Earlier quoted context omitted.
> Yes but that would have meant giving up sales in exchange for actually backing up their words. I saw that you moved the goalposts in your reply, but anyway: which words? > They aren’t even going to use the developed encrypted RCS protocol. The protocol that was designed by Google and in which Google’s infrastructure is crucial? It’s not Apple’s fault that RCS does not have mandatory end-to-end encryption. > I have…
I worked on several integration attempts between Apple and Google. They often presented specs that clearly showed security holes then simply would deny they were there or say “that’s secure”. It was a truly wild experience.
iMessage with PQ3 Cryptographic Protocol
181–190 of 280 posts
Re: iMessage with PQ3 Cryptographic Protocol
#182Earlier quoted context omitted.
You text them a link to join the call. The Android user can’t be the one to initiate.
Oh. Ok that's never going to work. "Hey there please click on this link to talk to me" => Malware! Blocked.
Re: iMessage with PQ3 Cryptographic Protocol
#183Earlier quoted context omitted.
You text them a link to join the call. The Android user can’t be the one to initiate.
> The Android user can’t be the one to initiate. That sounds like a bad joke. "Everyone can use Facetime, except if you're on a certain platform you have to ask someone on the 'real' platform to initiate the call." That's... not a viable communication method.
Re: iMessage with PQ3 Cryptographic Protocol
#184This is pretty fascinating. For easier reading, the Signal blog post [0] they link to is great. Both Signal and Apple went with CRYSTALS-Kyber [1] as their post-quantum algorithm. If you're interested in the math, and maybe learned at some point about how classic public key cryptography is built on the idea that it's easy to multiply two primes, but hard to factor them, and how this (or other math problems) can be us…
I'm way out of my depth in terms of the math here. But my 'software engineer brain' likes the ideal of using the prime factoring problem, because it's so simple to understand, and feels like some kind of universal primitive. "It's easy to multiply but hard to factor." It just seems so intuitive. But I'm reading the 'learning with errors' wiki page and it's beyond my comprehension. There's a weird fear in my mind that…
Re: iMessage with PQ3 Cryptographic Protocol
#185Advanced encryption, until it comes time to text 70% of the phones in the world, in which case it defaults to a protocol released 32 years ago.
Re: iMessage with PQ3 Cryptographic Protocol
#186Earlier quoted context omitted.
> There's a weird fear in my mind that all these "post quantum algorithms" are so complicated, with such a large surface area, that they may hide flaws. That's correct (emphasis on "may", of course), and is why it's absolutely imperative to always use PQC/ECC hybrid cryptosystems rather than pure PQC. See eg [0] for a more detailed explanation. 0: https://blog.cr.yp.to/20240102-hybrid.html
There are essentially no mainstream systems that don't do this. That's why new systems deploy things like PQ3.
> There are essentially no mainstream systems that don't [use PQC/ECC hybrid cryptosystems?].
If so, good. I'll admit my expectations are a bit biased from having to deal with projects that go out of their way to produce defective software (eg DRM, malicious abuse of undefined behaviour by compliers, cloudflare and other captcha-walls, etc) so I tend to assume the worst by default.
Re: iMessage with PQ3 Cryptographic Protocol
#187Earlier quoted context omitted.
I'm way out of my depth in terms of the math here. But my 'software engineer brain' likes the ideal of using the prime factoring problem, because it's so simple to understand, and feels like some kind of universal primitive. "It's easy to multiply but hard to factor." It just seems so intuitive. But I'm reading the 'learning with errors' wiki page and it's beyond my comprehension. There's a weird fear in my mind that…
The explanation in this video is what made it click for me: https://www.youtube.com/watch?v=K026C5YaB3A
Re: iMessage with PQ3 Cryptographic Protocol
#188Earlier quoted context omitted.
> "messages in icloud" is end to end encrypted, and enabling it disables messages for being included in icloud backup. This is misleading at best. Careful reading of Apple's disclosures reveals that the "messages in iCloud" encryption keys are still included in iCloud backups, giving Apple the capability to decrypt your messages on demand for law enforcement or for any other reason of their choosing. The messages may…
Just a bit lower on the same page: > When iCloud Backup is turned on, everything inside it is end-to-end encrypted, including the Messages in iCloud encryption key. Meaning that Apple does not actually have access to that key, because it is encrypted before being saved to their servers.
Re: iMessage with PQ3 Cryptographic Protocol
#189Earlier quoted context omitted.
For me, Signal is so much better for my friend or work group chats. My friends are on a mix of devices and platforms, and Signal is a lot nicer for embedded media sharing. And the auto disappearing feature is a must!
The main things holding back Signal usage in my case is practically nobody in my social circle using it and the desktop client not being as nice as that of Messages or Telegram, the latter being particularly relevant for myself and contacts who primarily message with their computers rather than their phones.
Getting messages to flow across all of them is impossible.
Re: iMessage with PQ3 Cryptographic Protocol
#190Earlier quoted context omitted.
Sounds like time to become an evangelist then. I had to do this in my group and other than security a major benefit is just that getting potatos instead of pictures has significantly declined. Here's my advice: don't sell security as the foremost feature. Sell it as "iMessage, but for everyone." You got stickers, reactions, high quality videos and images. Then mention security, it is the cherry on top.
Every single person I converted to using Signal stopped using it when SMS support was removed. HN tends to be a younger crowd whose peers cycled through a number of social-networking and messaging apps as popularity waxed and waned. But older generations don't see any compelling reason why they should bother splitting their conversations over multiple apps, when literally everyone with a mobile has texting. Being a d…
I don't like splitting my conversations over multiple apps when literally everyone with a mobile in Argentina has WhatsApp. SMS costs money and having it in the same app as a free messaging platform sounds risky :P