Live data from Hacker News

Apple will notify users about state-sponsored cybersecurity threats

support.apple.com

101–110 of 166 posts

Re: Apple will notify users about state-sponsored cybersecurity threats

#101
post #73

Earlier quoted context omitted.

iMessage is extremely secure and utilizes end-to-end encryption, why is this concerning to you?

Aren't iMessages backed up to icloud that does not have end to end encryption.

Not anymore[*].

[*] If you enable "Messages" sync in iCloud, encrypted message history is synced across your iCloud devices in an E2E manner.

Re: Apple will notify users about state-sponsored cybersecurity threats

#102
post #73

Earlier quoted context omitted.

Is it concerning to any security people with more knowledge than me that this is sent via iMessage?!

iMessage is extremely secure and utilizes end-to-end encryption, why is this concerning to you?

iMessage does not have a mechanism to verify the devices associated with the destination account is actually theirs. It is feasible to assume an attacker/Apple/NSA could register an additional device key associated with your iMessage ID and snoop all future messages sent to that user from that moment on, even if they are not able to decrypt past messages. (This is true even if you assume iMessage client binary does what Apple says it does and is not tampered with/backdoored).

Re: Apple will notify users about state-sponsored cybersecurity threats

#103

Earlier quoted context omitted.

Thank you for your crack forensic work, this guy seems like a really reprehensible character, it's a wonder that his throwaway troll account has accrued so much karma and even regularly commented on a variety of topics to avoid arousing suspicion. After some more OSINT (open source intelligence for my fellow Redditors out there) we even discovered that he had accounts on other sites, where he also espoused original o…

Let me paraphrase your own quote: ”Please stop posting these long-winded [hate] essays every couple days. It would be one thing if this was [Reddit], but the slimyness and dishonesty here is yet another brick in the wall of non-fungible sketchiness.” A reminder to you that it is against Hacker News rules to do any ideological warfare, “trolling”, or bad-faith commentary.

The only one provoking people here is you. I made an on-topic comment, and you decided to develop it into a personal attack. Luckily for the both of us, I really don't care what you think of me, so you can spin your wheels complaining about my rhetoric for as long as you like. It doesn't bother me in the slightest. Have fun editing your comments and recontextualizing as you please, but I'm done here.

Re: Apple will notify users about state-sponsored cybersecurity threats

#104
post #73

Earlier quoted context omitted.

Is it concerning to any security people with more knowledge than me that this is sent via iMessage?!

iMessage is extremely secure and utilizes end-to-end encryption, why is this concerning to you?

iMessage has no concept of a "verified user account" (iMessage for Business is separate), so there's zero indication this message is genuinely from Apple, except an email address that can possibly be faked. It's strange Apple hasn't built-in visible confirmation that this specific Threat Notifications sender is legitimate.

Re: Apple will notify users about state-sponsored cybersecurity threats

#105
post #75

Earlier quoted context omitted.

And it has spam problems: https://www.wired.com/2014/08/apples-imessage-is-being-taken... The problem is authenticity and authority, not encryption. How can the user know this message really came from Apple and not a spammer?

That article is seven years old and in no way reflects current reality. In fact it has never reflected my own experience or that of anyone I know, where iMessage spam has been near enough to non-existent. And even if there were a spam problem, the risk is mostly on the upside anyway. It would only be an issue if iMessage got a reputation for flooding people with admonishments to take security seriously, purportedly f…

> That article is seven years old and in no way reflects current reality. In fact it has never reflected my own experience or that of anyone I know, where iMessage spam has been near enough to non-existent.

Your anecdotal lived experience is not representative of the entire population.

I personally have encountered at least a dozen spam iMessages (not SMS) in the past year, and several friends of mine have described the same experience. I googled iMessage spam and this was on the second page, just from last year: https://thisrupt.co/lifestyle/imessage-spam-not-thai-chana/ Feel free to research yourself to discover that it is in fact a widespread issue for many people, if not as widespread as it once was since the "Unknown sender" tab was introduced.

Regardless, SMS spam remains an issue, and on iOS, many users may not know the difference, as they're in the same app.

> And even if there were a spam problem, the risk is mostly on the upside anyway. It would only be an issue if iMessage got a reputation for flooding people with admonishments to take security seriously, purportedly from Apple.

You're missing the point. iMessage spam (though it does exist as I've shown above) is not the problem. The problem is iMessage doesn't have a good way to "verify" that messages that purport to be from Apple or anyone else truly are from a known and trusted sender. This deficiency is what enables iMessage spam, and creates the same potential for abuse with this new feature.

Re: Apple will notify users about state-sponsored cybersecurity threats

#106
post #77

Earlier quoted context omitted.

Respond by using 2fa if you weren't already, not signing into the account from untrusted devices, checking OAuth grants for apps you don't recognize, not using same pw elsewhere

Yeah, we were doing that, so the response was to just shrug. Without a lot more context it's hard to know what your reaction should be to something like that.

Google's approach (and possibly Apple's) is commendable, but very poor UX-wise. Google specifically seems to include "phishing attempts" in their government-attack detection, and the direct reason seems to be that phishing was used in compromising the DNC in 2016. But there's a huge difference between a hacker-for-hire group that may have tenuous government links sending a mediocre phishing email (as in https://blog.google/threat-analysis-group/updates-about-gove...), and advanced zero-click zero-day use on all personal devices by a direct government body. Lumping them together makes zero sense.

Re: Apple will notify users about state-sponsored cybersecurity threats

#107
post #81
post #75

Earlier quoted context omitted.

And it has spam problems: https://www.wired.com/2014/08/apples-imessage-is-being-taken... The problem is authenticity and authority, not encryption. How can the user know this message really came from Apple and not a spammer?

>How can the user know Read the document of the original top post (the document from Apple). The answer to your question is right there in the document.

That does nothing to verify authenticity within iMessage itself, creating the opportunity for abuse and impersonation I outlined in my other comment in this thread. A simple solution to this problem would be a "verified" indicator for users to know that the iMessage did in fact originate from Apple, without them having to first know that such a support document exists.

Re: Apple will notify users about state-sponsored cybersecurity threats

#109
post #77

Earlier quoted context omitted.

Respond by using 2fa if you weren't already, not signing into the account from untrusted devices, checking OAuth grants for apps you don't recognize, not using same pw elsewhere

Yeah, we were doing that, so the response was to just shrug. Without a lot more context it's hard to know what your reaction should be to something like that.

I can only guess, but I suppose the context in which they would trigger something like this would be that some of their accounts get hijacked to send things to a bunch of email addresses, which later turn out to be links to zero-day exploits attribuable to state-sponsored attackers, so they warn the recipients of those emails. But it's got to be a relatively scattershot warning - Google doesn't really know how vigilant you are. A friend of mine working for an NGO got the Gmail warning back in 2012 and upgraded a few overdue things.

Re: Apple will notify users about state-sponsored cybersecurity threats

#110
post #73

Earlier quoted context omitted.

iMessage is extremely secure and utilizes end-to-end encryption, why is this concerning to you?

iMessage has no concept of a "verified user account" (iMessage for Business is separate), so there's zero indication this message is genuinely from Apple, except an email address that can possibly be faked. It's strange Apple hasn't built-in visible confirmation that this specific Threat Notifications sender is legitimate.

> iMessage has no concept of a "verified user account" (iMessage for Business is separate), so there's zero indication this message is genuinely from Apple

According to this screenshot, it appears they do: https://twitter.com/norbertmao/status/1463364241688305664

Post reply on HN