Live data from Hacker News

Apple Explains How Secure iMessage Is

techcrunch.com

111–120 of 126 posts

Re: Apple Explains How Secure iMessage Is

#111

Earlier quoted context omitted.

Which was my point...

What was your point? All I said was that they could prove it. If allowing sideloading is required, so what?

In reply to:

    Apple cannot prove they aren't reading your iMessages.
You said:

    Sure they could. They could change the protocol and UI so that the users could verify and pin keys, and they could publish the iMessage source[1] to allow people to check it and compile it themselves.
My point is that publishing the source is not enough since you cannot verify that is the source running on your iPhone. Even if we concede that Apple could let you sideload your own compiled binary (which is not the case today), you still couldn't prove it since you couldn't know that the iPhone is running your binary and not a backdoored binary in the OS.

None of which is to say that Apple should have to prove any of this. If you cannot trust your phone vendor, then you cannot use any function of that phone, be it purportedly-secure messaging or location services or even the web browser.

Re: Apple Explains How Secure iMessage Is

#112
post #32

Earlier quoted context omitted.

When there are secret courts and laws, it is evil. It is indistinguishable from the surveillance state.

Hardly. I think people's concern is with the use of warrants that apply to a massive range of people to justify (legally) data collection en masse without being backed by intelligence and probabal cause. Declaring that all warrants for communications material are evil because a certain subset are evil does not work to improve our situation at all; it is a tabloid worthy knee jerk reaction, and while such populism is…

Let's say you are the German foreign ministry's IT guy. Are you really going to say "Hey, it's OK to use services and equipment from the companies on the PRISM participants list because we can trust the denials that they work with the NSA and we can trust LI not to be a gateway for spying Athens Affair."

This is not a matter of populism or even of principle. US technology can't be trusted any more. How are you going to restore that trust without making the technology verifiable and without providing simple, reliable ways for end users to routinely put their communications and data out of reach of surveillance?

Where is the "populism" in this? This is about many 10s of billions of dollars in revenue lost and even more in lost shareholder value and opportunity.

Re: Apple Explains How Secure iMessage Is

#113

Earlier quoted context omitted.

After reading a post by a Google engineer on this issue, I'm going to err on the side of believing that Google, Apple, and others aren't actually actively inserting back doors into their code. https://plus.google.com/108799184931623330498/posts/SfYy8xbD...

By all accounts, these secret court orders often come with gagging clauses - which would likely extend to even gagging one employee from telling another. For all I know the guy next to me could be under a secret court order forcing him to insert backdoors. Of course, as there's no way to disprove this hypothesis, and there's no proof of it, you can still err any way you like :)

So why would Apple voluntarily issue an update to fix the problem if they were gagged under a secret court order?

Re: Apple Explains How Secure iMessage Is

#114

The way Apple could "read" the messages is by sending a keybag down to the person sending the messages with another public key, one that Apple holds the private key for. For example if you have 3 devices (iPhone, iPad, MBP) and someone goes to send you a message, they have to re-encrypt the message three times because Apple would have sent them three public keys. Now if Apple were evil because of a government order,…

My iPhone gives me a loud, blaring notification whenever my keybag gets changed, so it wouldn't necessarily be easy to modify my keybag without me knowing, unless they already have code in place with that specifically in mind.

Re: Apple Explains How Secure iMessage Is

#115
post #103
post #63

Earlier quoted context omitted.

I am really curious why/how you think the byzantine link relates to key distribution and the web of trust?

The byzantine Trust issue is really just all agreeing on a a value. A handle/name and public key pair is such a value. We can distribute public keys in a block-chain. This pushes MIM attacks down to the last mile between a block-chain server and client and to the identifier exchange. The user can run their of own Block-chain server and authenticate via sneakernet if need be and we can at least be assured that you are…

I cant understand anything that you wrote. Yes you can distribute keys in a blockchain. After Alice grabs a key out of the blockchain how does she know it is Bob's key and not Eve's?

Re: Apple Explains How Secure iMessage Is

#116

Earlier quoted context omitted.

Right, but isn't the point that they could do it in a targeted fashion? Granted, it beats the dragnet situation we have now, but it's not quite at the point of "Apple couldn't intercept your messages even if they wanted to".

Granted. That said, "Apple couldn't undetectably intercept your messages even if they wanted to" is surprisingly close.

See rpdillon's comment above.

Re: Apple Explains How Secure iMessage Is

#117
post #115
post #103

Earlier quoted context omitted.

The byzantine Trust issue is really just all agreeing on a a value. A handle/name and public key pair is such a value. We can distribute public keys in a block-chain. This pushes MIM attacks down to the last mile between a block-chain server and client and to the identifier exchange. The user can run their of own Block-chain server and authenticate via sneakernet if need be and we can at least be assured that you are…

I cant understand anything that you wrote. Yes you can distribute keys in a blockchain. After Alice grabs a key out of the blockchain how does she know it is Bob's key and not Eve's?

This is a better summary then I can hack together: http://namecoin.info/

I have issues with their implementation, but in general the message is right.

Re: Apple Explains How Secure iMessage Is

#118
post #19

Earlier quoted context omitted.

Are the NSA's intercepts lawful?

The NSA's intercepts are a lot different from this. The problem with PRISM and the FISA courts that the NSA is intercepting all the data they think they'll ever need, then they need a warrant to query it. It inverts the intention of what warrants are for, which is to require just cause before any surveillance happens. With iMessage, if the FBI gives apple a warrant to include their snooping pubkey as an additional en…

My comment to which you replied was tongue-in-cheek, responding to the fellow who was defending lawful intercept. The point is that the NSA's intercepts, though controversial, have not halted nor have they been declared unlawful. (Not talking here about 215 programs.)

You're correct about iMessage, which is an important point to make. But you're not correct about PRISM; see my article from last summer: http://news.cnet.com/8301-13578_3-57588337-38/

Re: Apple Explains How Secure iMessage Is

#120

Earlier quoted context omitted.

And it's far better than other messaging services where messages can be read by the server (e.g. Google talk). If they/the government wanted to read your messages, at last they'd have to jump through some hoops.

A single, very easily jumpable hoop: sending a lawyer to the nearest friendly judge, asking him/her to sign a warrant.

I don't have a problem with a judge granting a warrant for a search. That's the whole point of warrants. The problem is the warrant less dragnet surveillance
Post reply on HN