Live data from Hacker News

Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

techcrunch.com

31–40 of 116 posts

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#31
post #12

There is zero control over what public keys get handed over to your phone to encrypt an iMessage with. For all we know, whenever you want to send a message to $USER, your phone gets a public key for $USERs iPhone, her iPad and the NSA master key. Tim Cook can state that they can't decrypt the message all he wants, but as long as there's no control over what public keys we encrypt the message with, the statement that…

It's even worse that that. As of about a year ago, iMessage didn't do any certificate pinning: http://blog.quarkslab.com/imessage-privacy.html

Unless that's been fixed (I haven't come across any evidence one way or the other), you're not just worrying about Apple and the NSA: Your iMessages are vulnerable to anyone who can forge a certificate and MITM your connection to Apple's servers. I'd say that's a reasonably high bar except for one thing: I believe it covers the vast majority of corporate iPhones used on company-internal networks.

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#32
post #27
post #12

There is zero control over what public keys get handed over to your phone to encrypt an iMessage with. For all we know, whenever you want to send a message to $USER, your phone gets a public key for $USERs iPhone, her iPad and the NSA master key. Tim Cook can state that they can't decrypt the message all he wants, but as long as there's no control over what public keys we encrypt the message with, the statement that…

He didn't make a statement that Apple or the NSA can't read your messages. He said that Apple can't read your messages. However since you are so concerned about half truths, if you're going to criticise someone's statements, it would be nice if you'd address what they actually are saying. It's entirely possible that the NSA has hacked Apple, or that an Apple employee has been subverted by the NSA and inserted a back…

The half-truth is here:

If the government laid a subpoena to get iMessages, we can’t provide it. It’s encrypted and we don’t have a key.

It's encrypted and they don't have the key, but since the user does not have any control over the public keys being added, they could add a trusted public key and get it anyway. So they can actually provide messages if they really wanted to.

I don't believe they really want to. But the thing we should've learnt from last year's revelations is (1) that companies can be forced to do so anyway via secret courts; and (2) the NSA is willing to make a 'technical solution' otherwise.

So, Tim Cook is not being completely honest here. Apart from what hardware can do, the only way to trust such an application is if you had the source code, the source code of the operating system and the source code to firmware blobs, and some way to prove that everything was compiled from public source code without modifications. Since that is not going to happen, iMessage should be considered as secure as unencrypted e-mail when it comes to governments. Of course, it does provide more protection than e-mail against less equipped actors.

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#33
post #29

"Our business is not based on having information about you. You’re not our product. Our product are these, and this watch, and Macs and so forth. And so we run a very different company. I think everyone has to ask, how do companies make their money? Follow the money. And if they’re making money mainly by collecting gobs of personal data, I think you have a right to be worried. And you should really understand what’s…

Of course, there's nothing stopping Apple from selling both the product and the user...

They are publicly traded, so they publish their financials. Something would show up there. Even if they cook their books, something would show up in somebody else's books.

If you are paranoid, you may think of the options "Sell the product and give away the user" and "Everyone is in on this". I think those are far-fetched.

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#34
post #27
post #12

There is zero control over what public keys get handed over to your phone to encrypt an iMessage with. For all we know, whenever you want to send a message to $USER, your phone gets a public key for $USERs iPhone, her iPad and the NSA master key. Tim Cook can state that they can't decrypt the message all he wants, but as long as there's no control over what public keys we encrypt the message with, the statement that…

He didn't make a statement that Apple or the NSA can't read your messages. He said that Apple can't read your messages. However since you are so concerned about half truths, if you're going to criticise someone's statements, it would be nice if you'd address what they actually are saying. It's entirely possible that the NSA has hacked Apple, or that an Apple employee has been subverted by the NSA and inserted a back…

>He said that Apple can't read your messages.

which is also a half-truth. They can't read messages encrypted with another phones public key, but they can certainly read messages encrypted with their public key which they might or might not send to your phone in addition to the actual recipient's public key.

Neither me nor he is saying that Apple does in-fact read your messages (they probably don't), but saying that they can't read your messages is not correct. They certainly can by sending your phone an additional public key.

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#35
post #27
post #12

There is zero control over what public keys get handed over to your phone to encrypt an iMessage with. For all we know, whenever you want to send a message to $USER, your phone gets a public key for $USERs iPhone, her iPad and the NSA master key. Tim Cook can state that they can't decrypt the message all he wants, but as long as there's no control over what public keys we encrypt the message with, the statement that…

He didn't make a statement that Apple or the NSA can't read your messages. He said that Apple can't read your messages. However since you are so concerned about half truths, if you're going to criticise someone's statements, it would be nice if you'd address what they actually are saying. It's entirely possible that the NSA has hacked Apple, or that an Apple employee has been subverted by the NSA and inserted a back…

"Let's not worry about it, it's probably all ok, you can't say anything unless you have 100% cast-iron proof"?

That's an excellent recipe for sleepwalking into this mess.

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#37

"Our business is not based on having information about you. You’re not our product. Our product are these, and this watch, and Macs and so forth. And so we run a very different company. I think everyone has to ask, how do companies make their money? Follow the money. And if they’re making money mainly by collecting gobs of personal data, I think you have a right to be worried. And you should really understand what’s…

For as much as you may criticize Apple for many things, you can't really say they are not sincere when they say something like this. A company has to make profits, and profits come from a well executed business plan. Apple's business plan is to sell hardware and create software and platforms that drive hardware sales. Collecting data for reasons that are not related to the functioning of a service makes no sense for the bottom line. Google makes profit selling ads crafted on people's data and a new controlled user accessing the Internet is entering its realm. That is good for the bottom line. It may be an oversimplification, but I guess that you can say a lot and get back to this.

Anything that has to do with NSA mass surveillance, though, shouldn't be transposed on this discourse. Not Tim Cook, nor Larry Page, nor any other CEO, individually and in their function, can possibly know everything about their company. Fifth columns, NSA rats, unconstitutional secret requests of information... They are American citizens, running American organizations they have to comply to the rules or they may compromise billions of shareholders dollars. But are they lying to us right now? I think they are not, because it will hurt their bottom lines more than ever. Is Google in a weaker position than Apple because of the very nature of its business model based on data collection? Absolutely yes.

The problem is ingrained with the system though and the only solution is to extirpate the cancer called NSA. I doubt it will happen anytime soon, though. We all love our gadgets and services too much, and we don't really have time to wrap our brain around such big problems for nerds.

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#38
post #17

Earlier quoted context omitted.

Do any down-voters care to offer a comment? Is it that one contests that Apple is a PRISM participant?

I think you're being downvoted because you got a little too excited while bashing Apple. iMessage is most certainly more secure than plain text in most cases, save for the VERY exceptional case where the NSA might be watching IF they do have a key on your phone. Plus, anyone who's used Apple's partner portals knows they're just as capable of shitty design as everyone else.

"In most cases" isn't enough any more these days. People are targeted alone by metadata - and killed too.

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#39
post #5
post #4

Earlier quoted context omitted.

"When a user turns on iMessage, the device generates two pairs of keys for use with the service: an RSA 1280-bit key for encryption and an ECDSA 256-bit key for signing. For each key pair, the private keys are saved in the device’s keychain and the public keys are sent to Apple’s directory service" "The user’s outgoing message is individually encrypted using AES-128 in CTR mode for each of the recipient’s devices, si…

But they could just inject a "fake" recipient device with their own public/private key and decrypt messages as they transit the system. They might not be able to decrypt messages you've sent in the past, but I can see no reason why they couldn't read messages as you send them if they wanted to (or were required by a wiretapping agency, for example). I also recall a while ago a researcher who showed that if you forgot…

It is not impossible so long as there is a linked device that has access to the data. Was there a precise accounting of the state of the researcher's icloud account before the reset, and everything done during the reset?

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#40
post #29

"Our business is not based on having information about you. You’re not our product. Our product are these, and this watch, and Macs and so forth. And so we run a very different company. I think everyone has to ask, how do companies make their money? Follow the money. And if they’re making money mainly by collecting gobs of personal data, I think you have a right to be worried. And you should really understand what’s…

Of course, there's nothing stopping Apple from selling both the product and the user...

But that reduces the value of the product. I also don't think it is in Apple's DNA to do that.

My concern is more that, given how bad they generally are at providing robust cloud applications [1], that their security is equally bad.

[1] iTunes Match would always refuse to play some songs from my collection. Even when a stopped using an iPhone last december, iMessages would often come in in non-chronological order and sometimes not at all, etc.

Post reply on HN