Live data from Hacker News

iMessage with PQ3 Cryptographic Protocol

security.apple.com

111–120 of 280 posts

Re: iMessage with PQ3 Cryptographic Protocol

#111

Earlier quoted context omitted.

For me, Signal is so much better for my friend or work group chats. My friends are on a mix of devices and platforms, and Signal is a lot nicer for embedded media sharing. And the auto disappearing feature is a must!

The main things holding back Signal usage in my case is practically nobody in my social circle using it and the desktop client not being as nice as that of Messages or Telegram, the latter being particularly relevant for myself and contacts who primarily message with their computers rather than their phones.

Using Linux iMessages doesn't even have a client...

Re: iMessage with PQ3 Cryptographic Protocol

#113
post #102

Earlier quoted context omitted.

To clear up the FUD here, this is only true if you turn on iCloud backups (many users do, but still) and don't turn on Advanced Data Protection. ADP is off by default because it means you'll lose all your backups if you forget your iCloud password. > it’s a platform designed to aid illegal government surveillance. Come on.

>> it’s a platform designed to aid illegal government surveillance. > Come on. Whilst I agree with the general skepticism, Apple didn’t add E2E encryption to (certain parts of) iCloud backups at the explicit request of the FBI . https://arstechnica.com/tech-policy/2020/01/apple-reportedly...

That's still not the same as claiming that iMessage is designed specifically for the purpose of aiding government surveillance.

Re: iMessage with PQ3 Cryptographic Protocol

#114

Earlier quoted context omitted.

I don't intend to dispute your stance here, but I am interested in understanding a bit more about it. Do you mind giving an example and what the alternative(s) are?

Search for "Pegasus, NSO, spyware, imessage" or https://archive.is/4fl6o One quote from the article: “Your iPhone, and a billion other Apple devices out-of-the-box, automatically run famously insecure software to preview iMessages, whether you trust the sender or not,” said security researcher Bill Marczak, a fellow at Citizen Lab, a research institute based at the University of Toronto’s Munk School of Global Affair…

Have any zero-day vulnerabilities been found that work on devices in Lockdown Mode?

Re: iMessage with PQ3 Cryptographic Protocol

#115

Earlier quoted context omitted.

For me, Signal is so much better for my friend or work group chats. My friends are on a mix of devices and platforms, and Signal is a lot nicer for embedded media sharing. And the auto disappearing feature is a must!

The main things holding back Signal usage in my case is practically nobody in my social circle using it and the desktop client not being as nice as that of Messages or Telegram, the latter being particularly relevant for myself and contacts who primarily message with their computers rather than their phones.

Sounds like time to become an evangelist then. I had to do this in my group and other than security a major benefit is just that getting potatos instead of pictures has significantly declined.

Here's my advice: don't sell security as the foremost feature. Sell it as "iMessage, but for everyone." You got stickers, reactions, high quality videos and images. Then mention security, it is the cherry on top.

Re: iMessage with PQ3 Cryptographic Protocol

#116

Earlier quoted context omitted.

For me, Signal is so much better for my friend or work group chats. My friends are on a mix of devices and platforms, and Signal is a lot nicer for embedded media sharing. And the auto disappearing feature is a must!

The main things holding back Signal usage in my case is practically nobody in my social circle using it and the desktop client not being as nice as that of Messages or Telegram, the latter being particularly relevant for myself and contacts who primarily message with their computers rather than their phones.

I used Telegram during a time when I lived a cross-border and cross-platform lifestyle.

Telegram, and really Telegram on desktop, was great. I am a stubborn old man at the age of 40, and I really prefer to type on a keyboard. It had a great UI, it always delivered messages, and syncing between devices was seemingly instant. iMessage, somehow, is still not perfect at syncing between devices, and while Signal is quite good at that, it's a pain to start using on a new device, as it doesn't bring along your message history. (For legitimate reasons, mind you.)

Re: iMessage with PQ3 Cryptographic Protocol

#117
post #28

I wonder if Apple will use this as an excuses to not comply when it comes to providing cross platform messaging in the EU.

The EU already decided that under the DMA, iMessage is too small to qualify for the interoperability requirement. Apple is however adding (unencrypted) RCS support to comply with Chinese government law, which requires that all 5G phones support RCS.

You don’t need (unencrypted) in this. RCS is not encrypted. It never has been.

Google has a proprietary extension that puts encrypted blobs into RCS messages, but that would be no different from apple shoving iMessage blobs into RCS and calling it RCS.

Re: iMessage with PQ3 Cryptographic Protocol

#118
post #99

Earlier quoted context omitted.

It's not strange in the slightest. Apple deserves criticism until they fix this. They're going around claiming "end-to-end" and people don't understand that they are constantly handing over people's decrypted messages to law enforcement. It's misleading at best; I call it fraud. It's not as though Apple is merely failing to prevent a third party from breaking their end-to-end encryption here. Apple does it itself! iM…

> It's not strange in the slightest. It very much is strange. > Apple deserves criticism until they fix this. There's nothing to fix, or rather they already "fixed" it by offering an E2EE iCloud backup option to go along with local backups. As I said I think backups should simply be fully under owner control, but as it stands there is absolutely no need to backup without full key control should people wish. And even…

> There's nothing to fix

The default. They need to fix the default.

> By your twisted definition, there is no such thing as E2EE for any transport in existence

What a ridiculous misunderstanding of my position. iMessage and iCloud are inseparable parts of the whole of iOS, all from the same company, and their default configuration is not end-to-end encrypted. My position is that it is fraudulent to treat them as if they were separate to claim "end-to-end" encryption in only part when it's broken by the other part by default. Plenty of other systems are legitimately made of multiple parts by different companies and can claim end-to-end individually when their defaults are appropriate, even if they aren't when combined together by users in non-default configurations. There is no contradiction here, it's quite unambiguous.

> No, if you use their full E2EE options, any of them, and you lose all your devices, your password, and recovery key (including any backups you've chosen to make on your own), you are hosed for any of the data that is E2EE protected.

This is false. Apple and Google both now have a system that uses your phone passcode (distinct from your account password and practically impossible to forget as it is so short and you practice entering it literally every day) as the key to unlock your encrypted backups. They use secure elements in the datacenter to protect the weak passcode from brute force attacks, even from themselves.

> The Reuters piece is obsolete.

The Reuters piece is as relevant as ever until Apple changes the default for iOS so that Apple can't read the vast majority of all iMessages.

Re: iMessage with PQ3 Cryptographic Protocol

#119

Just as a reminder making crack-proof encryption standard everywhere is a trade off. It’s often discussed and presented in forums like this as the only and just choice (and I believe net it is), but in doing so WILL lead to bad outcomes. Terrible crimes, unsolvable murders, large scale terrorism, emboldened enemies attacking a country, more successful coups, etc. It would be nice as a community to acknowledge nothing…

(1) crimes happen, and have happened forever

(2) historically people simply did not create a huge written record (texts etc) detailing their crimes, so there’s no change in available information

(3) even before any of this tech police are not good a solving crimes, and generally rely on errors by criminals

(4) and finally. Your argument is definitionally the slippery slope and is the reason the 4th and 5th amendments exist in the US. Your argument is trivially extended to literally everything: why shouldn’t all communication be routed through government servers to find evidence of crimes? Why shouldn’t all device locations be available to police at all times? Why shouldn’t you have video and audio recorders in every home (most child abuse, the quintessential horror) is committed by family members in the home.

Having actual privacy does not result in crime, and mandating that privacy should be illegal in only a single case is clearly nonsense. Either you have a right to privacy or you don’t.

Re: iMessage with PQ3 Cryptographic Protocol

#120

Earlier quoted context omitted.

In my experience, these markets can overlap but don’t necessarily always do so. I message everyone via iMessage, and while I enjoy the feeling of security from the blue bubble it’s not a must-have for me. Signal on the other hand seems like a must-have for many people living under oppressive regimes or whose data is significantly more valuable than mine. I am one data point, but that’s what I’ve noticed in my bubble.

For me, Signal is so much better for my friend or work group chats. My friends are on a mix of devices and platforms, and Signal is a lot nicer for embedded media sharing. And the auto disappearing feature is a must!

Signal is actually pretty good for the occasional "cross-iOS/Android" video chat. Can't use iOS Facetime, don't want to use $META, google/meet is OK, but isn't quite as straightforward as "@Signal => CALL_ME".
Post reply on HN