Live data from Hacker News

iMessage with PQ3 Cryptographic Protocol

security.apple.com

141–150 of 280 posts

Re: iMessage with PQ3 Cryptographic Protocol

#141
post #125

Earlier quoted context omitted.

I'm a bit puzzled. Suppose you do single Kyber key exchange, and you then hash the shared secret with a domain separator to get a fingerprint, wouldn't that mean you now have a shared secret that you can verify wasn't under MITM. You then can build post quantum future secrecy / key rotation on top of that, by mixing in new key material and it remains secure from MITM, as long as the internal state of the endpoint isn…

Key exchange (whether it's a PQ scheme or more classical DH) does not prevent active-MITM on its own, you need authentication too.

Yeah that's what the fingerprint is for, you compare it to authenticate the key exchange.

Re: iMessage with PQ3 Cryptographic Protocol

#142

This is pretty fascinating. For easier reading, the Signal blog post [0] they link to is great. Both Signal and Apple went with CRYSTALS-Kyber [1] as their post-quantum algorithm. If you're interested in the math, and maybe learned at some point about how classic public key cryptography is built on the idea that it's easy to multiply two primes, but hard to factor them, and how this (or other math problems) can be us…

I'm way out of my depth in terms of the math here. But my 'software engineer brain' likes the ideal of using the prime factoring problem, because it's so simple to understand, and feels like some kind of universal primitive. "It's easy to multiply but hard to factor." It just seems so intuitive. But I'm reading the 'learning with errors' wiki page and it's beyond my comprehension. There's a weird fear in my mind that…

Well, one way to think about this is: how much abstract algebra are you keeping in your head to reassure yourself of the security of classical asymmetric cryptography? It's surprisingly deep. Some programmers are "comfortable" with it because they've been brought up being taught that "factoring" is just the way asymmetric cryptography works, but that has never really been the whole case.

Elliptic curve is not at all simple to comprehend! It's easy to implement, but the motivation for designing systems around them (the effectiveness of the index calculus on elliptic curve groups) and the discoveries made on attacking them (like the MOV attack that transforms ECDLP problems to FFDLP problems) are not at all simple.

Arguably, elliptic curve is an odder corner of mathematics than lattices.

Re: iMessage with PQ3 Cryptographic Protocol

#143
post #86

Earlier quoted context omitted.

Was the CRYSTALS-Kyber name intentionally, or accidentally, a reference to Kyber Crystals (I.e. The Lightsaber energy source?)

Absolutely a reference. Dilithium (from Star Trek) is name of their signature algorithm.

The trick to naming things is to first find a cool word/reference, and then 'reverse engineer' it as an acronym second:

* https://en.wikipedia.org/wiki/Backronym

Re: iMessage with PQ3 Cryptographic Protocol

#144

Earlier quoted context omitted.

The top 7 phones sold last year were all iPhones. https://www.macrumors.com/2024/02/21/iphones-top-7-best-sell... Too bad the other vendors don’t bother keeping up.

There is a flaw with your thinking. Any given year there are only 5-6 iPhones to choose from, where there are plenty of Android phones. This leads to "top phone sold" being iPhones because it is 5 phones against hundreds of Android phones that people get to choose from. You should instead look at Market share. https://www.statista.com/statistics/272698/global-market-sha...

> Any given year there are only 5-6 iPhones to choose from, where there are plenty of Android phones.

There is such a thing as 'too much' choice:

* https://en.wikipedia.org/wiki/Overchoice

* https://en.wikipedia.org/wiki/Decision_fatigue

* https://www.behavioraleconomics.com/resources/mini-encyclope...

* https://thedecisionlab.com/biases/choice-overload-bias

Re: iMessage with PQ3 Cryptographic Protocol

#145

Earlier quoted context omitted.

There is a flaw with your thinking. Any given year there are only 5-6 iPhones to choose from, where there are plenty of Android phones. This leads to "top phone sold" being iPhones because it is 5 phones against hundreds of Android phones that people get to choose from. You should instead look at Market share. https://www.statista.com/statistics/272698/global-market-sha...

> you should instead look at Market share. Unless your goal is to make money on the platform, then you should look at wallet share, not market share.

The goal isn't to make money or calculate wallet share. The goal is to send encrypted messages to contacts.

You should look at the percentage of smartphone owners. It does not matter in the slightest how many dollars they have in their pockets. The question is: is the average user going to have a significant number of Android contacts, with which Messages requires plain-text communication to contact.

And the answer for most people is: undoubtedly yes. I would say that most people who are using Messages as their primary messenger for all of their contacts are sending unencrypted messages on the regular.

Re: iMessage with PQ3 Cryptographic Protocol

#146
post #69
post #59

Earlier quoted context omitted.

Wouldn't SMS be more insecure?

For message security, absolutely. For endpoint security (iMessage as exploit surface), not so much.

Just gonna add here. Do not switch from iMessage to SMS no matter what. Only switch to something like Signal if you need the cross-platform support etc.

Re: iMessage with PQ3 Cryptographic Protocol

#147

Earlier quoted context omitted.

In my experience, these markets can overlap but don’t necessarily always do so. I message everyone via iMessage, and while I enjoy the feeling of security from the blue bubble it’s not a must-have for me. Signal on the other hand seems like a must-have for many people living under oppressive regimes or whose data is significantly more valuable than mine. I am one data point, but that’s what I’ve noticed in my bubble.

Do you not send messages to any Android users? That is incredibly hard to imagine for me. My friend group is very mixed and Signal is what we use.

[deleted]

Re: iMessage with PQ3 Cryptographic Protocol

#148
post #131

Earlier quoted context omitted.

Every single person I converted to using Signal stopped using it when SMS support was removed. HN tends to be a younger crowd whose peers cycled through a number of social-networking and messaging apps as popularity waxed and waned. But older generations don't see any compelling reason why they should bother splitting their conversations over multiple apps, when literally everyone with a mobile has texting. Being a d…

Yeah I think this was a bad move for Signal, but I didn't see that happen to my group fortunately. In Signal's defense, my understanding is that this was really an Apple thing. That Apple only lets iMessage connect to SMS so the apps were differing significantly. I also get the fatigue. Moxie said centralized because they needed to move faster. But Signal has always moved very slow, so it does feel off. But to be fai…

They were talking about on Android. Signal supporting SMS was never a thing on iOS.

Re: iMessage with PQ3 Cryptographic Protocol

#149

Earlier quoted context omitted.

Anyone can use FaceTime now. Non Apple devices will just join via a browser.

What? how does that work? If you call the cell number of an Android device on facetime, what happens on the android end?

You text them a link to join the call. The Android user can’t be the one to initiate.

Re: iMessage with PQ3 Cryptographic Protocol

#150

Earlier quoted context omitted.

There is a flaw with your thinking. Any given year there are only 5-6 iPhones to choose from, where there are plenty of Android phones. This leads to "top phone sold" being iPhones because it is 5 phones against hundreds of Android phones that people get to choose from. You should instead look at Market share. https://www.statista.com/statistics/272698/global-market-sha...

Actually my point was companies-responsible-for-encryption development. You could argue it’s Google vs Apple on this front, but it could also be Apple vs Samsung, or Apple vs any of the other top tier android implementations. So you can either say Apple is reserving this development for a subset of the market, or Google is withholding it from a massive portion of the market share.

Samsung is not the reason why iMessages can't be sent to Android users or to Windows devices. Samsung does not decide which platforms Apple will and won't support.

Coordination with even Google would not be necessary for Apple to offer encrypted conversations with users on other devices. There's no rule saying they need to use an open standard or a Google standard or be cross-compatible with another app. It's not that Apple is trying desperately to get iMessage onto other phones and failing because Google and Samsung just won't let them do it.

Of course, Google has its own problems[0]. But the inability to use the Messages app to communicate securely with Android users[1], is solely 100% Apple's decision. Apple does not need to ask permission or coordinate with any other company to increase that security, they would just need to throw a messaging app up on the app store.

Heck, they wouldn't need to support iMessage on Android. They could throw a messaging app up that had no encryption other than that it worked over HTTPS and data instead of SMS when messaging iOS users, changed nothing about the capabilities or features that they supported for non-iMessage users, and even only doing that -- if Android users could download it and set it as their default SMS client on Android then iPhone security would be better.

----

As a comparison here, if Signal dropped support for iOS tomorrow, would you blame Apple for not building support for Signal into iOS? No, that would be absurd to suggest. No one would claim that Apple had some obligation to support the Signal protocol or make Signal compatible with iMessage, or to build an open protocol -- we would all correctly point out that Signal decides where to make its app available. The same is true of Apple. The fact that you literally can't make many Messages conversations secure without completely abandoning the app and using a separate 3rd-party service for those conversations -- it is purely and entirely the result of a decision that Apple has made.

----

[0]: And in fact their proprietary encryption standard is no better than Apple's and they're pulling the exact same crap as Apple is for the same flimsy reasons.

[1]: Note that I don't say non-Apple users, you can have an iMessages account through other devices and you still won't be able to use it with an Android phone number.

Post reply on HN