Live data from Hacker News

iMessage with PQ3 Cryptographic Protocol

security.apple.com

151–160 of 280 posts

Re: iMessage with PQ3 Cryptographic Protocol

#151

Earlier quoted context omitted.

I used Telegram during a time when I lived a cross-border and cross-platform lifestyle. Telegram, and really Telegram on desktop, was great. I am a stubborn old man at the age of 40, and I really prefer to type on a keyboard. It had a great UI, it always delivered messages, and syncing between devices was seemingly instant. iMessage, somehow, is still not perfect at syncing between devices, and while Signal is quite…

Yeah Telegram absolutely nails the desktop experience like few other chat apps do. The way they put all the functional bits into a library to make it easy to build high quality third-party clients helps, too; while the Qt client is quite good across platforms, users also have the option of a Swift-based client on Apple platforms, a WinUI/UWP client on Windows, GTK client for GTK-based Linux desktops, etc which takes…

Sure. Different projects, different goals. At every instant where Telegram had a decision to make between better user experience or user security & privacy, Telegram opted to make a better experience. Signal took significant UX hits to make the privacy promises it makes. The two projects are essentially not comparable. Like, the sane thing to compare Telegram to at this point is Matrix.

Re: iMessage with PQ3 Cryptographic Protocol

#153
post #105

Earlier quoted context omitted.

Can you point to a source for that outside your memory?

They’re confusing it with FaceTime: https://youtu.be/JOxf9tEXEKQ

I figured that was the case. I just wanted one of these folks that keep claiming it to cough up some evidence. It's a tired thing. There are lots of things to criticize Apple (and most companies) for, at least pick something that isn't imaginary.

Re: iMessage with PQ3 Cryptographic Protocol

#154

Earlier quoted context omitted.

> you should instead look at Market share. Unless your goal is to make money on the platform, then you should look at wallet share, not market share.

The goal isn't to make money or calculate wallet share. The goal is to send encrypted messages to contacts. You should look at the percentage of smartphone owners . It does not matter in the slightest how many dollars they have in their pockets. The question is: is the average user going to have a significant number of Android contacts, with which Messages requires plain-text communication to contact. And the answer…

Completely fair, I had shifted topics from phone owners, to platform relevance to makers on HN.

Your point stands.

Re: iMessage with PQ3 Cryptographic Protocol

#155
post #61

Earlier quoted context omitted.

The top 7 phones sold last year were all iPhones. https://www.macrumors.com/2024/02/21/iphones-top-7-best-sell... Too bad the other vendors don’t bother keeping up.

that's only 16% of total market.

But 50% of revenue share (and has been as high as 110% of profit share):

https://www.counterpointresearch.com/insights/iphone-hits-re...

That's not the point if you're talking about who you can have an encrypted conversation with, but it matters if you want to know if you can afford building an encryption tool to serve phone buyers.

Re: iMessage with PQ3 Cryptographic Protocol

#156

Advanced encryption, until it comes time to text 70% of the phones in the world, in which case it defaults to a protocol released 32 years ago.

RCS is unencrypted unless you use Google's closed garden Google Messages' extensions. Apple is apparently working with GSMA to add encryption to the standard though. (They probably wouldn't add RCS otherwise.)

They would if a regulator made them. They're adding it because China requires it.

Re: iMessage with PQ3 Cryptographic Protocol

#157
post #89

Earlier quoted context omitted.

To clear up the FUD here, this is only true if you turn on iCloud backups (many users do, but still) and don't turn on Advanced Data Protection. ADP is off by default because it means you'll lose all your backups if you forget your iCloud password. > it’s a platform designed to aid illegal government surveillance. Come on.

These are the defaults. You don’t need to turn on iCloud Backup, it’s already on. You don’t need to turn off Advanced Data Protection, it’s already off. Literally all you need to do is turn on a new iPhone and try to install any app. It will prompt for your Apple ID login (impossible to install apps without it) and will automatically enable iCloud, iCloud Backup, and iMessage (and will not enable ADP). https://www.fo…

> and will not enable ADP

Not only will it not enable ADP, it won't even ask you about it.

Re: iMessage with PQ3 Cryptographic Protocol

#158
post #89

Earlier quoted context omitted.

These are the defaults. You don’t need to turn on iCloud Backup, it’s already on. You don’t need to turn off Advanced Data Protection, it’s already off. Literally all you need to do is turn on a new iPhone and try to install any app. It will prompt for your Apple ID login (impossible to install apps without it) and will automatically enable iCloud, iCloud Backup, and iMessage (and will not enable ADP). https://www.fo…

iMessage is excluded by default on iCloud backups, that's what the other guy is saying

Messages in iCloud (different thing, used for syncing iMessage conversations to all your devices) is off by default, to my knowledge backups of the iMessage database is on by default in the iCloud backup setting, but admittedly I haven't setup a new device without restoring an iCloud backup in many many years.

Re: iMessage with PQ3 Cryptographic Protocol

#159
post #86

Earlier quoted context omitted.

Absolutely a reference. Dilithium (from Star Trek) is name of their signature algorithm.

The trick to naming things is to first find a cool word/reference, and then 'reverse engineer' it as an acronym second: * https://en.wikipedia.org/wiki/Backronym

Though you can easily take it too far; I think US legislators have been running out of reasonable backronyms :)

Re: iMessage with PQ3 Cryptographic Protocol

#160
post #53

Isn't all this post quantum stuff a little premature? The standards haven't settled. We don't even know if there is a possible quantum threat to cryptography yet. The more we work on the problem the less likely it seems. Last I heard we were 1 or 2 orders of magnitude away from physical noise performance that would make such a threat possible. Edit, added: Harvest now, decrypt later applies to any encrypted data. The…

You'd be right except that anything encrypted now can be stored and cracked later. I remember as part of the snowden leaks there was documentation about this kind of delayed phase collection. Basically store as much signals data as you can and try to crack it later if there's a weakness discovered with the protocol or computing power starts being capable of wholesale attack. You might remember that hashes are signifi…

RSA isn't anywhere near 10 years away from being attackable with a classical computer. (More like eons.)

It's not a matter of time, it's just a matter of quantum computers existing.

Post reply on HN