Live data from Hacker News

Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

techcrunch.com

91–100 of 116 posts

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#92
post #52

Earlier quoted context omitted.

No, it doesn’t, not really. Look at where their money is coming from. You mentioned health. Apple has no plans at all to make money with that. It’s just an API that makes devices more useful for users . Think critically about this, but please do it in a honest way.

> You mentioned health. Apple has no plans at all to make money with that. It’s just an API that makes devices more useful for users. So there's no 'Made For Iphone' program?

That seems quite unlikely, given how the API is structured (and how that market currently operates; please inform yourself before making claims).

Even if there were such a program for health hardware I’m not sure how it follows that Apple will want to sell user data … that’s just completely illogical.

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#93

Earlier quoted context omitted.

The half-truth is here: If the government laid a subpoena to get iMessages, we can’t provide it. It’s encrypted and we don’t have a key. It's encrypted and they don't have the key, but since the user does not have any control over the public keys being added, they could add a trusted public key and get it anyway. So they can actually provide messages if they really wanted to. I don't believe they really want to. But…

And the source code to the compiler they use. And the source code to those compilers, ad infinitum. And the masks for every IC inside the products, and the schematics of all the circuitry. And then someone to verify that they are all the correct ones.

And someone to verify that the verifier is correct, and someone to verify her...

Ad absurdom...

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#94
Honestly, I really don't care if they have the key or not. My concern is if they can read my messages. I am more worried about backdoors added to iMessage by Apple. This is known to happen often in Apple products, maybe for the purpose of Development or Support, but it is still there. That is exactly what I want to know. Because if Apple can use that backdoor, a patient hacker can too.

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#95
post #12

There is zero control over what public keys get handed over to your phone to encrypt an iMessage with. For all we know, whenever you want to send a message to $USER, your phone gets a public key for $USERs iPhone, her iPad and the NSA master key. Tim Cook can state that they can't decrypt the message all he wants, but as long as there's no control over what public keys we encrypt the message with, the statement that…

I don't really disagree with the reasoning, I just disagree with how Apple only is the recipient of such scrutiny. Same deal with payments stuff. And the reason basically boils down to, they have fancy ads and their products look really nice so they must be lying to us.

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#96

Honestly, I really don't care if they have the key or not. My concern is if they can read my messages. I am more worried about backdoors added to iMessage by Apple. This is known to happen often in Apple products, maybe for the purpose of Development or Support, but it is still there. That is exactly what I want to know. Because if Apple can use that backdoor, a patient hacker can too.

> This is known to happen often in Apple products, maybe for the purpose of Development or Support, but it is still there.

Could you elaborate on this? Are you talking about the development tools that require your phone to be cabled to a laptop?

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#97

Earlier quoted context omitted.

Not really. He's pretty clear: "If the government laid a subpoena to get iMessages, we can’t provide it. It’s encrypted and we don’t have a key." There's no wiggle room there. He's not saying we don't have the users key, he's saying categorically they can't provide iMessage information. I don't understand why you think that can be read as they can't get the information through mechanism X but that they can through me…

Or Cook could just reap some PR-points with a convincingly stated flat out lie. It's not like anyone will remember it in a couple of weeks anyway.

I disagree. If things go south (meaning they do what they claimed they couldn't, and then get caught) people will surely remember it, and in that case it would be negative PR-points, doubled. That doesn't mean he's not lying, it just makes it less likely.

Re: Tim Cook on iMessage Security: It’s Encrypted, and We Don’t Have a Key

#99
post #42

Earlier quoted context omitted.

They can't create trusted public keys after the fact, they'd have to already have them. So there's no half truth. Either they currently create and store such public keys or they don't. Tim Cooke is saying they don't. That statement can't be half true. It's either true or false.

They can't create trusted public keys after the fact, Of course they can. They own the directory server that hands out keys. http://blog.cryptographyengineering.com/2013/06/can-apple-re... tl;dr: Apple can send you a public key of Bob's new device. Apple can pretend to send you a public key of Bob's new device. And since it's proprietary software, they can trigger a resend of your recent messages to Bob. Moreover, if…

So this ends up being as "simple" as answering the question: Do you trust Apple? Given they control the operating system and all around it, having the directory server controlled by someone else (or distributed) doesn't solve the problem as they have access to anything they want in your device, meaning they don't need any keys to begin with.
Post reply on HN