I know of one case of a Polish prosecutor who does not obey (do not want to bend the law) Zbigniew Ziobro, who is both the minister of justice and the prosecutor general. She received a notification from Apple just today. Source: https://mobile.twitter.com/e_wrzosek/status/1463551631648251...
Is it concerning to any security people with more knowledge than me that this is sent via iMessage?!
Apple will notify users about state-sponsored cybersecurity threats
111–120 of 166 posts
Re: Apple will notify users about state-sponsored cybersecurity threats
#112Has anyone put forward some theories as to how they are pulling this off? Are they tapping into iMessage Metadata, scanning crash logs, or something along those lines? While I totally understand the need for them to keep how they are doing this private, I do find it slightly concerning. Unless they are just flagging suspicious iCloud login attempts. If it’s relating to crash logs, it would be nice to know as I’m sure…
It is not possible to disable all telemetry entirely.
Re: Apple will notify users about state-sponsored cybersecurity threats
#113Earlier quoted context omitted.
Is it concerning to any security people with more knowledge than me that this is sent via iMessage?!
The transport is secure, but if an attacker has already found their way into the device, they can intercept notifications/iMessages and remove it automatically anyway, so yes it's a bit or concern. But at that point, anything will be concerning, not only iMessage.
Obviously, that only really works once.
Re: Apple will notify users about state-sponsored cybersecurity threats
#114Earlier quoted context omitted.
> Can you provide citation for this? Apple's cooperation with PRISM[0] is well documented[1], but if you want to find the particularly damning details you'll need to do your own research. The dust has settled since the Snowden revelations, and many mentions of the program have been sterilized. > Also how they are different from any other tech company? It's not. But the claim that Apple puts extra effort into protecti…
I shouldn't be arguing with the trolls - but in case anyone was curious about these (nonsense) allegations: Your links do not document cooperation with PRISM other than that the NSA believed they got information from them, which is very different. For all we know, it could have been the NSA abusing an API endpoint. Also, it said that it got lots of stuff like email, address, and so on when all of these services were…
Re: Apple will notify users about state-sponsored cybersecurity threats
#115I see a lot of people in the comments conflating legal requests and attacks. Regardless of your opinion on either of those issues, they are different things.
NSA surveillance is illegal. Will we be notified?
Re: Apple will notify users about state-sponsored cybersecurity threats
#116I'm surprised to see protection against state sponsored attacks implemented by a company as big as Apple. Is any other 'mainstream' company offering a similar feature? Warrant canary [0] comes to mind, but that is usually a message to all users, as opposed to notifying an individual user. [0]: https://en.wikipedia.org/wiki/Warrant_canary
You mean apart from basically every other mainstream tech company? [1] [2] [3]
[1] https://www.washingtonpost.com/business/economy/google-to-al...
[2] https://www.wired.com/2015/10/facebook-now-warns-users-of-st...
[3] https://threatpost.com/twitter-warns-some-users-of-nation-st...
Re: Apple will notify users about state-sponsored cybersecurity threats
#117Earlier quoted context omitted.
That article is seven years old and in no way reflects current reality. In fact it has never reflected my own experience or that of anyone I know, where iMessage spam has been near enough to non-existent. And even if there were a spam problem, the risk is mostly on the upside anyway. It would only be an issue if iMessage got a reputation for flooding people with admonishments to take security seriously, purportedly f…
> That article is seven years old and in no way reflects current reality. In fact it has never reflected my own experience or that of anyone I know, where iMessage spam has been near enough to non-existent. Your anecdotal lived experience is not representative of the entire population. I personally have encountered at least a dozen spam iMessages (not SMS) in the past year, and several friends of mine have described…
Of course. That goes without saying. But neither you nor this person you cherry picked from a Google search is representative either. (And it's noteworthy that you had to drill down into Google search results in order to find a useful citation. That alone is evidence of iMessage spam not being a broadly pervasive issue.)
> You're missing the point. iMessage spam (though it does exist as I've shown above)
Huh? I never said it didn't exist.
> is not the problem.
Huh? I never said it was the problem.
> The problem is iMessage doesn't have a good way to "verify" that messages that purport to be from Apple or anyone else truly are from a known and trusted sender.
I completely agree. I never disputed that.
Re: Apple will notify users about state-sponsored cybersecurity threats
#118Earlier quoted context omitted.
Aren't iMessages backed up to icloud that does not have end to end encryption.
Not anymore[*]. [*] If you enable "Messages" sync in iCloud, encrypted message history is synced across your iCloud devices in an E2E manner.
Syncing messages across your devices is very much different than backing up your iPhone to iCloud.
The above should be pretty well known by now, but unfortunately isn’t the case.
If someone wants to dispute my comment, please cite supporting evidence.
Re: Apple will notify users about state-sponsored cybersecurity threats
#119Before Apple sends a notification, do they cross reference any existing warrants they received and make sure they don’t notify the customer that the US tried to hack their account, or iPhone, or requested their info?
Or are we to assume that Apple only means non-USA based attacks?
Or is the US gov going ape shit right now that all their targets they been infiltrating are going to get notified of that fact?
Or are we to assume anything FISA related means Apple happily and willingly had over the data and really isn’t a hack attempt?
Re: Apple will notify users about state-sponsored cybersecurity threats
#120Earlier quoted context omitted.
iMessage has no concept of a "verified user account" (iMessage for Business is separate), so there's zero indication this message is genuinely from Apple, except an email address that can possibly be faked. It's strange Apple hasn't built-in visible confirmation that this specific Threat Notifications sender is legitimate.
> iMessage has no concept of a "verified user account" (iMessage for Business is separate), so there's zero indication this message is genuinely from Apple According to this screenshot, it appears they do: https://twitter.com/norbertmao/status/1463364241688305664