Live data from Hacker News

iMessage Key Verification

support.apple.com

61–70 of 127 posts

Re: iMessage Key Verification

#61

This seems somewhat similar to Matrix's (and other apps') approach of comparing keys to verify identity (plus with I guess some extra hardware requirements and attestation). I'm interested to see what the uptake is among users, because even though Matrix has done a fair amount to smooth this process, verification is still a pretty large source of friction from what I can tell, and I'm not completely sure how it could…

Tangential, but Keybase (and later Keyoxide [1]) with their “social proof” mechanics are a more human-friendly way to verify the encryption keys. I kinda wish Matrix had that integrated, too. [1]: Here's my Keyoxide page for example: https://keyoxide.org/alexander@notpushk.in

Is Keyoxide based on the Keybase codebase, or is it a new development?

I quite enjoyed Keybase back in the day, but then they pivoted to being a crypto wallet, and were ultimately acquired by Zoom (a move I understand less every day, since they obviously gave up on their bold promises of end-to-end encryption they made back in 2020).

Re: iMessage Key Verification

#62
post #32

Sucks that it requires iCloud Keychain enabled, and also removing your appleid from any legacy macs and iphones. Wish they explained the reasons for this, because I'm having a hard time seeing one.

Beeper?

In fact, it seems like this would make Beeper and similar approaches an order of magnitude harder.

And I could totally see Apple making non-verified contacts' bubbles a different color sooner rather than later...

Re: iMessage Key Verification

#63
post #20

So like is “sophisticated threats” a passive-aggressive way of saying “Beeper”?

Theoretically the two are orthogonal. There's no reason why Beeper wouldn't be able to implement contact key verification; there's no hardware attestation component to it, as far as I can tell.

Practically, the added complexity of having to integrate with iCloud Keychain certainly won't help.

Re: iMessage Key Verification

#64

Earlier quoted context omitted.

Only for mass attacks. A targeted attack will encounter the risk of the attacker being exposed. Think journalists, politicians, public figures

It might still be an acceptable risk. Most governments around the world probably don’t care that much if it’s discovered they are surveiling a journalist or lawyer. In most of the world everyone knows that journalists and lawyers are being monitored.

I think you and notpushkin are perhaps missing some of the "economic" angles on this. It's not just about the what, it's about the how. High value targets are highly likely to be following decent practices and at least staying up to date on software. Which implies that cracking iMessage would require use of a 0-day, of which there are not an infinite number at any given time, and which Apple will immediately eliminate forever if they discover it. Part of the point of highly targeted careful attacks is to stretch those out, it's not just about keeping the target from knowing (though that's not irrelevant), it's also about future targets.

So as with a lot of matters in intelligence work it's subject to cost benefit calcs. If using it against a given target means they are incredibly unlikely to notice and it can then be used again and again, it doesn't take much target value for a government to deploy it which pushes towards more mass use. On the opposite end if using it means it will immediately become useless ever again, then the expected target value has to at least exceed the market cost (which itself will rise more quickly if 0-days are being consumed more quickly vs production), every time. In between is a spectrum of less or more use. Apple wants it as far towards "use it and lose it" as possible, but Trevor Perrin's argument makes sense here: even a relatively small increase in percentage of "use it and lose it" amongst the population could significantly change the mean weighted cost for threat actors.

If they could know for sure whether a given counter measure was deployed that'd reduce the cost again, but if they can't there is indeed a population benefit. It's like a mine field, there don't have to be that many mines scattered around to really hurt people's willingness to cross it!

Re: iMessage Key Verification

#65

Earlier quoted context omitted.

The article is a little short on details, but it's not immediately clear to me how Apple's UX will differ. This is exactly my concern, I agree that Matrix's setup can be difficult for new users, but I'm not sure what a good UX for this even is. Apple's non-public verification method seems to be (at least at first glance) almost identical to what Matrix is doing. If Apple rolls out a similar system and it works or the…

This Apple support page describes how both automatic and manual verification UI/UX presents itself to the user. https://support.apple.com/en-us/HT213465

Same thoughts, I guess. This describes the process, and the process (at least for on-device comparison) sounds almost identical to what Matrix does today. I'm not sure what code is going to be compared, Matrix uses emoji which I've found helps a lot, neither article for Apple specifies what they'll use.

But :shrug: unless I'm not seeing a broader picture or there are details here that I don't understand, it does kind of sound like this is going to have the same problems that Matrix has. Although, to be fair, I've run into validation errors and syncing problems with Matrix before that theoretically Apple won't have? So maybe it'll be the same UX, but slightly more stable? Although also to be fair, Matrix doesn't require me to update all of my computers in order to verify an identity and Apple seems to be saying that users will need to do that, so I'm not necessarily taking it as a given that Apple's system system won't have its own share of annoying caveats.

It's a tiny bit disappointing, my takeaway from Matrix is that this all needs to be easier to do, and I was mildly hopeful that there would be some UI takeaways from Apple's implementation.

Or maybe people will just be more tolerant if it's Apple asking them to jump through the hoops instead of an Open Source messenger? If that's the case, and if the UX really is basically the same as Matrix's, maybe some of that tolerance will bleed over to Matrix as well.

Re: iMessage Key Verification

#66
post #57

Quite disappointingly, this requires being logged in with iCloud as well as iMessage on the same device, so I can't use it on my work computer (I have different Apple IDs at work and home). I don't really see why the two need to be tangled together.

You sign into your personal Apple accounts on your work computer? Seems like a very bad idea to mix work and personal.

Re: iMessage Key Verification

#67
post #58

It looks like I would need the following for this to work: To use iMessage Contact Key Verification, you’ll need: iOS 17.2, watchOS 9.2 and macOS 14.2 on all devices where you’ve signed in to iMessage with your Apple ID Unfortunately my work iMac isn’t on Sonoma, it’s on Monterey. I suppose I could log out on that machine, but still, a bit of a shame older versions aren’t supported. Am I reading the requirements corr…

Yep, I have an 2017 iMac at home and won’t be able to use CKV unless a sign out of iCloud on that machine.

Re: iMessage Key Verification

#68

Earlier quoted context omitted.

This Apple support page describes how both automatic and manual verification UI/UX presents itself to the user. https://support.apple.com/en-us/HT213465

Same thoughts, I guess. This describes the process, and the process (at least for on-device comparison) sounds almost identical to what Matrix does today. I'm not sure what code is going to be compared, Matrix uses emoji which I've found helps a lot, neither article for Apple specifies what they'll use. But :shrug: unless I'm not seeing a broader picture or there are details here that I don't understand, it does kind…

Here’s my verification key, so you know what they look like, since you were wondering what would be shown/compared:

APKTIDJ_J3S3UhVqZKCX5EgKYnh9ez4pO9Hsr5YWv_5pXF5GUcLA

Re: iMessage Key Verification

#69
post #66
post #57

Quite disappointingly, this requires being logged in with iCloud as well as iMessage on the same device, so I can't use it on my work computer (I have different Apple IDs at work and home). I don't really see why the two need to be tangled together.

You sign into your personal Apple accounts on your work computer? Seems like a very bad idea to mix work and personal.

That's exactly what I'm not doing (iMessage is ok for me, all my iCloud data definitely not), hence no contact key verification for me.
Post reply on HN