6 ms·
I was gonna make exactly this point. I know Forstall got forced out by management, but don't we have him to thank for iMessage's architecture? Before Signal, i
by __blockcipher__ 6y ago
I was gonna make exactly this point. I know Forstall got forced out by management, but don't we have him to thank for iMessage's architecture?
Before Signal, iMessage was pretty much the only secure messaging system readily available to consumers. And more broadly Forstall had a huge role in making the Apple we know today.
- Solstinox 6y agoThe nature of lofty awards, fellowships, and titles is political, social, and if the former allow, merit-based.
- ChuckNorris89 6y agoSo much this. You can be the best in the world but should you land on some higher-up's bad side good luck making the cut.
- Andrew_nenakhov 6y agoOh come on, 'the only secure messaging system'. Xmpp was around for ages, it is decentralised and had OTR encryption since maybe 2001
- sillysaurusx 6y agoOpt-in OTR encryption. Kind of a big difference.
- Andrew_nenakhov 6y agoWhen you control your own server you kinda don't really need end to end encryption. It only enhances security when you don't trust the entity delivering your messages. It also degrades UX considerably: if the server does not know the contents of your message, it can't do server side archive search, you can't sync devices easily, etc.
- filoleg 6y ago>It only enhances security when you don't trust the entity delivering your messages Trust in entities is fleeting. You trust an entity today, you might not trust it tomorrow. End-to-end encryption, in contrast, is not fleeting, as long as you trust math.
- Andrew_nenakhov 6y agoI was actually talking about running your own server. If someone is _really_ caring about his privacy, he can allow himself to spend $2/month on it. And if someone's trust for his own service is fleeting... uh-oh.
- jychang 6y ago> And if someone's trust for his own service is fleeting... uh-oh. I definitely won't trust my own code to keep me alive, if that's what's preventing a government from killing me or something. There's a very good chance my homemade server config or encryption code has a big side channel vulnerability or something.
- Andrew_nenakhov 6y agoXMPP servers are really good these days, you know. And, I repeat, if you run your own server, you don't really need e2ee, cause the only one who can access the DB with your messages is a server operator - yourself, i this case, and why would you protect you from yourself? Also, if you are concerned about privacy, chances are, you are not a private individual and have specially trained people to install that server for you. Then again, even if you DO need encryption to transmit a critical password or something, well, XMPP clients developers know their business (at least, some of them do), so it is unlikely that you'd be able to screw up something.
- monadic2 6y ago> And, I repeat, if you run your own server, you don't really need e2ee, cause the only one who can access the DB with your messages is a server operator - yourself, i this case, and why would you protect you from yourself? The typical idea is being concerned that a state will physically seize your server—you know, real security and privacy concerns. > Also, if you are concerned about privacy, chances are, you are not a private individual and have specially trained people to install that server for you. Is this not ultimtely what iMessages is to people?
- deleted 6y ago[deleted]
- sascha_sl 6y agoDo note "readily available to consumers". XMPP never reached a level of polish outside being embedded in part-proprietary solutions that it'd be available to your average user, not to even talk about OTR.
- Andrew_nenakhov 6y agoGtalk was polished enough. It didn't have OTR built in, but majority of users don't really need end to end encryption anyway, it only makes their life not good. Also, iMessage never reached a level of polish to work on anything not produced by Apple. If we're taking proprietary vendor specific secure services, Blackberry did it before Apple, too. So, definitely not the first and not the only.
- derefr 6y agoE2E encryption is mostly for people whose lives are already not good. It only works to help those people, though, if enough “civilian” traffic is also using it that any ISP blocking it would be considered to be breaking the Internet. BBM was not E2E encrypted. BlackBerry always retained the capability to read your message traffic. Apple does not.
- Andrew_nenakhov 6y ago> Apple does not. Well, I'm not _that_ familiar with BBM since it was never available in my country. But what makes you think Apple can't read your messages? Do you have any encryption keys that you share between devices? Or you just enter login/password on a new device and voilà all your messages are displayed to you? If that is so, I guess I'll have to tell you something... Anyway. Last time I checked, iMessage apps source code was not available, you can't verify fingerprints of your contacts in iMessage, so... how do you know Apple doesn't insert a very simple MitM agent that does e2ee both for your and your chat partner, having all messages nicely decrypted in the middle? So far it looks like the only thing that makes you think Apple can't do that is because they pinky promised this to you. Sorry.
- agloeregrets 6y agoYou have him to thank for the iPhone in whole. He ran the team that developed iOS and defined the modern smartphone interface. Literally one of the largest software leadership contributions in history.