Live data from Hacker News

iMessage with PQ3 Cryptographic Protocol

security.apple.com

211–220 of 280 posts

Re: iMessage with PQ3 Cryptographic Protocol

#212

This is pretty fascinating. For easier reading, the Signal blog post [0] they link to is great. Both Signal and Apple went with CRYSTALS-Kyber [1] as their post-quantum algorithm. If you're interested in the math, and maybe learned at some point about how classic public key cryptography is built on the idea that it's easy to multiply two primes, but hard to factor them, and how this (or other math problems) can be us…

https://kyberslash.cr.yp.to

Re: iMessage with PQ3 Cryptographic Protocol

#213

Earlier quoted context omitted.

This lack of backups makes Signal less appealing to anyone who isn't a security/privacy enthusiast/nut. 99+% of people want their messages to work and not lose them when their phone is broken.

No I do not agree with you. Majority of people never read their message history, want their messages to self-detruct and don't want to get into a situation like when a new partner reads chat history with all previous partners. Majority of people do not record their conversations and do not need this. And most messaging applications are designed countrary to what people need - they preserve history specially for that…

>> No I do not agree with you. Majority of people never read their message history, want their messages to self-detruct

Citation needed.

Re: iMessage with PQ3 Cryptographic Protocol

#214
post #201

Earlier quoted context omitted.

> resigned to the idea that cross-platform RCS is the only thing that will bring encryption to the majority of my contacts I thought RCS explicitly wasn’t E2EE?

The current standard isn't. Google uses non-standard E2EE, and they and Apple are working on getting it standardized.

If so, how will they meet China's demand that all mobile devices support RCS, presumably because it doesn't employ E2EE?

Re: iMessage with PQ3 Cryptographic Protocol

#215
post #189

Earlier quoted context omitted.

Signal UX is AWFUL if you have a work PC, a home PC, a phone, and a tablet. Getting messages to flow across all of them is impossible.

Getting messages to flow across lots of different platforms for a single account has been a source for a number of very bad security problems in other messengers. (Recent example: Matrix, Nebuchadnezzar). Different projects, different priorities.

Signal already has the ability to register multiple devices with the same account, though. The only thing they haven't done with this is support sync of past messages. That seems like it should be much simpler than supporting multiple devices in the first place, and I'm wondering if there's some non-obvious attack that they're simply not talking about or if it just hasn't reached the top of their priority list yet.

Re: iMessage with PQ3 Cryptographic Protocol

#216

Earlier quoted context omitted.

Hmm… Does signal only really work when everyone uses it? Or can you include people who are just using regular SMS?

It used to have SMS support but they yanked it maybe a year or so ago. The big issue on the user end was, if someone deleted Signal and you used Signal for your SMS, it would keep sending them signal messages and not SMS. So you were left not realizing you were texting essentially a dead number.

...much like iMessage.

Re: iMessage with PQ3 Cryptographic Protocol

#217

Earlier quoted context omitted.

> They aren’t even going to use the developed encrypted RCS protocol. End-to-end RCS encryption is via proprietary Google extension and not even available to other Android RCS messaging apps.

It was made available to Apple.

Under what terms, and with what promises?

If Google's strategy was anything other than "get Apple to adopt, then screw them", Google would have contributed the enhancements back to the standard.

Re: iMessage with PQ3 Cryptographic Protocol

#218
post #172

Earlier quoted context omitted.

I know that thinking, but learning more about RSA, I came to realize that there's a flipside of this. People think "RSA is easy", because someone gave them a lecture of a simplified/wrong/insecure version of RSA. Pretty much all "simple introductions to RSA" you can find out there are wrong. The truth is: RSA isn't that simple. If you want to have RSA, and want to have it secure, there's a whole bunch of things to co…

I love that security by difficulty is the new security by obscurity, but actually secure.

Is it new? Security by difficulty _is_ security.

Re: iMessage with PQ3 Cryptographic Protocol

#219
post #172

Earlier quoted context omitted.

I know that thinking, but learning more about RSA, I came to realize that there's a flipside of this. People think "RSA is easy", because someone gave them a lecture of a simplified/wrong/insecure version of RSA. Pretty much all "simple introductions to RSA" you can find out there are wrong. The truth is: RSA isn't that simple. If you want to have RSA, and want to have it secure, there's a whole bunch of things to co…

I love that security by difficulty is the new security by obscurity, but actually secure.

Yeah talking about difficulty, then you will love this: https://www.science.org/content/article/china-s-quantum-sate...

If we really wanna be security, then entailment is a good bet. I could imagine essential financial clearing, emergency infrastructure could use this level security. Don't know how feasible it is for consumer grade usage yet though.

Re: iMessage with PQ3 Cryptographic Protocol

#220

Just as a reminder making crack-proof encryption standard everywhere is a trade off. It’s often discussed and presented in forums like this as the only and just choice (and I believe net it is), but in doing so WILL lead to bad outcomes. Terrible crimes, unsolvable murders, large scale terrorism, emboldened enemies attacking a country, more successful coups, etc. It would be nice as a community to acknowledge nothing…

https://www.eureporter.co/world/human-rights-category/europe...

Yes, giving people privacy means giving everyone privacy, whether they're doing good things or bad. Pointing cameras into everyone's window would also prevent some crimes, and we shouldn't do that either.

I don't think "This has tradeoffs but those tradeoffs are absolutely worth it" is a level of nuance that's possible in the face of the level of scaremongering against E2EE.

Post reply on HN