9 ms·
Presumably, this would affect Apple and iMessage as well, correct? Hopefully, Apple will publically denounce this act, putting stronger pressure on representat
by pgm8705 6y ago
Presumably, this would affect Apple and iMessage as well, correct?
Hopefully, Apple will publically denounce this act, putting stronger pressure on representatives and increasing public awareness.
- maqp 6y agoApple can already silently eavesdrop on all iMessages, because they control the public keys inserted to your device. There are no fingerprints to verify you're not under MITM attack so they can just start attacking everyone. Read my longer post on this topic here: https://news.ycombinator.com/item?id=21425897 https://news.ycombinator.com/item?id=21425897
- saagarjha 6y agoApple cannot do this "silently".
- maximente 6y agowhat evidence do you have to refute the longer post that the OP linked to where they explain the exact mechanism that this can be done silently?
- saagarjha 6y agoThe fact that adding a new key is no longer silent? iMessage will alert you when a new device is added to the account.
- maqp 6y agoDoes it alert you when your contact's key changes? Does it alert you when your contact buys another iDevice and installs iMessage on it? Thought so. That's where the attack happens, when you receive a new public key for contact's device. Just because your account keeps track of your devices, doesn't mean Apple can't do this attack.
- saagarjha 6y agoThere’s no need to be confrontational or try to “gotcha” people here; Hacker News is for thoughtful discussion. As for your scenario: yes, Apple could do this. But I’m not sure what your solution to this would be? Some UI to show the addition of a new key? Hashes that you could match? There’s no reason they couldn’t backdoor the UI as well as the key distribution for a casual user; and a sophisticated one who’s looking for this kind of attack can just check the keys Apple sends them manually…
- maqp 6y agoMy intention was not to be confrontational. But such posts spreading misinformation aren't really thoughtful and shouldn't be tolerated. The standard method to detect MITM attacks from server side is with public key fingerprints. Sure, that feature could be backdoored too, I've seen that in a real life product. But that's only half of the equation: you need FOSS client with reproducible builds to ensure the feature actually works. After that, the users can verify their E2EE is working the way it should. Fingerprints alone aren't enough. As I point out in the long post, use Signal that allows this.
- comex 6y agoOut of curiosity, do you actually verify your Signal contacts' safety numbers? I think most Signal users do not.