Live data from Hacker News

iMessage with PQ3 Cryptographic Protocol

security.apple.com

51–60 of 280 posts

Re: iMessage with PQ3 Cryptographic Protocol

#51
post #20
post #2

Does anyone know if this is still vulnerable to the iCloud Backups problem? The only solution to that right now is for you and your contact to turn on Advanced Data Protection. Curious if that’s still required.

> Does anyone know if this is still vulnerable to the iCloud Backups problem? The only solution to that right now is for you and your contact to turn on Advanced Data Protection. This is such a strange two sentences as a "problem". E2EE security, as it says in the name, is about the protection of dara transmission between two trusted end points. That's it. What the trusted end points themselves choose to do with that…

> No communication service stops people from backing up with encryption or not, local or remote, or from copy/pasting or for that matter taking photos of the screen ("analog hole").

At least for the first part on backing up without copy pasting or using the “analog hole”, Signal expressly prohibits and doesn’t allow any kind of backup — encrypted or not — on iOS/iPadOS/macOS.

Re: iMessage with PQ3 Cryptographic Protocol

#52
post #17
post #2

Does anyone know if this is still vulnerable to the iCloud Backups problem? The only solution to that right now is for you and your contact to turn on Advanced Data Protection. Curious if that’s still required.

>The only solution to that right now is for you and your contact to turn on Advanced Data Protection or don't use icloud backup. Also, confusingly "messages in icloud" is end to end encrypted, and enabling it disables messages for being included in icloud backup.

> "messages in icloud" is end to end encrypted, and enabling it disables messages for being included in icloud backup.

This is misleading at best. Careful reading of Apple's disclosures reveals that the "messages in iCloud" encryption keys are still included in iCloud backups, giving Apple the capability to decrypt your messages on demand for law enforcement or for any other reason of their choosing. The messages may not be in your "iCloud backups", but that's just because they are stored on Apple's "Messages in iCloud" servers instead. Apple still has them and the keys to decrypt them.

https://support.apple.com/guide/security/security-of-icloud-...

> When iCloud Backup is turned on, the backup includes a copy of the Messages in iCloud encryption key so Apple can help the user recover their messages even if they have lost access to iCloud Keychain and their trusted devices.

Re: iMessage with PQ3 Cryptographic Protocol

#53

Isn't all this post quantum stuff a little premature? The standards haven't settled. We don't even know if there is a possible quantum threat to cryptography yet. The more we work on the problem the less likely it seems. Last I heard we were 1 or 2 orders of magnitude away from physical noise performance that would make such a threat possible. Edit, added: Harvest now, decrypt later applies to any encrypted data. The…

You'd be right except that anything encrypted now can be stored and cracked later.

I remember as part of the snowden leaks there was documentation about this kind of delayed phase collection.

Basically store as much signals data as you can and try to crack it later if there's a weakness discovered with the protocol or computing power starts being capable of wholesale attack.

You might remember that hashes are significantly easier to crack with "rainbow tables", and so we added cryptographic "salts" to online password storage. We discovered that about 15 years ago and started salting all our passwords, but for a large window of time all of those old leaked databases were suddenly extremely easy to crack.

Now, Imagine the NSA is 10 years ahead of us (and you might be close with that estimation), so even if they can't crack RSA right now they're much closer than we are, and even we get there we will likely have a large window of time before we fix it properly. (not that we're talking RSA here, but you get my point).

https://www.forbes.com/sites/andygreenberg/2013/06/20/leaked...

Re: iMessage with PQ3 Cryptographic Protocol

#54
Would be great if we could uninstall iMessage completely out of iPhone for security reasons or make it opt in by default. Unfortunately it's not possible and it will be a gateway for security issues and malware in the following years to come. Post quantum cryptography is nice but that's one of the smallest problems with iMessage.

Re: iMessage with PQ3 Cryptographic Protocol

#55

Isn't all this post quantum stuff a little premature? The standards haven't settled. We don't even know if there is a possible quantum threat to cryptography yet. The more we work on the problem the less likely it seems. Last I heard we were 1 or 2 orders of magnitude away from physical noise performance that would make such a threat possible. Edit, added: Harvest now, decrypt later applies to any encrypted data. The…

One reason to move sooner rather than later is to mitigate the threat of previously stored data. There may be a government entity simply storing all imessage traffic in the hopes of one day decrypting it when/if a breakthrough happens. If you transition sooner, you increase the age of the latest data that could be decrypted, thusly hopefully making it safer.

Re: iMessage with PQ3 Cryptographic Protocol

#56

Isn't all this post quantum stuff a little premature? The standards haven't settled. We don't even know if there is a possible quantum threat to cryptography yet. The more we work on the problem the less likely it seems. Last I heard we were 1 or 2 orders of magnitude away from physical noise performance that would make such a threat possible. Edit, added: Harvest now, decrypt later applies to any encrypted data. The…

Like the article says, it's protection from harvest-now-break-later.

Apple users and communications are today a state-secret affair as shown by the impact of NSO/Pegasus.

So even if Google,IBM,et al _might_ have approached feasibility in the open there is still a significant risk in state-level adversaries having poured enough funding to still be ahead, plus they will benefit from all open research in the hidden with extra funding to take more leaps.

So no, it's not premature if there is hidden or open leaps just 10 years in the future.

Re: iMessage with PQ3 Cryptographic Protocol

#57

Would be great if we could uninstall iMessage completely out of iPhone for security reasons or make it opt in by default. Unfortunately it's not possible and it will be a gateway for security issues and malware in the following years to come. Post quantum cryptography is nice but that's one of the smallest problems with iMessage.

iMessage can be disabled in Settings > Messages

Re: iMessage with PQ3 Cryptographic Protocol

#58

Would be great if we could uninstall iMessage completely out of iPhone for security reasons or make it opt in by default. Unfortunately it's not possible and it will be a gateway for security issues and malware in the following years to come. Post quantum cryptography is nice but that's one of the smallest problems with iMessage.

You can very easily disable iMessage completely

Re: iMessage with PQ3 Cryptographic Protocol

#59

Would be great if we could uninstall iMessage completely out of iPhone for security reasons or make it opt in by default. Unfortunately it's not possible and it will be a gateway for security issues and malware in the following years to come. Post quantum cryptography is nice but that's one of the smallest problems with iMessage.

Wouldn't SMS be more insecure?

Re: iMessage with PQ3 Cryptographic Protocol

#60

Would be great if we could uninstall iMessage completely out of iPhone for security reasons or make it opt in by default. Unfortunately it's not possible and it will be a gateway for security issues and malware in the following years to come. Post quantum cryptography is nice but that's one of the smallest problems with iMessage.

I don't intend to dispute your stance here, but I am interested in understanding a bit more about it. Do you mind giving an example and what the alternative(s) are?
Post reply on HN