Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key
1–10 of 116 posts
Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key
#2At first I thought that if just an iphone held the encryption keys and these were not on apple servers this statement could be true ...
however considering that imessage can be setup on a Mac and an iPhone via your Apple ID ... its more likely that this statement is just hyperbole for the Apple's approach to privacy
Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key
#3Is actually possible to not have the ability to decrypt messages remotely? At first I thought that if just an iphone held the encryption keys and these were not on apple servers this statement could be true ... however considering that imessage can be setup on a Mac and an iPhone via your Apple ID ... its more likely that this statement is just hyperbole for the Apple's approach to privacy
But the system is not currently designed to allow message interception. The details about how it operates can be found in the iOS Security PDF from February:
http://www.apple.com/ipad/business/docs/iOS_Security_Feb14.p...
Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key
#4Is actually possible to not have the ability to decrypt messages remotely? At first I thought that if just an iphone held the encryption keys and these were not on apple servers this statement could be true ... however considering that imessage can be setup on a Mac and an iPhone via your Apple ID ... its more likely that this statement is just hyperbole for the Apple's approach to privacy
"The user’s outgoing message is individually encrypted using AES-128 in CTR mode for each of the recipient’s devices, signed using the sender’s private key, and then dis- patched to the APNs for delivery."
Source: http://www.apple.com/ipad/business/docs/iOS_Security_Feb14.p...
When you send an iMessage, you actually send a separate encrypted and signed copy for each recipient device. So, it is possible, but these are the lengths you have to go to.
Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key
#5Is actually possible to not have the ability to decrypt messages remotely? At first I thought that if just an iphone held the encryption keys and these were not on apple servers this statement could be true ... however considering that imessage can be setup on a Mac and an iPhone via your Apple ID ... its more likely that this statement is just hyperbole for the Apple's approach to privacy
"When a user turns on iMessage, the device generates two pairs of keys for use with the service: an RSA 1280-bit key for encryption and an ECDSA 256-bit key for signing. For each key pair, the private keys are saved in the device’s keychain and the public keys are sent to Apple’s directory service" "The user’s outgoing message is individually encrypted using AES-128 in CTR mode for each of the recipient’s devices, si…
I also recall a while ago a researcher who showed that if you forgot your iCloud password, there was a way to get Apple to reset the password and give you access to all your previously-stored data. If they had no way to decrypt your data remotely, that should be impossible.
Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key
#6Earlier quoted context omitted.
"When a user turns on iMessage, the device generates two pairs of keys for use with the service: an RSA 1280-bit key for encryption and an ECDSA 256-bit key for signing. For each key pair, the private keys are saved in the device’s keychain and the public keys are sent to Apple’s directory service" "The user’s outgoing message is individually encrypted using AES-128 in CTR mode for each of the recipient’s devices, si…
But they could just inject a "fake" recipient device with their own public/private key and decrypt messages as they transit the system. They might not be able to decrypt messages you've sent in the past, but I can see no reason why they couldn't read messages as you send them if they wanted to (or were required by a wiretapping agency, for example). I also recall a while ago a researcher who showed that if you forgot…
Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key
#7Earlier quoted context omitted.
"When a user turns on iMessage, the device generates two pairs of keys for use with the service: an RSA 1280-bit key for encryption and an ECDSA 256-bit key for signing. For each key pair, the private keys are saved in the device’s keychain and the public keys are sent to Apple’s directory service" "The user’s outgoing message is individually encrypted using AES-128 in CTR mode for each of the recipient’s devices, si…
But they could just inject a "fake" recipient device with their own public/private key and decrypt messages as they transit the system. They might not be able to decrypt messages you've sent in the past, but I can see no reason why they couldn't read messages as you send them if they wanted to (or were required by a wiretapping agency, for example). I also recall a while ago a researcher who showed that if you forgot…
Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key
#8How do I know? How can I even know that YOUR own device for which YOU wrote software and YOU designed hardware (although it may be based on some standards, no one can guarantee it's unmodified) won't share my private information with YOU?
How can I know that you're not sending my private key encrypted with your server's public key (one simple example of many) to your side?
Am I supposed to take your word on it? No thanks.
As much as I'm against Apple and their policy, these statements make no sense from anyone (Google, Apple, whatever). Unless you design your own phone from scratch, you can not be sure that it is secure (however, when you do that, all medium your phone may use is still not secure). It is simply not worth it. Anything in digital world is not secure (only a matter of attacker's determination and resources available to them) and there is no point in saying otherwise.
Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key
#9Take what Timmy says with a grain of salt, until they should you the source code. Oh wait...
Apple fan boys: bring on the downvotes, but enjoy your surveilling
Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key
#10Honestly, I am starting to see the wisdom behind consumers choosing the companies with these kinds of business models. Its not that I dont trust the companies -- I guess its that I accept that governments and laws transcend companies and their explicit arrangements with their consumers.