Live data from Hacker News

Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

techcrunch.com

51–60 of 116 posts

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#51
post #45
post #42

Earlier quoted context omitted.

They can't create trusted public keys after the fact, they'd have to already have them. So there's no half truth. Either they currently create and store such public keys or they don't. Tim Cooke is saying they don't. That statement can't be half true. It's either true or false.

True. But they can replace any program on any iPhone with an NSA/Justice system version, and give the replacement access to any keys stored on the iPhone. There can never be any security on a closed system where a central party has all the control. That means apple's system is a lost cause for user security.

Apple can silently slipstream applications onto a users iPhone ? That would means dozens of employees would be involved in a conspiracy with the US government. And over all the years none of them has leaked anything ? Sounds far fetched.

Also better not use a phone. Because Android and Windows Phone would have the same problem.

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#52

"Our business is not based on having information about you. You’re not our product. Our product are these, and this watch, and Macs and so forth. And so we run a very different company. I think everyone has to ask, how do companies make their money? Follow the money. And if they’re making money mainly by collecting gobs of personal data, I think you have a right to be worried. And you should really understand what’s…

Applications and software? Songs? Television? Movies? Health? Seems to be a bit disingenuous to suggest that they aren't making any money from your habits and data.

No, it doesn’t, not really. Look at where their money is coming from.

You mentioned health. Apple has no plans at all to make money with that. It’s just an API that makes devices more useful for users.

Think critically about this, but please do it in a honest way.

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#53
post #42

Earlier quoted context omitted.

The half-truth is here: If the government laid a subpoena to get iMessages, we can’t provide it. It’s encrypted and we don’t have a key. It's encrypted and they don't have the key, but since the user does not have any control over the public keys being added, they could add a trusted public key and get it anyway. So they can actually provide messages if they really wanted to. I don't believe they really want to. But…

They can't create trusted public keys after the fact, they'd have to already have them. So there's no half truth. Either they currently create and store such public keys or they don't. Tim Cooke is saying they don't. That statement can't be half true. It's either true or false.

They can't create trusted public keys after the fact,

Of course they can. They own the directory server that hands out keys.

http://blog.cryptographyengineering.com/2013/06/can-apple-re...

tl;dr: Apple can send you a public key of Bob's new device. Apple can pretend to send you a public key of Bob's new device. And since it's proprietary software, they can trigger a resend of your recent messages to Bob.

Moreover, if you use iCloud backups, they have the keys to your kingdom, since it fails the 'mud puddle test':

http://arstechnica.com/security/2013/06/can-apple-read-your-...

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#54
post #42

Earlier quoted context omitted.

The half-truth is here: If the government laid a subpoena to get iMessages, we can’t provide it. It’s encrypted and we don’t have a key. It's encrypted and they don't have the key, but since the user does not have any control over the public keys being added, they could add a trusted public key and get it anyway. So they can actually provide messages if they really wanted to. I don't believe they really want to. But…

They can't create trusted public keys after the fact, they'd have to already have them. So there's no half truth. Either they currently create and store such public keys or they don't. Tim Cooke is saying they don't. That statement can't be half true. It's either true or false.

They can't create them for old messages, but they could theoretically add them for messages going forward. So it could work like an old-fashioned wiretap, where you get the subpoena, install a bug and start listening -- but can't go back in time and listen.

How? iMessage encrypts and sends a copy of every message to every device registered to a recipient (iPads, iPhones, Macs, etc.), each of which has distinct public keys. It's actually a pretty ingenious aspect of iMessage, that it can support multiple devices without any private key exchange.

But..... those recipient public keys are provided by Apple. So in theory Apple could add itself or law enforcement as another "device" -- let's call it "fbiPad" -- completely bypassing all that security.

However the "good" news is whether Apple is actually doing that in a given instance could theoretically be detectable by analyzing network traffic, since it would result in an additional copy being sent. Even though it's encrypted you could probably tell by the amount of data.

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#55
post #34
post #27

Earlier quoted context omitted.

He didn't make a statement that Apple or the NSA can't read your messages. He said that Apple can't read your messages. However since you are so concerned about half truths, if you're going to criticise someone's statements, it would be nice if you'd address what they actually are saying. It's entirely possible that the NSA has hacked Apple, or that an Apple employee has been subverted by the NSA and inserted a back…

>He said that Apple can't read your messages. which is also a half-truth. They can't read messages encrypted with another phones public key, but they can certainly read messages encrypted with their public key which they might or might not send to your phone in addition to the actual recipient's public key. Neither me nor he is saying that Apple does in-fact read your messages (they probably don't), but saying that t…

Not really. He's pretty clear:

"If the government laid a subpoena to get iMessages, we can’t provide it. It’s encrypted and we don’t have a key."

There's no wiggle room there. He's not saying we don't have the users key, he's saying categorically they can't provide iMessage information. I don't understand why you think that can be read as they can't get the information through mechanism X but that they can through mechanism Y.

That's not to say the NSA can't read them - possibly with Apple's help, possibly without - but he's really not in a position to talk about what the NSA can and can't do.

From a corporate PR perspective, he really doesn't have to say anything about this. He doesn't do many interviews, he could have declined this, or declined to talk about certain topics as part of the conditions around doing the interview. If Apple can indeed read your messages then the easiest thing for him would be to shut up and say nothing so it would seem odd to go public with a lie when he has that option.

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#58
post #45

Earlier quoted context omitted.

True. But they can replace any program on any iPhone with an NSA/Justice system version, and give the replacement access to any keys stored on the iPhone. There can never be any security on a closed system where a central party has all the control. That means apple's system is a lost cause for user security.

Apple can silently slipstream applications onto a users iPhone ? That would means dozens of employees would be involved in a conspiracy with the US government. And over all the years none of them has leaked anything ? Sounds far fetched. Also better not use a phone. Because Android and Windows Phone would have the same problem.

They can issue an "update" for the system that adds that functionality, they have the trusted keys to sign apps.

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#59
post #45

Earlier quoted context omitted.

True. But they can replace any program on any iPhone with an NSA/Justice system version, and give the replacement access to any keys stored on the iPhone. There can never be any security on a closed system where a central party has all the control. That means apple's system is a lost cause for user security.

Apple can silently slipstream applications onto a users iPhone ? That would means dozens of employees would be involved in a conspiracy with the US government. And over all the years none of them has leaked anything ? Sounds far fetched. Also better not use a phone. Because Android and Windows Phone would have the same problem.

Apple can remotely delete apps on iPhones. They've used it to delete apps that were removed from the app store. Apple can force your phone to download the latest U2 album. Upgrading your apps silently is probably not outside their control if they wanted to.

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#60
post #45

Earlier quoted context omitted.

True. But they can replace any program on any iPhone with an NSA/Justice system version, and give the replacement access to any keys stored on the iPhone. There can never be any security on a closed system where a central party has all the control. That means apple's system is a lost cause for user security.

Apple can silently slipstream applications onto a users iPhone ? That would means dozens of employees would be involved in a conspiracy with the US government. And over all the years none of them has leaked anything ? Sounds far fetched. Also better not use a phone. Because Android and Windows Phone would have the same problem.

"Hey, where'd this U2 album come from???"

Of course Apple can "silently slipstream applications onto a user's iPhone". Whether they'd risk getting caught doing it (even for non-all-powerful law enforcement agencies) without a court order or for anything less indefensable than a kiddie porn investigation is less clear. (And whether the NSA would even need Apples help to do it themselves is questionable - I suspect whoever owns the baseband has as much access as you'd even need, so now you're relying on AT&T/Comcast/Verizon/TMobile to put protecting your privacy above keeping the corporation on-side with powerful government agencies...)

Post reply on HN