Live data from Hacker News

iMessage Key Verification

support.apple.com

71–80 of 127 posts

Re: iMessage Key Verification

#71

Earlier quoted context omitted.

Same thoughts, I guess. This describes the process, and the process (at least for on-device comparison) sounds almost identical to what Matrix does today. I'm not sure what code is going to be compared, Matrix uses emoji which I've found helps a lot, neither article for Apple specifies what they'll use. But :shrug: unless I'm not seeing a broader picture or there are details here that I don't understand, it does kind…

Here’s my verification key, so you know what they look like, since you were wondering what would be shown/compared: APKTIDJ_J3S3UhVqZKCX5EgKYnh9ez4pO9Hsr5YWv_5pXF5GUcLA

Ow. Okay, I take it back, unless there's something I'm missing then Matrix's system is better than this.

I'm sorry, I just can not imagine asking a non-technical person to copy and paste that into a messenger and then needing to help them debug which letter they left off. It's hard enough to get them to validate "I see a cat, a dog, a horse, a pizza, and a basketball."

I guess I'll wait and see what happens with it, but I'm going to temper my expectations about people adopting this.

Re: iMessage Key Verification

#72
post #51
post #25

There is a huge opportunity here for Apple to do a proper chain of trust. “You want to talk to Adam, but you haven’t verified their keys yet. However your contacts Anna and Derek have confirmed Adam’s identity”

This is such a privacy leak that I have a hard time thinking you're serious. “You want to talk to Family Lawyer D. Ivorstein, but you haven’t verified their keys yet. However your contact Wife has confirmed D. Ivorstein’s identity”

It would have to be an optional sharing. The UX would need a bit of work.

I would trust my technical friend with their chain of trust, but not my hair dresser.

Re: iMessage Key Verification

#73
post #66
post #57

Quite disappointingly, this requires being logged in with iCloud as well as iMessage on the same device, so I can't use it on my work computer (I have different Apple IDs at work and home). I don't really see why the two need to be tangled together.

You sign into your personal Apple accounts on your work computer? Seems like a very bad idea to mix work and personal.

I think many people end up in that situation.

An Apple account is required in many situations (e.g. you want to download something from the Mac Store, you want Find My Mac etc.), but Apple doesn't cleanly support multiple accounts on any of their devices (and they probably have no incentives to do so)

It's also a PITA to have single devices with single accounts. For instance 2FA is a pain, you also can't use features like sidecar.

All in all, Apple is really bad at this and makes you jump through hoops if you intend to have clean separation between your work and personal accounts.

Re: iMessage Key Verification

#74
post #64

Earlier quoted context omitted.

It might still be an acceptable risk. Most governments around the world probably don’t care that much if it’s discovered they are surveiling a journalist or lawyer. In most of the world everyone knows that journalists and lawyers are being monitored.

I think you and notpushkin are perhaps missing some of the "economic" angles on this. It's not just about the what, it's about the how . High value targets are highly likely to be following decent practices and at least staying up to date on software. Which implies that cracking iMessage would require use of a 0-day, of which there are not an infinite number at any given time, and which Apple will immediately elimina…

> High value targets are highly likely to be following decent practices and at least staying up to date on software.

Not even close. The vast majority of journalists, lawyers, activists, even public figures, don't have the knowledge to secure their digital lives, don't have access to an expert to do it for them, and in many cases aren't even fully aware of the nature of the threat (beyond some vague idea along the lines of "I'm probably being monitored").

On top of that, it has been my experience that people who don't understand threat mechanics on a deeper level (such as active MITM attacks) quickly stop following whatever best practices they have been trained to adhere to (in this case, peer key verification), because those practices have no observable effect to them and without actually understanding what's going on, it's hard for them to see what the point is.

Re: iMessage Key Verification

#75
post #66

Earlier quoted context omitted.

You sign into your personal Apple accounts on your work computer? Seems like a very bad idea to mix work and personal.

I think many people end up in that situation. An Apple account is required in many situations (e.g. you want to download something from the Mac Store, you want Find My Mac etc.), but Apple doesn't cleanly support multiple accounts on any of their devices (and they probably have no incentives to do so) It's also a PITA to have single devices with single accounts. For instance 2FA is a pain, you also can't use features…

That's exactly the problem, in a nutshell. Everything is tangled in a big ball of yarn with Apple:

Theoretically the iTunes/App Store/TV account is independent of iCloud – except that it's tangled to Apple Podcasts.

- iMessage used to be mostly standalone (iCloud sync was explicitly optional!) – but not it's tied to iCloud via contact key verification.

- Books is a weird mix of iCloud (for media) and iTunes (for purchases).

- Having my device as a trusted login factor is a complete mess: I still haven't figured out what makes or doesn't make a device "capable of generating authentication codes".

- iTunes subscriptions can somehow only be managed on an Apple device or iTunes – and logging in for that purpose messes up podcasts (see the first point).

At least on macOS, it's possible to make a second account and log in to most of these cleanly, but it's still a hassle compared to e.g. Google's seamless support for multiple accounts in almost all of their products.

Re: iMessage Key Verification

#76

Earlier quoted context omitted.

Not a great argument IMO. If only 0.1% people check the keys, the attacker may be just okay with the 0.1% chance of being discovered – especially if there's no consequences for them.

Only for mass attacks. A targeted attack will encounter the risk of the attacker being exposed. Think journalists, politicians, public figures

> A targeted attack will encounter the risk of the attacker being exposed.

What "risk" is there? I'm not aware of illegal spying by intelligence or law enforcement agencies having ever had any adverse consequences for them, in any country, at any point in history.

Re: iMessage Key Verification

#78
post #57

Quite disappointingly, this requires being logged in with iCloud as well as iMessage on the same device, so I can't use it on my work computer (I have different Apple IDs at work and home). I don't really see why the two need to be tangled together.

If you use two different Apple IDs on two different devices, how does that prevent you from using iMessage Key Verification? As far as this system is concerned, you are essentially two different people, both of whom can have key verification on independently (sort of the point).

The only scenario where this might break is if you log into personal accounts on work devices or vice-versa. I think that’d be ill-advised…

Re: iMessage Key Verification

#79
post #66

Earlier quoted context omitted.

You sign into your personal Apple accounts on your work computer? Seems like a very bad idea to mix work and personal.

I think many people end up in that situation. An Apple account is required in many situations (e.g. you want to download something from the Mac Store, you want Find My Mac etc.), but Apple doesn't cleanly support multiple accounts on any of their devices (and they probably have no incentives to do so) It's also a PITA to have single devices with single accounts. For instance 2FA is a pain, you also can't use features…

The solution I landed on is having 2 iCloud accounts in the same “family” so things can be shared, but in a controlled manner.

Re: iMessage Key Verification

#80
post #14

Earlier quoted context omitted.

Trevor Perrin, who co-designed the Signal Protocol, made the point that most people don’t have to do this. If a few people do, an adversary won’t know if the target is verified or not. If they MITM they might be discovered instantly. Which gives the entire herd protection. - https://www.youtube.com/watch?t=2001&v=7WnwSovjYMs

Not a great argument IMO. If only 0.1% people check the keys, the attacker may be just okay with the 0.1% chance of being discovered – especially if there's no consequences for them.

The argument is context dependent, as is essentially anything related to security. Key verification isn't for most people and can even create more noise as normal people frequently change phones. But the average threat environment isn't the only threat environment. In higher risk settings (politicians, journalists, etc) verification rates are expected to be higher than 0.1% because these people frequently are also more knowledgeable of security practices and/or have better advisors than the general public. While the context isn't explicitly stated I think it is fair to assume that most can infer this and that if not someone can explain it. Often things that appear ridiculous but are common practice aren't if context is considered (doesn't mean good thing but just less absurd and it can be understood why the ridiculous thing is done).
Post reply on HN