Live data from Hacker News

Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

techcrunch.com

11–20 of 116 posts

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#11
Apple is a PRISM participant, as of Oct 2012 (one year after Steve Jobs died). I highly doubt any iMessage is more secure than a plain text SMS sent via any cell carrier's network. Apple probably offers a sexy interface for the Feds to read everything.

Reference: http://tctechcrunch2011.files.wordpress.com/2013/06/prism-sl...

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#12
There is zero control over what public keys get handed over to your phone to encrypt an iMessage with. For all we know, whenever you want to send a message to $USER, your phone gets a public key for $USERs iPhone, her iPad and the NSA master key.

Tim Cook can state that they can't decrypt the message all he wants, but as long as there's no control over what public keys we encrypt the message with, the statement that Apple or the NSA can't read the messages is a half-truth at best.

Don't use iMessage for anything you wouldn't be using email for. Assume every message you send over iMessage to be public.

>If the government laid a subpoena to get iMessages, we can’t provide it. It’s encrypted and we don’t have a key. And so it’s sort of — the door is closed.

But the government can (and probably has) force you to have the phones send a copy of every message to some government server encrypted with the government's public key. They don't need to subpoena messages - they already got them all.

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#13

Apple is a PRISM participant, as of Oct 2012 (one year after Steve Jobs died). I highly doubt any iMessage is more secure than a plain text SMS sent via any cell carrier's network. Apple probably offers a sexy interface for the Feds to read everything. Reference: http://tctechcrunch2011.files.wordpress.com/2013/06/prism-sl...

Do any down-voters care to offer a comment? Is it that one contests that Apple is a PRISM participant?

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#14
post #12

There is zero control over what public keys get handed over to your phone to encrypt an iMessage with. For all we know, whenever you want to send a message to $USER, your phone gets a public key for $USERs iPhone, her iPad and the NSA master key. Tim Cook can state that they can't decrypt the message all he wants, but as long as there's no control over what public keys we encrypt the message with, the statement that…

"as long as there's no control over what public keys we encrypt the message with, the statement that Apple or the NSA can't read the messages is a half-truth at best."

This.

That said, it is reasonable to believe the way iMessage is architected would likely make mass surveillance harder in general, just like widespread use of SSL does, so it is not entirely useless either.

The bigger problem IMO is that they then upload the message database unencrypted (from server's standpoint) to iCloud in the backup process (which is admittedly optional, but effectively on for most users). That, of course, is easily readable, as the celebrity hack shows.

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#15
post #6
post #5

Earlier quoted context omitted.

But they could just inject a "fake" recipient device with their own public/private key and decrypt messages as they transit the system. They might not be able to decrypt messages you've sent in the past, but I can see no reason why they couldn't read messages as you send them if they wanted to (or were required by a wiretapping agency, for example). I also recall a while ago a researcher who showed that if you forgot…

On the first point, you're coreect. That's also why you get those extremely annoying modal dialogs each time a device/key pair is added to your iMessage account, because a device added without your knowledge could be used to eavesdrop on you.

You only get that dialog for the devices you add. The public key added by the NSA or Apple themselves does not trigger the dialog.

(explanatory note as the sarcasm in the comment might not have been obvious: I do not know whether such a facility exists in the services or not, so this might or might not be true.

But: The fact that it's possible that this "feature" already exists or can easily be added in the future, potentially even without an update of the client leads me to my current opinion which is that iMessage is not secure and all traffic is open to Apple, rogue employees at Apple and whatever government Apple is cooperating with).

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#16

Is actually possible to not have the ability to decrypt messages remotely? At first I thought that if just an iphone held the encryption keys and these were not on apple servers this statement could be true ... however considering that imessage can be setup on a Mac and an iPhone via your Apple ID ... its more likely that this statement is just hyperbole for the Apple's approach to privacy

Apple previously said that in order to read your iMessages they would have to re-architect the entire system. Technically, they could in fact do that, so if they really wanted to, they could. But the system is not currently designed to allow message interception. The details about how it operates can be found in the iOS Security PDF from February: http://www.apple.com/ipad/business/docs/iOS_Security_Feb14.p...

>But the system is not currently designed to allow message interception. The details about how it operates can be found in the iOS Security PDF from February

The system is currently designed to allow very easy message interception by just sending both Alice and Bob a fake public key of their respective communications partner.

You have zero control over what public keys your phone encrypts data with.

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#17

Apple is a PRISM participant, as of Oct 2012 (one year after Steve Jobs died). I highly doubt any iMessage is more secure than a plain text SMS sent via any cell carrier's network. Apple probably offers a sexy interface for the Feds to read everything. Reference: http://tctechcrunch2011.files.wordpress.com/2013/06/prism-sl...

Do any down-voters care to offer a comment? Is it that one contests that Apple is a PRISM participant?

I think you're being downvoted because you got a little too excited while bashing Apple. iMessage is most certainly more secure than plain text in most cases, save for the VERY exceptional case where the NSA might be watching IF they do have a key on your phone. Plus, anyone who's used Apple's partner portals knows they're just as capable of shitty design as everyone else.

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#18
post #17

Earlier quoted context omitted.

Do any down-voters care to offer a comment? Is it that one contests that Apple is a PRISM participant?

I think you're being downvoted because you got a little too excited while bashing Apple. iMessage is most certainly more secure than plain text in most cases, save for the VERY exceptional case where the NSA might be watching IF they do have a key on your phone. Plus, anyone who's used Apple's partner portals knows they're just as capable of shitty design as everyone else.

Thanks for the insight. Rather than excitement, I am actually most disappointed in Apple caving into the PRISM scheme because I hold them to a bit higher standard than other companies when it comes to privacy.. kind of like being told that Santa doesn't exist.

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#19
post #12

There is zero control over what public keys get handed over to your phone to encrypt an iMessage with. For all we know, whenever you want to send a message to $USER, your phone gets a public key for $USERs iPhone, her iPad and the NSA master key. Tim Cook can state that they can't decrypt the message all he wants, but as long as there's no control over what public keys we encrypt the message with, the statement that…

"as long as there's no control over what public keys we encrypt the message with, the statement that Apple or the NSA can't read the messages is a half-truth at best." This. That said, it is reasonable to believe the way iMessage is architected would likely make mass surveillance harder in general, just like widespread use of SSL does, so it is not entirely useless either. The bigger problem IMO is that they then upl…

make mass surveillance harder in general

More specifically, it makes it so that Apple is not forced to conduct mass surveillance by giving up everything when they receive a legal wiretap order, in the vein of Lavabit.

If you see someone else running a message system that has no way for the cops to read it, that should be a sign that it's insecure -- not technologically, but architecturally.

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#20

Earlier quoted context omitted.

"as long as there's no control over what public keys we encrypt the message with, the statement that Apple or the NSA can't read the messages is a half-truth at best." This. That said, it is reasonable to believe the way iMessage is architected would likely make mass surveillance harder in general, just like widespread use of SSL does, so it is not entirely useless either. The bigger problem IMO is that they then upl…

make mass surveillance harder in general More specifically, it makes it so that Apple is not forced to conduct mass surveillance by giving up everything when they receive a legal wiretap order, in the vein of Lavabit. If you see someone else running a message system that has no way for the cops to read it, that should be a sign that it's insecure -- not technologically, but architecturally.

> If you see someone else running a message system that has no way for the cops to read it, that should be a sign that it's insecure -- not technologically, but architecturally.

What's that supposed to mean? What about OTR or TextSecure or PGP over email?

Post reply on HN