Pretty great advertisement for Signal, as the sole cross-platform option in the PQC bucket. Does it seem likely they will match Apple here eventually?
In my experience, these markets can overlap but don’t necessarily always do so. I message everyone via iMessage, and while I enjoy the feeling of security from the blue bubble it’s not a must-have for me. Signal on the other hand seems like a must-have for many people living under oppressive regimes or whose data is significantly more valuable than mine. I am one data point, but that’s what I’ve noticed in my bubble.
iMessage with PQ3 Cryptographic Protocol
71–80 of 280 posts
Re: iMessage with PQ3 Cryptographic Protocol
#72Earlier quoted context omitted.
You either have to enable E2EE or disable both Messages in iCloud and device backups. Otherwise the device backups contain a copy of your messages.
The "Messages in iCloud" sync is end to end, so you can enable it and disable iCloud backup, or manually backup on your computer: https://support.apple.com/en-us/102651
Re: iMessage with PQ3 Cryptographic Protocol
#73Does anyone know if this is still vulnerable to the iCloud Backups problem? The only solution to that right now is for you and your contact to turn on Advanced Data Protection. Curious if that’s still required.
> Does anyone know if this is still vulnerable to the iCloud Backups problem? The only solution to that right now is for you and your contact to turn on Advanced Data Protection. This is such a strange two sentences as a "problem". E2EE security, as it says in the name, is about the protection of dara transmission between two trusted end points. That's it. What the trusted end points themselves choose to do with that…
This is not a UX issue or an engineering issue. Apple already built end-to-end encryption for sensitive data types that is still recoverable from backups even if you lose all your devices and forget your iCloud account password. They do it the same way Google does, and they already use it by default for important stuff you don't want to lose like passwords stored in Keychain and health data and a bunch of other stuff too. Literally all they need to do is store the iMessage encryption keys in this system by default. They continuously choose not to, and the reason is reported by Reuters to be a secret compromise agreement with the FBI. https://web.archive.org/web/20200121123026/https://www.reute...
Re: iMessage with PQ3 Cryptographic Protocol
#74Just as a reminder making crack-proof encryption standard everywhere is a trade off. It’s often discussed and presented in forums like this as the only and just choice (and I believe net it is), but in doing so WILL lead to bad outcomes. Terrible crimes, unsolvable murders, large scale terrorism, emboldened enemies attacking a country, more successful coups, etc. It would be nice as a community to acknowledge nothing…
Imagine I’m planning something malicious. If I literally do anything other than talk about it, there’s going to be evidence, and that evidence won’t be encrypted.
Plus, crack-proof encryption existed at least back to Roman times - simply because making a secure code was fairly easy and we didn’t have codebreakers. We managed.
Re: iMessage with PQ3 Cryptographic Protocol
#75Just as a reminder making crack-proof encryption standard everywhere is a trade off. It’s often discussed and presented in forums like this as the only and just choice (and I believe net it is), but in doing so WILL lead to bad outcomes. Terrible crimes, unsolvable murders, large scale terrorism, emboldened enemies attacking a country, more successful coups, etc. It would be nice as a community to acknowledge nothing…
we don’t remove all rights to privacy for people in their homes because criminals use homes too. tech should be no different
Re: iMessage with PQ3 Cryptographic Protocol
#76Just as a reminder making crack-proof encryption standard everywhere is a trade off. It’s often discussed and presented in forums like this as the only and just choice (and I believe net it is), but in doing so WILL lead to bad outcomes. Terrible crimes, unsolvable murders, large scale terrorism, emboldened enemies attacking a country, more successful coups, etc. It would be nice as a community to acknowledge nothing…
Re: iMessage with PQ3 Cryptographic Protocol
#77Earlier quoted context omitted.
That's still required.
I don't anticipate this changing either - because, let's face it, losing all of your Photos and Messages is, to most people, a bigger deal than perfect security. I'm experienced with Apple products - but there was one time that I actually got stuck in an E2EE loop and was forced to reset all E2EE data on iCloud. I don't know what I did wrong - but if someone in tech, like myself, can get stuck in an E2EE lockout, I c…
Apple turns over customer data on over 70,000 customers per year without a warrant under FISA/702 (prism) and NSLs. The number gets bigger every year. This isn’t a theoretical threat. The number is even bigger if you include all the search warrants, too.
EDIT: Even if you enable their optional e2ee for backups (which nobody does), iMessage the platform is still vulnerable because the conversations you have with others are insecure because the other end of the conversation is escrowing their keys to Apple via non-e2ee backups. If you enable ADP iMessage only becomes secure for the case where you are only iMessaging yourself.
It’s simply not private or secure. You can’t be “slightly encrypted” or “mostly private”.
Re: iMessage with PQ3 Cryptographic Protocol
#78Just as a reminder making crack-proof encryption standard everywhere is a trade off. It’s often discussed and presented in forums like this as the only and just choice (and I believe net it is), but in doing so WILL lead to bad outcomes. Terrible crimes, unsolvable murders, large scale terrorism, emboldened enemies attacking a country, more successful coups, etc. It would be nice as a community to acknowledge nothing…
Re: iMessage with PQ3 Cryptographic Protocol
#79Earlier quoted context omitted.
In my experience, these markets can overlap but don’t necessarily always do so. I message everyone via iMessage, and while I enjoy the feeling of security from the blue bubble it’s not a must-have for me. Signal on the other hand seems like a must-have for many people living under oppressive regimes or whose data is significantly more valuable than mine. I am one data point, but that’s what I’ve noticed in my bubble.
For me, Signal is so much better for my friend or work group chats. My friends are on a mix of devices and platforms, and Signal is a lot nicer for embedded media sharing. And the auto disappearing feature is a must!
Re: iMessage with PQ3 Cryptographic Protocol
#80This is pretty fascinating. For easier reading, the Signal blog post [0] they link to is great. Both Signal and Apple went with CRYSTALS-Kyber [1] as their post-quantum algorithm. If you're interested in the math, and maybe learned at some point about how classic public key cryptography is built on the idea that it's easy to multiply two primes, but hard to factor them, and how this (or other math problems) can be us…