Live data from Hacker News

iMessage Key Verification

support.apple.com

91–100 of 127 posts

Re: iMessage Key Verification

#91
post #89
post #59

Earlier quoted context omitted.

> I'm interested to see what the uptake is among users My suspicion is that it'll be quite low for many years, for two reasons: - It requires a recent iOS and macOS version on all of a user's devices. Still got an old iPad lying around somewhere that doesn't receive software updates anymore? No key verification for you. (In a similar way, Apple has been making older devices obsolete by preventing Notes sync in some p…

iCloud Advanced Data Protection also requires modern hardware and won’t enable if you have outdated/vintage stuff logged in on your Apple account.

This is super annoying. I don't have iCloud stuff enabled on my old iPad, but it works just fine as a media streaming device for the kids. I want to enable Advanced Data Protection, but it won't let me until I replace the perfectly good iPad :(

Re: iMessage Key Verification

#92
post #58

It looks like I would need the following for this to work: To use iMessage Contact Key Verification, you’ll need: iOS 17.2, watchOS 9.2 and macOS 14.2 on all devices where you’ve signed in to iMessage with your Apple ID Unfortunately my work iMac isn’t on Sonoma, it’s on Monterey. I suppose I could log out on that machine, but still, a bit of a shame older versions aren’t supported. Am I reading the requirements corr…

Yep, I have an 2017 iMac at home and won’t be able to use CKV unless a sign out of iCloud on that machine.

That’s what I wondered!

Re: iMessage Key Verification

#93
post #76

Earlier quoted context omitted.

> A targeted attack will encounter the risk of the attacker being exposed. What "risk" is there? I'm not aware of illegal spying by intelligence or law enforcement agencies having ever had any adverse consequences for them, in any country, at any point in history.

I don't mean to be snippy, but this is kinda what the whole Cold War was about. There were constant consequences for the spying. For domestic I think we can point to Watergate, Contra Affair, Snowden Leaks. I have some more recent examples but I think mentioning them will result in arguing and move from the topic at hand. You may not agree that the consequences were severe enough, but there were consequences. I think…

What consequences did the Snowden Leaks have?

I mean for the intelligence agencies – not for Edward Snowden. I'm of course aware his life has been destroyed. But what consequences were there for the people and institutions responsible?

Re: iMessage Key Verification

#94
post #91
post #89

Earlier quoted context omitted.

iCloud Advanced Data Protection also requires modern hardware and won’t enable if you have outdated/vintage stuff logged in on your Apple account.

This is super annoying. I don't have iCloud stuff enabled on my old iPad, but it works just fine as a media streaming device for the kids. I want to enable Advanced Data Protection, but it won't let me until I replace the perfectly good iPad :(

Any idea what happens if you sign out, enable it, and try to sign back in? Is the error as cryptic as I might imagine?

Re: iMessage Key Verification

#95

Earlier quoted context omitted.

Here’s my verification key, so you know what they look like, since you were wondering what would be shown/compared: APKTIDJ_J3S3UhVqZKCX5EgKYnh9ez4pO9Hsr5YWv_5pXF5GUcLA

Ow. Okay, I take it back, unless there's something I'm missing then Matrix's system is better than this. I'm sorry, I just can not imagine asking a non-technical person to copy and paste that into a messenger and then needing to help them debug which letter they left off. It's hard enough to get them to validate "I see a cat, a dog, a horse, a pizza, and a basketball." I guess I'll wait and see what happens with it,…

To be clear, that code is only for offline verification. For live verification (akin to Matrix's emojis) Apple has you compare an 8 digit code.

Re: iMessage Key Verification

#96
post #33

Earlier quoted context omitted.

But the verification code is stored in the contact card, so the parent comment still stands. Anything that can access contacts, e.g. apps or iCloud (since Contacts are not part of Advanced Data Protection i.e. E2E encryption), can modify the verification code in the contact used by Messages for validation.

According to https://security.apple.com/blog/imessage-contact-key-verific... , the actual verified hash of the account key is stored in an end-to-end encrypted CloudKit container and merely linked to from the contact card.

Oh interesting, that is not at all clear based on the Contacts UI which shows it like any other field

Re: iMessage Key Verification

#97
post #85
post #74

Earlier quoted context omitted.

> High value targets are highly likely to be following decent practices and at least staying up to date on software. Not even close. The vast majority of journalists, lawyers, activists, even public figures, don't have the knowledge to secure their digital lives, don't have access to an expert to do it for them, and in many cases aren't even fully aware of the nature of the threat (beyond some vague idea along the li…

> Not even close. The vast majority of journalists, lawyers, activists, even public figures, don't have the knowledge to secure their digital lives, don't have access to an expert to do it for them, and in many cases aren't even fully aware of the nature of the threat (beyond some vague idea along the lines of "I'm probably being monitored"). Citation needed. Because everything I have ever seen is that iOS users almo…

> Because everything I have ever seen is that iOS users almost all leave on autoupdate and the move to the latest version is the overwhelming majority, very rapidly.

Outside of the US, Android's market share dwarfs iOS's. And most people's Android phones are from vendors that stop providing updates, including security updates, after 2 years or so. There are hundreds of millions, if not billions, of vulnerable Android phones out there.

> Literally the entire point of this new feature is to create an observable effect of tampering.

Which, since most connections aren't tampered with, isn't actually observable in practice for most people. So the next time they meet someone new, they might not even bother asking them to do key verification.

Re: iMessage Key Verification

#98
post #85
post #74

Earlier quoted context omitted.

> High value targets are highly likely to be following decent practices and at least staying up to date on software. Not even close. The vast majority of journalists, lawyers, activists, even public figures, don't have the knowledge to secure their digital lives, don't have access to an expert to do it for them, and in many cases aren't even fully aware of the nature of the threat (beyond some vague idea along the li…

> Not even close. The vast majority of journalists, lawyers, activists, even public figures, don't have the knowledge to secure their digital lives, don't have access to an expert to do it for them, and in many cases aren't even fully aware of the nature of the threat (beyond some vague idea along the lines of "I'm probably being monitored"). Citation needed. Because everything I have ever seen is that iOS users almo…

Turning on automatic updates, while a great choice for the vast majority of iOS users, does not protect against sophisticated adversaries who use zero day exploits. The fact that everyone is already on the latest version (they’re not, because of phased rollout, but it’s not too relevant here) means that an exploit that has value targets latest iOS by default.

Opt-in additional protections, such as Lockdown Mode, which aren’t perfect but help are rarely enabled by those who need it, despite being marketed to people who are targeted. Part of this is that it’s opt-in, but part of it is that a lot of the people targeted aren’t journalists: they’re the spouses of political leaders, or random government leaders, who don’t have a good security posture nor do they have people managing their devices for them to create one.

Also, do note that just because someone appears to have tampered with a conversation doesn’t mean you’ve burned your 0-day: it provides no indication of how they did so.

Re: iMessage Key Verification

#99
post #14

Earlier quoted context omitted.

Trevor Perrin, who co-designed the Signal Protocol, made the point that most people don’t have to do this. If a few people do, an adversary won’t know if the target is verified or not. If they MITM they might be discovered instantly. Which gives the entire herd protection. - https://www.youtube.com/watch?t=2001&v=7WnwSovjYMs

Not a great argument IMO. If only 0.1% people check the keys, the attacker may be just okay with the 0.1% chance of being discovered – especially if there's no consequences for them.

Apple’s installed base is so large (around 2 billion devices) that if 0.1% of them verified their keys, that’s still a useful deterrent.

Re: iMessage Key Verification

#100
post #93

Earlier quoted context omitted.

I don't mean to be snippy, but this is kinda what the whole Cold War was about. There were constant consequences for the spying. For domestic I think we can point to Watergate, Contra Affair, Snowden Leaks. I have some more recent examples but I think mentioning them will result in arguing and move from the topic at hand. You may not agree that the consequences were severe enough, but there were consequences. I think…

What consequences did the Snowden Leaks have? I mean for the intelligence agencies – not for Edward Snowden. I'm of course aware his life has been destroyed. But what consequences were there for the people and institutions responsible?

This contains a decent summary, including some laws: https://www.eff.org/deeplinks/2023/05/10-years-after-snowden...

I'd mention there are two big but abstract consequences.

1) The leaks significantly harmed international relationships and the result of this game much more ammunition to political adversaries like China and Russia. People argue that this is a consequence of Snowden's leak but that's like arguing that a mass shooting was only problematic because the news informed everyone. In a way yes, but it's not like those people would be alive if the news didn't report... It's not the real problem even if you wanted to argue over-sensationalism.

2) It seriously galvanized the battle for encryption and laid the pathway for the subsequent rapid rise in usage of tools like Signal and more funding and energy for building tools like Matrix and many others. Google's Project Zero certainly was influenced by this event.

While I get that these are more abstract, they are certainly consequences and certainly nothing to be scoffed at. This is another problem with the perception of consequences, is that often they are more subtle or abstract. But subtle or abstract doesn't mean any less impactful, just more difficult to trace. More opaque. We don't have a counterfactual to prove that these things wouldn't have happened without the leaks, but I'm certain the timing and degree would have been different. Do you think the world would be different had he not released them? I don't think this is an easy question to answer because it requires being exceptionally detailed and paying very close attention to a lot of events.

Post reply on HN