Live data from Hacker News

iMessage with PQ3 Cryptographic Protocol

security.apple.com

81–90 of 280 posts

Re: iMessage with PQ3 Cryptographic Protocol

#81
post #71

Earlier quoted context omitted.

In my experience, these markets can overlap but don’t necessarily always do so. I message everyone via iMessage, and while I enjoy the feeling of security from the blue bubble it’s not a must-have for me. Signal on the other hand seems like a must-have for many people living under oppressive regimes or whose data is significantly more valuable than mine. I am one data point, but that’s what I’ve noticed in my bubble.

[flagged]

To clear up the FUD here, this is only true if you turn on iCloud backups (many users do, but still) and don't turn on Advanced Data Protection. ADP is off by default because it means you'll lose all your backups if you forget your iCloud password.

> it’s a platform designed to aid illegal government surveillance.

Come on.

Re: iMessage with PQ3 Cryptographic Protocol

#82

Just as a reminder making crack-proof encryption standard everywhere is a trade off. It’s often discussed and presented in forums like this as the only and just choice (and I believe net it is), but in doing so WILL lead to bad outcomes. Terrible crimes, unsolvable murders, large scale terrorism, emboldened enemies attacking a country, more successful coups, etc. It would be nice as a community to acknowledge nothing…

For a minute I thought you were only talking about non-state actors performing those terrible things, then remembered history is full of nations doing all those things.

Re: iMessage with PQ3 Cryptographic Protocol

#83
post #51
post #20

Earlier quoted context omitted.

> Does anyone know if this is still vulnerable to the iCloud Backups problem? The only solution to that right now is for you and your contact to turn on Advanced Data Protection. This is such a strange two sentences as a "problem". E2EE security, as it says in the name, is about the protection of dara transmission between two trusted end points. That's it. What the trusted end points themselves choose to do with that…

> No communication service stops people from backing up with encryption or not, local or remote, or from copy/pasting or for that matter taking photos of the screen ("analog hole"). At least for the first part on backing up without copy pasting or using the “analog hole”, Signal expressly prohibits and doesn’t allow any kind of backup — encrypted or not — on iOS/iPadOS/macOS.

>Signal expressly prohibits and doesn’t allow any kind of backup — encrypted or not — on iOS/iPadOS/macOS.

I do not think you are correct, or perhaps alternatively this is a distinction without meaning. iDevices do indeed lock down against owner control unless the device is jailbroken. But Signal for Mac only requires 10.15 or later. Even if they wanted to, old Intel Macs simply do not offer the hardware guarantees to protect against the owner getting access to their own data if they want to, though even current ones will still let you turn off SIP etc if you wish. I don't even need to look to guarantee that if someone wants access to their own Signal data on the Mac (or Windows, or Linux which can be run with any 64-bit distributions supporting APT), or any of these virtualized (and thus on the BSDs which aren't formally supported [0]), they can get it. And again, this is somewhat a distinction without meaning. Like, how does someone read their messages on Signal for Desktop after setting it up and it's syncing going forward? They login to the system, and there is a saved key and that makes it work. If they then choose to backup said system or VM without encryption now what?

I have heard that on iOS Signal has always been somewhat evil in attempting to steal people's data away from them, which is part of the reason I avoided it. But fortunately we don't yet live in a world where the same games can be pulled on regular computers. And hopefully eventually legislation will make it illegal on all computers, including handhelds, too.

----

0: 64-bit distributions supporting APT

Re: iMessage with PQ3 Cryptographic Protocol

#84

Isn't all this post quantum stuff a little premature? The standards haven't settled. We don't even know if there is a possible quantum threat to cryptography yet. The more we work on the problem the less likely it seems. Last I heard we were 1 or 2 orders of magnitude away from physical noise performance that would make such a threat possible. Edit, added: Harvest now, decrypt later applies to any encrypted data. The…

> Edit, added: Harvest now, decrypt later applies to any encrypted data. There is nothing special about the quantum threat. This all only makes sense if we can predict what the actual threat is ... and so far we can't.

But we know Shor's algorithm, and we've started building prototype quantum computers. Isn't that enough to build something that counters them? Worst case, we deploy new ciphers and realize that the threat was empty 50 years from now. What's the downside?

Re: iMessage with PQ3 Cryptographic Protocol

#85

Just as a reminder making crack-proof encryption standard everywhere is a trade off. It’s often discussed and presented in forums like this as the only and just choice (and I believe net it is), but in doing so WILL lead to bad outcomes. Terrible crimes, unsolvable murders, large scale terrorism, emboldened enemies attacking a country, more successful coups, etc. It would be nice as a community to acknowledge nothing…

For a minute I thought you were only talking about non-state actors performing those terrible things, then remembered history is full of nations doing all those things.

It’s all of the above. That’s my point. Good, bad, ok if you’re on their side, some never have a side to be on.

Re: iMessage with PQ3 Cryptographic Protocol

#86

This is pretty fascinating. For easier reading, the Signal blog post [0] they link to is great. Both Signal and Apple went with CRYSTALS-Kyber [1] as their post-quantum algorithm. If you're interested in the math, and maybe learned at some point about how classic public key cryptography is built on the idea that it's easy to multiply two primes, but hard to factor them, and how this (or other math problems) can be us…

Was the CRYSTALS-Kyber name intentionally, or accidentally, a reference to Kyber Crystals (I.e. The Lightsaber energy source?)

Absolutely a reference. Dilithium (from Star Trek) is name of their signature algorithm.

Re: iMessage with PQ3 Cryptographic Protocol

#87
post #77

Earlier quoted context omitted.

I don't anticipate this changing either - because, let's face it, losing all of your Photos and Messages is, to most people, a bigger deal than perfect security. I'm experienced with Apple products - but there was one time that I actually got stuck in an E2EE loop and was forced to reset all E2EE data on iCloud. I don't know what I did wrong - but if someone in tech, like myself, can get stuck in an E2EE lockout, I c…

iMessage’s practical lack of e2ee isn’t a matter of “perfect security”. It’s simply not e2ee because the keys are escrowed to the middle service. It’s not even a little bit secure. The encryption has been fully backdoored by sharing the endpoint keys off of the device. Apple turns over customer data on over 70,000 customers per year without a warrant under FISA/702 (prism) and NSLs. The number gets bigger every year.…

Unless you enable Advanced Data Protection, which escrows the keys solely on your device. This is hardly a secret or a scandal.

Re: iMessage with PQ3 Cryptographic Protocol

#88

Earlier quoted context omitted.

> They aren’t even going to use the developed encrypted RCS protocol. End-to-end RCS encryption is via proprietary Google extension and not even available to other Android RCS messaging apps.

It was made available to Apple.

Doesn't really help the argument that it is a proprietary Google technology. The fact that it had to be "made available" to Apple means that it isn't an open standard and requires trusting Google, which many of us don't.

Re: iMessage with PQ3 Cryptographic Protocol

#89
post #71

Earlier quoted context omitted.

[flagged]

To clear up the FUD here, this is only true if you turn on iCloud backups (many users do, but still) and don't turn on Advanced Data Protection. ADP is off by default because it means you'll lose all your backups if you forget your iCloud password. > it’s a platform designed to aid illegal government surveillance. Come on.

These are the defaults. You don’t need to turn on iCloud Backup, it’s already on. You don’t need to turn off Advanced Data Protection, it’s already off.

Literally all you need to do is turn on a new iPhone and try to install any app. It will prompt for your Apple ID login (impossible to install apps without it) and will automatically enable iCloud, iCloud Backup, and iMessage (and will not enable ADP).

https://www.forbes.com/sites/kateoflahertyuk/2020/01/21/appl...

They explicitly killed the e2ee support for backups some time ago at the behest of the FBI to preserve the backdoor. It’s still practically backdoored for nearly all iMessage users because it is off by default (and the UX sucks even if you turn it on). Approximately nobody is using it; the status quo is preserved. iMessage is backdoored and is not e2ee due to key escrow. If you message someone on iMessage, Apple will be able to read the message, even if you have ADP enabled (because the other endpoint does not). That’s fact, today.

Additionally, even if you turn on ADP, the hashes of unencrypted file content in iCloud are stored non-e2ee, so Apple can still see who has which unique files and when, and who else receives them and when. This allows them to monitor social graphs, too.

Re: iMessage with PQ3 Cryptographic Protocol

#90
post #71

Earlier quoted context omitted.

In my experience, these markets can overlap but don’t necessarily always do so. I message everyone via iMessage, and while I enjoy the feeling of security from the blue bubble it’s not a must-have for me. Signal on the other hand seems like a must-have for many people living under oppressive regimes or whose data is significantly more valuable than mine. I am one data point, but that’s what I’ve noticed in my bubble.

[flagged]

As far as I'm aware, iCloud for Messages is not enabled by default. Security-conscious users should know not to turn it on, though -- if iCloud servicing warrants is part of their threat model.

Further, Apple ended up rolling out Advanced Data Protection for iCloud in 2023, so users who truly don't want Apple holding those keys can effectively take them from Apple.

https://support.apple.com/guide/security/advanced-data-prote...

EDIT: Just confirmed with a test device and test apple id, iCloud for Messages is not enabled on it.

Post reply on HN