Live data from Hacker News

iMessage with PQ3 Cryptographic Protocol

security.apple.com

41–50 of 280 posts

Re: iMessage with PQ3 Cryptographic Protocol

#41

Earlier quoted context omitted.

For me, Signal is so much better for my friend or work group chats. My friends are on a mix of devices and platforms, and Signal is a lot nicer for embedded media sharing. And the auto disappearing feature is a must!

Hmm… Does signal only really work when everyone uses it? Or can you include people who are just using regular SMS?

Only Signal users. The Android app used to work with SMS/MMS until a couple years ago.

Re: iMessage with PQ3 Cryptographic Protocol

#43

Advanced encryption, until it comes time to text 70% of the phones in the world, in which case it defaults to a protocol released 32 years ago.

Why does 70% of world phones matter here? There are phones in the world that do not support any encryption when sending messages or doing calls.

SMS/RCS

Re: iMessage with PQ3 Cryptographic Protocol

#44

Advanced encryption, until it comes time to text 70% of the phones in the world, in which case it defaults to a protocol released 32 years ago.

RCS is unencrypted unless you use Google's closed garden Google Messages' extensions.

Apple is apparently working with GSMA to add encryption to the standard though. (They probably wouldn't add RCS otherwise.)

Re: iMessage with PQ3 Cryptographic Protocol

#45

Earlier quoted context omitted.

Yes but that would have meant giving up sales in exchange for actually backing up their words. They aren’t even going to use the developed encrypted RCS protocol. Apple, when it comes to their values, is all lip service. I have intimate experience here with them both openly lying and purposefully deceiving their user base in this case.

> Yes but that would have meant giving up sales in exchange for actually backing up their words. I saw that you moved the goalposts in your reply, but anyway: which words? > They aren’t even going to use the developed encrypted RCS protocol. The protocol that was designed by Google and in which Google’s infrastructure is crucial? It’s not Apple’s fault that RCS does not have mandatory end-to-end encryption. > I have…

RCS was not designed by Google. Google has (so far) embraced it after repeatedly self-sabotaging their own chat efforts. RCS is a carrier standard that the carriers had trouble deploying.

Re: iMessage with PQ3 Cryptographic Protocol

#46
>When iMessage launched in 2011, it was the first widely available messaging app to provide end-to-end encryption by default,...

Until very recently, iMessage provided no way to verify that you and your correspondent were not both connected to the server, rather than each other. So guaranteed end-to end encryption wasn't possible. Even now, with a recent version of iOS, they allow the users to blithely exchange messages without any identity verification. The identity numbers used to do this are hidden behind menus. So not really E2EE in any practical sense.

Re: iMessage with PQ3 Cryptographic Protocol

#47

Earlier quoted context omitted.

For me, Signal is so much better for my friend or work group chats. My friends are on a mix of devices and platforms, and Signal is a lot nicer for embedded media sharing. And the auto disappearing feature is a must!

Hmm… Does signal only really work when everyone uses it? Or can you include people who are just using regular SMS?

I don't think any app besides iMessage can even get permission to read SMS on iOS, there are no alternative message apps I'm aware of like with android.

Re: iMessage with PQ3 Cryptographic Protocol

#48
Isn't all this post quantum stuff a little premature? The standards haven't settled. We don't even know if there is a possible quantum threat to cryptography yet. The more we work on the problem the less likely it seems. Last I heard we were 1 or 2 orders of magnitude away from physical noise performance that would make such a threat possible.

Edit, added: Harvest now, decrypt later applies to any encrypted data. There is nothing special about the quantum threat. This all only makes sense if we can predict what the actual threat is ... and so far we can't. This reminds me of Pascal's Wager[1]

[1] https://en.wikipedia.org/wiki/Pascal%27s_wager

Re: iMessage with PQ3 Cryptographic Protocol

#49

Advanced encryption, until it comes time to text 70% of the phones in the world, in which case it defaults to a protocol released 32 years ago.

The top 7 phones sold last year were all iPhones. https://www.macrumors.com/2024/02/21/iphones-top-7-best-sell... Too bad the other vendors don’t bother keeping up.

There is a flaw with your thinking. Any given year there are only 5-6 iPhones to choose from, where there are plenty of Android phones. This leads to "top phone sold" being iPhones because it is 5 phones against hundreds of Android phones that people get to choose from.

You should instead look at Market share. https://www.statista.com/statistics/272698/global-market-sha...

Re: iMessage with PQ3 Cryptographic Protocol

#50
post #28

I wonder if Apple will use this as an excuses to not comply when it comes to providing cross platform messaging in the EU.

The EU already decided that under the DMA, iMessage is too small to qualify for the interoperability requirement. Apple is however adding (unencrypted) RCS support to comply with Chinese government law, which requires that all 5G phones support RCS.

[deleted]
Post reply on HN