Earlier quoted context omitted.
Any evidence of this? I had read and posted about the same, but more recently found an older discussion on HN (which, absurdly, I cannot find now) which explains in more detail how the end to end encryption actually works and does so in a way that Apple almost definitely cannot intercept the plaintext messages.
See my first post in this thread. Short version: Users can enable iMessage on their devices by signing in to their Apple account. Therefore, Apple is capable by themselves of configuring which devices receive messages from particular accounts. Therefore, Apple is capable of configuring a device you do not control to receive your messages.
On Confirmed Assumptions or, Not Trusting Google is a Good Idea
221–230 of 230 posts
Re: On Confirmed Assumptions or, Not Trusting Google is a Good Idea
#222Earlier quoted context omitted.
Any evidence of this? I had read and posted about the same, but more recently found an older discussion on HN (which, absurdly, I cannot find now) which explains in more detail how the end to end encryption actually works and does so in a way that Apple almost definitely cannot intercept the plaintext messages.
See my first post in this thread. Short version: Users can enable iMessage on their devices by signing in to their Apple account. Therefore, Apple is capable by themselves of configuring which devices receive messages from particular accounts. Therefore, Apple is capable of configuring a device you do not control to receive your messages.
Re: On Confirmed Assumptions or, Not Trusting Google is a Good Idea
#223Earlier quoted context omitted.
See my first post in this thread. Short version: Users can enable iMessage on their devices by signing in to their Apple account. Therefore, Apple is capable by themselves of configuring which devices receive messages from particular accounts. Therefore, Apple is capable of configuring a device you do not control to receive your messages.
You are pretending that this is equivalent to asserting that they have access to arbitrary message histories, which they in fact do not.
Re: On Confirmed Assumptions or, Not Trusting Google is a Good Idea
#224Earlier quoted context omitted.
See my first post in this thread. Short version: Users can enable iMessage on their devices by signing in to their Apple account. Therefore, Apple is capable by themselves of configuring which devices receive messages from particular accounts. Therefore, Apple is capable of configuring a device you do not control to receive your messages.
They could do so, yes, but it would pop up a message on your actual devices which you would have to agree to before that device can receive and decrypt new messages.
Re: On Confirmed Assumptions or, Not Trusting Google is a Good Idea
#225Earlier quoted context omitted.
> iMessage proves that Google could engineer a system > to protect users privacy iMessage does not protect privacy, because Apple is capable of intercepting your messages messages and sending them to third parties. To be a private communications medium, it should be considered impossible for messages to be intercepted. The only thing worse than a product that doesn't offer privacy is a product which claims to, but ac…
No modern computer can be constructed by an individual without trusting a corporation not to have coopted some part of the system. Therefore no communication system can exist that meets your criteria. (E.g. Because the CPU could be compromised) Your argument is the equivalent of 'we can't trust any corporation'. It's a coherent position to take but it is extreme and doesn't lead to meaningful discussions about what i…
> Therefore no communication system can exist that meets
> your criteria. (E.g. Because the CPU could be compromised)
For the purposes of this discussion it's reasonable to assume that consumer hardware does not contain backdoors, because such extensive compromise of the computing infrastructure would require conspiracy on a massive scale (approximately every electronics manufacturer in the world).Re: On Confirmed Assumptions or, Not Trusting Google is a Good Idea
#226Earlier quoted context omitted.
You are pretending that this is equivalent to asserting that they have access to arbitrary message histories, which they in fact do not.
No, I'm not. At no point have I ever claimed that being able to intercept messages is equivalent to having access to previous messages.
Therefore although Apple could add another device to the communication protocol, without the password another device cannot be added to the encryption session, or without alerting the end user.
Re: On Confirmed Assumptions or, Not Trusting Google is a Good Idea
#227Earlier quoted context omitted.
No modern computer can be constructed by an individual without trusting a corporation not to have coopted some part of the system. Therefore no communication system can exist that meets your criteria. (E.g. Because the CPU could be compromised) Your argument is the equivalent of 'we can't trust any corporation'. It's a coherent position to take but it is extreme and doesn't lead to meaningful discussions about what i…
> Therefore no communication system can exist that meets > your criteria. (E.g. Because the CPU could be compromised) For the purposes of this discussion it's reasonable to assume that consumer hardware does not contain backdoors, because such extensive compromise of the computing infrastructure would require conspiracy on a massive scale (approximately every electronics manufacturer in the world).
Re: On Confirmed Assumptions or, Not Trusting Google is a Good Idea
#228Earlier quoted context omitted.
They could do so, yes, but it would pop up a message on your actual devices which you would have to agree to before that device can receive and decrypt new messages.
In the case of a wiretap, I assume Apple would choose not to notify the target that they have been wiretapped.
When a new device is added to the keybag, the other devices report the change - this isn't controlled by the server and isn't optional. Apple can control the transport infrastructure, but they cannot enrol new devices into the cryptographic session without the user being involved.
Re: On Confirmed Assumptions or, Not Trusting Google is a Good Idea
#229Earlier quoted context omitted.
Doing that wouldn't provide access to the history. Unless they always do this for every single device, there is no mountain of data to analyze. The point we are discussing is not whether iMessage provides perfect security. The point is that iMessage doesn't give Apple a stockpile of personal data that can be indiscriminately targeted at any time the way GMail can. I'm not saying it's a panacea or arguing in favor of…
> iMessage proves that Google could engineer a system > to protect users privacy iMessage does not protect privacy, because Apple is capable of intercepting your messages messages and sending them to third parties. To be a private communications medium, it should be considered impossible for messages to be intercepted. The only thing worse than a product that doesn't offer privacy is a product which claims to, but ac…
IMO, Apple's claim that iMessage is private is irresponsible because it endangers people who take that claim at face value.
By this logic, your claims are irresponsible. Apple's claim is true and you are misleading people into not taking advantage of the privacy they offer.Re: On Confirmed Assumptions or, Not Trusting Google is a Good Idea
#230Earlier quoted context omitted.
I think he's right. There's something terrible, here. Google services let us search/share/store data with an efficiency yet unseen at this scale. It's probably not that much of an exaggeration to say google is empowering humanity. But doing so, it handles so much data about so much people that even with good will, it's a danger. How secret services and cops could not be interested in the huge amount of data magically…
I'm playing Devil's Advocate here, but why would I be worried about Google? I search through Bing. My email is through Hotmail/Outlook. My online cloud sync is through Skydrive. Why am I cowering from Google any more than MS or anyone else that I give huge amounts of my data too?
It doesn't take much to imagine what kind of dossier could be constructed on an individual from that data. Quite likely they do know more about many people than those people know about themselves. Of course this can be used beneficially, but it's also the exact information needed to manipulate people.
That is far more than any other service is able to aggregate, and Google's business is fundamentally about mining that data in a way that is not for other corporations.
But yes, the others are a problem too - just on an orders of magnitude lower scale than Google.