Live data from Hacker News

Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

techcrunch.com

71–80 of 116 posts

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#71
post #34

Earlier quoted context omitted.

>He said that Apple can't read your messages. which is also a half-truth. They can't read messages encrypted with another phones public key, but they can certainly read messages encrypted with their public key which they might or might not send to your phone in addition to the actual recipient's public key. Neither me nor he is saying that Apple does in-fact read your messages (they probably don't), but saying that t…

Not really. He's pretty clear: "If the government laid a subpoena to get iMessages, we can’t provide it. It’s encrypted and we don’t have a key." There's no wiggle room there. He's not saying we don't have the users key, he's saying categorically they can't provide iMessage information. I don't understand why you think that can be read as they can't get the information through mechanism X but that they can through me…

What is missing is that they can add another key for intercept. They really need to be able to do so to comply with the law.

It's well established that the police can intercept communications with a warrant. Many HN posters have an issue with that too, but that is just a hard truth with decades if legal precedence.

The issue, IMO, is the warrantless collection part. IMO, iMessages probably protects you against the latter, although 3-letter agencies may record the messages and use other means to decrypt them later.

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#72

"Our business is not based on having information about you. You’re not our product. Our product are these, and this watch, and Macs and so forth. And so we run a very different company. I think everyone has to ask, how do companies make their money? Follow the money. And if they’re making money mainly by collecting gobs of personal data, I think you have a right to be worried. And you should really understand what’s…

"Our business is not based on having information about you."

That would be awesome if that was true, but Apple knows a lot about all of us, including our credit card numbers (iTunes/Appple Pay), your music, movie and media purchases, contacts, files, photos ... the list goes on.

Cook can draw the line where he think it's appropriate, but for others that line is much, much different.

Apple is simply on a spectrum of companies that store personal information about you. They aren't the worst, but they certainly aren't the best either.

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#73
post #56

It's Encrypted, and We Don't Have a Key. But it's not open source so you don't get to check. ... and we control the key distribution. We also do control your device, so technically , we don't need the key. Fixed that for him.

And we put music on your device without asking you.

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#74
post #34

Earlier quoted context omitted.

>He said that Apple can't read your messages. which is also a half-truth. They can't read messages encrypted with another phones public key, but they can certainly read messages encrypted with their public key which they might or might not send to your phone in addition to the actual recipient's public key. Neither me nor he is saying that Apple does in-fact read your messages (they probably don't), but saying that t…

Not really. He's pretty clear: "If the government laid a subpoena to get iMessages, we can’t provide it. It’s encrypted and we don’t have a key." There's no wiggle room there. He's not saying we don't have the users key, he's saying categorically they can't provide iMessage information. I don't understand why you think that can be read as they can't get the information through mechanism X but that they can through me…

[deleted]

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#75
post #42

Earlier quoted context omitted.

They can't create trusted public keys after the fact, they'd have to already have them. So there's no half truth. Either they currently create and store such public keys or they don't. Tim Cooke is saying they don't. That statement can't be half true. It's either true or false.

They can't create trusted public keys after the fact, Of course they can. They own the directory server that hands out keys. http://blog.cryptographyengineering.com/2013/06/can-apple-re... tl;dr: Apple can send you a public key of Bob's new device. Apple can pretend to send you a public key of Bob's new device. And since it's proprietary software, they can trigger a resend of your recent messages to Bob. Moreover, if…

>And since it's proprietary software, they can trigger a resend of your recent messages to Bob.

Apple control iOS so they could just release an update that disables crypto and leaks all the messages - your point is irrelevant since they can't trigger a resend without an update to iOS.

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#76
post #69
post #30

Earlier quoted context omitted.

I didn't downvote you, but I imagine it has less to do with what you said and more with how you said it. NSLs as a "boogeyman" is a poor substitute for lacking evidence. So far, we know that these things are sent to US companies which are in the business of collecting and bartering data. While Apple has a corner of that market, it isn't its entirety. So here they have snippets of our information Ex: email, credit car…

In a post-Snowden world, when it comes to leaking your data, companies are guilty until proven innocent. That is the only sensible stance to take given what we have learned in the last year.

This.

The Director of National Intelligence James Clapper tells Congress that the NSA doesn't conduct intelligence on American citizens, and then later gets caught out. He committed Perjury without any ramifications.

Why do people think that CEOs are telling the truth when they are all in the same boat paddling up shit river?

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#77

Earlier quoted context omitted.

They can't create trusted public keys after the fact, Of course they can. They own the directory server that hands out keys. http://blog.cryptographyengineering.com/2013/06/can-apple-re... tl;dr: Apple can send you a public key of Bob's new device. Apple can pretend to send you a public key of Bob's new device. And since it's proprietary software, they can trigger a resend of your recent messages to Bob. Moreover, if…

>And since it's proprietary software, they can trigger a resend of your recent messages to Bob. Apple control iOS so they could just release an update that disables crypto and leaks all the messages - your point is irrelevant since they can't trigger a resend without an update to iOS.

And you know this ability isn't latent with iOS currently how?

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#78
post #34

Earlier quoted context omitted.

>He said that Apple can't read your messages. which is also a half-truth. They can't read messages encrypted with another phones public key, but they can certainly read messages encrypted with their public key which they might or might not send to your phone in addition to the actual recipient's public key. Neither me nor he is saying that Apple does in-fact read your messages (they probably don't), but saying that t…

Not really. He's pretty clear: "If the government laid a subpoena to get iMessages, we can’t provide it. It’s encrypted and we don’t have a key." There's no wiggle room there. He's not saying we don't have the users key, he's saying categorically they can't provide iMessage information. I don't understand why you think that can be read as they can't get the information through mechanism X but that they can through me…

Or Cook could just reap some PR-points with a convincingly stated flat out lie. It's not like anyone will remember it in a couple of weeks anyway.

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#79
post #12

There is zero control over what public keys get handed over to your phone to encrypt an iMessage with. For all we know, whenever you want to send a message to $USER, your phone gets a public key for $USERs iPhone, her iPad and the NSA master key. Tim Cook can state that they can't decrypt the message all he wants, but as long as there's no control over what public keys we encrypt the message with, the statement that…

Your presumption is that iMessage encryption is useless if the NSA can still read the messages. Speaking for myself, I don't care if the NSA can read my messages. My biggest concern is keeping my private data protected from for-profit corporations like Apple and Google.
Post reply on HN