Live data from Hacker News

A Formal Analysis of Apple's iMessage PQ3 Protocol [pdf]

usenix.org

71–80 of 141 posts

Re: A Formal Analysis of Apple's iMessage PQ3 Protocol [pdf]

#71
post #2

All that security, and then by default Apple literally just sends themselves a copy of your encryption keys to store in iCloud backup, the only cloud backup solution Apple allows you to use. "to help you recover your data" [1] (oh and also to send law enforcement your message history in plaintext on request, but we don't talk about that). [1] https://support.apple.com/en-us/102651#:~:text=in%20iCloud%2...

What about the “Advanced Data Protection” end to end encryption? Or by “sending copy of keys to iCloud” you mean those? It even says that “Apple will not be able to help you recover if you switch to End to end advanced data protection”.

Re: A Formal Analysis of Apple's iMessage PQ3 Protocol [pdf]

#72
post #57
post #42

Earlier quoted context omitted.

I think the story around privacy and security in general has become diluted in marketing talk. Every single default on both iOS and macOS effectively makes one’s data, well, accessible and not private. The gap between perception and reality when it comes to Apple as a “privacy champion” has never been so big as it is today.

Most customers do want it this way, but Apple still allows to exchange comfort for privacy, if you want to. I actually think it's a pretty sensible approach to capture both the big segment of people who don't care, and those who do and know which knobs to tweak. You can still turn everything compromising off and end up with a device secured to paranoid levels. That's definitely more than an empty promise, or what oth…

> Most customers do want it this way, but Apple still allows

I don't believe this is the case. Apple generally prefers to diminish the importance and risks of specific actions unless they have some monetary advantage. e.g. Apple is happy to warn you (multiple times) that an alternative marketplace is "dangerous" and yet iMessage iCloud Backups are just a click away with a friendly "so your messages are available everywhere".

Another example is Photos - Apple has no problem activating features that collect "anonymized" information from my pictures. Yes, there is an opt-out, but having all that on by default is not in the spirit of a privacy-minded operation.

And about the choice - someone already pointed out in other comments, there really is no way to replace iCloud with anything else for backups and app data sync. So the choice is not really a choice.

Re: A Formal Analysis of Apple's iMessage PQ3 Protocol [pdf]

#73
post #55

[flagged]

Nice! That way you can chat with yourself at all times! I mean, everyone else will continue using a different messenger, but they don't have anything interesting to say anyway!

Not OP, so I don't have to bear the snark, but also, let's not pretend that iMessage is some virtuous and ethical standard worth recommending in general. It's nothing but a tool by the monopolist Apple to execute vendor lock-in and subjugate its users into a closed ecosystem. Of course, that says nothing about the quality of said ecosystem (or that of XMPP, for that matter), only about a well-placed sense of priorities that I find laudable.

Re: A Formal Analysis of Apple's iMessage PQ3 Protocol [pdf]

#74
post #51
post #19

Earlier quoted context omitted.

Good to know, hence my 95% certainty. Fortunately for me, each new device starts with DFU restore and installation of my own Configuration Profile which supervises the device, disable automatic pairing with new devices, disables useless apps like Game Center, and most importantly disables iCloud Backup entirely, etc.

How do you make backups of your data; e.g. Photos, Notes and Messages?

I keep "optimized storage" turned off for Photos and back up directly from the filesystem. The photo library sits in $HOME/Pictures with all originals and the SQLite database intact - any regular backup solution works fine with this.

For Notes, I've migrated to Obsidian since I couldn't find a reliable backup method for Apple Notes.

Messages is tricky - I just screenshot anything important since it's so tightly integrated with Apple's ecosystem. Most of my important conversations happen on WhatsApp anyway, which lets me export anything I need to preserve.

Re: A Formal Analysis of Apple's iMessage PQ3 Protocol [pdf]

#75
post #51
post #19

Earlier quoted context omitted.

Good to know, hence my 95% certainty. Fortunately for me, each new device starts with DFU restore and installation of my own Configuration Profile which supervises the device, disable automatic pairing with new devices, disables useless apps like Game Center, and most importantly disables iCloud Backup entirely, etc.

How do you make backups of your data; e.g. Photos, Notes and Messages?

For Apple Notes, you can technically export using Shortcuts with a loop for entire folders, but it's quite limited. From my experience, it doesn't work with locked/encrypted notes at all - just returns blank pages when you try to access those. That's one of the reasons I switched to Obsidian.

Re: A Formal Analysis of Apple's iMessage PQ3 Protocol [pdf]

#77
post #2

All that security, and then by default Apple literally just sends themselves a copy of your encryption keys to store in iCloud backup, the only cloud backup solution Apple allows you to use. "to help you recover your data" [1] (oh and also to send law enforcement your message history in plaintext on request, but we don't talk about that). [1] https://support.apple.com/en-us/102651#:~:text=in%20iCloud%2...

Most users demand: 1. That their messages won't be lost when they migrate between devices. 2. That their messages won't be lost when their device is stolen and they set up the new one from nothing but a password. 3. That Apple's password recovery flows work like any other password recovery flows, AKA that forgetting your password is a minor inconvenience, to be overcome at the Apple Store at worst, not a data loss di…

Apple has the opportunity to add “extra security” features like disappearing messages, or to treat certain chats the same way they treat your web history (back this chat up, but require my passcode.) For the latter feature one can argue that it’s too advanced for the ordinary Apple user. But disappearing messages are a common security feature in virtually every messaging app, and Apple still won’t deploy those.

I used to think this was because they were intimidated by law enforcement, but they claimed otherwise. The recent UK attempt to backdoor Advanced Data Protection has made me believe them a bit less.

Re: A Formal Analysis of Apple's iMessage PQ3 Protocol [pdf]

#78

Earlier quoted context omitted.

Unlike Google's comparable backup encryption feature, ADP is off by default. And ADP protects your messages from Apple only to the extent that everyone you message also turns on this non-default option; otherwise your messages are still Apple's to read as they please with no notification to you.

To be clear, ADP default on would mean a massive influx in support requests for people that lose their data because they don't have the recovery key. Same reason FileVault isn't on by default on macs.

On the one hand: yes. On the other hand, the ADP setting is located in the moral equivalent of the bottom of a locked filing cabinet stuck in a disused lavatory with a sign on the door saying ‘Beware of the Leopard.’

Apple could do a lot to promote this feature to more advanced users, but they don’t. I don’t believe for a second this decision is unrelated to the government pressure they’ve been receiving from the UK.

Re: A Formal Analysis of Apple's iMessage PQ3 Protocol [pdf]

#79

Earlier quoted context omitted.

Not if you have "Advanced Data Protection" turned on: https://support.apple.com/en-us/108756

Not if you live in the UK.

I’m not sure how that, specifically, is Apple’s fault. Maybe I’m missing something obvious but I think disabling that in the UK was Apple’s least abhorrent option. They also put down their foot rather firmly on not providing a backdoor.

Maybe people think that was all for show but I’m struggling to think of other examples of massive companies saying that so publicly/firmly. See also, all the times the police/FBI/etc have complained or even tried to force Apple to provide a backdoor.

All that said, I guess a, very legitimate, argument could be made that if Apple provided ways to swap out iCloud for whatever service you wanted then there might be an escape hatch of sorts even if iCloud was compromised/limited.

Re: A Formal Analysis of Apple's iMessage PQ3 Protocol [pdf]

#80

Earlier quoted context omitted.

Most users demand: 1. That their messages won't be lost when they migrate between devices. 2. That their messages won't be lost when their device is stolen and they set up the new one from nothing but a password. 3. That Apple's password recovery flows work like any other password recovery flows, AKA that forgetting your password is a minor inconvenience, to be overcome at the Apple Store at worst, not a data loss di…

Apple has the opportunity to add “extra security” features like disappearing messages, or to treat certain chats the same way they treat your web history (back this chat up, but require my passcode.) For the latter feature one can argue that it’s too advanced for the ordinary Apple user. But disappearing messages are a common security feature in virtually every messaging app, and Apple still won’t deploy those. I use…

You can set messages to auto-delete. (I do this so I won’t get into the bad habit of relying on finding ancient messages.)

But it’s all or nothing and has to be applied to the entire account.

Post reply on HN