>When iMessage launched in 2011, it was the first widely available messaging app to provide end-to-end encryption by default,... Until very recently, iMessage provided no way to verify that you and your correspondent were not both connected to the server, rather than each other. So guaranteed end-to end encryption wasn't possible. Even now, with a recent version of iOS, they allow the users to blithely exchange messa…
Same thing with Signal and most other messengers. Can you link to some documentation that shows iMessage even has the identity numbers?
iMessage with PQ3 Cryptographic Protocol
191–200 of 280 posts
Re: iMessage with PQ3 Cryptographic Protocol
#192Earlier quoted context omitted.
This lack of backups makes Signal less appealing to anyone who isn't a security/privacy enthusiast/nut. 99+% of people want their messages to work and not lose them when their phone is broken.
No I do not agree with you. Majority of people never read their message history, want their messages to self-detruct and don't want to get into a situation like when a new partner reads chat history with all previous partners. Majority of people do not record their conversations and do not need this. And most messaging applications are designed countrary to what people need - they preserve history specially for that…
Re: iMessage with PQ3 Cryptographic Protocol
#193This is pretty fascinating. For easier reading, the Signal blog post [0] they link to is great. Both Signal and Apple went with CRYSTALS-Kyber [1] as their post-quantum algorithm. If you're interested in the math, and maybe learned at some point about how classic public key cryptography is built on the idea that it's easy to multiply two primes, but hard to factor them, and how this (or other math problems) can be us…
I was reading the NIST comments and djb is not very happy with how they present things, and the other commenters seem to think he is a prick.
And I'd like the US/The west to declare 1 part as secure, and I'd like Russia to declare the other part as secure.
I'm fairly confident that Russia and the US won't collude to push a known-weak algorithm.
Re: iMessage with PQ3 Cryptographic Protocol
#194Re: iMessage with PQ3 Cryptographic Protocol
#195Earlier quoted context omitted.
There are essentially no mainstream systems that don't do this. That's why new systems deploy things like PQ3.
Do you mean: > There are essentially no mainstream systems that don't [use PQC/ECC hybrid cryptosystems?]. If so, good. I'll admit my expectations are a bit biased from having to deal with projects that go out of their way to produce defective software (eg DRM, malicious abuse of undefined behaviour by compliers, cloudflare and other captcha-walls, etc) so I tend to assume the worst by default.
Re: iMessage with PQ3 Cryptographic Protocol
#196Earlier quoted context omitted.
The main things holding back Signal usage in my case is practically nobody in my social circle using it and the desktop client not being as nice as that of Messages or Telegram, the latter being particularly relevant for myself and contacts who primarily message with their computers rather than their phones.
Signal UX is AWFUL if you have a work PC, a home PC, a phone, and a tablet. Getting messages to flow across all of them is impossible.
Re: iMessage with PQ3 Cryptographic Protocol
#197Earlier quoted context omitted.
Yeah I think this was a bad move for Signal, but I didn't see that happen to my group fortunately. In Signal's defense, my understanding is that this was really an Apple thing. That Apple only lets iMessage connect to SMS so the apps were differing significantly. I also get the fatigue. Moxie said centralized because they needed to move faster. But Signal has always moved very slow, so it does feel off. But to be fai…
They were talking about on Android. Signal supporting SMS was never a thing on iOS.
Signal is only like 42 people.[0] You gotta triage a lot of stuff. I wish the feature still existed, but I can totally understand why they did that. I'm pretty sure not all 42 people are programmers.
[0] https://projects.propublica.org/nonprofits/organizations/824...
Re: iMessage with PQ3 Cryptographic Protocol
#198Earlier quoted context omitted.
Sounds like time to become an evangelist then. I had to do this in my group and other than security a major benefit is just that getting potatos instead of pictures has significantly declined. Here's my advice: don't sell security as the foremost feature. Sell it as "iMessage, but for everyone." You got stickers, reactions, high quality videos and images. Then mention security, it is the cherry on top.
Every single person I converted to using Signal stopped using it when SMS support was removed. HN tends to be a younger crowd whose peers cycled through a number of social-networking and messaging apps as popularity waxed and waned. But older generations don't see any compelling reason why they should bother splitting their conversations over multiple apps, when literally everyone with a mobile has texting. Being a d…
I thought RCS explicitly wasn’t E2EE?
Re: iMessage with PQ3 Cryptographic Protocol
#199Earlier quoted context omitted.
> The default. They need to fix the default. No, they do not. That you don't give a shit about people losing data is a value tradeoff you believe in, but you've got a lot of work to argue it's an objective universal. > What a ridiculous misunderstanding of my position. It's amazing how you can say this with a virtual straight face, then immediately go on to directly argue that yep, that's your position. > iMessage an…
> You do not need to use iCloud Backups You do if you want cloud backups (as most people do), because Apple prohibits you from doing it any other way. You can't uninstall the iCloud backup software, you can't replace it, and you can't buy an iOS device without it. It's literally inseparable from iOS by Apple's design, and iMessage is too in exactly the same way. > So that must mean HTTPS is somehow no longer E2EE eit…
Re: iMessage with PQ3 Cryptographic Protocol
#200Earlier quoted context omitted.
The main things holding back Signal usage in my case is practically nobody in my social circle using it and the desktop client not being as nice as that of Messages or Telegram, the latter being particularly relevant for myself and contacts who primarily message with their computers rather than their phones.
Sounds like time to become an evangelist then. I had to do this in my group and other than security a major benefit is just that getting potatos instead of pictures has significantly declined. Here's my advice: don't sell security as the foremost feature. Sell it as "iMessage, but for everyone." You got stickers, reactions, high quality videos and images. Then mention security, it is the cherry on top.
People's eyes glaze over and they go right back to using WhatsApp, which offers nearly everything Signal does, but also full sync. Most people don't care about the differences in privacy.