - so it’s complete bullshit. iMessage is end to end encrypted. There is no back door. The article is lying. On the other hand it’s true that iCloud backups are not encrypted. That’s a major problem. Worse in many ways since all your private documents, tax returns etc, are in there too. But let’s not lie about iMessage not being end to end encrypted. It certainly is. The problem is that the end is then backed up to…

iCloud Backup, on by default, backs up the complete plaintext iMessage history to Apple via the network, automatically, using Apple keys. It also backs up the device's iMessage keys, to Apple via the network, automatically, using Apple keys. That's called key escrow. The plaintext message content backup bypasses the end-to-end encryption entirely, providing the service-in-the-middle with complete plaintext. Apple is…

Can you substantiate that the keys are backed up?

Is messages in iCloud on by default? I remember being asked.

Re: Your Computer Isn't Yours

#7
Thanks for summarizing a bunch of changes that make me depressed about modern computing. Now Android, 'privacy apple' macOS, iOS & Windows all act in similar way. The only thing left is bad user experience linux.

Re: Your Computer Isn't Yours

#8
post #7

Thanks for summarizing a bunch of changes that make me depressed about modern computing. Now Android, 'privacy apple' macOS, iOS & Windows all act in similar way. The only thing left is bad user experience linux.

I've opted to purchase the new MBAir, and will only use it in conjunction with a travel router, on which I have root, and can default-deny all network traffic from the laptop except for the stuff I explicitly permit. Dual-Wi-Fi, small travel routers will run for quite some time on a USB battery pack.

I've been meaning to do this for some time anyway, due to the pervasive spyware that's embedded in most iOS apps, which Apple explicitly permits in the App Store. One travel router device should serve me for phone+tablet+laptop. I'll probably have it just do LTE+WireGuard back to a server I run, and then do all of the filtering/monitoring on the VPN server.

It sucks that it's come to this. Hopefully Apple can find their way back. I have a machine running KDE Plasma, which is worlds better than it was in years past, but still has enough rough edges compared to macOS's mirror sheen that it's annoying to use. I'm keeping my intel rMBP 16" I just got as it's likely the last machine of this quality level that will be able to run such a system.

Re: Your Computer Isn't Yours

#9
post #5
post #4

Earlier quoted context omitted.

Ok - so it’s complete bullshit. iMessage is end to end encrypted. There is no back door. The article is lying. On the other hand it’s true that iCloud backups are not encrypted. That’s a major problem. Worse in many ways since all your private documents, tax returns etc, are in there too. But let’s not lie about iMessage not being end to end encrypted. It certainly is. The problem is that the end is then backed up to…

iCloud Backup, on by default, backs up the complete plaintext iMessage history to Apple via the network, automatically, using Apple keys. It also backs up the device's iMessage keys, to Apple via the network, automatically, using Apple keys. That's called key escrow. The plaintext message content backup bypasses the end-to-end encryption entirely, providing the service-in-the-middle with complete plaintext. Apple is…

Just turn off iCloud backup. It’s what I do.

Re: Your Computer Isn't Yours

#10
post #9
post #5

Earlier quoted context omitted.

iCloud Backup, on by default, backs up the complete plaintext iMessage history to Apple via the network, automatically, using Apple keys. It also backs up the device's iMessage keys, to Apple via the network, automatically, using Apple keys. That's called key escrow. The plaintext message content backup bypasses the end-to-end encryption entirely, providing the service-in-the-middle with complete plaintext. Apple is…

Just turn off iCloud backup. It’s what I do.

And everyone you iMessage with? Both parties to the conversation have the plaintext and a key that will decrypt the whole conversation.

Unless you are 100% certain that everyone you iMessage with has also done this, your conversations are still not reliably private.

Even then, Apple can silently inject additional escrowed wiretap keys into the keylist for one or both participants, although this is an active attack and can be detected by monitoring changes to the keylist for a given phone number or Apple ID provided by Apple's iMessage APIs.

Post reply on HN