Live data from Hacker News

A Formal Analysis of Apple's iMessage PQ3 Protocol [pdf]

usenix.org

81–90 of 141 posts

Re: A Formal Analysis of Apple's iMessage PQ3 Protocol [pdf]

#81
post #53

Earlier quoted context omitted.

There are some fundamental different between two ecosystems. On Google, the Google Drive and Photo are encrypted to a key owned by google. On iCloud, the iCloud Drive and Photo are encrypted to your account key. In which, without ADP, this key is shared with Apple. When ADP is enabled, Apple does not store this key. iCloud Backup is stored with the same technology as iCloud Drive. When it comes to lost password accou…

You aren't understanding the point being made in OP. Everyone here understands the crypto for ADP vs non-ADP, there's no need to explain it. The simple fact of the matter is that if I have ADP enabled, my chats should be excluded from the backups of those I'm communicating with (it should be as an opt-in basis at the very least). Not having this renders ADP useless for the purpose of its stated threat model.

Why does your desire for complete privacy and _control_ outweigh mine to keep a complete history of my communications?

Why can you reach into my phone and wipe data you sent to me?

Why are _you_ the final arbiter?

Once you send a message it is _out of your hands_. You do not own that message. You do not have the right to dictate to others what they can do with what you send to them. That’s life, that’s reality.

If you want to be able to delete your sent messages from other’s devices, there are many apps out there that can provide it to you and both you and the person you are talking to can go in “eyes wide open” to what you agreeing to (I can delete messages I sent to you and you have no record).

The potential for abuse of this is high and the vast majority of users would _not_ want this feature. The same way that mostly people probably shouldn’t use ADP due to the risks, this type of feature will cause way more issues IMHO. It doesn’t take much imagination to get to “Grandpa pressed the wrong button and deleted years (decades) of conversation from everyone’s phone”.

I am not interesting my normal conversations potentially disappearing. That was not the agreement that we had and changing the rules later on that is gross to me. If you want disappearing chats or the ability to wipe all the messages you’ve sent there are other apps (with their own pitfalls, what if I keep my phone offline and never get the update to clear out your conversations?).

Re: A Formal Analysis of Apple's iMessage PQ3 Protocol [pdf]

#82
post #2

All that security, and then by default Apple literally just sends themselves a copy of your encryption keys to store in iCloud backup, the only cloud backup solution Apple allows you to use. "to help you recover your data" [1] (oh and also to send law enforcement your message history in plaintext on request, but we don't talk about that). [1] https://support.apple.com/en-us/102651#:~:text=in%20iCloud%2...

More people need to watch Ivan Krstic's Black Hat presentation to understand the efforts Apple goes through to ensure sensitive data (like the User Escrow Keys which get stored in Apple's Cloud Key Vault) is protected from adversarial attacks... even from inside Apple.

https://www.youtube.com/watch?v=BLGFriOKz6U&t=26m50s

(Be sure to watch through the section from 34m to 36m...)

Re: A Formal Analysis of Apple's iMessage PQ3 Protocol [pdf]

#83
post #2

All that security, and then by default Apple literally just sends themselves a copy of your encryption keys to store in iCloud backup, the only cloud backup solution Apple allows you to use. "to help you recover your data" [1] (oh and also to send law enforcement your message history in plaintext on request, but we don't talk about that). [1] https://support.apple.com/en-us/102651#:~:text=in%20iCloud%2...

You can turn it off.

Re: A Formal Analysis of Apple's iMessage PQ3 Protocol [pdf]

#84
post #2

All that security, and then by default Apple literally just sends themselves a copy of your encryption keys to store in iCloud backup, the only cloud backup solution Apple allows you to use. "to help you recover your data" [1] (oh and also to send law enforcement your message history in plaintext on request, but we don't talk about that). [1] https://support.apple.com/en-us/102651#:~:text=in%20iCloud%2...

[deleted]

Re: A Formal Analysis of Apple's iMessage PQ3 Protocol [pdf]

#85

Earlier quoted context omitted.

To be clear, ADP default on would mean a massive influx in support requests for people that lose their data because they don't have the recovery key. Same reason FileVault isn't on by default on macs.

On the one hand: yes. On the other hand, the ADP setting is located in the moral equivalent of the bottom of a locked filing cabinet stuck in a disused lavatory with a sign on the door saying ‘Beware of the Leopard.’ Apple could do a lot to promote this feature to more advanced users, but they don’t. I don’t believe for a second this decision is unrelated to the government pressure they’ve been receiving from the UK.

It requires two physical security keys. You can promote the hell out of it, but having to buy and set up security keys is going to stop most people.

Re: A Formal Analysis of Apple's iMessage PQ3 Protocol [pdf]

#86
post #82
post #2

All that security, and then by default Apple literally just sends themselves a copy of your encryption keys to store in iCloud backup, the only cloud backup solution Apple allows you to use. "to help you recover your data" [1] (oh and also to send law enforcement your message history in plaintext on request, but we don't talk about that). [1] https://support.apple.com/en-us/102651#:~:text=in%20iCloud%2...

More people need to watch Ivan Krstic's Black Hat presentation to understand the efforts Apple goes through to ensure sensitive data (like the User Escrow Keys which get stored in Apple's Cloud Key Vault) is protected from adversarial attacks... even from inside Apple. https://www.youtube.com/watch?v=BLGFriOKz6U&t=26m50s (Be sure to watch through the section from 34m to 36m...)

The problem isn't that the technical challenges aren't addressed. The problem is that no amount of tech can un-do a design that forces in a "just trust me bro" control relationship.

For some people it isn't a concern and that's fine, just so long as we acknowledge that it is a real and legitimate concern for other people, and that's also fine.

Re: A Formal Analysis of Apple's iMessage PQ3 Protocol [pdf]

#87
post #38

Earlier quoted context omitted.

How are you achieving this? I’d like to know more. Thanks in advance.

Perhaps I should document it and link to it in detail but basically you use Apple Configurator to create a profile and set its restriction flags accordingly and keep it somewhere you can redeploy with ease and simply DFU restore the iOS device so that it gets the latest clean iOS image. After that you don’t activate it by going through the setup screen. Instead you use the connected Mac with Apple Configurator to “Pr…

Yes please, document this, this sounds great!

Re: A Formal Analysis of Apple's iMessage PQ3 Protocol [pdf]

#88

Earlier quoted context omitted.

> Most customers do want it this way, but Apple still allows to exchange comfort for privacy […] more than an empty promise, or what other vendors provide. That’s pretty much exactly what all the other vendors in the market provide: insecure and spying by default. I don’t really understand why Apple should somehow get good points for their stance on privacy when they are actually doing pretty much the same thing than…

While I'm not on the Apple bandwagon, there is a difference between insecure by default and active spying. Even as a Pixel user, I'm fairly confident that my data would be (ab)used less on the Apple side. Users want convenience, and security always brings inconveniences (e.g., inter-client sync, no chat data before a client logged in first time, etc.). Some vendors might provide convenience because they want to have…

> that my data would be (ab)used less on the Apple side.

Honest question, apart for the marketing, why?

Does Apple collect your data? Yes. Does Apple operate an advertising platform and give itself a large amount of rights on your data for advertisement purpose? Yes. Is Apple an American company and therefore subject to the non sensical and draconian USA spying laws? Yes.

I don’t really see how Apple is better than Google here. Both are pretty much equally bad.

Re: A Formal Analysis of Apple's iMessage PQ3 Protocol [pdf]

#89

Earlier quoted context omitted.

Yes but when Messages in iCloud is enabled that "client-side" encryption key is itself included in your iCloud backup (that Apple can read), as disclosed. So Apple can read your messages regardless of whether you enable or disable Messages in iCloud. The only things that prevent it are disabling cloud backups entirely, or enabling ADP. But even those don't really prevent it because unless everyone you message also do…

No, that's not what it means. The key is stored on their server, but you still need to provide a password to unlock the key. In the same way that you can password protect an SSH key. It's also the same way ProtonMail encrypts their email. They have to store the private key for you to be able to use the email on any browser.

This is demonstrably false: you can restore an iCloud backup on a new device without the original device password. Only with iCloud credentials which can be reset by Apple.

Only enabling ADP, disabled by default and unavailable in UK, makes it like you describe.

Re: A Formal Analysis of Apple's iMessage PQ3 Protocol [pdf]

#90
post #51
post #19

Earlier quoted context omitted.

Good to know, hence my 95% certainty. Fortunately for me, each new device starts with DFU restore and installation of my own Configuration Profile which supervises the device, disable automatic pairing with new devices, disables useless apps like Game Center, and most importantly disables iCloud Backup entirely, etc.

How do you make backups of your data; e.g. Photos, Notes and Messages?

You could always sync and backup (make sure it has a password so that keychain data is stored in the backup) your iPhone to your Mac since the dawn of iPhone OS. You can still use iCloud sync for contacts and notes if you choose to for convenience, but I absolutely do not want iCloud backup.
Post reply on HN