Live data from Hacker News

Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

techcrunch.com

21–30 of 116 posts

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#21
post #20

Earlier quoted context omitted.

make mass surveillance harder in general More specifically, it makes it so that Apple is not forced to conduct mass surveillance by giving up everything when they receive a legal wiretap order, in the vein of Lavabit. If you see someone else running a message system that has no way for the cops to read it, that should be a sign that it's insecure -- not technologically, but architecturally.

> If you see someone else running a message system that has no way for the cops to read it, that should be a sign that it's insecure -- not technologically, but architecturally. What's that supposed to mean? What about OTR or TextSecure or PGP over email?

someone else running

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#22

These statements again... Time to get some downvotes, I guess. How do I know? How can I even know that YOUR own device for which YOU wrote software and YOU designed hardware (although it may be based on some standards , no one can guarantee it's unmodified) won't share my private information with YOU? How can I know that you're not sending my private key encrypted with your server's public key (one simple example of…

I tend to agree, it's much easier to just assume all online commutations are monitored than to try to escape the gaze of the five eyes (of Sauron).

Maybe this attitude means they have already won?

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#23
post #12

There is zero control over what public keys get handed over to your phone to encrypt an iMessage with. For all we know, whenever you want to send a message to $USER, your phone gets a public key for $USERs iPhone, her iPad and the NSA master key. Tim Cook can state that they can't decrypt the message all he wants, but as long as there's no control over what public keys we encrypt the message with, the statement that…

The fact that Apple could in the future modify their system to permit them to read iMessages (e.g. by interposing themselves between sender and receiver using fake public keys) is not really a fair basis for alleging that Tim Cook or anyone else is telling "half-truths" in respect of what Apple is currently doing. He has said they are not reading them and that, at present, they cannot read them. I'm not aware of any basis for impugning his credibility in that respect.

But it remains the case that anyone seriously concerned about security should continue to guard against that possibility in the future.

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#24

These statements again... Time to get some downvotes, I guess. How do I know? How can I even know that YOUR own device for which YOU wrote software and YOU designed hardware (although it may be based on some standards , no one can guarantee it's unmodified) won't share my private information with YOU? How can I know that you're not sending my private key encrypted with your server's public key (one simple example of…

I tend to agree, it's much easier to just assume all online commutations are monitored than to try to escape the gaze of the five eyes (of Sauron). Maybe this attitude means they have already won?

For some reason I think only diversity may help.

1000s different systems built differently are harder to milk for useful information if user is smart.. Centralization is the enemy of privacy (centralized = compromised).

Unless they have an AI which can analyze such systems' patterns at the speed of light and present solutions (which is not as unbelievable as self-conscious AI) but it's still more of a fiction.

Really, the problem is not in tech, it's in people. We're not fixing this one anytime soon.

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#25

Earlier quoted context omitted.

"as long as there's no control over what public keys we encrypt the message with, the statement that Apple or the NSA can't read the messages is a half-truth at best." This. That said, it is reasonable to believe the way iMessage is architected would likely make mass surveillance harder in general, just like widespread use of SSL does, so it is not entirely useless either. The bigger problem IMO is that they then upl…

make mass surveillance harder in general More specifically, it makes it so that Apple is not forced to conduct mass surveillance by giving up everything when they receive a legal wiretap order, in the vein of Lavabit. If you see someone else running a message system that has no way for the cops to read it, that should be a sign that it's insecure -- not technologically, but architecturally.

I'm unclear as to what you mean by that last sentence. If someone is running a message system that is distributed and keys to encrypt and decrypt are store locally, not on the server, then why wouldn't it be secure? The message system may be anything as simple as an addressing system

Ex: Email, which is run by any number of providers, however if an email client is configured to use PGP and access is via POP/IMAP and not webmail, it's still secure as far as we know. A message system that may not be email, but still doesn't store keys on the server, still provides no way for cops to read it. Except perhaps to see some message was sent, not what the message was.

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#26

These statements again... Time to get some downvotes, I guess. How do I know? How can I even know that YOUR own device for which YOU wrote software and YOU designed hardware (although it may be based on some standards , no one can guarantee it's unmodified) won't share my private information with YOU? How can I know that you're not sending my private key encrypted with your server's public key (one simple example of…

[deleted]

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#27
post #12

There is zero control over what public keys get handed over to your phone to encrypt an iMessage with. For all we know, whenever you want to send a message to $USER, your phone gets a public key for $USERs iPhone, her iPad and the NSA master key. Tim Cook can state that they can't decrypt the message all he wants, but as long as there's no control over what public keys we encrypt the message with, the statement that…

He didn't make a statement that Apple or the NSA can't read your messages. He said that Apple can't read your messages. However since you are so concerned about half truths, if you're going to criticise someone's statements, it would be nice if you'd address what they actually are saying.

It's entirely possible that the NSA has hacked Apple, or that an Apple employee has been subverted by the NSA and inserted a back door into the encryption system. Tim Cook wouldn't know about that and can't give assurances of that kind, and isn't trying to. All he can do is state what Apple as a company intends and can do acting according to it's policies.

So yes it's entirely possible Apple or the NSA has back door keys to iMessage. Tim Cook is now publicly on record saying that Apple don't. That's not a 'half truth at best'. It's either true or it's a lie. I'm not telling you to believe him or not, but historically these things have a way of coming to light eventually, one way or another.

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#28
post #26

These statements again... Time to get some downvotes, I guess. How do I know? How can I even know that YOUR own device for which YOU wrote software and YOU designed hardware (although it may be based on some standards , no one can guarantee it's unmodified) won't share my private information with YOU? How can I know that you're not sending my private key encrypted with your server's public key (one simple example of…

[deleted]

It's just.. this statement barely has any meaning to it then. Carefully crafted sentences, yes, but what difference does it make to the outcome, to the end user?

We most certainly know that iMessage (like any other service) is not secure and now we are also left pondering if he is telling the truth or not about something that doesn't even matter in the end :)

Maybe I'm being too critical or maybe I'm missing something.

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#29

"Our business is not based on having information about you. You’re not our product. Our product are these, and this watch, and Macs and so forth. And so we run a very different company. I think everyone has to ask, how do companies make their money? Follow the money. And if they’re making money mainly by collecting gobs of personal data, I think you have a right to be worried. And you should really understand what’s…

Of course, there's nothing stopping Apple from selling both the product and the user...

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#30

3 words - National Security Letter. Take what Timmy says with a grain of salt, until they should you the source code. Oh wait... Apple fan boys: bring on the downvotes, but enjoy your surveilling

I didn't downvote you, but I imagine it has less to do with what you said and more with how you said it. NSLs as a "boogeyman" is a poor substitute for lacking evidence. So far, we know that these things are sent to US companies which are in the business of collecting and bartering data. While Apple has a corner of that market, it isn't its entirety.

So here they have snippets of our information Ex: email, credit card, home address for app purchases. However, it's just as possible to use the phone normally without downloading a single app. That leaves the SIM provider holding the bag for your information ready to be collected by the authorities. Effectively, Apple washes its hands of your data on phone calls, but there is no reason to presume lies regarding backdoors on iMessage.

Also, I'm not an "Apple fan boy". I'm just unconvinced of widespread eavesdropping at Apple and that they're willing to risk destroying such a massive advantage over Google's Hangouts platform.

Post reply on HN