Live data from Hacker News

Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

techcrunch.com

61–70 of 116 posts

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#61
post #27

Earlier quoted context omitted.

He didn't make a statement that Apple or the NSA can't read your messages. He said that Apple can't read your messages. However since you are so concerned about half truths, if you're going to criticise someone's statements, it would be nice if you'd address what they actually are saying. It's entirely possible that the NSA has hacked Apple, or that an Apple employee has been subverted by the NSA and inserted a back…

The half-truth is here: If the government laid a subpoena to get iMessages, we can’t provide it. It’s encrypted and we don’t have a key. It's encrypted and they don't have the key, but since the user does not have any control over the public keys being added, they could add a trusted public key and get it anyway. So they can actually provide messages if they really wanted to. I don't believe they really want to. But…

[deleted]

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#62
Let's take this to the extreme: If you are threat to the NSA, you'd use an iPhone to send a message because Tim Cook said it's encrypted?

YES - NO - I DON'T KNOW

ps. Let's wait for Apple to do a better job at keeping private naked pictures people make for fun using an iPhone and we'll talk iMessage encryption later.

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#64
post #12

There is zero control over what public keys get handed over to your phone to encrypt an iMessage with. For all we know, whenever you want to send a message to $USER, your phone gets a public key for $USERs iPhone, her iPad and the NSA master key. Tim Cook can state that they can't decrypt the message all he wants, but as long as there's no control over what public keys we encrypt the message with, the statement that…

Even if you could set your own keys, there's no guarantee their infrastructure doesn't leak them to NSA. And considering Snowden's revelations, it's more likely than not.

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#67
post #59

Earlier quoted context omitted.

Apple can silently slipstream applications onto a users iPhone ? That would means dozens of employees would be involved in a conspiracy with the US government. And over all the years none of them has leaked anything ? Sounds far fetched. Also better not use a phone. Because Android and Windows Phone would have the same problem.

Apple can remotely delete apps on iPhones. They've used it to delete apps that were removed from the app store. Apple can force your phone to download the latest U2 album. Upgrading your apps silently is probably not outside their control if they wanted to.

iPhones by default are set to automatically download purchased content from the iTunes Store. It's a feature so purchases made on one device automatically appear on others. All Apple did was "buy" the U2 for everyone. Nothing magical about it.

To bring that up in the context of iMessage security shows either ignorance or stupidity.

And remote deleting is quite a bit different to silently upgrading apps for the purpose of spying.

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#68
post #59

Earlier quoted context omitted.

Apple can silently slipstream applications onto a users iPhone ? That would means dozens of employees would be involved in a conspiracy with the US government. And over all the years none of them has leaked anything ? Sounds far fetched. Also better not use a phone. Because Android and Windows Phone would have the same problem.

Apple can remotely delete apps on iPhones. They've used it to delete apps that were removed from the app store. Apple can force your phone to download the latest U2 album. Upgrading your apps silently is probably not outside their control if they wanted to.

My phone certain did not automatically download Songs of Innocence. For those users whose phones DID automatically download it, they must have enabled the "automatically add purchased content to this phone" feature.

According to my research, Apple has NEVER used the "kill switch", unlike Google: 'Google also possesses a remote "kill switch" for Android apps, but unlike Apple, it has made use of the feature before. In 2010 the Android security team deleted two apps created by a security researcher after they "misrepresented their purpose in order to encourage user downloads." Its kill switch is referred to by the company as the "Remote Application Removal Feature.' [1]

[1] http://www.businessinsider.com/brazil-orders-apple-to-use-ip...

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#69
post #30

3 words - National Security Letter. Take what Timmy says with a grain of salt, until they should you the source code. Oh wait... Apple fan boys: bring on the downvotes, but enjoy your surveilling

I didn't downvote you, but I imagine it has less to do with what you said and more with how you said it. NSLs as a "boogeyman" is a poor substitute for lacking evidence. So far, we know that these things are sent to US companies which are in the business of collecting and bartering data. While Apple has a corner of that market, it isn't its entirety. So here they have snippets of our information Ex: email, credit car…

In a post-Snowden world, when it comes to leaking your data, companies are guilty until proven innocent. That is the only sensible stance to take given what we have learned in the last year.
Post reply on HN