Live data from Hacker News

iMessage with PQ3 Cryptographic Protocol

security.apple.com

241–250 of 280 posts

Re: iMessage with PQ3 Cryptographic Protocol

#241

Earlier quoted context omitted.

Oh. Ok that's never going to work. "Hey there please click on this link to talk to me" => Malware! Blocked.

It’s how many Zoom and Teams calls terminate. Not saying it’s a good idea, but it’s not especially unusual.

But you don't get zoom links via _SMS_ do you?

Almost all links I get via SMS are phishing. The rest is OTP, there is sometimes a link in the same SMS but I _never_ clicked a link in an SMS...

My point is, the inhibition to click a link inside an SMS is very high with lots of users, hence I can't imagine this working well.

Also, it's purely inconvenient. You're not having a conf call at a previously agreed time, you want to call someone, this means it's spontaneous or somewhat urgent...

Re: iMessage with PQ3 Cryptographic Protocol

#242
post #173

Earlier quoted context omitted.

Same thing with Signal and most other messengers. Can you link to some documentation that shows iMessage even has the identity numbers?

https://support.apple.com/en-us/HT213465#verify

Wonderful, thank you so much! Good to see Apple fix their app finally.

Re: iMessage with PQ3 Cryptographic Protocol

#243
The only question that I have, will it break my old devices, so they would be forced out of the iMessages ecosystem? I believe that would happen. I don’t use it heavily, but that’s one of the reasons I keep an iPhone these days. The other reason is FaceTime support, so I could easily connect with those with iPhones. I do use not very modern iPhones (the very first SE currently), as that’s what I need my iPhones for: to make a call (via FaceTime most times) and to send a message (via iMessage, sometimes). If Apple breaks that for me, I’m either forced to buy a newer iPhone (which I’m not sure I want, considering I’m all in Linux and Android). Or they force me to rethink my priorities and just leave this. I can live with that, it’s just less convenient.

Re: iMessage with PQ3 Cryptographic Protocol

#244

Earlier quoted context omitted.

It’s how many Zoom and Teams calls terminate. Not saying it’s a good idea, but it’s not especially unusual.

But you don't get zoom links via _SMS_ do you? Almost all links I get via SMS are phishing. The rest is OTP, there is sometimes a link in the same SMS but I _never_ clicked a link in an SMS... My point is, the inhibition to click a link inside an SMS is very high with lots of users, hence I can't imagine this working well. Also, it's purely inconvenient. You're not having a conf call at a previously agreed time, you…

Most people lead up to an invitation to a video call with text messages (e.g. "When are you free for a video call?") unless they're very familiar with the other party.

Re: iMessage with PQ3 Cryptographic Protocol

#245

Earlier quoted context omitted.

While I agree with your point and I think you're right, let's remember that part of the issue is Apple. Might be worth reading this comment from the devs[0]. I wish the feature existed too, but I get it and don't think all blame is on them. For lost devices, well... is that a bug? Where would the backup come from? Signal is anti-cloud, as they should be. BUT, I do think people store too much data. Pictures, messages,…

Can't Signal export the local messages? Wire on iOS has local export.

The post addresses that a bit, but it is a few years old now. I'm not a app dev so I have no clue about these systems. But the claim is that Apple doesn't give you a lot of control and that sounds like a very Apple thing to me. I mean aren't they well known for "my way or the highway" attitude?

Re: iMessage with PQ3 Cryptographic Protocol

#247

This is pretty fascinating. For easier reading, the Signal blog post [0] they link to is great. Both Signal and Apple went with CRYSTALS-Kyber [1] as their post-quantum algorithm. If you're interested in the math, and maybe learned at some point about how classic public key cryptography is built on the idea that it's easy to multiply two primes, but hard to factor them, and how this (or other math problems) can be us…

I'm way out of my depth in terms of the math here. But my 'software engineer brain' likes the ideal of using the prime factoring problem, because it's so simple to understand, and feels like some kind of universal primitive. "It's easy to multiply but hard to factor." It just seems so intuitive. But I'm reading the 'learning with errors' wiki page and it's beyond my comprehension. There's a weird fear in my mind that…

Curiously, the "large surface area hiding flaws" is actually what happened with RSA. Examples are

1. (large) speedups in solving it in the 90s, 2. issues where if enough of your key leaks, it can all be recovered. This leakage can occur via certain side-channel attacks 3. the "easy RSA" people learn is hard to make secure, which perhaps took a decade of doing very wrong to get right. By this, I mean padding attacks on RSA.

As for understanding LWE, see for example the blog posts

https://mark-schultz.github.io/nist-standard-out/

Re: iMessage with PQ3 Cryptographic Protocol

#248
post #161

Earlier quoted context omitted.

Messages in iCloud is separate from the inclusion of the iMessage database in the regular iPhone iCloud backups. Could you check what that setting is set to on your newly setup device?

Right, that’s why I am trying to clarify that it’s iCloud for Messages that is not enabled by default. iCloud backup IS enabled. But Messages in iCloud is off.

Right, and in iCloud backups you can choose to include or don't include iMessage data in those, is the iMessage data included by default?

Re: iMessage with PQ3 Cryptographic Protocol

#249
post #239
post #223

Would syncing to iCloud would compromise E2E encryption?

Fair question, and it actually depends on how iMessage is being backed up to iCloud (sorta). By default, iMessage is included in your iCloud device backup, which when Advanced Data Protection is disabled, is NOT E2E encrypted. That said, if Messages in iCloud is enabled, which instead syncs your messages to iCloud, They are always E2E encrypted, regardless of if ADP is enabled [1]. Even more confusingly, if ADP is of…

> the only way to use iMessage E2E encrypted is with Advanced Data Protection enabled

If iMessage backup relies on ADP encryption, will ADP move to PQ3 Cryptographic Protocol?

Re: iMessage with PQ3 Cryptographic Protocol

#250

Earlier quoted context omitted.

For me, Signal is so much better for my friend or work group chats. My friends are on a mix of devices and platforms, and Signal is a lot nicer for embedded media sharing. And the auto disappearing feature is a must!

The main things holding back Signal usage in my case is practically nobody in my social circle using it and the desktop client not being as nice as that of Messages or Telegram, the latter being particularly relevant for myself and contacts who primarily message with their computers rather than their phones.

Don’t worry, whatsapp uses the signal protocol and everybody uses whatsapp nowadays
Post reply on HN