Live data from Hacker News

iMessage with PQ3 Cryptographic Protocol

security.apple.com

231–240 of 280 posts

Re: iMessage with PQ3 Cryptographic Protocol

#231

Earlier quoted context omitted.

Hmm… Does signal only really work when everyone uses it? Or can you include people who are just using regular SMS?

It used to have SMS support but they yanked it maybe a year or so ago. The big issue on the user end was, if someone deleted Signal and you used Signal for your SMS, it would keep sending them signal messages and not SMS. So you were left not realizing you were texting essentially a dead number.

It didn't show the icon for the message status, same as any other signal message?

Re: iMessage with PQ3 Cryptographic Protocol

#232
post #131

Earlier quoted context omitted.

Every single person I converted to using Signal stopped using it when SMS support was removed. HN tends to be a younger crowd whose peers cycled through a number of social-networking and messaging apps as popularity waxed and waned. But older generations don't see any compelling reason why they should bother splitting their conversations over multiple apps, when literally everyone with a mobile has texting. Being a d…

Are you from the USA? I don't like splitting my conversations over multiple apps when literally everyone with a mobile in Argentina has WhatsApp. SMS costs money and having it in the same app as a free messaging platform sounds risky :P

> I don't like splitting my conversations over multiple apps

Most people don't. The issue isn't what country I live in (fuck man, I got SMS, WhatsApp, Signal, Slack, KakaoTalk, and I've even forced some people to not contact me through some apps so I could reduce). You missed the actual content of the message about how there is a reasoning for this change beyond Signal. You got to be careful with blame because there are often things upstream that cause things downstream but the fingers are often pointed at what's downstream, not upstream. We can't resolve problems if we only focus on downstream. You have to consider both. I hate it too, because it is the mental version of using multiple apps. But that's the way things are and I want to actually reduce the problems, not run around with a box of bandaids.

Re: iMessage with PQ3 Cryptographic Protocol

#233
post #179

Earlier quoted context omitted.

I was reading the NIST comments and djb is not very happy with how they present things, and the other commenters seem to think he is a prick.

I want an encryption algorithm composed of 2 parts chained, such that both parts need to be broken for the whole thing to be broken. And I'd like the US/The west to declare 1 part as secure, and I'd like Russia to declare the other part as secure. I'm fairly confident that Russia and the US won't collude to push a known-weak algorithm.

Alternatively we could use hash-based signature schemes which have been proven secure under certain assumptions about hash functions, such as SPHINCS, or ZKP based schemes along the lines of Picnic (Picnic in particular uses LowMC which is somewhat new). In that case a backup seems unnecessary.

Re: iMessage with PQ3 Cryptographic Protocol

#234

Earlier quoted context omitted.

Sounds like time to become an evangelist then. I had to do this in my group and other than security a major benefit is just that getting potatos instead of pictures has significantly declined. Here's my advice: don't sell security as the foremost feature. Sell it as "iMessage, but for everyone." You got stickers, reactions, high quality videos and images. Then mention security, it is the cherry on top.

Before anyone goes evangelizing Signal, make sure to tell your iOS friends that if they ever lose their phone they lose every message they ever sent on Signal with no way to restore them, and the same applies if they ever get an Android phone (latter also true of iMessage, but WhatsApp is totally cross-platform).

While I agree with your point and I think you're right, let's remember that part of the issue is Apple.

Might be worth reading this comment from the devs[0]. I wish the feature existed too, but I get it and don't think all blame is on them. For lost devices, well... is that a bug? Where would the backup come from? Signal is anti-cloud, as they should be.

BUT, I do think people store too much data. Pictures, messages, etc. I think we're getting very little value for maintaining all of this and that it is mostly laziness. Don't get me wrong, I do it too and I like it and it does come in handy time to time, but my life wouldn't significantly change were this not the case. It's something I'll be irked about when I hit the speed bump the first time but move on quickly (like quitting Facebook). 99.999% of the time it would just result in me asking someone about something months ago and it's never been anything important (because if it was, I'd have made that information redundant, and that's not a action because Signal, that's an action because the information is important and I do this wherever that type of info comes from.) Truth is that >>99.9% of that data is junk. It's only the nuggets we care about and I think it's a bit weird we treat it all the same.

[0] https://community.signalusers.org/t/ios-backup-keeping-messa...

Re: iMessage with PQ3 Cryptographic Protocol

#235

Earlier quoted context omitted.

Sounds like time to become an evangelist then. I had to do this in my group and other than security a major benefit is just that getting potatos instead of pictures has significantly declined. Here's my advice: don't sell security as the foremost feature. Sell it as "iMessage, but for everyone." You got stickers, reactions, high quality videos and images. Then mention security, it is the cherry on top.

"iMessage, except you can't sync message history between devices because Signal feels you're a fucking idiot who can't be trusted, and that Apple's hardware security (market-leading and resistant to near-nation-state-level attacks) is insufficient." People's eyes glaze over and they go right back to using WhatsApp, which offers nearly everything Signal does, but also full sync. Most people don't care about the differ…

We're talking about the same company who wanted to scan all your files you uploaded, right?

Re: iMessage with PQ3 Cryptographic Protocol

#236

Earlier quoted context omitted.

Sounds like time to become an evangelist then. I had to do this in my group and other than security a major benefit is just that getting potatos instead of pictures has significantly declined. Here's my advice: don't sell security as the foremost feature. Sell it as "iMessage, but for everyone." You got stickers, reactions, high quality videos and images. Then mention security, it is the cherry on top.

Before anyone goes evangelizing Signal, make sure to tell your iOS friends that if they ever lose their phone they lose every message they ever sent on Signal with no way to restore them, and the same applies if they ever get an Android phone (latter also true of iMessage, but WhatsApp is totally cross-platform).

I actually think one of the best parts about signal is the disappearing messages feature

Re: iMessage with PQ3 Cryptographic Protocol

#239
post #223

Would syncing to iCloud would compromise E2E encryption?

Fair question, and it actually depends on how iMessage is being backed up to iCloud (sorta). By default, iMessage is included in your iCloud device backup, which when Advanced Data Protection is disabled, is NOT E2E encrypted. That said, if Messages in iCloud is enabled, which instead syncs your messages to iCloud, They are always E2E encrypted, regardless of if ADP is enabled [1]. Even more confusingly, if ADP is off, the keys for Messages in iCloud are still stored in your iCloud backup [2]. So essentially, the only way to use iMessage E2E encrypted is with Advanced Data Protection enabled, regardless of if you're using Messages in iCloud or not.

[1] https://support.apple.com/en-us/102651

[2] https://support.apple.com/guide/security/security-of-icloud-...

Re: iMessage with PQ3 Cryptographic Protocol

#240

Earlier quoted context omitted.

Before anyone goes evangelizing Signal, make sure to tell your iOS friends that if they ever lose their phone they lose every message they ever sent on Signal with no way to restore them, and the same applies if they ever get an Android phone (latter also true of iMessage, but WhatsApp is totally cross-platform).

While I agree with your point and I think you're right, let's remember that part of the issue is Apple. Might be worth reading this comment from the devs[0]. I wish the feature existed too, but I get it and don't think all blame is on them. For lost devices, well... is that a bug? Where would the backup come from? Signal is anti-cloud, as they should be. BUT, I do think people store too much data. Pictures, messages,…

Can't Signal export the local messages? Wire on iOS has local export.
Post reply on HN