Live data from Hacker News

iMessage Key Verification

support.apple.com

111–120 of 127 posts

Re: iMessage Key Verification

#111
Why does Apple couple iMessage with rest of iCloud? Why is iCloud and iCloud Keychain being on a requirement for secure iMessage to function? That seems like a poor design choice to me.

For someone who cares about their communication security deeply enough to do contact public key verification, they would likely want to turn off iCloud syncing iMessage across multiple devices. They are likely to not have same iCloud account on multiple devices. In such cases, what's the value of having iCloud Keychain being turned on?

Re: iMessage Key Verification

#112

Earlier quoted context omitted.

Not a great argument IMO. If only 0.1% people check the keys, the attacker may be just okay with the 0.1% chance of being discovered – especially if there's no consequences for them.

WhatsApp has this scheme. And to my knowledge, never had there been a report of verification failing. If an adversary was discovered 0.1% of the time. There would be at least one person on a support forum with the text of the error that occurs when it fails...

I get the warning "your contact key has changed.." all the time with various contacts on WhatsApp. What am I supposed to do? there's no clear next steps to debug / report of suspicious activity. In such cases, users get trained to become complacent of such warnings.

Re: iMessage Key Verification

#113

Why does Apple couple iMessage with rest of iCloud? Why is iCloud and iCloud Keychain being on a requirement for secure iMessage to function? That seems like a poor design choice to me. For someone who cares about their communication security deeply enough to do contact public key verification, they would likely want to turn off iCloud syncing iMessage across multiple devices. They are likely to not have same iCloud…

Maybe it's a dark pattern, like safari downloads defaulting to iCloud instead of the phone.

Re: iMessage Key Verification

#114

Earlier quoted context omitted.

WhatsApp has this scheme. And to my knowledge, never had there been a report of verification failing. If an adversary was discovered 0.1% of the time. There would be at least one person on a support forum with the text of the error that occurs when it fails...

I get the warning "your contact key has changed.." all the time with various contacts on WhatsApp. What am I supposed to do? there's no clear next steps to debug / report of suspicious activity. In such cases, users get trained to become complacent of such warnings.

You're supposed to meet up with that contact and verify the new key.

If even 0.1% of users did that, it would be 2 million verifications. And yet nobody has ever announced they have found a non-matching key.

Re: iMessage Key Verification

#115
post #61

Earlier quoted context omitted.

Tangential, but Keybase (and later Keyoxide [1]) with their “social proof” mechanics are a more human-friendly way to verify the encryption keys. I kinda wish Matrix had that integrated, too. [1]: Here's my Keyoxide page for example: https://keyoxide.org/alexander@notpushk.in

Is Keyoxide based on the Keybase codebase, or is it a new development? I quite enjoyed Keybase back in the day, but then they pivoted to being a crypto wallet, and were ultimately acquired by Zoom (a move I understand less every day, since they obviously gave up on their bold promises of end-to-end encryption they made back in 2020).

It's completely new, and based entirely on PGP. The proofs are stored with your PGP key, so it's also decentralized. It doesn't have any amenities like chat or file storage – it only maps your social networks to a given PGP key. But I believe third parties (like Matrix) could step up and support it natively – all the benefits of Keybase, none of the drawbacks.

Re: iMessage Key Verification

#116
post #96

Earlier quoted context omitted.

According to https://security.apple.com/blog/imessage-contact-key-verific... , the actual verified hash of the account key is stored in an end-to-end encrypted CloudKit container and merely linked to from the contact card.

Oh interesting, that is not at all clear based on the Contacts UI which shows it like any other field

That’s just good UI design. Make complex stuff look dead simple.

Re: iMessage Key Verification

#117
Doesn’t sharing your pub code also kind of build a network of “proof” this is you? As in sure Billy knows its you but so will a court have that same evidence, making denial “thats a spoofed message” harder.

Re: iMessage Key Verification

#118

Earlier quoted context omitted.

Here’s my verification key, so you know what they look like, since you were wondering what would be shown/compared: APKTIDJ_J3S3UhVqZKCX5EgKYnh9ez4pO9Hsr5YWv_5pXF5GUcLA

Ow. Okay, I take it back, unless there's something I'm missing then Matrix's system is better than this. I'm sorry, I just can not imagine asking a non-technical person to copy and paste that into a messenger and then needing to help them debug which letter they left off. It's hard enough to get them to validate "I see a cat, a dog, a horse, a pizza, and a basketball." I guess I'll wait and see what happens with it,…

Is it any different from copying an url? That said it might be formatted as an url like totp url.

Re: iMessage Key Verification

#119
post #107
post #102

Earlier quoted context omitted.

You can remove that iPad from your account if you don't need iCloud for it

We do use it for TV+ shows like Snoopy in Space, so alas, I'm stuck with it being registered

Unregister your account, register a new iCloud and add it to your iCloud family. You can have 6 people in your family account.

I have ADP on my devices but no one else in my family has it on and we’re all in the same iCloud family.

Re: iMessage Key Verification

#120

Why does Apple couple iMessage with rest of iCloud? Why is iCloud and iCloud Keychain being on a requirement for secure iMessage to function? That seems like a poor design choice to me. For someone who cares about their communication security deeply enough to do contact public key verification, they would likely want to turn off iCloud syncing iMessage across multiple devices. They are likely to not have same iCloud…

Maybe it's a dark pattern, like safari downloads defaulting to iCloud instead of the phone.

Given how hard it is to find your downloads locally on your phone, I think most users want sharing with other devices my default.

Makes sense to download stuff and have it be in downloads on the laptop or iPad.

I don’t think that’s really that dark.

Post reply on HN