Live data from Hacker News

iMessage with PQ3 Cryptographic Protocol

security.apple.com

251–260 of 280 posts

Re: iMessage with PQ3 Cryptographic Protocol

#251

Advanced encryption, until it comes time to text 70% of the phones in the world, in which case it defaults to a protocol released 32 years ago.

Barely anyone uses sms nowadays. People use WhatsApp, FB Messenger and co (outside of the USA).

I think people who downvoted you did so after reading just your first sentence and not the entire comment. Outside of USA, I don't think anybody uses SMS for anything other than the occasional OTP or bank message.

In India, nobody used anything other than WhatsApp till a few years ago. Now, teenagers use Instagram's chat feature and WhatsApp, and middle-aged adults use FB Messenger and WhatsApp.

Re: iMessage with PQ3 Cryptographic Protocol

#252

Earlier quoted context omitted.

There is a flaw with your thinking. Any given year there are only 5-6 iPhones to choose from, where there are plenty of Android phones. This leads to "top phone sold" being iPhones because it is 5 phones against hundreds of Android phones that people get to choose from. You should instead look at Market share. https://www.statista.com/statistics/272698/global-market-sha...

> Any given year there are only 5-6 iPhones to choose from, where there are plenty of Android phones. There is such a thing as 'too much' choice: * https://en.wikipedia.org/wiki/Overchoice * https://en.wikipedia.org/wiki/Decision_fatigue * https://www.behavioraleconomics.com/resources/mini-encyclope... * https://thedecisionlab.com/biases/choice-overload-bias

Yes but point here is that in the end there are more Android phones in the world than iPhones. So 'best selling phone' is not relevant in context of this thread.

Re: iMessage with PQ3 Cryptographic Protocol

#253

Advanced encryption, until it comes time to text 70% of the phones in the world, in which case it defaults to a protocol released 32 years ago.

Barely anyone uses sms nowadays. People use WhatsApp, FB Messenger and co (outside of the USA).

I do not use Meta apps. I use just SMS/iMessage and Signal. So most of the time it is SMS, since this is outside of USA and not many people use Signal.

But even I send 'green bubble' from iPhone to iPhone sometimes. If there is no good internet coverage.

Re: iMessage with PQ3 Cryptographic Protocol

#254
post #172

Earlier quoted context omitted.

I'm way out of my depth in terms of the math here. But my 'software engineer brain' likes the ideal of using the prime factoring problem, because it's so simple to understand, and feels like some kind of universal primitive. "It's easy to multiply but hard to factor." It just seems so intuitive. But I'm reading the 'learning with errors' wiki page and it's beyond my comprehension. There's a weird fear in my mind that…

I know that thinking, but learning more about RSA, I came to realize that there's a flipside of this. People think "RSA is easy", because someone gave them a lecture of a simplified/wrong/insecure version of RSA. Pretty much all "simple introductions to RSA" you can find out there are wrong. The truth is: RSA isn't that simple. If you want to have RSA, and want to have it secure, there's a whole bunch of things to co…

People rolling their own crypto still makes my jaw drop.

I get people want something custom but the tradeoffs are just too great.

Re: iMessage with PQ3 Cryptographic Protocol

#255
post #238
post #94

Is this country dependent?

No. This will be rolled out to everyone in iOS 17.4, iPadOS 17.4, macOS 14.4, and watchOS 10.4, and is already in the corresponding developer preview and beta releases[1]. [1] https://security.apple.com/blog/imessage-pq3/

China included?

Re: iMessage with PQ3 Cryptographic Protocol

#256

This is pretty fascinating. For easier reading, the Signal blog post [0] they link to is great. Both Signal and Apple went with CRYSTALS-Kyber [1] as their post-quantum algorithm. If you're interested in the math, and maybe learned at some point about how classic public key cryptography is built on the idea that it's easy to multiply two primes, but hard to factor them, and how this (or other math problems) can be us…

Was the CRYSTALS-Kyber name intentionally, or accidentally, a reference to Kyber Crystals (I.e. The Lightsaber energy source?)

I'm amused by the Padmé reference as well.

Re: iMessage with PQ3 Cryptographic Protocol

#257

Earlier quoted context omitted.

This lack of backups makes Signal less appealing to anyone who isn't a security/privacy enthusiast/nut. 99+% of people want their messages to work and not lose them when their phone is broken.

No I do not agree with you. Majority of people never read their message history, want their messages to self-detruct and don't want to get into a situation like when a new partner reads chat history with all previous partners. Majority of people do not record their conversations and do not need this. And most messaging applications are designed countrary to what people need - they preserve history specially for that…

This has happened to me multiple times: convince non-technical person to download Signal, they delete app or get a new phone, they call me asking why they can’t see all their messages, they are very upset to learn they are all gone. Either I’m extremely unlucky or average users do want this.

Re: iMessage with PQ3 Cryptographic Protocol

#258
post #239

Earlier quoted context omitted.

Fair question, and it actually depends on how iMessage is being backed up to iCloud (sorta). By default, iMessage is included in your iCloud device backup, which when Advanced Data Protection is disabled, is NOT E2E encrypted. That said, if Messages in iCloud is enabled, which instead syncs your messages to iCloud, They are always E2E encrypted, regardless of if ADP is enabled [1]. Even more confusingly, if ADP is of…

> the only way to use iMessage E2E encrypted is with Advanced Data Protection enabled If iMessage backup relies on ADP encryption, will ADP move to PQ3 Cryptographic Protocol?

It is data at rest which is different from the exchange of messages themselves.

I believe the backups are protected via AES.

Re: iMessage with PQ3 Cryptographic Protocol

#259
post #20

Earlier quoted context omitted.

> Does anyone know if this is still vulnerable to the iCloud Backups problem? The only solution to that right now is for you and your contact to turn on Advanced Data Protection. This is such a strange two sentences as a "problem". E2EE security, as it says in the name, is about the protection of dara transmission between two trusted end points. That's it. What the trusted end points themselves choose to do with that…

Your argument about iMessage on Mac’s holds water, but the iPhone is sold as an appliance and there is no concept of a file system presented to the user. They sell the messaging platform as “encrypted” and the word “encrypted” is plastered all over iCloud marketing and documentation. You really can’t blame the user for assuming the appliance is secure by default. When you first set up an iPhone it just asks you if yo…

in what way is iCloud backup 'insecure' or 'unencrypted'?

Re: iMessage with PQ3 Cryptographic Protocol

#260

Earlier quoted context omitted.

"iMessage, except you can't sync message history between devices because Signal feels you're a fucking idiot who can't be trusted, and that Apple's hardware security (market-leading and resistant to near-nation-state-level attacks) is insufficient." People's eyes glaze over and they go right back to using WhatsApp, which offers nearly everything Signal does, but also full sync. Most people don't care about the differ…

We're talking about the same company who wanted to scan all your files you uploaded, right?

Uploaded? You forgot what it was about. It was on-device scanning that was the problem.
Post reply on HN