Earlier quoted context omitted.
We're talking about the same company who wanted to scan all your files you uploaded, right?
Uploaded? You forgot what it was about. It was on-device scanning that was the problem.
iMessage with PQ3 Cryptographic Protocol
271–280 of 280 posts
Re: iMessage with PQ3 Cryptographic Protocol
#272Earlier quoted context omitted.
> No communication service stops people from backing up with encryption or not, local or remote, or from copy/pasting or for that matter taking photos of the screen ("analog hole"). At least for the first part on backing up without copy pasting or using the “analog hole”, Signal expressly prohibits and doesn’t allow any kind of backup — encrypted or not — on iOS/iPadOS/macOS.
> Signal expressly prohibits and doesn’t allow any kind of backup — encrypted or not — on iOS/iPadOS/macOS. I do not think you are correct, or perhaps alternatively this is a distinction without meaning. iDevices do indeed lock down against owner control unless the device is jailbroken. But Signal for Mac only requires 10.15 or later. Even if they wanted to, old Intel Macs simply do not offer the hardware guarantees…
Re: iMessage with PQ3 Cryptographic Protocol
#273Earlier quoted context omitted.
> No communication service stops people from backing up with encryption or not, local or remote, or from copy/pasting or for that matter taking photos of the screen ("analog hole"). At least for the first part on backing up without copy pasting or using the “analog hole”, Signal expressly prohibits and doesn’t allow any kind of backup — encrypted or not — on iOS/iPadOS/macOS.
Signal perhaps does not allow you to export your message history through the front door, however decrypting and exporting your message history is relatively low effort. You messages are stored in encrypted SQLite3 database. The Signal encryption key is in ~/Library/Application\ Support/Signal/config.json in plain text. If you have SQLCipher ( https://github.com/sqlcipher/sqlcipher ) compiled you can decrypt your Sign…
Re: iMessage with PQ3 Cryptographic Protocol
#274Earlier quoted context omitted.
>The only solution to that right now is for you and your contact to turn on Advanced Data Protection or don't use icloud backup. Also, confusingly "messages in icloud" is end to end encrypted, and enabling it disables messages for being included in icloud backup.
> "messages in icloud" is end to end encrypted, and enabling it disables messages for being included in icloud backup. This is misleading at best. Careful reading of Apple's disclosures reveals that the "messages in iCloud" encryption keys are still included in iCloud backups, giving Apple the capability to decrypt your messages on demand for law enforcement or for any other reason of their choosing. The messages may…
Re: iMessage with PQ3 Cryptographic Protocol
#275Earlier quoted context omitted.
I thought the fix was trivial - all I need to do is go to settings > my face >> icloud >>> show all >>>> messages and make sure the toggle is off? doesn't that stop iCloud syncing, at least on my end? I understand I can't control what happens on the other end of the conversation but that is all I need to do on my end, right?
Correct. I was referring to the OP asking if Apple would ever fix E2EE not protecting, by default, Photos and Messages and so forth.
If you choose to have some of your data in iCloud, it is transported and stored encrypted. However, one of the keys is escrowed in a HSM cluster for an audited recovery process.
This is how you go request access be restored via technical support with Apple. This is also how surviving family members can get access to photos and the like (requiring a court order, at least in the US). Since they have the key, government entities can request access within the extent of their respective local laws.
If you turn on the Advanced Data Protection feature, Apple no longer has that key escrowed, cannot help with account recovery, and can no longer give out a key they don't have.
Re: iMessage with PQ3 Cryptographic Protocol
#276Earlier quoted context omitted.
Your argument about iMessage on Mac’s holds water, but the iPhone is sold as an appliance and there is no concept of a file system presented to the user. They sell the messaging platform as “encrypted” and the word “encrypted” is plastered all over iCloud marketing and documentation. You really can’t blame the user for assuming the appliance is secure by default. When you first set up an iPhone it just asks you if yo…
in what way is iCloud backup 'insecure' or 'unencrypted'?
By default, iCloud backups are “secured” by a key that Apple stores and controls. This means that both Apple and anyone who can compel or hack Apple can still access your data.
Here’s the official documentation: https://support.apple.com/en-us/102651
Re: iMessage with PQ3 Cryptographic Protocol
#277Earlier quoted context omitted.
No. This will be rolled out to everyone in iOS 17.4, iPadOS 17.4, macOS 14.4, and watchOS 10.4, and is already in the corresponding developer preview and beta releases[1]. [1] https://security.apple.com/blog/imessage-pq3/
China included?
Re: iMessage with PQ3 Cryptographic Protocol
#278Earlier quoted context omitted.
For me, Signal is so much better for my friend or work group chats. My friends are on a mix of devices and platforms, and Signal is a lot nicer for embedded media sharing. And the auto disappearing feature is a must!
The main things holding back Signal usage in my case is practically nobody in my social circle using it and the desktop client not being as nice as that of Messages or Telegram, the latter being particularly relevant for myself and contacts who primarily message with their computers rather than their phones.
What i did is, the people i chat with 90% of the time are those in a very small circle around me - maybe 3 people (which i think is the case for most users?)
So, i just installed Signal on the phones of these 3 people;
Problem solved: now most of my messaging happens via an app that respects my privacy.
Re: iMessage with PQ3 Cryptographic Protocol
#279Earlier quoted context omitted.
The main things holding back Signal usage in my case is practically nobody in my social circle using it and the desktop client not being as nice as that of Messages or Telegram, the latter being particularly relevant for myself and contacts who primarily message with their computers rather than their phones.
Signal UX is AWFUL if you have a work PC, a home PC, a phone, and a tablet. Getting messages to flow across all of them is impossible.
I've had 0 issues syncing between my iPhone/iPad/Mac... and i use the app daily.
Re: iMessage with PQ3 Cryptographic Protocol
#280Earlier quoted context omitted.
I worked on several integration attempts between Apple and Google. They often presented specs that clearly showed security holes then simply would deny they were there or say “that’s secure”. It was a truly wild experience.
This sounds fascinating, you really should write about this.
1) This tier of work is roundly invisible to almost everyone in the field. Many in the field are so confident in their knowledge of 'how things work.' that they simply can't accept the real 'in the room' realities of whats going on. Often engineers most of all, who are often deceived by their executives on the real goals. Are you and eng? Have you ever had that feeling of being gaslit by your VP? Yea you probably were, and you didn't know why.
2) Even at that level, I had a limited picture and a good extrapolation of what was going on in other rooms, but nothing I can say fully factually
3) No one wants to know. People love the just-so stories of these companies and really genuinely seem to get hurt/be in denial when they are faced with the reality that they are made up of ultra-selfish, shark like people with very little invested in the consumer, the company, or really anyone else. It's a game played to win for personal satisfaction. I've found that most people, simply cannot accept this.