Live data from Hacker News

A Formal Analysis of Apple's iMessage PQ3 Protocol [pdf]

usenix.org

91–100 of 141 posts

Re: A Formal Analysis of Apple's iMessage PQ3 Protocol [pdf]

#91

Earlier quoted context omitted.

On the one hand: yes. On the other hand, the ADP setting is located in the moral equivalent of the bottom of a locked filing cabinet stuck in a disused lavatory with a sign on the door saying ‘Beware of the Leopard.’ Apple could do a lot to promote this feature to more advanced users, but they don’t. I don’t believe for a second this decision is unrelated to the government pressure they’ve been receiving from the UK.

It requires two physical security keys. You can promote the hell out of it, but having to buy and set up security keys is going to stop most people.

You don't need security keys to enable ADP. You need to setup a Recovery Contact or create a Recovery Key.

Re: A Formal Analysis of Apple's iMessage PQ3 Protocol [pdf]

#92

Earlier quoted context omitted.

To be clear, ADP default on would mean a massive influx in support requests for people that lose their data because they don't have the recovery key. Same reason FileVault isn't on by default on macs.

On the one hand: yes. On the other hand, the ADP setting is located in the moral equivalent of the bottom of a locked filing cabinet stuck in a disused lavatory with a sign on the door saying ‘Beware of the Leopard.’ Apple could do a lot to promote this feature to more advanced users, but they don’t. I don’t believe for a second this decision is unrelated to the government pressure they’ve been receiving from the UK.

Is “Settings -> iCloud -> Advanced Data Protection” really the “moral equivalent of the bottom of a locked filing cabinet stuck in a disused lavatory with a sign on the door saying Beware of the leopard”? Where else would you put it? I could see an argument for putting it in “Settings -> Privacy and Security -> Advanced Data Protection” but that to me feels like a “six if one, half dozen of the other” change.

Re: A Formal Analysis of Apple's iMessage PQ3 Protocol [pdf]

#93

Earlier quoted context omitted.

While I'm not on the Apple bandwagon, there is a difference between insecure by default and active spying. Even as a Pixel user, I'm fairly confident that my data would be (ab)used less on the Apple side. Users want convenience, and security always brings inconveniences (e.g., inter-client sync, no chat data before a client logged in first time, etc.). Some vendors might provide convenience because they want to have…

> that my data would be (ab)used less on the Apple side. Honest question, apart for the marketing, why? Does Apple collect your data? Yes. Does Apple operate an advertising platform and give itself a large amount of rights on your data for advertisement purpose? Yes. Is Apple an American company and therefore subject to the non sensical and draconian USA spying laws? Yes. I don’t really see how Apple is better than G…

None of your points is about whether or not the company spies or not. You also conflate the malice of the country they are in with the malice of the company itself.

Google's primary business is and have always been ads, and they practically invented the kind of global tracking we have all come to know and hate. Google actively tries to expand tracking and ad exposure to their own benefit. See the Google TV Streamer home screen as an example of their ad behaviors.

Apple has a miniscule ad business, and from the estimates I can find, the money in that is just a fraction of the Google search sponsorship they get (which counts towards the revenue of the same "services" bracket as their own ads). Apple actively tries to limit tracking, pissing other ad companies like Meta off. See the Apple TV home screen as an example of their ad behaviors.

In general, having access to data and using it are entirely orthogonal, and many companies that have your data consider it a liability they would much rather be without - it's just sometimes hard to provide a service without data passing through, and not everything can reasonably be E2E (either for technical or UX reasons).

Re: A Formal Analysis of Apple's iMessage PQ3 Protocol [pdf]

#94

Earlier quoted context omitted.

> that my data would be (ab)used less on the Apple side. Honest question, apart for the marketing, why? Does Apple collect your data? Yes. Does Apple operate an advertising platform and give itself a large amount of rights on your data for advertisement purpose? Yes. Is Apple an American company and therefore subject to the non sensical and draconian USA spying laws? Yes. I don’t really see how Apple is better than G…

None of your points is about whether or not the company spies or not. You also conflate the malice of the country they are in with the malice of the company itself. Google's primary business is and have always been ads, and they practically invented the kind of global tracking we have all come to know and hate. Google actively tries to expand tracking and ad exposure to their own benefit. See the Google TV Streamer h…

> Apple has a miniscule ad business

They're expanding it: https://www.axios.com/2024/11/19/apple-news-ads-direct-sales...

> many companies that have your data consider it a liability they would much rather be without - it's just sometimes hard to provide a service without data passing through

Apple collects much more data than needed for the service. They also make it practically impossible to use the phones without giving a ton of personal information:

https://news.ycombinator.com/item?id=39927657

Re: A Formal Analysis of Apple's iMessage PQ3 Protocol [pdf]

#95
post #2

All that security, and then by default Apple literally just sends themselves a copy of your encryption keys to store in iCloud backup, the only cloud backup solution Apple allows you to use. "to help you recover your data" [1] (oh and also to send law enforcement your message history in plaintext on request, but we don't talk about that). [1] https://support.apple.com/en-us/102651#:~:text=in%20iCloud%2...

Most users demand: 1. That their messages won't be lost when they migrate between devices. 2. That their messages won't be lost when their device is stolen and they set up the new one from nothing but a password. 3. That Apple's password recovery flows work like any other password recovery flows, AKA that forgetting your password is a minor inconvenience, to be overcome at the Apple Store at worst, not a data loss di…

> There's no way to satisfy those demands and have your desired level of security

Google provides it: https://news.ycombinator.com/item?id=43933626

Re: A Formal Analysis of Apple's iMessage PQ3 Protocol [pdf]

#97
post #82
post #2

All that security, and then by default Apple literally just sends themselves a copy of your encryption keys to store in iCloud backup, the only cloud backup solution Apple allows you to use. "to help you recover your data" [1] (oh and also to send law enforcement your message history in plaintext on request, but we don't talk about that). [1] https://support.apple.com/en-us/102651#:~:text=in%20iCloud%2...

More people need to watch Ivan Krstic's Black Hat presentation to understand the efforts Apple goes through to ensure sensitive data (like the User Escrow Keys which get stored in Apple's Cloud Key Vault) is protected from adversarial attacks... even from inside Apple. https://www.youtube.com/watch?v=BLGFriOKz6U&t=26m50s (Be sure to watch through the section from 34m to 36m...)

> even from inside Apple

sure, reminder 'Apple pays millions to woman after explicit photos posted online'

'Technicians posted the private photos and video from her iPhone after she sent it to Apple for repair, according to legal documents'

https://www.telegraph.co.uk/business/2021/06/06/apple-pays-m...

Re: A Formal Analysis of Apple's iMessage PQ3 Protocol [pdf]

#98
post #2

All that security, and then by default Apple literally just sends themselves a copy of your encryption keys to store in iCloud backup, the only cloud backup solution Apple allows you to use. "to help you recover your data" [1] (oh and also to send law enforcement your message history in plaintext on request, but we don't talk about that). [1] https://support.apple.com/en-us/102651#:~:text=in%20iCloud%2...

Most users demand: 1. That their messages won't be lost when they migrate between devices. 2. That their messages won't be lost when their device is stolen and they set up the new one from nothing but a password. 3. That Apple's password recovery flows work like any other password recovery flows, AKA that forgetting your password is a minor inconvenience, to be overcome at the Apple Store at worst, not a data loss di…

> There's no way to satisfy those demands and have your desired level of security

False. Google has done it with their backups. And Apple already does it too! Keychain passwords, health data, and a lot of other stuff is end-to-end encrypted in backups even when ADP is disabled, with recovery options if you lose your devices, no yubikey required. They simply choose not to apply the same solution to message data.

Re: A Formal Analysis of Apple's iMessage PQ3 Protocol [pdf]

#99

Earlier quoted context omitted.

On the one hand: yes. On the other hand, the ADP setting is located in the moral equivalent of the bottom of a locked filing cabinet stuck in a disused lavatory with a sign on the door saying ‘Beware of the Leopard.’ Apple could do a lot to promote this feature to more advanced users, but they don’t. I don’t believe for a second this decision is unrelated to the government pressure they’ve been receiving from the UK.

It requires two physical security keys. You can promote the hell out of it, but having to buy and set up security keys is going to stop most people.

This is not correct.

Re: A Formal Analysis of Apple's iMessage PQ3 Protocol [pdf]

#100
post #71
post #2

All that security, and then by default Apple literally just sends themselves a copy of your encryption keys to store in iCloud backup, the only cloud backup solution Apple allows you to use. "to help you recover your data" [1] (oh and also to send law enforcement your message history in plaintext on request, but we don't talk about that). [1] https://support.apple.com/en-us/102651#:~:text=in%20iCloud%2...

What about the “Advanced Data Protection” end to end encryption? Or by “sending copy of keys to iCloud” you mean those? It even says that “Apple will not be able to help you recover if you switch to End to end advanced data protection”.

ADP is overkill. Apple already end-to-end encrypts keychain passwords, health data, and other stuff even if you don't enable ADP. They need to do the same with iMessage, or otherwise they need to stop falsely advertising iMessage as a strong e2ee system when it literally uploads its encryption keys to Apple by default.

Also, even if you enable ADP Apple can likely still read the vast majority of your messages in other people's default-non-e2ee backups. The bad default is the problem here.

Post reply on HN