Live data from Hacker News

Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

techcrunch.com

101–110 of 116 posts

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#101
post #99

Earlier quoted context omitted.

They can't create trusted public keys after the fact, Of course they can. They own the directory server that hands out keys. http://blog.cryptographyengineering.com/2013/06/can-apple-re... tl;dr: Apple can send you a public key of Bob's new device. Apple can pretend to send you a public key of Bob's new device. And since it's proprietary software, they can trigger a resend of your recent messages to Bob. Moreover, if…

So this ends up being as "simple" as answering the question: Do you trust Apple? Given they control the operating system and all around it, having the directory server controlled by someone else (or distributed) doesn't solve the problem as they have access to anything they want in your device, meaning they don't need any keys to begin with.

I wouldn't trust any company that blatantly dodges the question of security with a half truth. It's clear he's playing word games for PR points.

You can reset your password and redownload all of your messages to a new device if you use iCloud backup. Cook is full of shit when he says that Apple doesn't have the capability. They own the system.

Even a dedicated civilian could reset your password, associate a device with your account and receive all messages going forward. To state that Apple cannot is such a laughable claim that it becomes clear that it's just a PR game. Which calls into question how sincere he is in his feelings about privacy.

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#102
post #99

Earlier quoted context omitted.

So this ends up being as "simple" as answering the question: Do you trust Apple? Given they control the operating system and all around it, having the directory server controlled by someone else (or distributed) doesn't solve the problem as they have access to anything they want in your device, meaning they don't need any keys to begin with.

I wouldn't trust any company that blatantly dodges the question of security with a half truth. It's clear he's playing word games for PR points. You can reset your password and redownload all of your messages to a new device if you use iCloud backup . Cook is full of shit when he says that Apple doesn't have the capability. They own the system. Even a dedicated civilian could reset your password, associate a device w…

For the record, you cannot redownload old messages in iMessage; if you use iCloud Backup, a civilian could fetch messages from there, but if not, they're out of luck.

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#103
post #102

Earlier quoted context omitted.

I wouldn't trust any company that blatantly dodges the question of security with a half truth. It's clear he's playing word games for PR points. You can reset your password and redownload all of your messages to a new device if you use iCloud backup . Cook is full of shit when he says that Apple doesn't have the capability. They own the system. Even a dedicated civilian could reset your password, associate a device w…

For the record, you cannot redownload old messages in iMessage; if you use iCloud Backup, a civilian could fetch messages from there, but if not, they're out of luck.

Fair enough, I was mistaken. Security is hard, but no one should get a pass playing games like this when it comes to security.

A civilian could still associate another key (device) to the account if they're dedicated with the password or a password reset (not as stealthy) assuming 2FA is disabled. And Apple could surely do it stealthily since they own the system.

They have the capability, and it's too kind to his statement by calling it a half-truth in that respect because it's really a lie when he says "[Apple doesn't] have the capability."

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#104
post #27

Earlier quoted context omitted.

He didn't make a statement that Apple or the NSA can't read your messages. He said that Apple can't read your messages. However since you are so concerned about half truths, if you're going to criticise someone's statements, it would be nice if you'd address what they actually are saying. It's entirely possible that the NSA has hacked Apple, or that an Apple employee has been subverted by the NSA and inserted a back…

The half-truth is here: If the government laid a subpoena to get iMessages, we can’t provide it. It’s encrypted and we don’t have a key. It's encrypted and they don't have the key, but since the user does not have any control over the public keys being added, they could add a trusted public key and get it anyway. So they can actually provide messages if they really wanted to. I don't believe they really want to. But…

Even if a new public key is added to the keybag, the NSA wouldn't get old messages, only messages from that point forward.

Still troublesome, and I wish there was some way to see what keys are being used and cross verify them with the remote user, so that if a new key is added you would be notified.

But there is no way for Apple to retrieve old messages and send them to the NSA.

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#106
post #68
post #59

Earlier quoted context omitted.

Apple can remotely delete apps on iPhones. They've used it to delete apps that were removed from the app store. Apple can force your phone to download the latest U2 album. Upgrading your apps silently is probably not outside their control if they wanted to.

My phone certain did not automatically download Songs of Innocence. For those users whose phones DID automatically download it, they must have enabled the "automatically add purchased content to this phone" feature. According to my research, Apple has NEVER used the "kill switch", unlike Google: 'Google also possesses a remote "kill switch" for Android apps, but unlike Apple, it has made use of the feature before. In…

The point is they have the capability and because of your government's secret court system the general public very well may never find out whether or not the capability has been taken advantage of.

I can guarantee you that the "automatically add purchased content to this phone" check box does absolutely nothing to protect your phone from downloading and integrating data from Apple silently if they should choose to target you. And you would likely never know if they choose to target you.

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#107
post #52

Earlier quoted context omitted.

Applications and software? Songs? Television? Movies? Health? Seems to be a bit disingenuous to suggest that they aren't making any money from your habits and data.

No, it doesn’t, not really. Look at where their money is coming from. You mentioned health. Apple has no plans at all to make money with that. It’s just an API that makes devices more useful for users . Think critically about this, but please do it in a honest way.

Rubbish[1].

The idea that Apple is in the market to sell these things, and specifically, to sell more, isn't a leap of neurological fortitude.

To suggest that Apple isn't analysing your purchasing to augment sales in some capacity is akin to clinging to the fallacy that they avoid market research[2].

There is no myth of constancy here; Apple is not strictly a hardware vendor any longer. However it is spun, it would seem entirely plausible that they leverage past purchases and other such metrics of data against future purchases.

I apologize for not abiding by your definition of thinking “critically” in an “honest” way.

[1] http://9to5mac.com/2014/08/21/apple-talked-healthkit-with-in...

[2] Apple vs. Samsung debunked this myth entirely.

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#108
post #83
post #31

Earlier quoted context omitted.

It's even worse that that. As of about a year ago, iMessage didn't do any certificate pinning: http://blog.quarkslab.com/imessage-privacy.html Unless that's been fixed (I haven't come across any evidence one way or the other), you're not just worrying about Apple and the NSA: Your iMessages are vulnerable to anyone who can forge a certificate and MITM your connection to Apple's servers. I'd say that's a reasonably hi…

Certificate pinning usually (ex: Chrome) is implemented with an exception to allow a company administrator to install a new root CA cert on the device and MITM connections. Does iMessage not allow this?

This Chrome behavior surprised me so I checked the source. Indeed, you are correct. Pin checking is short-circuited if the cert is signed by a root.

` if (!is_issued_by_known_root || !HasPublicKeyPins(host, sni_available)) { return true; } `

https://code.google.com/p/chromium/codesearch#chromium/src/n...

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#109
post #59

Earlier quoted context omitted.

Apple can remotely delete apps on iPhones. They've used it to delete apps that were removed from the app store. Apple can force your phone to download the latest U2 album. Upgrading your apps silently is probably not outside their control if they wanted to.

iPhones by default are set to automatically download purchased content from the iTunes Store. It's a feature so purchases made on one device automatically appear on others. All Apple did was "buy" the U2 for everyone. Nothing magical about it. To bring that up in the context of iMessage security shows either ignorance or stupidity. And remote deleting is quite a bit different to silently upgrading apps for the purpos…

So when do we find out the NSA has made it's own little "purchase" for everyone ?

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#110

Earlier quoted context omitted.

The half-truth is here: If the government laid a subpoena to get iMessages, we can’t provide it. It’s encrypted and we don’t have a key. It's encrypted and they don't have the key, but since the user does not have any control over the public keys being added, they could add a trusted public key and get it anyway. So they can actually provide messages if they really wanted to. I don't believe they really want to. But…

Even if a new public key is added to the keybag, the NSA wouldn't get old messages, only messages from that point forward. Still troublesome, and I wish there was some way to see what keys are being used and cross verify them with the remote user, so that if a new key is added you would be notified. But there is no way for Apple to retrieve old messages and send them to the NSA.

Euhm, no, it would have access to any message you can see from the phone, old or new. Plus I don't think there's a per-message key at all. So they could have logged the messages, then install a patched iMessage on your phone to send them the key.

That is assuming Apple's claim is true at all, and they need this in the first place.

Post reply on HN