Live data from Hacker News

iMessage with PQ3 Cryptographic Protocol

security.apple.com

161–170 of 280 posts

Re: iMessage with PQ3 Cryptographic Protocol

#161
post #71

Earlier quoted context omitted.

[flagged]

As far as I'm aware, iCloud for Messages is not enabled by default. Security-conscious users should know not to turn it on, though -- if iCloud servicing warrants is part of their threat model. Further, Apple ended up rolling out Advanced Data Protection for iCloud in 2023, so users who truly don't want Apple holding those keys can effectively take them from Apple. https://support.apple.com/guide/security/advanced-da…

Messages in iCloud is separate from the inclusion of the iMessage database in the regular iPhone iCloud backups. Could you check what that setting is set to on your newly setup device?

Re: iMessage with PQ3 Cryptographic Protocol

#162

Earlier quoted context omitted.

Yeah Telegram absolutely nails the desktop experience like few other chat apps do. The way they put all the functional bits into a library to make it easy to build high quality third-party clients helps, too; while the Qt client is quite good across platforms, users also have the option of a Swift-based client on Apple platforms, a WinUI/UWP client on Windows, GTK client for GTK-based Linux desktops, etc which takes…

Sure. Different projects, different goals. At every instant where Telegram had a decision to make between better user experience or user security & privacy, Telegram opted to make a better experience. Signal took significant UX hits to make the privacy promises it makes. The two projects are essentially not comparable. Like, the sane thing to compare Telegram to at this point is Matrix.

Of course, but it’s not just UX that’s being traded off but also potential for mass adoption, and evangelism is likely not enough to close the gap.

Re: iMessage with PQ3 Cryptographic Protocol

#163
post #53

Isn't all this post quantum stuff a little premature? The standards haven't settled. We don't even know if there is a possible quantum threat to cryptography yet. The more we work on the problem the less likely it seems. Last I heard we were 1 or 2 orders of magnitude away from physical noise performance that would make such a threat possible. Edit, added: Harvest now, decrypt later applies to any encrypted data. The…

You'd be right except that anything encrypted now can be stored and cracked later. I remember as part of the snowden leaks there was documentation about this kind of delayed phase collection. Basically store as much signals data as you can and try to crack it later if there's a weakness discovered with the protocol or computing power starts being capable of wholesale attack. You might remember that hashes are signifi…

That Forbes article is about a loophole involving encryption that could allow the NSA to collect and store data that they might not otherwise be able to. Now that everything is encrypted, that loophole might cover everything.

Nothing in the article implies that the NSA can magically collect all the encrypted data in the world and keep it for many years.

Re: iMessage with PQ3 Cryptographic Protocol

#164
post #149

Earlier quoted context omitted.

What? how does that work? If you call the cell number of an Android device on facetime, what happens on the android end?

You text them a link to join the call. The Android user can’t be the one to initiate.

Oh. Ok that's never going to work.

"Hey there please click on this link to talk to me"

=> Malware! Blocked.

Re: iMessage with PQ3 Cryptographic Protocol

#165

This is pretty fascinating. For easier reading, the Signal blog post [0] they link to is great. Both Signal and Apple went with CRYSTALS-Kyber [1] as their post-quantum algorithm. If you're interested in the math, and maybe learned at some point about how classic public key cryptography is built on the idea that it's easy to multiply two primes, but hard to factor them, and how this (or other math problems) can be us…

I'm way out of my depth in terms of the math here. But my 'software engineer brain' likes the ideal of using the prime factoring problem, because it's so simple to understand, and feels like some kind of universal primitive. "It's easy to multiply but hard to factor." It just seems so intuitive. But I'm reading the 'learning with errors' wiki page and it's beyond my comprehension. There's a weird fear in my mind that…

The LWE problem is one level of abstraction away from the fundamental lattice problems it reduces to. It is somewhat analogous to the Diffie-Hellman problem that many constructions reduce to, which itself is related to the lower-level discrete logarithm problem.

The lattice equivalent of integer factorization is the shortest vector problem: you're given n vectors of length m, and you have to find the sum of integer multiples of those vectors that comes closest to (or a small factor away from the closest) the zero vector. Say you have the 4 vectors

    [ 3 92  4  2]
    [54  0 92 41]
    [19 91 61 48]
    [39 59 40 14].
The shortest vector that you can obtain from adding integer multiples of these vectors is [19 -8 -15 2], which you can obtain by 3*[39 59 40 14] + [19 91 61 48] - 2*[54 0 92 41] - 3*[ 3 92 4 2].

With only 4 vectors it is easy to find the solution here. But the hardness grows exponentially with the dimension, and the dimensions in cryptographically relevant lattices are in the hundreds to thousands.

Re: iMessage with PQ3 Cryptographic Protocol

#166
post #17

Earlier quoted context omitted.

>The only solution to that right now is for you and your contact to turn on Advanced Data Protection or don't use icloud backup. Also, confusingly "messages in icloud" is end to end encrypted, and enabling it disables messages for being included in icloud backup.

> "messages in icloud" is end to end encrypted, and enabling it disables messages for being included in icloud backup. This is misleading at best. Careful reading of Apple's disclosures reveals that the "messages in iCloud" encryption keys are still included in iCloud backups, giving Apple the capability to decrypt your messages on demand for law enforcement or for any other reason of their choosing. The messages may…

Just a bit lower on the same page:

> When iCloud Backup is turned on, everything inside it is end-to-end encrypted, including the Messages in iCloud encryption key.

Meaning that Apple does not actually have access to that key, because it is encrypted before being saved to their servers.

Re: iMessage with PQ3 Cryptographic Protocol

#167
post #149

Earlier quoted context omitted.

What? how does that work? If you call the cell number of an Android device on facetime, what happens on the android end?

You text them a link to join the call. The Android user can’t be the one to initiate.

> The Android user can’t be the one to initiate.

That sounds like a bad joke. "Everyone can use Facetime, except if you're on a certain platform you have to ask someone on the 'real' platform to initiate the call." That's... not a viable communication method.

Re: iMessage with PQ3 Cryptographic Protocol

#168
post #131

Earlier quoted context omitted.

Sounds like time to become an evangelist then. I had to do this in my group and other than security a major benefit is just that getting potatos instead of pictures has significantly declined. Here's my advice: don't sell security as the foremost feature. Sell it as "iMessage, but for everyone." You got stickers, reactions, high quality videos and images. Then mention security, it is the cherry on top.

Every single person I converted to using Signal stopped using it when SMS support was removed. HN tends to be a younger crowd whose peers cycled through a number of social-networking and messaging apps as popularity waxed and waned. But older generations don't see any compelling reason why they should bother splitting their conversations over multiple apps, when literally everyone with a mobile has texting. Being a d…

> HN tends to be a younger crowd whose peers cycled through a number of social-networking and messaging apps as popularity waxed and waned. But older generations

What is your definition of younger and older? Anybody born in the 70s or later experienced an ongoing procession of instant messaging choices. I would tell you it is precisely that experience that informs my apathy towards the latest and greatest Hot Thing, and makes me appreciate boring old SMS (and by extension, iMessage) that I know will just work with anyone I meet.

Re: iMessage with PQ3 Cryptographic Protocol

#169

Advanced encryption, until it comes time to text 70% of the phones in the world, in which case it defaults to a protocol released 32 years ago.

This is getting downvoted, but it really does feel like a variant of the wrench problem: https://xkcd.com/538/ It's already incredibly hard to get people to use secure messaging systems. Downgrading to SMS isn't necessarily wrong (it's become harder to get people to use Signal now that it's dropped support for SMS), but it's a huge hole and effectively means that many customers will never have a significant number of…

> It's the wrench problem. You're not going to get spied on by a quantum computer.

I'll take that one step further; it's the trusting trust problem. In the words of Ken Thomson, "To what extent should one trust a statement that a program is free of Trojan horses?"

You're not going to be spied on by a quantum computer because intelligence agencies already use classical computing for that. Some governments write Apple or Google a strongly worded email, others install a backdoor using iMessage. There's no need to crack your encryption because you're not going up against quantum adversaries; those people all have better options than bruteforcing Apple's lock. Sufficiently-motivated actors skip the wrench and pay Bob or Alice for your password.

There's no perfect solution to this issue. Apple would sooner die than lower the drawbridge to iMessage, and Google can't be bothered to write an altruistic RFC to save their life. Now we get the worst of both worlds; divided and surveilled.

Re: iMessage with PQ3 Cryptographic Protocol

#170
post #135

Earlier quoted context omitted.

That's still not the same as claiming that iMessage is designed specifically for the purpose of aiding government surveillance.

Not adding E2E was a conscious design decision by Apple specifically to aid surveillance. Virtually every other big messaging service offered (optional) E2E at that point. I’m not sure how much clearer you want it. “Surveillance” doesn’t have to mean that Apple allowed the FBI to jack directly into the iCloud servers.

Wasn't it an attempt to take the fangs out of the FBI's push for encryption backdoors? As one of the largest messaging platforms in the US, what Apple does with E2E absolutely factors into public policymaking.
Post reply on HN