Live data from Hacker News

iMessage with PQ3 Cryptographic Protocol

security.apple.com

171–180 of 280 posts

Re: iMessage with PQ3 Cryptographic Protocol

#171

Earlier quoted context omitted.

Sure. Different projects, different goals. At every instant where Telegram had a decision to make between better user experience or user security & privacy, Telegram opted to make a better experience. Signal took significant UX hits to make the privacy promises it makes. The two projects are essentially not comparable. Like, the sane thing to compare Telegram to at this point is Matrix.

Of course, but it’s not just UX that’s being traded off but also potential for mass adoption, and evangelism is likely not enough to close the gap.

Again: different projects, different goals. What Telegram is doing is inherently viral; the platform has an emphasis on bringing huge groups of people together, and the resulting design affordances, and that's a goal that basically works against privacy in the first place. Signal's original goal is to replace intimate messaging.

People who love the Telegram affordances wish that the platform would also suffice for intimate messages. Why have two platforms, two UX's, and (most importantly) two user bases? People who live Signal wish the other thing.

But you can't have both. They are incompatible design spaces. Telegram's security story is atrocious. It's best compared with Slack, not with Signal. If you're looking to compare a serious secure messenger with Telegram, look at Matrix, which has many of the same goals.

It is important that there be a messaging platform in common (if not universal) use that is fit for purpose for secure messaging when it really matters: when the compromise a message could cost lives or fortunes. Most "secure messaging" is LARPing; it doesn't matter if the "E2EE" in a pseudonymous 500-person chat room is secure. By all means, make it harder to dragnet that channel, modernize the protocols, whatever. But you can see right away how little security really matters to these groups, whether they're on Telegram (with no group security) or Matrix (which at least tries), because messaging app affordances are all people talk about with them.

Re: iMessage with PQ3 Cryptographic Protocol

#172

This is pretty fascinating. For easier reading, the Signal blog post [0] they link to is great. Both Signal and Apple went with CRYSTALS-Kyber [1] as their post-quantum algorithm. If you're interested in the math, and maybe learned at some point about how classic public key cryptography is built on the idea that it's easy to multiply two primes, but hard to factor them, and how this (or other math problems) can be us…

I'm way out of my depth in terms of the math here. But my 'software engineer brain' likes the ideal of using the prime factoring problem, because it's so simple to understand, and feels like some kind of universal primitive. "It's easy to multiply but hard to factor." It just seems so intuitive. But I'm reading the 'learning with errors' wiki page and it's beyond my comprehension. There's a weird fear in my mind that…

I know that thinking, but learning more about RSA, I came to realize that there's a flipside of this.

People think "RSA is easy", because someone gave them a lecture of a simplified/wrong/insecure version of RSA. Pretty much all "simple introductions to RSA" you can find out there are wrong.

The truth is: RSA isn't that simple. If you want to have RSA, and want to have it secure, there's a whole bunch of things to consider. But RSA looks simple.

So lots of people go ahead and implement their RSA. And then you end up with, hey, I can break almost a third of the top 100 webpage's RSA implementations. (I'm not kidding, I did that -> https://robotattack.org/ .)

I think the fact that crystals-kyber is obviously not that simple may actually protect us. Because hopefully most peopple will end up using some hopefully well audited optimized free implementation, because they won't even have the idea that they could do this on their own.

Re: iMessage with PQ3 Cryptographic Protocol

#173

>When iMessage launched in 2011, it was the first widely available messaging app to provide end-to-end encryption by default,... Until very recently, iMessage provided no way to verify that you and your correspondent were not both connected to the server, rather than each other. So guaranteed end-to end encryption wasn't possible. Even now, with a recent version of iOS, they allow the users to blithely exchange messa…

Same thing with Signal and most other messengers. Can you link to some documentation that shows iMessage even has the identity numbers?

Re: iMessage with PQ3 Cryptographic Protocol

#174

This is pretty fascinating. For easier reading, the Signal blog post [0] they link to is great. Both Signal and Apple went with CRYSTALS-Kyber [1] as their post-quantum algorithm. If you're interested in the math, and maybe learned at some point about how classic public key cryptography is built on the idea that it's easy to multiply two primes, but hard to factor them, and how this (or other math problems) can be us…

I'm way out of my depth in terms of the math here. But my 'software engineer brain' likes the ideal of using the prime factoring problem, because it's so simple to understand, and feels like some kind of universal primitive. "It's easy to multiply but hard to factor." It just seems so intuitive. But I'm reading the 'learning with errors' wiki page and it's beyond my comprehension. There's a weird fear in my mind that…

> There's a weird fear in my mind that all these "post quantum algorithms" are so complicated, with such a large surface area, that they may hide flaws.

That's correct (emphasis on "may", of course), and is why it's absolutely imperative to always use PQC/ECC hybrid cryptosystems rather than pure PQC. See eg [0] for a more detailed explanation.

0: https://blog.cr.yp.to/20240102-hybrid.html

Re: iMessage with PQ3 Cryptographic Protocol

#175

Earlier quoted context omitted.

> Yes but that would have meant giving up sales in exchange for actually backing up their words. I saw that you moved the goalposts in your reply, but anyway: which words? > They aren’t even going to use the developed encrypted RCS protocol. The protocol that was designed by Google and in which Google’s infrastructure is crucial? It’s not Apple’s fault that RCS does not have mandatory end-to-end encryption. > I have…

RCS was not designed by Google. Google has (so far) embraced it after repeatedly self-sabotaging their own chat efforts. RCS is a carrier standard that the carriers had trouble deploying.

> RCS was not designed by Google.

Encrypted RCS was. And it is proprietary.

Re: iMessage with PQ3 Cryptographic Protocol

#176

Earlier quoted context omitted.

I'm way out of my depth in terms of the math here. But my 'software engineer brain' likes the ideal of using the prime factoring problem, because it's so simple to understand, and feels like some kind of universal primitive. "It's easy to multiply but hard to factor." It just seems so intuitive. But I'm reading the 'learning with errors' wiki page and it's beyond my comprehension. There's a weird fear in my mind that…

> There's a weird fear in my mind that all these "post quantum algorithms" are so complicated, with such a large surface area, that they may hide flaws. That's correct (emphasis on "may", of course), and is why it's absolutely imperative to always use PQC/ECC hybrid cryptosystems rather than pure PQC. See eg [0] for a more detailed explanation. 0: https://blog.cr.yp.to/20240102-hybrid.html

There are essentially no mainstream systems that don't do this. That's why new systems deploy things like PQ3.

Re: iMessage with PQ3 Cryptographic Protocol

#177
post #20
post #2

Does anyone know if this is still vulnerable to the iCloud Backups problem? The only solution to that right now is for you and your contact to turn on Advanced Data Protection. Curious if that’s still required.

> Does anyone know if this is still vulnerable to the iCloud Backups problem? The only solution to that right now is for you and your contact to turn on Advanced Data Protection. This is such a strange two sentences as a "problem". E2EE security, as it says in the name, is about the protection of dara transmission between two trusted end points. That's it. What the trusted end points themselves choose to do with that…

This is how Constantinople fell to the Ottomans: they had very high hard to penetrate walls, but forgot to lock one gate. *

Replace the walls with highly secure encryption e2e algorithm, and the gate with easily accessible backup, and you'll see why things like this are not out of scope.

* - this story is disputed by some historians

Re: iMessage with PQ3 Cryptographic Protocol

#178
post #132

Earlier quoted context omitted.

> There's nothing to fix The default. They need to fix the default. > By your twisted definition, there is no such thing as E2EE for any transport in existence What a ridiculous misunderstanding of my position. iMessage and iCloud are inseparable parts of the whole of iOS, all from the same company, and their default configuration is not end-to-end encrypted. My position is that it is fraudulent to treat them as if t…

> The default. They need to fix the default. No, they do not. That you don't give a shit about people losing data is a value tradeoff you believe in, but you've got a lot of work to argue it's an objective universal. > What a ridiculous misunderstanding of my position. It's amazing how you can say this with a virtual straight face, then immediately go on to directly argue that yep, that's your position. > iMessage an…

> You do not need to use iCloud Backups

You do if you want cloud backups (as most people do), because Apple prohibits you from doing it any other way. You can't uninstall the iCloud backup software, you can't replace it, and you can't buy an iOS device without it. It's literally inseparable from iOS by Apple's design, and iMessage is too in exactly the same way.

> So that must mean HTTPS is somehow no longer E2EE either

Safari doesn't backup the contents of your HTTPS connections to Apple, nor even the URLs for the vast majority (only top level page navigations are stored in history). The analogous situation would be if Safari would relay all the content of every HTTPS connection to Apple servers along with the keys to decrypt it. Maybe you would defend such a system as "end-to-end encrypted", but you would be in a very small minority.

> My phone password is

... completely irrelevant. Who cares? You're not seriously arguing that 21 character phone unlock passcodes are typical? We're talking about defaults here.

> I almost never enter it because of Face ID

I was wrong. I thought that you had to enter the passcode at least once daily, but it's actually at least once weekly. However my point stands. It's extremely unlikely for the vast majority of people to forget their passcode, which is distinct from their account password, which is almost invariably very short, and which they practice entering at least weekly.

As for the edge cases you mention, every system has edge cases. The non-E2EE account recovery case has edge cases too. It requires navigating Apple's support process and proving your identity via whatever means they request which not everyone will be able to do successfully. Also it's vulnerable to social engineering attacks on the support reps. No system is perfect. If the forgetting issues were so bad, then Apple wouldn't by default encrypt Keychain passwords with true E2EE. Losing those is actually super inconvenient too, but Apple has no problem with E2EE there. That's because law enforcement cares more about reading your messages than logging into your Reddit account (or they can just go to Reddit directly).

> PINs are just a kind of password

A very special kind of password which is by design much easier to remember and practiced more often. They are very different in practice, don't pretend there's no relevant difference.

> I'm starting to wonder if you actually own and use iDevices at all

I owned and loved the OG iPhone and many other generations too. Although my current phone is Android, I still use iPhones and iPads casually from time to time.

Look, I could continue all day, but long experience has taught me that it's pointless to argue with someone so clearly stuck in the reality distortion field. I believe I've made my points clearly for any other reader of this thread. I won't be responding further.

Re: iMessage with PQ3 Cryptographic Protocol

#179

This is pretty fascinating. For easier reading, the Signal blog post [0] they link to is great. Both Signal and Apple went with CRYSTALS-Kyber [1] as their post-quantum algorithm. If you're interested in the math, and maybe learned at some point about how classic public key cryptography is built on the idea that it's easy to multiply two primes, but hard to factor them, and how this (or other math problems) can be us…

I was reading the NIST comments and djb is not very happy with how they present things, and the other commenters seem to think he is a prick.

Re: iMessage with PQ3 Cryptographic Protocol

#180

Pretty great advertisement for Signal, as the sole cross-platform option in the PQC bucket. Does it seem likely they will match Apple here eventually?

I am not sure if I understand things correctly, but what apple did seems like a lot of work for little benefit. Symmetric encryption is not threatened nearly as much by quantum computers. Using a PQ key exchange should make adequately safe until someone breaks symmetric encryption, which seems like a high odds bet. The author of age wrote some time ago why aes128 is good enough.

But I am a classical musician so for the love of god don't listen to me.

Post reply on HN