Live data from Hacker News

iMessage Key Verification

support.apple.com

51–60 of 127 posts

Re: iMessage Key Verification

#51
post #25

There is a huge opportunity here for Apple to do a proper chain of trust. “You want to talk to Adam, but you haven’t verified their keys yet. However your contacts Anna and Derek have confirmed Adam’s identity”

This is such a privacy leak that I have a hard time thinking you're serious.

“You want to talk to Family Lawyer D. Ivorstein, but you haven’t verified their keys yet. However your contact Wife has confirmed D. Ivorstein’s identity”

Re: iMessage Key Verification

#52
post #26
post #20

So like is “sophisticated threats” a passive-aggressive way of saying “Beeper”?

This was announced last year, way before any of Beeper’s shenanigans. https://www.macrumors.com/2022/12/07/new-imessage-apple-id-s...

Beeper was released at least two years prior to that.

Re: iMessage Key Verification

#53

Earlier quoted context omitted.

If you have a cryptographic primitive and a robust system to protect it (secure hardware, biometric auth), if you can confirm digital identity in real life you can be reasonably assured Adam is reading. Chain of integrity.

Just like blockchain, meat space applications of digital chains of trust require too much benevolence. At the end of all the state of the art crypto is Grandma pushing a button.

Speaks to the robustness of the legal system, and code simply a crude layer on top of it.

Re: iMessage Key Verification

#54
post #25

There is a huge opportunity here for Apple to do a proper chain of trust. “You want to talk to Adam, but you haven’t verified their keys yet. However your contacts Anna and Derek have confirmed Adam’s identity”

I'm always confused by this. This merely validates that Anna at the time thought that was Adam's number, what else? Does not guarantee it's Adam reading.

At its best it verifies that "Adam" is using a device that was verified by a trusted 3rd party as being added to the network by Adam himself. So, it is more about trusting devices than individual interactions.

Re: iMessage Key Verification

#55

Earlier quoted context omitted.

Not a great argument IMO. If only 0.1% people check the keys, the attacker may be just okay with the 0.1% chance of being discovered – especially if there's no consequences for them.

Only for mass attacks. A targeted attack will encounter the risk of the attacker being exposed. Think journalists, politicians, public figures

It might still be an acceptable risk. Most governments around the world probably don’t care that much if it’s discovered they are surveiling a journalist or lawyer.

In most of the world everyone knows that journalists and lawyers are being monitored.

Re: iMessage Key Verification

#56
post #51
post #25

There is a huge opportunity here for Apple to do a proper chain of trust. “You want to talk to Adam, but you haven’t verified their keys yet. However your contacts Anna and Derek have confirmed Adam’s identity”

This is such a privacy leak that I have a hard time thinking you're serious. “You want to talk to Family Lawyer D. Ivorstein, but you haven’t verified their keys yet. However your contact Wife has confirmed D. Ivorstein’s identity”

Perhaps you could address that issue through explicit "family" or "friend" groups, where people can chose who they wish to verify for. That would limit the usefulness of the trust network but prevent the privacy issue you mention.

Re: iMessage Key Verification

#57
Quite disappointingly, this requires being logged in with iCloud as well as iMessage on the same device, so I can't use it on my work computer (I have different Apple IDs at work and home). I don't really see why the two need to be tangled together.

Re: iMessage Key Verification

#58
It looks like I would need the following for this to work:

To use iMessage Contact Key Verification, you’ll need: iOS 17.2, watchOS 9.2 and macOS 14.2 on all devices where you’ve signed in to iMessage with your Apple ID

Unfortunately my work iMac isn’t on Sonoma, it’s on Monterey. I suppose I could log out on that machine, but still, a bit of a shame older versions aren’t supported.

Am I reading the requirements correctly? Does this mean that for all devices to work with CKV, then all OS’s need to be updated, or will it not do CKV on any devices if even one device is not supported?

Re: iMessage Key Verification

#59

This seems somewhat similar to Matrix's (and other apps') approach of comparing keys to verify identity (plus with I guess some extra hardware requirements and attestation). I'm interested to see what the uptake is among users, because even though Matrix has done a fair amount to smooth this process, verification is still a pretty large source of friction from what I can tell, and I'm not completely sure how it could…

> I'm interested to see what the uptake is among users

My suspicion is that it'll be quite low for many years, for two reasons:

- It requires a recent iOS and macOS version on all of a user's devices. Still got an old iPad lying around somewhere that doesn't receive software updates anymore? No key verification for you. (In a similar way, Apple has been making older devices obsolete by preventing Notes sync in some previous iOS version. This is only an issue because all of these apps are not updateable outside of the core OS.)

- It requires users to be logged in to the same Apple ID for iCloud and iMessage.

The former will only change once these old devices completely die – I just don't think many users will value key verification enough.

Re: iMessage Key Verification

#60
post #22

Seems like Apple is tacitly acknowledging that sophisticated actors have successfully been man-in-the-middling iMessage users. I wonder if they have clear evidence of that since I haven’t seen any coverage on this.

Or! they're trying to get ahead of legislation (looking at the UK) by presenting a fait-accompli
Post reply on HN