Live data from Hacker News

iMessage with PQ3 Cryptographic Protocol

security.apple.com

221–230 of 280 posts

Re: iMessage with PQ3 Cryptographic Protocol

#221
post #161

Earlier quoted context omitted.

As far as I'm aware, iCloud for Messages is not enabled by default. Security-conscious users should know not to turn it on, though -- if iCloud servicing warrants is part of their threat model. Further, Apple ended up rolling out Advanced Data Protection for iCloud in 2023, so users who truly don't want Apple holding those keys can effectively take them from Apple. https://support.apple.com/guide/security/advanced-da…

Messages in iCloud is separate from the inclusion of the iMessage database in the regular iPhone iCloud backups. Could you check what that setting is set to on your newly setup device?

Right, that’s why I am trying to clarify that it’s iCloud for Messages that is not enabled by default.

iCloud backup IS enabled. But Messages in iCloud is off.

Re: iMessage with PQ3 Cryptographic Protocol

#222
post #20
post #2

Does anyone know if this is still vulnerable to the iCloud Backups problem? The only solution to that right now is for you and your contact to turn on Advanced Data Protection. Curious if that’s still required.

> Does anyone know if this is still vulnerable to the iCloud Backups problem? The only solution to that right now is for you and your contact to turn on Advanced Data Protection. This is such a strange two sentences as a "problem". E2EE security, as it says in the name, is about the protection of dara transmission between two trusted end points. That's it. What the trusted end points themselves choose to do with that…

The only backup provider allowed is also the communication service provider, which defeats the point of E2EE because the keys are also stores transparently (ie, not even encrypted with the device passcode).

That is the problem. Apple's business decision to ban other backup providers like Backblaze etc is making their privacy efforts meaningless.

Why is it a problem? Because governments and powerful entities need only contact Apple (the communication provider) to know the contents of the message. And I as a user have no way of knowing if others in the chat have advanced protection enabled, as I am only protected if every participant in the conversation has the correct settings, which are not the default settings.

So while this might meet some technical definition of E2EE, it does not meet the common-sense definition of E2EE where the communication provider has zero visibility into content.

Re: iMessage with PQ3 Cryptographic Protocol

#224
post #131

Earlier quoted context omitted.

Every single person I converted to using Signal stopped using it when SMS support was removed. HN tends to be a younger crowd whose peers cycled through a number of social-networking and messaging apps as popularity waxed and waned. But older generations don't see any compelling reason why they should bother splitting their conversations over multiple apps, when literally everyone with a mobile has texting. Being a d…

Yeah I think this was a bad move for Signal, but I didn't see that happen to my group fortunately. In Signal's defense, my understanding is that this was really an Apple thing. That Apple only lets iMessage connect to SMS so the apps were differing significantly. I also get the fatigue. Moxie said centralized because they needed to move faster. But Signal has always moved very slow, so it does feel off. But to be fai…

> I also get the fatigue.

Agreed. I put most of the blame on Google for deciding to implement RCS as a feature of Messages, rather than an Android OS library/service that any developer could use like SMS.

Re: iMessage with PQ3 Cryptographic Protocol

#225
post #158

Earlier quoted context omitted.

iMessage is excluded by default on iCloud backups, that's what the other guy is saying

Messages in iCloud (different thing, used for syncing iMessage conversations to all your devices) is off by default, to my knowledge backups of the iMessage database is on by default in the iCloud backup setting, but admittedly I haven't setup a new device without restoring an iCloud backup in many many years.

Messages is iCloud is mostly used to free up local storage, and to sync old messages to new devices. You don’t need it to sync messages most of the time.

Re: iMessage with PQ3 Cryptographic Protocol

#226

Isn't all this post quantum stuff a little premature? The standards haven't settled. We don't even know if there is a possible quantum threat to cryptography yet. The more we work on the problem the less likely it seems. Last I heard we were 1 or 2 orders of magnitude away from physical noise performance that would make such a threat possible. Edit, added: Harvest now, decrypt later applies to any encrypted data. The…

One reason to move sooner rather than later is to mitigate the threat of previously stored data. There may be a government entity simply storing all imessage traffic in the hopes of one day decrypting it when/if a breakthrough happens. If you transition sooner, you increase the age of the latest data that could be decrypted, thusly hopefully making it safer.

this is capitalism. why would they care unless the decryption happens this fiscal quarter?

Re: iMessage with PQ3 Cryptographic Protocol

#227
post #201

Earlier quoted context omitted.

The current standard isn't. Google uses non-standard E2EE, and they and Apple are working on getting it standardized.

If so, how will they meet China's demand that all mobile devices support RCS, presumably because it doesn't employ E2EE?

iOS already has different behaviours inside China compared to elsewhere, for example showing Taiwan's flag or the nine-dash line in the south sea in Maps app.

Based on how those work, the answer is likely: When a SIM from a mainland mobile company is in the device, E2EE is disabled.

Re: iMessage with PQ3 Cryptographic Protocol

#228
post #77

Earlier quoted context omitted.

I don't anticipate this changing either - because, let's face it, losing all of your Photos and Messages is, to most people, a bigger deal than perfect security. I'm experienced with Apple products - but there was one time that I actually got stuck in an E2EE loop and was forced to reset all E2EE data on iCloud. I don't know what I did wrong - but if someone in tech, like myself, can get stuck in an E2EE lockout, I c…

iMessage’s practical lack of e2ee isn’t a matter of “perfect security”. It’s simply not e2ee because the keys are escrowed to the middle service. It’s not even a little bit secure. The encryption has been fully backdoored by sharing the endpoint keys off of the device. Apple turns over customer data on over 70,000 customers per year without a warrant under FISA/702 (prism) and NSLs. The number gets bigger every year.…

As far as I know, iMessage keys are not escrowed to any middle service. What are you basing that belief on?

Re: iMessage with PQ3 Cryptographic Protocol

#229

This is pretty fascinating. For easier reading, the Signal blog post [0] they link to is great. Both Signal and Apple went with CRYSTALS-Kyber [1] as their post-quantum algorithm. If you're interested in the math, and maybe learned at some point about how classic public key cryptography is built on the idea that it's easy to multiply two primes, but hard to factor them, and how this (or other math problems) can be us…

I'm way out of my depth in terms of the math here. But my 'software engineer brain' likes the ideal of using the prime factoring problem, because it's so simple to understand, and feels like some kind of universal primitive. "It's easy to multiply but hard to factor." It just seems so intuitive. But I'm reading the 'learning with errors' wiki page and it's beyond my comprehension. There's a weird fear in my mind that…

It's not at all clear that factoring is actually hard. I fully expect factoring to be broken classically within my lifetime. FWIW I am a practicing cryptographer.

Re: iMessage with PQ3 Cryptographic Protocol

#230
post #16

Earlier quoted context omitted.

The "Messages in iCloud" sync is end to end, so you can enable it and disable iCloud backup, or manually backup on your computer: https://support.apple.com/en-us/102651

Yeah, it is end to end encrypted, but the keys are part of your device's iCloud backup. So unless you turn on end to end encryption for that backup or disable it, Apple can access the keys required to decrypt the iMessage in iCloud messages.

I believe the reason iMessages aren't protected with iCloud Backup is because they're stored decrypted in the SQLite database iMessage uses, chat.db.
Post reply on HN