Live data from Hacker News

Signal says it won’t compromise on encryption

theverge.com

31–40 of 336 posts

Re: Signal says it won’t compromise on encryption

#31
post #7
post #4

Reminder that Apple did this domestically for the FBI/iMessage. They intentionally maintain a backdoor in the end to end crypto of iMessage: https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...

This is incorrect. iMessage is encrypted, the encryption is end-to-end, there are no backdoors. The unencrypted backup is a clear and annoying hole in the apple privacy story, but the non-e2ee iCloud backup does not include any messages (SMS, MMS, or iMessage), Contacts, Calendars, Notes, iCloud Photos, or health data. A local backup is local, and is protected by filesystem encryption on your local storage. So no, iM…

> iMessage is encrypted, the encryption is end-to-end, there are no backdoors.

How would/could we know? If the NSA doesn't have a backdoor (whether that's in the non-public iMessage code, the hardware RNG on iPhones, or somewhere else), what are they even doing all day?

Re: Signal says it won’t compromise on encryption

#33
post #7
post #4

Reminder that Apple did this domestically for the FBI/iMessage. They intentionally maintain a backdoor in the end to end crypto of iMessage: https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...

This is incorrect. iMessage is encrypted, the encryption is end-to-end, there are no backdoors. The unencrypted backup is a clear and annoying hole in the apple privacy story, but the non-e2ee iCloud backup does not include any messages (SMS, MMS, or iMessage), Contacts, Calendars, Notes, iCloud Photos, or health data. A local backup is local, and is protected by filesystem encryption on your local storage. So no, iM…

iCloud Backup is effectively unencrypted and on by default, and sends the end device keys to Apple. Apple knows this, and went about encrypting iCloud Backups (like Google does on Android) but then stopped to preserve this vulnerability to avoid antagonizing the FBI, leaving Apple in possession of cleartext endpoint keys of all of their customers. Approximately nobody uses local iOS backups because iCloud Backup is enabled by default (even if you don't want to use iCloud and only log in with your Apple ID to install apps in the App Store).

If the middle relay service has the keys, it's not end to end encrypted.

The non-e2ee iCloud Backup does include your photos, includes your messages (if you have Messages in iCloud disabled) or includes your message sync keys (which are equivalent to your messages) if you have Messages in iCloud enabled. Your photos, contacts, calendars, notes, etc are never end to end encrypted and don't even pretend to be.

Even if you disable iCloud Backup and do only local backups: everyone you iMessage with will have iCloud Backup still enabled, sending either the sync keys (Messages in iCloud on) or the messages themselves (Messages in iCloud off) to Apple in plaintext in the backup that is done automatically each night.

Re: Signal says it won’t compromise on encryption

#34
post #16

Earlier quoted context omitted.

If my iPhone got run over by a truck, and I log in my apple ID to another iPhone, will I get my messages back?

Nope, unless you’re using iCloud backup, or your messages can be synced from other devices in the key ring.

No this is the whole point: if you are using iCloud backups, your messages are not backed up.

The _only_ online way to maintain your iMessages is (checks settings) "Messages in the Cloud", which is e2e encrypted - if you lose all your devices there is no recovery path except for the "iCloud Key Vault", but I honestly don't know if that can get you to a point where old messages can be recovered.

Re: Signal says it won’t compromise on encryption

#35

India wants to read everything? Why don't they just forbid the use of https. So that everyone can read everything on the internet

I read the linked source. Could not find any reference to any Indian law or Govt. order. Can you please point me to any source with credible information on the supposed provisions which are causing Signal to "exit" India.

Re: Signal says it won’t compromise on encryption

#36

India wants to read everything? Why don't they just forbid the use of https. So that everyone can read everything on the internet

I read the linked source. Could not find any reference to any Indian law or Govt. order. Can you please point me to any source with credible information on the supposed provisions which are causing Signal to "exit" India.

https://www.hindustantimes.com/india-news/govt-proposes-law-...

Re: Signal says it won’t compromise on encryption

#37
post #31
post #7

Earlier quoted context omitted.

This is incorrect. iMessage is encrypted, the encryption is end-to-end, there are no backdoors. The unencrypted backup is a clear and annoying hole in the apple privacy story, but the non-e2ee iCloud backup does not include any messages (SMS, MMS, or iMessage), Contacts, Calendars, Notes, iCloud Photos, or health data. A local backup is local, and is protected by filesystem encryption on your local storage. So no, iM…

> iMessage is encrypted, the encryption is end-to-end, there are no backdoors. How would/could we know? If the NSA doesn't have a backdoor (whether that's in the non-public iMessage code, the hardware RNG on iPhones, or somewhere else), what are they even doing all day?

We know authoritatively. Buy a new iPhone and create a new Apple ID. Install an app (which automatically logs you in to iCloud and automatically enables iCloud backup).

Wait 24 hours plugged in to AC power.

Remove the SIM card and throw the iPhone into the sea. Forget the password for the Apple ID.

Buy a new iPhone, and get Apple to reset the Apple ID password using PII/SMS/whatever. Log in and restore your iCloud backup.

Your messages are still right there, and you have provided no key material. Apple has them in plaintext or plaintext-equivalent.

Re: Signal says it won’t compromise on encryption

#38

Tech companies will make all sort of noise when India, China, Turkey ask to have access and control over the data of their own people. However when NSA comes around with their secret laws and courts, they all bend the knee ...

That's because the NSA doesn't make big public statements. They just install a little black box in your servers and you don't say anything.

Re: Signal says it won’t compromise on encryption

#39
post #34
post #16

Earlier quoted context omitted.

Nope, unless you’re using iCloud backup, or your messages can be synced from other devices in the key ring.

No this is the whole point: if you are using iCloud backups, your messages are not backed up. The _only_ online way to maintain your iMessages is (checks settings) "Messages in the Cloud", which is e2e encrypted - if you lose all your devices there is no recovery path except for the "iCloud Key Vault", but I honestly don't know if that can get you to a point where old messages can be recovered.

https://support.apple.com/en-us/HT202303

Please read this article. The Messages in iCloud sync feature is e2e encrypted - but the sync key itself for the e2e is included in the (non-e2e) iCloud Backup which is done every night.

From Apple themselves:

> For Messages in iCloud, if you have iCloud Backup turned on, your backup includes a copy of the key protecting your messages. This ensures you can recover your messages if you lose access to your Keychain and your trusted devices. When you turn off iCloud Backup, a new key is generated on your device to protect future messages and isn't stored by Apple.

This is actually worse. It means that Apple has the cross-device Messages in iCloud sync key in effectively unencrypted form from the backup the night before - which means that they can decrypt the iMessages as they sync between your devices in realtime. This enables realtime iMessage surveillance because of this backdoor in the end to end crypto (the effectively unencrypted iCloud Backup, which includes the e2e keys for the Messages in iCloud feature).

The technical term for this is "key escrow". When you escrow the key to the middle transit service that is supposedly end to end, you backdoor the end to end encryption.

Re: Signal says it won’t compromise on encryption

#40

Why doesn't govt improve its own machinery instead of trying to spy on its citizens? Do they think this way they'll improve the society? Like China?

The first function of a state is to ensure the continued existence of the state. Which is threatened a lot more by civil uprisings as compared to an external actor, especially in a time when international relations are relatively stable (current security events being the formerly-normal that is today's extreme). Another "storm on the Capitol" is so much more damaging to the US as it exists today as compared to a border skirmish with the Chinese over Taiwan.
Post reply on HN