Live data from Hacker News

iMessage with PQ3 Cryptographic Protocol

security.apple.com

121–130 of 280 posts

Re: iMessage with PQ3 Cryptographic Protocol

#121

Earlier quoted context omitted.

For me, Signal is so much better for my friend or work group chats. My friends are on a mix of devices and platforms, and Signal is a lot nicer for embedded media sharing. And the auto disappearing feature is a must!

Hmm… Does signal only really work when everyone uses it? Or can you include people who are just using regular SMS?

It used to have SMS support but they yanked it maybe a year or so ago. The big issue on the user end was, if someone deleted Signal and you used Signal for your SMS, it would keep sending them signal messages and not SMS. So you were left not realizing you were texting essentially a dead number.

Re: iMessage with PQ3 Cryptographic Protocol

#122

Earlier quoted context omitted.

The top 7 phones sold last year were all iPhones. https://www.macrumors.com/2024/02/21/iphones-top-7-best-sell... Too bad the other vendors don’t bother keeping up.

There is a flaw with your thinking. Any given year there are only 5-6 iPhones to choose from, where there are plenty of Android phones. This leads to "top phone sold" being iPhones because it is 5 phones against hundreds of Android phones that people get to choose from. You should instead look at Market share. https://www.statista.com/statistics/272698/global-market-sha...

Actually my point was companies-responsible-for-encryption development. You could argue it’s Google vs Apple on this front, but it could also be Apple vs Samsung, or Apple vs any of the other top tier android implementations.

So you can either say Apple is reserving this development for a subset of the market, or Google is withholding it from a massive portion of the market share.

Re: iMessage with PQ3 Cryptographic Protocol

#123

Earlier quoted context omitted.

For me, Signal is so much better for my friend or work group chats. My friends are on a mix of devices and platforms, and Signal is a lot nicer for embedded media sharing. And the auto disappearing feature is a must!

Signal is actually pretty good for the occasional "cross-iOS/Android" video chat. Can't use iOS Facetime, don't want to use $META, google/meet is OK, but isn't quite as straightforward as "@Signal => CALL_ME".

Anyone can use FaceTime now. Non Apple devices will just join via a browser.

Re: iMessage with PQ3 Cryptographic Protocol

#124
post #58

Would be great if we could uninstall iMessage completely out of iPhone for security reasons or make it opt in by default. Unfortunately it's not possible and it will be a gateway for security issues and malware in the following years to come. Post quantum cryptography is nice but that's one of the smallest problems with iMessage.

You can very easily disable iMessage completely

How?

Re: iMessage with PQ3 Cryptographic Protocol

#125
post #70

Did anyone figure out how MITM attacks are handled? How does the key transparency work and does it replace public key fingerprints?

This (and Signal's solution as well) does not protect against active MITM attackers with quantum computers . They would need to incorporate post-quantum signatures into it as well. The reason why it is missing (but seemingly planned in the future) is because it is not as critical as this change. This change prevents attackers from recording conversations now and decrypting them when (in the next ?? years/decades) the…

I'm a bit puzzled. Suppose you do single Kyber key exchange, and you then hash the shared secret with a domain separator to get a fingerprint, wouldn't that mean you now have a shared secret that you can verify wasn't under MITM.

You then can build post quantum future secrecy / key rotation on top of that, by mixing in new key material and it remains secure from MITM, as long as the internal state of the endpoint isn't compromised. The endpoint compromise is outside networked TCB threat model, as such compromise could also be used to exfiltrate long term post-quantum identity keys for undetectable MITM).

Re: iMessage with PQ3 Cryptographic Protocol

#126

This is pretty fascinating. For easier reading, the Signal blog post [0] they link to is great. Both Signal and Apple went with CRYSTALS-Kyber [1] as their post-quantum algorithm. If you're interested in the math, and maybe learned at some point about how classic public key cryptography is built on the idea that it's easy to multiply two primes, but hard to factor them, and how this (or other math problems) can be us…

I'm way out of my depth in terms of the math here.

But my 'software engineer brain' likes the ideal of using the prime factoring problem, because it's so simple to understand, and feels like some kind of universal primitive. "It's easy to multiply but hard to factor." It just seems so intuitive.

But I'm reading the 'learning with errors' wiki page and it's beyond my comprehension.

There's a weird fear in my mind that all these "post quantum algorithms" are so complicated, with such a large surface area, that they may hide flaws. While prime factoring, or even the elliptic key stuff, is so simple to comprehend.

that said, obviously the experts know what they're doing, and I'll use what they suggest. just saying that this thought has crossed my mind.

Re: iMessage with PQ3 Cryptographic Protocol

#127
post #51

Earlier quoted context omitted.

> No communication service stops people from backing up with encryption or not, local or remote, or from copy/pasting or for that matter taking photos of the screen ("analog hole"). At least for the first part on backing up without copy pasting or using the “analog hole”, Signal expressly prohibits and doesn’t allow any kind of backup — encrypted or not — on iOS/iPadOS/macOS.

This lack of backups makes Signal less appealing to anyone who isn't a security/privacy enthusiast/nut. 99+% of people want their messages to work and not lose them when their phone is broken.

No I do not agree with you. Majority of people never read their message history, want their messages to self-detruct and don't want to get into a situation like when a new partner reads chat history with all previous partners.

Majority of people do not record their conversations and do not need this.

And most messaging applications are designed countrary to what people need - they preserve history specially for that curious new partner. Or maybe for a marketing department to analyze user's interests.

Re: iMessage with PQ3 Cryptographic Protocol

#128

Earlier quoted context omitted.

Signal is actually pretty good for the occasional "cross-iOS/Android" video chat. Can't use iOS Facetime, don't want to use $META, google/meet is OK, but isn't quite as straightforward as "@Signal => CALL_ME".

Anyone can use FaceTime now. Non Apple devices will just join via a browser.

Which is ridiculous

Re: iMessage with PQ3 Cryptographic Protocol

#130

Earlier quoted context omitted.

For me, Signal is so much better for my friend or work group chats. My friends are on a mix of devices and platforms, and Signal is a lot nicer for embedded media sharing. And the auto disappearing feature is a must!

Hmm… Does signal only really work when everyone uses it? Or can you include people who are just using regular SMS?

The regular SMS/MMS feature was removed and for good reason. Many people cried about it but it was the right call. Messages would not be E2EE and people could easily think all messages sent through Signal are safe when they weren't.
Post reply on HN