Live data from Hacker News

iMessage Key Verification

support.apple.com

81–90 of 127 posts

Re: iMessage Key Verification

#81

Earlier quoted context omitted.

Only for mass attacks. A targeted attack will encounter the risk of the attacker being exposed. Think journalists, politicians, public figures

It might still be an acceptable risk. Most governments around the world probably don’t care that much if it’s discovered they are surveiling a journalist or lawyer. In most of the world everyone knows that journalists and lawyers are being monitored.

Has warrantless mass surveillance really become so normalized that such gross violation of people's rights is just casually brushed aside like some unsurprising everyday occurrence, so common it can't be helped? Lawyers and journalists are people too, they're citizens, human beings with rights and they don't deserve to be "monitored" by anyone. If "everyone knows" they're being monitored, why is nobody doing a thing about it?

All these three letter agencies operate in the darkness and away from the public eye. That's where they belong, because what they do to their own citizens is supposed to be unconstitutional. If they've really gotten so brazen as to operate openly instead of clandestinely and are still enjoying complete impunity then there really is no hope left.

Re: iMessage Key Verification

#82
post #15

How safe is the contact that is uploaded to the iCloud? How safe is the contact from being modified by some app on your iPhone? The contact containing the verification code seems to be one of the weaker link in this whole thing. If Mallory can change the verification code in the contact to their own, the communication between Alice and Bob is no longer protected.

It doesn’t matter, the keyword is “in transit” but since it requires iCloud Keychain - it also means it’s compromised with LE. Also the fact that most people they have iCloud also will backup their messages…. So it’s nice that it’s encrypted in transit but since iMessage is apple only and requires.. see above!

iCloud Keychain compromised with LE? As in law enforcement?

How do? iCloud Keychain is E2EE with a key derived from your device password/passcode.

Re: iMessage Key Verification

#83
post #76

Earlier quoted context omitted.

Only for mass attacks. A targeted attack will encounter the risk of the attacker being exposed. Think journalists, politicians, public figures

> A targeted attack will encounter the risk of the attacker being exposed. What "risk" is there? I'm not aware of illegal spying by intelligence or law enforcement agencies having ever had any adverse consequences for them, in any country, at any point in history.

Risk of revealing their attack and losing whatever exploit made it possible, if nothing else. The stuff Citizen Lab has published is also making problems for some of the companies selling spyware

Re: iMessage Key Verification

#84
post #76

Earlier quoted context omitted.

Only for mass attacks. A targeted attack will encounter the risk of the attacker being exposed. Think journalists, politicians, public figures

> A targeted attack will encounter the risk of the attacker being exposed. What "risk" is there? I'm not aware of illegal spying by intelligence or law enforcement agencies having ever had any adverse consequences for them, in any country, at any point in history.

I don't mean to be snippy, but this is kinda what the whole Cold War was about. There were constant consequences for the spying. For domestic I think we can point to Watergate, Contra Affair, Snowden Leaks. I have some more recent examples but I think mentioning them will result in arguing and move from the topic at hand. You may not agree that the consequences were severe enough, but there were consequences. I think there's also a strong bias in that consequences take place after (often months or years) and there's less attention given to them so we often aren't even aware. But if consequences do happen, it does mean the rage machine was effective even if far from optimal. Worth noting that there is a danger in lack of attention to consequences, since it can lead to apathy and thus actually enable consequent-less actions in a self-fulfilling prophecy.

Re: iMessage Key Verification

#85
post #74
post #64

Earlier quoted context omitted.

I think you and notpushkin are perhaps missing some of the "economic" angles on this. It's not just about the what, it's about the how . High value targets are highly likely to be following decent practices and at least staying up to date on software. Which implies that cracking iMessage would require use of a 0-day, of which there are not an infinite number at any given time, and which Apple will immediately elimina…

> High value targets are highly likely to be following decent practices and at least staying up to date on software. Not even close. The vast majority of journalists, lawyers, activists, even public figures, don't have the knowledge to secure their digital lives, don't have access to an expert to do it for them, and in many cases aren't even fully aware of the nature of the threat (beyond some vague idea along the li…

>Not even close. The vast majority of journalists, lawyers, activists, even public figures, don't have the knowledge to secure their digital lives, don't have access to an expert to do it for them, and in many cases aren't even fully aware of the nature of the threat (beyond some vague idea along the lines of "I'm probably being monitored").

Citation needed. Because everything I have ever seen is that iOS users almost all leave on autoupdate and the move to the latest version is the overwhelming majority, very rapidly. Seriously, look at adoption each time over the last 5 years on a site like statista [0] or wherever, or various ones aimed at developers. If you want to claim that people at higher risk aren't part of the 60-85% I'd honestly be curious to see your numbers. Note I said "decent" not "best" practices. Whatever its flaws, mixed incentives, and issues (which are real), Apple has expended significant effort in making the normal default paths provide an ok baseline security for regular people and discouraging leaving them. Which isn't even something a lot of HNers like! If anything, I'd be unsurprised if HN types to lag in some respects because we want more control and to do things outside the well trod path. I've jailbroken a lot, is that something most people do? No.

In this specific case, the minimum needed to avoid a zero-day exploit is (by definition) merely to always have the OS updated and all security patches applied while staying firmly within the walled garden. Which it's objectively clear the super majority of regular people do. If you just go with the default and let Apple update your device whenever Apple wants, then it's a truism that anything you get hit by is something Apple hasn't yet patched. And in turn anything that raises the population probability that the 0-day actually gets noticed and potentially reported raises the risk of using the 0-day. The whole point of this feature is that it'd let a normal person who doesn't necessarily understand threat mechanics go "huh, that's funny" and then maybe say so on their social media/blog/wherever, at which point if even one person who follows them (and we're talking journalists or other types with enough influence to get targeted by major threat actors right?) recognizes what's going on and says "quick call Apple/security researcher/tell HN" now it's out there.

>because those practices have no observable effect to them

Literally the entire point of this new feature is to create an observable effect of tampering. Kind of a weird statement in context.

----

0: https://www.statista.com/statistics/565270/apple-devices-ios...

Re: iMessage Key Verification

#86
post #52
post #26

Earlier quoted context omitted.

This was announced last year, way before any of Beeper’s shenanigans. https://www.macrumors.com/2022/12/07/new-imessage-apple-id-s...

Beeper was released at least two years prior to that.

And that’s not what I’m referring to by their shenanigans.

Specifically I’m talking about their beeper mini spoofing of Apple devices, not the other beeper setup that forwarded content to/from an actual Mac.

Re: iMessage Key Verification

#87

Earlier quoted context omitted.

Here’s my verification key, so you know what they look like, since you were wondering what would be shown/compared: APKTIDJ_J3S3UhVqZKCX5EgKYnh9ez4pO9Hsr5YWv_5pXF5GUcLA

Ow. Okay, I take it back, unless there's something I'm missing then Matrix's system is better than this. I'm sorry, I just can not imagine asking a non-technical person to copy and paste that into a messenger and then needing to help them debug which letter they left off. It's hard enough to get them to validate "I see a cat, a dog, a horse, a pizza, and a basketball." I guess I'll wait and see what happens with it,…

They both suck, TOFU is bad. Apple should apply their central pki to certify that contact with their icloud id.

TOFU is a good idea when you don't want a central party arbitraring identities like with federated matrix. Makes little sense with apple.

Re: iMessage Key Verification

#88

I wonder, why now? Smells like a warrant canary.

How do you mean? As in Apple is requested to share info, & when they do so they modify data that would cause the key verification to fail, notifying any contacts of the suspected user via notification?

Re: iMessage Key Verification

#89
post #59

This seems somewhat similar to Matrix's (and other apps') approach of comparing keys to verify identity (plus with I guess some extra hardware requirements and attestation). I'm interested to see what the uptake is among users, because even though Matrix has done a fair amount to smooth this process, verification is still a pretty large source of friction from what I can tell, and I'm not completely sure how it could…

> I'm interested to see what the uptake is among users My suspicion is that it'll be quite low for many years, for two reasons: - It requires a recent iOS and macOS version on all of a user's devices. Still got an old iPad lying around somewhere that doesn't receive software updates anymore? No key verification for you. (In a similar way, Apple has been making older devices obsolete by preventing Notes sync in some p…

iCloud Advanced Data Protection also requires modern hardware and won’t enable if you have outdated/vintage stuff logged in on your Apple account.

Re: iMessage Key Verification

#90

I wonder, why now? Smells like a warrant canary.

How do you mean? As in Apple is requested to share info, & when they do so they modify data that would cause the key verification to fail, notifying any contacts of the suspected user via notification?

Yes, and they are not allowed to disclose that, but they are allowed to ship new security features.
Post reply on HN