Live data from Hacker News

iMessage with PQ3 Cryptographic Protocol

security.apple.com

101–110 of 280 posts

Re: iMessage with PQ3 Cryptographic Protocol

#101
post #96

Earlier quoted context omitted.

What word? They never said they'd open iMessage. FaceTime is what they intended (or at least Jobs announced the intent) to open, and then that got caught up in a patent dispute.

I remember them saying releasing iMessage as an open standard.

Can you point to a source for that outside your memory?

Re: iMessage with PQ3 Cryptographic Protocol

#102
post #71

Earlier quoted context omitted.

[flagged]

To clear up the FUD here, this is only true if you turn on iCloud backups (many users do, but still) and don't turn on Advanced Data Protection. ADP is off by default because it means you'll lose all your backups if you forget your iCloud password. > it’s a platform designed to aid illegal government surveillance. Come on.

>> it’s a platform designed to aid illegal government surveillance.

> Come on.

Whilst I agree with the general skepticism, Apple didn’t add E2E encryption to (certain parts of) iCloud backups at the explicit request of the FBI.

https://arstechnica.com/tech-policy/2020/01/apple-reportedly...

Re: iMessage with PQ3 Cryptographic Protocol

#103

Advanced encryption, until it comes time to text 70% of the phones in the world, in which case it defaults to a protocol released 32 years ago.

This is getting downvoted, but it really does feel like a variant of the wrench problem: https://xkcd.com/538/

It's already incredibly hard to get people to use secure messaging systems. Downgrading to SMS isn't necessarily wrong (it's become harder to get people to use Signal now that it's dropped support for SMS), but it's a huge hole and effectively means that many customers will never have a significant number of their conversations encrypted.

That's a boring security hole, sure. But at some point you have to think about UX as being a part of security, and a messaging system that isn't cross-platform is hard to call secure, because good luck trying to get your contacts to all use it. People get upset about this, but the reality is it does not matter what encryption scheme a messenger is using if it's impossible for you to get your contacts to use it. The same way that it does not matter how secure your 2FA system is if you can't get people to turn it on.

I felt like on net Signal's support for SMS was a boon for security more than a hindrance because it made it easier for me to get people to sign up for Signal. In contrast, Signal's take was that having a secure and insecure service bundled up into the same messenger would on average make people more lax about security and would make it harder for them to make strong security guarantees. They viewed SMS support essentially as a security vulnerability.

I do wish Signal had kept SMS and tried harder on the UX, I honestly feel somewhat strongly that removing support made secure messaging harder -- but while we can debate the security downsides and the onboarding downsides, I also have grown to kind of see their point? And iMessage falls very squarely into that problem, except with Signal I can at least tell my contacts how to get it.

I don't know, it feels petty but like... if you have secure encryption but it doesn't get turned on for a bunch of messages, then that does seem like it has a security impact. I don't think that's a complicated or controversial thing to say, it's no different from calling out that some chat services require E2EE to be opt-in instead of opt-out. Good security requires thinking about that kind of stuff.

It's the wrench problem. You're not going to get spied on by a quantum computer. You're going to get spied on because there's a decent chance that ~50% of your contacts or more aren't on iPhone and you'll be talking to them in plain text. And realistically for most users, switching to a cross-platform E2EE messenger that allows them to use one consistent service for all of their encrypted conversations is going to be meaningfully more secure even if it doesn't have quantum-resistant encryption. The most important problem for any secure messenger to solve is how to get people to use it. Sometimes that means compromising on other security standards, sometimes it means being harsher about security standards that would otherwise be optional. Sometimes it means caring about availability and onboarding, and not sending the majority of messages in an easily intercepted plain-text format.

Re: iMessage with PQ3 Cryptographic Protocol

#104
post #96

Earlier quoted context omitted.

What word? They never said they'd open iMessage. FaceTime is what they intended (or at least Jobs announced the intent) to open, and then that got caught up in a patent dispute.

I remember them saying releasing iMessage as an open standard.

That was FaceTime, and it was because it was a peer-to-peer protocol. Then Apple was sued over a patent and had to implement a more normal design, where it pays for and runs the servers. Apple didn't want to run the servers for Android people to talk to each other.

Re: iMessage with PQ3 Cryptographic Protocol

#106
post #70

Did anyone figure out how MITM attacks are handled? How does the key transparency work and does it replace public key fingerprints?

This (and Signal's solution as well) does not protect against active MITM attackers with quantum computers. They would need to incorporate post-quantum signatures into it as well.

The reason why it is missing (but seemingly planned in the future) is because it is not as critical as this change. This change prevents attackers from recording conversations now and decrypting them when (in the next ?? years/decades) they get access to an actually powerful quantum computer. On the other hand, you can do MITM only after you factorized RSA key (or solved discrete log).

The additional reason I presume is that this typically requires a change to the whole public key infrastructure (certificates, OCSP, etc.) which is a lot of additional work.

Re: iMessage with PQ3 Cryptographic Protocol

#107

Would be great if we could uninstall iMessage completely out of iPhone for security reasons or make it opt in by default. Unfortunately it's not possible and it will be a gateway for security issues and malware in the following years to come. Post quantum cryptography is nice but that's one of the smallest problems with iMessage.

You can enable lockdown mode to decrease the attack surface.

https://support.apple.com/en-us/105120

Re: iMessage with PQ3 Cryptographic Protocol

#108

Earlier quoted context omitted.

> They aren’t even going to use the developed encrypted RCS protocol. End-to-end RCS encryption is via proprietary Google extension and not even available to other Android RCS messaging apps.

It was made available to Apple.

Citation?

Beeper was explicitly told it was not available to others when they wanted to implement Google's encrypted RCS on their Android client.

https://twitter.com/ericmigi/status/1557050351974420480

Re: iMessage with PQ3 Cryptographic Protocol

#109

Isn't all this post quantum stuff a little premature? The standards haven't settled. We don't even know if there is a possible quantum threat to cryptography yet. The more we work on the problem the less likely it seems. Last I heard we were 1 or 2 orders of magnitude away from physical noise performance that would make such a threat possible. Edit, added: Harvest now, decrypt later applies to any encrypted data. The…

We have reason to believe that conventionally encrypted data isn't threatened within the next 50 years by anything other than quantum computing, which is what's special about the quantum threat.

Re: iMessage with PQ3 Cryptographic Protocol

#110
post #65
post #17

Earlier quoted context omitted.

>The only solution to that right now is for you and your contact to turn on Advanced Data Protection or don't use icloud backup. Also, confusingly "messages in icloud" is end to end encrypted, and enabling it disables messages for being included in icloud backup.

If everyone you iMessage with has iCloud Backup still enabled (and I guarantee you 100% that they do because it is the default), then you turning yours off does nothing, as all of your conversations remain readable by Apple via the escrowed keys of the other endpoints. iMessage is not e2ee.

It does not appear to be the default.
Post reply on HN