Live data from Hacker News

iMessage Key Verification

support.apple.com

21–30 of 127 posts

Re: iMessage Key Verification

#21
post #14

Earlier quoted context omitted.

Trevor Perrin, who co-designed the Signal Protocol, made the point that most people don’t have to do this. If a few people do, an adversary won’t know if the target is verified or not. If they MITM they might be discovered instantly. Which gives the entire herd protection. - https://www.youtube.com/watch?t=2001&v=7WnwSovjYMs

Not a great argument IMO. If only 0.1% people check the keys, the attacker may be just okay with the 0.1% chance of being discovered – especially if there's no consequences for them.

Only for mass attacks. A targeted attack will encounter the risk of the attacker being exposed.

Think journalists, politicians, public figures

Re: iMessage Key Verification

#22
Seems like Apple is tacitly acknowledging that sophisticated actors have successfully been man-in-the-middling iMessage users. I wonder if they have clear evidence of that since I haven’t seen any coverage on this.

Re: iMessage Key Verification

#23

Earlier quoted context omitted.

> Published Date: December 11, 2023

https://security.apple.com/blog/imessage-contact-key-verific... is from October 27, 2023 though.

it's been a few months since that post. looking forward to the complete technical walkthrough of their implementation.

Re: iMessage Key Verification

#24
post #20

So like is “sophisticated threats” a passive-aggressive way of saying “Beeper”?

I don't think this is related. This is just public key verification, the kind that other E2E messaging apps already had. I don't know about the specifics but as I understand, Beeper Mini could implement this too if they want to.

Re: iMessage Key Verification

#25
There is a huge opportunity here for Apple to do a proper chain of trust.

“You want to talk to Adam, but you haven’t verified their keys yet. However your contacts Anna and Derek have confirmed Adam’s identity”

Re: iMessage Key Verification

#28
post #22

Seems like Apple is tacitly acknowledging that sophisticated actors have successfully been man-in-the-middling iMessage users. I wonder if they have clear evidence of that since I haven’t seen any coverage on this.

The attack is that anyone can make an iMessage account and pretend to be your friend ("new phone who this"); this feature is how you prevent that.

Re: iMessage Key Verification

#29
post #22

Seems like Apple is tacitly acknowledging that sophisticated actors have successfully been man-in-the-middling iMessage users. I wonder if they have clear evidence of that since I haven’t seen any coverage on this.

[deleted]

Re: iMessage Key Verification

#30
post #5
post #2

I wonder if the timing of this in response to Beeper Mini gaining access to the iMessage network?

I think it would be hard to push out such a feature in such a short span. Beeper’s userbase is tiny and not an immediate security threat to Apple.

Nor a distant security threat.
Post reply on HN