Live data from Hacker News

iMessage with PQ3 Cryptographic Protocol

security.apple.com

131–140 of 280 posts

Re: iMessage with PQ3 Cryptographic Protocol

#131

Earlier quoted context omitted.

The main things holding back Signal usage in my case is practically nobody in my social circle using it and the desktop client not being as nice as that of Messages or Telegram, the latter being particularly relevant for myself and contacts who primarily message with their computers rather than their phones.

Sounds like time to become an evangelist then. I had to do this in my group and other than security a major benefit is just that getting potatos instead of pictures has significantly declined. Here's my advice: don't sell security as the foremost feature. Sell it as "iMessage, but for everyone." You got stickers, reactions, high quality videos and images. Then mention security, it is the cherry on top.

Every single person I converted to using Signal stopped using it when SMS support was removed.

HN tends to be a younger crowd whose peers cycled through a number of social-networking and messaging apps as popularity waxed and waned. But older generations don't see any compelling reason why they should bother splitting their conversations over multiple apps, when literally everyone with a mobile has texting. Being a drop-in replacement for texting, so they could have additional features without additional hassle was the only thing that convinced them to switch and now it is gone.

I've given up evangelizing Signal, and resigned to the idea that cross-platform RCS is the only thing that will bring encryption to the majority of my contacts.

Re: iMessage with PQ3 Cryptographic Protocol

#132
post #99

Earlier quoted context omitted.

> It's not strange in the slightest. It very much is strange. > Apple deserves criticism until they fix this. There's nothing to fix, or rather they already "fixed" it by offering an E2EE iCloud backup option to go along with local backups. As I said I think backups should simply be fully under owner control, but as it stands there is absolutely no need to backup without full key control should people wish. And even…

> There's nothing to fix The default. They need to fix the default. > By your twisted definition, there is no such thing as E2EE for any transport in existence What a ridiculous misunderstanding of my position. iMessage and iCloud are inseparable parts of the whole of iOS, all from the same company, and their default configuration is not end-to-end encrypted. My position is that it is fraudulent to treat them as if t…

>The default. They need to fix the default.

No, they do not. That you don't give a shit about people losing data is a value tradeoff you believe in, but you've got a lot of work to argue it's an objective universal.

>What a ridiculous misunderstanding of my position.

It's amazing how you can say this with a virtual straight face, then immediately go on to directly argue that yep, that's your position.

>iMessage and iCloud are inseparable parts of the whole of iOS

They literally are not. Local syncing of iDevices predates iCloud backups even existing as a feature. You do not need to use iCloud Backups or data syncing. I never have. But if this logic applies, then it applies to everything! You can sync Safari browsing history, state etc too. Apps can sync data as well. So that must mean HTTPS is somehow no longer E2EE either. Unless you turn it off. Then magically it becomes E2EE? Be consistent.

>and their default configuration

This is a goalpost shift and stupid.

>My position is that it is fraudulent to treat them as if they were separate to claim "end-to-end" encryption in only part when it's broken by the other part by default

Because somehow you don't understand what E2EE even is. E2EE in communications solves one, specific and very important problem, which is data in flight. iMessage, HTTPS, or whatever else being E2EE, is a meaningful and significant difference then SMS or HTTP. It changes which potential actors can access that data, and how. End point security is an entire different problem with different sets of tradeoffs.

You're just objectively wrong and muddling an important distinction. Also, if you actually think it's "fraudulent" then by all means, sue them for false advertising, or contact your local authorities in charge of that. Good luck!

>This is false

Nope, it's correct, but there's a bit of a pattern here.

>Apple and Google both now have a system that uses your phone passcode (distinct from your account password and practically impossible to forget as it is so short and you practice entering it literally every day)

My phone password is 21 characters long and I almost never enter it because of Face ID. I'm starting to wonder if you actually own and use iDevices at all or if you're just regurgitating stuff you've read on the web? Even for people just using PINs, the vast super majority make heavy use of biometrics to the extent that Apple forces people to unlock once every few weeks just to try to help make sure they remember. But people forget anyway. Older people or those with other forms of memory loss forget a lot of simple stuff, including their own phone numbers, all the time. People have accidents. One of my cousins just got hit by a car while riding his bike and suffered a bad concussion followed by a long period of amnesia. At Apple's scale they absolutely need to, and should, care about such things.

You just said it was wrong that if someone loses their passwords (and PINs are just a kind of password, "something you know"), they are hosed on the data because... uh... people don't forget! Wild.

>The Reuters piece is as relevant as ever

Nope, it was specifically about there not being an option, at all.

Re: iMessage with PQ3 Cryptographic Protocol

#133

Earlier quoted context omitted.

The top 7 phones sold last year were all iPhones. https://www.macrumors.com/2024/02/21/iphones-top-7-best-sell... Too bad the other vendors don’t bother keeping up.

There is a flaw with your thinking. Any given year there are only 5-6 iPhones to choose from, where there are plenty of Android phones. This leads to "top phone sold" being iPhones because it is 5 phones against hundreds of Android phones that people get to choose from. You should instead look at Market share. https://www.statista.com/statistics/272698/global-market-sha...

> you should instead look at Market share.

Unless your goal is to make money on the platform, then you should look at wallet share, not market share.

Re: iMessage with PQ3 Cryptographic Protocol

#134

This is pretty fascinating. For easier reading, the Signal blog post [0] they link to is great. Both Signal and Apple went with CRYSTALS-Kyber [1] as their post-quantum algorithm. If you're interested in the math, and maybe learned at some point about how classic public key cryptography is built on the idea that it's easy to multiply two primes, but hard to factor them, and how this (or other math problems) can be us…

I'm way out of my depth in terms of the math here. But my 'software engineer brain' likes the ideal of using the prime factoring problem, because it's so simple to understand, and feels like some kind of universal primitive. "It's easy to multiply but hard to factor." It just seems so intuitive. But I'm reading the 'learning with errors' wiki page and it's beyond my comprehension. There's a weird fear in my mind that…

The explanation in this video is what made it click for me: https://www.youtube.com/watch?v=K026C5YaB3A

Re: iMessage with PQ3 Cryptographic Protocol

#135
post #102

Earlier quoted context omitted.

>> it’s a platform designed to aid illegal government surveillance. > Come on. Whilst I agree with the general skepticism, Apple didn’t add E2E encryption to (certain parts of) iCloud backups at the explicit request of the FBI . https://arstechnica.com/tech-policy/2020/01/apple-reportedly...

That's still not the same as claiming that iMessage is designed specifically for the purpose of aiding government surveillance.

Not adding E2E was a conscious design decision by Apple specifically to aid surveillance.

Virtually every other big messaging service offered (optional) E2E at that point.

I’m not sure how much clearer you want it.

“Surveillance” doesn’t have to mean that Apple allowed the FBI to jack directly into the iCloud servers.

Re: iMessage with PQ3 Cryptographic Protocol

#136
post #125

Earlier quoted context omitted.

This (and Signal's solution as well) does not protect against active MITM attackers with quantum computers . They would need to incorporate post-quantum signatures into it as well. The reason why it is missing (but seemingly planned in the future) is because it is not as critical as this change. This change prevents attackers from recording conversations now and decrypting them when (in the next ?? years/decades) the…

I'm a bit puzzled. Suppose you do single Kyber key exchange, and you then hash the shared secret with a domain separator to get a fingerprint, wouldn't that mean you now have a shared secret that you can verify wasn't under MITM. You then can build post quantum future secrecy / key rotation on top of that, by mixing in new key material and it remains secure from MITM, as long as the internal state of the endpoint isn…

Key exchange (whether it's a PQ scheme or more classical DH) does not prevent active-MITM on its own, you need authentication too.

Re: iMessage with PQ3 Cryptographic Protocol

#137

Earlier quoted context omitted.

The main things holding back Signal usage in my case is practically nobody in my social circle using it and the desktop client not being as nice as that of Messages or Telegram, the latter being particularly relevant for myself and contacts who primarily message with their computers rather than their phones.

I used Telegram during a time when I lived a cross-border and cross-platform lifestyle. Telegram, and really Telegram on desktop, was great. I am a stubborn old man at the age of 40, and I really prefer to type on a keyboard. It had a great UI, it always delivered messages, and syncing between devices was seemingly instant. iMessage, somehow, is still not perfect at syncing between devices, and while Signal is quite…

Yeah Telegram absolutely nails the desktop experience like few other chat apps do. The way they put all the functional bits into a library to make it easy to build high quality third-party clients helps, too; while the Qt client is quite good across platforms, users also have the option of a Swift-based client on Apple platforms, a WinUI/UWP client on Windows, GTK client for GTK-based Linux desktops, etc which takes it that extra mile. Heck there’s even CLI clients for users of that inclination.

Its security is questionable but it gets users by the boatload anyway because it doesn’t consider any platform an afterthought, they all get first-class treatment. Other cross platform messengers would do well to embrace a similar philosophy.

Re: iMessage with PQ3 Cryptographic Protocol

#138

Earlier quoted context omitted.

Signal is actually pretty good for the occasional "cross-iOS/Android" video chat. Can't use iOS Facetime, don't want to use $META, google/meet is OK, but isn't quite as straightforward as "@Signal => CALL_ME".

Anyone can use FaceTime now. Non Apple devices will just join via a browser.

What? how does that work? If you call the cell number of an Android device on facetime, what happens on the android end?

Re: iMessage with PQ3 Cryptographic Protocol

#139
post #131

Earlier quoted context omitted.

Sounds like time to become an evangelist then. I had to do this in my group and other than security a major benefit is just that getting potatos instead of pictures has significantly declined. Here's my advice: don't sell security as the foremost feature. Sell it as "iMessage, but for everyone." You got stickers, reactions, high quality videos and images. Then mention security, it is the cherry on top.

Every single person I converted to using Signal stopped using it when SMS support was removed. HN tends to be a younger crowd whose peers cycled through a number of social-networking and messaging apps as popularity waxed and waned. But older generations don't see any compelling reason why they should bother splitting their conversations over multiple apps, when literally everyone with a mobile has texting. Being a d…

Yeah I think this was a bad move for Signal, but I didn't see that happen to my group fortunately. In Signal's defense, my understanding is that this was really an Apple thing. That Apple only lets iMessage connect to SMS so the apps were differing significantly.

I also get the fatigue. Moxie said centralized because they needed to move faster. But Signal has always moved very slow, so it does feel off. But to be fair, it's not like most messenger apps do much.

Re: iMessage with PQ3 Cryptographic Protocol

#140

Pretty great advertisement for Signal, as the sole cross-platform option in the PQC bucket. Does it seem likely they will match Apple here eventually?

In my experience, these markets can overlap but don’t necessarily always do so. I message everyone via iMessage, and while I enjoy the feeling of security from the blue bubble it’s not a must-have for me. Signal on the other hand seems like a must-have for many people living under oppressive regimes or whose data is significantly more valuable than mine. I am one data point, but that’s what I’ve noticed in my bubble.

Do you not send messages to any Android users? That is incredibly hard to imagine for me.

My friend group is very mixed and Signal is what we use.

Post reply on HN