8 ms·
Each company wants to earn by using your data, and Signal doesnt allow that (but it can be backdoored). No company like google, apple, microsoft,... is going to
by _o_ 8y ago
Each company wants to earn by using your data, and Signal doesnt allow that (but it can be backdoored). No company like google, apple, microsoft,... is going to give you application where they cant intercept the content.
- TheCoreh 8y agoApple's iMessage is end-to-end encrypted
- gsich 8y agoYou can receive messages on multiple devices. So it would be easy for Apple to simply add a new device without showing you.
- jtbayly 8y agoWhat’s your point? The question at hand is whether any major company would allow consumers to send messages the company can’t harvest for data. The answer is yes. Apple does. Are you saying they don’t? —That they actually have backdoored their E2E messaging app already? If you are just saying that it’s not entirely impossible for them to do backdoor, I don’t see what bearing that has on the discussion.
- gsich 8y agoWhy backdoor the messaging app, when you can just add a new device. Apple does, but as far as trust goes, they are on the same level as WhatsApp (also E2E).
- briandear 8y agoWhatsApp is part of Facebook. Claiming Apple is on the same level as a Facebook-owned entity is absurd. Apple can’t see who your contacts are (it’s encrypted in iCloud) but Facebook can.
- gsich 8y agoSo Apple delivers your messages via magic? You are logged in from one endpoint. So Apple knows that you are you. It does also know who your other chat partner is. At some point there is a transmission of data from A to B. I don't see a way to hide the metadata if the data is transmitted through Apples network. If it's P2P, then yes.
- Angostura 8y agoFrom: https://techcrunch.com/2014/02/27/apple-explains-exactly-how-secure-imessage-really-is/ https://techcrunch.com/2014/02/27/apple-explains-exactly-how... You’ve actually got one set of keys for each device you add to iCloud, and each iMessage is encrypted independently for each device. So if you have two devices — say, an iPad and an iPhone — each message sent to you is actually encrypted (AES-128) and stored on Apple’s servers twice. Once for each device. When you pull down a message, it’s specifically encrypted for the device you’re on.
- briandear 8y agoNot true. They would have to have access to your iCloud credentials and you would have to confirm the new device from one of your old devices.
- zwily 8y agoOr they could push out a (targeted) software update that lets them do that silently. I don’t think they would, but they could.
- newscracker 8y agoI don't think there's any messaging platform in the world that's immune to this kind of an attack. So singling out Apple is pointless in that context.
- zwily 8y agoAgreed. See https://news.ycombinator.com/item?id=16903916 https://news.ycombinator.com/item?id=16903916.
- nothrabannosir 8y agoYour comment is close to hitting the weak point: you have to trust Apple. If you can’t, then this single / multiple devices detail doesn’t matter: they could find a million ways to silently subvert the encryption in a closed source app on a closed source OS. But if you can, then waxing on details doesn’t matter either: you trust them, so you trust them. The thing is: it is valid to trust a company to keep their explicit word. That’s a different issue from trusting a company who never explicitly said they wouldn’t listen to your data: companies can be held liable for these sorts of public statements. If Facebook silently (knowingly) subverts Whatsapp E2E, they’re in trouble. But reading regular Facebook messages for ads? Storing them plain text? They never said they wouldn’t. This is why Apple explicitly stating they E2E iMessage is a data point with value. It is valid to trust Apple more now, simply because they’ve upped the stakes for themselves. Compare this to a bar bet: someone makes a claim, I am sceptical. They say, honest! Still sceptical. They say ok, bet you £300. I suddenly am much more inclined to believe them. No money changed hands :)
- newscracker 8y agoWhenever a new device (AppleID/phone number) is associated with Messages/iMessage, a notification appears on other devices saying something like "Your phone number is now being used for iMessage on <device>", along with some more text. Apple also sends an email about that to the email address associated with the iCloud account. So I don't understand what you mean by "it would be easy for Apple to simply add a new device without showing you". If that refers to Apple circumventing this kind of warning for specific users for some reason, then I guess other popular messaging platforms/apps cannot be trusted either.
- _o_ 8y agoStop believing the marketing, they can say message is end to end encrypted even if they encrypt it twice, once with apple key and once with "end" key (actually it is more complicated, but for the sake of this debate it is good enough, for a simple algorithm, check bellow) Before you start downvoting spree, read this: For Apple: https://mashable.com/2013/10/17/apple-nsa-imessage https://mashable.com/2013/10/17/apple-nsa-imessage http://bgr.com/2015/08/06/iphone-fbi-imessage-facetime-backdoor/ http://bgr.com/2015/08/06/iphone-fbi-imessage-facetime-backd... https://www.tripwire.com/state-of-security/latest-security-news/apple-imessage-vulnerable-eavesdropping-mitm-attacks/ https://www.tripwire.com/state-of-security/latest-security-n... For WhatsApp: https://tobi.rocks/ https://tobi.rocks/ (encrypt data with random key with symmetric encryption algorythm (AES,...), which is then encrypted and stored with the mesage twice. Once encrypted with recipient public key (asymmetric: RSA,ECC) and once encrypted with apple public key. This way you can say that you are having end to end encryption while you can still read everything and you can also use all the nice words in marketing material, AES, end2end, RSA/ECC,...).
- zwily 8y agoThat article does not say that Apple is encrypting the per-message key with an Apple public key (alongside the device-specific keys), just that it could. Yes, there are many ways Apple could bypass its own E2E encryption, but we haven’t seen any evidence that it is or has.
- _o_ 8y agoWell, the point of E2E encryption is that you cant bypass it. That only the recipient is able to read it. Believe me that if I start making e2e encryption, no one will bypass it and I doubt the engineers at Apple are not able to do it, unless instructed otherwise. I will tell you another case: Skype. It had a p2p protocol, highly encrypted and obfuscated, also the application was armored. The communication wasn't going through Skype servers but directly between devices. Once Microsoft bought it, the next version was using Microsoft servers and p2p was gone. Interesting, right?
- 8y ago
- ScalaForever 8y agoE2E currently nicely converges with Apples business and brand.
- jrq 8y agoThis is overly pessimistic. Some companies do that sort of thing, but as consumers we have to look carefully and investigate companies to find one's that dont, and that we trust. Somebody already mentioned apple's e2e product, and Google doesn't stop anybody from using signal, or others. I don't think consumers will make the best choices if they think they're choosing the lesser of many evils.
- deleted 8y ago[deleted]