11 ms·
Apple can read your iMessages (even though they’re E2E encrypted)
- nostromo 5y ago… if you back up your device to iCloud. (Of course, almost everyone does.) Apple was apparently going to close this loophole, but decided not to. They probably received negative feedback from the three letter acronym agencies.
- Fizzadar 5y agoEven disabled, if the other party has them enabled Apple still have access to that content.
- lynndotpy 5y agoOr, as discussed there, if the person you're talking to backs up iMessage to iCloud. Both parties need to be willing to forego that convenience, and AFAIK, it can not be done on a per-message basis.
- ummonk 5y agoThere are limitations there though. E.g. if a broad warrant to reconstruct all your messages were issued, Apple would refuse to honor it, if only due to technical infeasibility. It's one thing to execute a warrant for "data of suspect A" and another thing to execute a warrant for "access the iCloud backups of every single person who has it enabled, decrypt their backed up messages, and return any message that was received from or sent to suspect A". On the other hand the government could certainly find a specific individual they know you've messaged with, and execute a warrant specifically for their conversations with you.
- upbeat_general 5y agoI believe they have metadata indicating who a person has sent messages to, so they wouldn't need to go through all iCloud backups but indeed a warrant for data for "suspect A" does not include data for all people "suspect A" communicated with.
- deleted 5y ago[deleted]
- deleted 5y ago[deleted]
- AshamedCaptain 5y agoApple can do anything they want. They can push a silent update to specific iPhones which uploads the data in whichever format they prefer.
- MaxBarraclough 5y agoSimilar discussion 9 days ago on the thread Apple urged to drop plans to scan iMessages, images for sex abuse: https://news.ycombinator.com/item?id=28233200 https://news.ycombinator.com/item?id=28233200 Perhaps we need a new term, other than E2E encrypted, to close the door on 'loopholes' such as the provider managing your keys.
- INTPenis 5y agoNo, let's just use common sense. You can't trust anything to be e2ee if it's not open source too. In this case Apple can do anything they want with the keys since it's a locked down and closed platform.
- yawaworht1978 5y agoThis is the only real sensible approach. Even with open source signal, people say they still might be able to see things. Is there no way to test this?
- Sebb767 5y ago> You can't trust anything to be e2ee if it's not open source too. You can't trust anything unless you built it yourself [0]. Just because I tell you that binary is built from the source code does not mean it's not backdoored. [0] Theoretically, reproducible builds provide the same security, but in the end you need to build it yourself to get the hash, at which point you just replace one `cp` with two `sha256sum`.
- api 5y agoNope. Not there yet. You also have to audit the source and make sure someone hasn’t slipped in a back door or intentionally introduced bug.
- ummonk 5y agoAnd of course have to audit the hardware design, and then audit the manufacturing and supply chain for that hardware to ensure someone hasn't substituted hardware with spyware installed.
- ummonk 5y agoWithout reading the post I assume it's talking about iCloud backup (which is on by default) backing up your raw messages with just an Apple encryption key? That's well documented and makes sense as a default functionality - average users would be too prone to losing their data if data weren't backed up without E2EE.
- jackjeff 5y agoYes. iCloud backups are the easiest way to get the messages in clear text. But honestly you don’t need it. Even though iMessage is end to end encrypted, Apple mediates the key exchange. It’d be trivial for them to do a man in the middle attack by saying the other guy has a new key.
- deleted 5y ago[deleted]
- WA 5y agoWhy not read the post? Because you are technically wrong. It’s about iCloud backups containing the decryption keys. iMessages are backed up encrypted.
- deleted 5y ago[deleted]
- ummonk 5y agoAh right. Caveat though that that applies if Messages is set to use iCloud. In that case iCloud backup backs up the decryption key to ensure you don't inadvertently lose access to the messages because they're end to end encrypted. If Messages is not toggled in iCloud, then as long as iCloud backup is toggled, it will directly back up the raw messages - encrypting with an Apple stored key just as for any other non end to end encrypted data.
- nostromo 5y agoEncrypted backups should be a user option at the very least.
- marto1 5y agoAren't they required by law to be able to do that ? (PATRIOT act, etc.)
- upbeat_general 5y agoSee Signal or a variety of other services. The answer is no.
- smoldesu 5y agoEdward Snowden's article earlier this week posited that some 80% of iPhone users leave auto-sync on for iCloud, meaning that there's about a 20% chance that the next thing you send over iMessage isn't encrypted. Why is guesswork like that acceptable in a privacy tool? Furthermore, who actually believed that Apple couldn't read their messages? 'End-to-end' means very little when both ends are Apple-controlled.
- zepto 5y agoI’d be surprised if it’s as low as 80%. It’s pretty simple. iMessage is relatively secure and most criminals, nation states etc, won’t be able to access your messages unless they have a legal means to do so. If you need protection from a nation state that can force Apple to divulge content, such as the US, use something else such as signal.
- AbjectFailure 5y agoiMessage actually isn’t included in iCloud backups by default. It’s the one thing toggled off in the settings of a fresh iOS install.
- ummonk 5y agoIt's included in iCloud backups, just not toggled to use end to end encrypted iCloud sync (in which case iCloud backups would back up the decryption key). See https://support.apple.com/en-us/HT207428 https://support.apple.com/en-us/HT207428, https://support.apple.com/en-us/HT208532 https://support.apple.com/en-us/HT208532, https://support.apple.com/guide/security/security-of-icloud-backup-sec2c21e7f49/1/web/1 https://support.apple.com/guide/security/security-of-icloud-..., and https://support.apple.com/en-us/HT202303 https://support.apple.com/en-us/HT202303
- ec109685 5y agoiCloud Message sync doesn’t expose your messages to Apple. Only setting that matters is the iCloud Backup.
- warning26 5y agoIf they can do this, surely this evaporates any security-related rationale for not providing a web-accessible version of iMessages. If they just added that, it would be so incredibly useful. I'm sure they won't though, because that might mean that people could access iMessages from non-Apple hardware (the HORROR).
- makach 5y agoE2E encryption != Encryption at rest.
- sschueller 5y agoThese Apple privacy ads [1] are not aging well and they aren't even old. [1] https://youtu.be/lHcf9ZkJ28o https://youtu.be/lHcf9ZkJ28o
- smoldesu 5y agoMy personal favorite is the 'what happens on your iPhone, stays on your iPhone' one.
- zepto 5y agoThat hasn’t changed.
- smoldesu 5y agoWell, now it's being hashed and logged by Apple, by default.
- threeseed 5y agoOnly if you use iCloud Photo Library i.e. you choose to have your photos hosted by Apple. In which case Apple is no different to every other cloud company which scans for CSAM.
- kitkat_new 5y agoin being not true? https://arstechnica.com/gadgets/2021/03/android-sends-20x-more-data-to-google-than-ios-sends-to-apple-study-says/ https://arstechnica.com/gadgets/2021/03/android-sends-20x-mo...
- zepto 5y agoWeird - that link has no obvious relevance.
- threeseed 5y agoiCloud Backup not being encrypted is not new and necessary. Apple's ads will age fine since they invest far more effort in keeping your data private than every other OEM. Even their CSAM effort which blew up is far better than other companies who are doing server-side scanning.
- jpxw 5y agoYet another reason to disable iCloud, if you’re privacy conscious. Although you’re relying on your recipient disabling it too. So really you have to use something else. Signal, etc. With that said, I still think an iPhone with iCloud disabled is better than other phones on the market privacy-wise. And for the average consumer, iPhones offer a good tradeoff between privacy and usability.
- whoknowswhat11 5y agoA better headline - users willing to give up privacy for convenience. Reality - there was a period where the icloud backups created backups that apple did not have access to. Critically, this mean that if you had any of a wide variety of things happen - unless you were very good about key management - your content was lost for good. ALL your photos (which could be heartbreaking) etc. It turns out this is NOT what people want. They want apple to have access to their content, so when they have a device stolen and don't have a super long recovery key properly saved, they are not hosed. Same issue BTW with bitlocker on windows. People DO NOT save those recovery keys, even if they should. Microsoft added a way to force a backup into an account admins and others would have access to, thank goodness, because otherwise users there would be hosed as well.
- gxs 5y agoThis is an insightful comment. Whenever someone loses their account the first thing they do is run to the vendor and flip their shit when the vendor is unable to do anything. I imagine from a business perspective it’s just better to keep access to data, sometimes without nefarious reasons like advertising, rather just keeping customers happy.
- threatofrain 5y agoA bit of a tangent, but I happened to flip my shit when my folks laptop was stolen, and the thief placed a password protection on it that Apple refused to lift, despite Apple having the technical capability to do so. They had records of my folks purchasing the laptop, but they argued that state ID's and credit cards can be faked and stolen, and were thus inadequate for their internal security purposes.
- judge2020 5y agoYour post is very light on details. Did they just place a new password on the device itself? If so, you can still use the laptop if you reinstall MacOS. It is only is rendered a brick if the attacker signed into their own iCloud account and enabled Find My, OR the attacker enabled Find My & enabled the recovery key feature on the existing Apple ID (meaning Apple can't let you log into the account without the key).
- nimbius 5y agoPatiently awaiting the obligatory HN 'iPhone considered harmful' thread at this point with complementary link to a medium article. Seriously though after the San Bernardino shooter fiasco and the ongoing us government regulation demands it was basically all but guaranteed apple would pull all the stops to get Sam off their back.
- deleted 5y ago[deleted]
- orastor 5y agoApple can also silently create a stealthy virtual device that will get all messages as your phone does
- Gaelan 5y agoUnless you know something about the protocol that I don't (quite possible), it's not silent: all you devices get "new device registered to iMessage" dialog box.
- giantrobot 5y agoI'm continually surprised that people can't seem to understand E2EE. For whatever reason they assume it means a message is encrypted forever and unreadable by anyone. There is zero guarantee from any E2EE system that the data is encrypted at rest by the sender and receiver. In fact in most cases, the data is not encrypted at rest because people want to do silly things like read messages. The exact same vulnerability exists on every platform that's automatically backing up local data to the cloud. Even if you disable cloud backups you're still stuck if whoever you're messaging has left them enabled. The only meaningful way around this hole when it comes to messaging apps is row-level encryption on the backing store. This has a lot of problems of its own and potential holes when it comes to indexing and searching.
- pkulak 5y agoI get what you're saying... but what's the relevance here? The issue is that what Apple is doing is not E2E encryption, not the public's understanding of a reasonably complicated information science topic.
- lemoncucumber 5y agoThe relevance is that Apple provides two independent services: * iMessage, which does use true E2E encryption in transit. * iCloud backup, which backs up the contents of your device (including your unencrypted at-rest iMessage data), and does NOT support E2E encryption. Technically if you (and all your friends) use iMessage and don’t use iCloud backup, then it is impossible for Apple to read your messages. In reality, the alternatives to iCloud backup are too risky and/or cumbersome, so most people use it, with the result that Apple can read your iMessages once they’ve been sent/received and your phone has performed a backup.
- giantrobot 5y ago> The issue is that what Apple is doing is not E2E encryption They are providing E2EE with iMessage. E2EE only provides security for data in transit. It ensures that only the endpoints can decrypt the communication. That is it. There's absolutely no promises of encryption at rest on those endpoints. Not only is Apple actually doing E2EE but the tech press (and apparently HN posters) seem to think E2EE means something that it does not.
- TameAntelope 5y agoI find this acceptable. My threat model includes pickpockets and nosy siblings. It doesn't include nation states and highly sophisticated attacks. If the government wants to look at my data, and has gone through the proper channels to do so, I believe that, generally, that system will protect me from a consequential privacy intrusion. It's not a perfect system, but I believe the benefits of the power of subpoena are worth the costs, so I'm happy to participate in it.
- pkulak 5y ago> It doesn't include nation states and highly sophisticated attacks. Do you really believe that only nation states can get into Apple's machines? I'd agree that Apple is pretty far up there in security reputation, but if there was a headline tomorrow of "iMessage Backups of 2 Million Users For Sale On Tor" would it really surprise you? I don't even trust _myself_. I self-host my family's Matrix server, and we still encrypt all our conversations.
- TameAntelope 5y agoWould it surprise me? Yes, it would surprise me substantially and force me to revise my beliefs around the security of my data at Apple. Hacking isn't a magic wand, where bad guys cast spells and good guys just look foolish. I've worked in cybersecurity for ~10 years, and I know generally what the reputations are of various large tech companies. Apple has a good reputation for protecting properly secured data. It is currently, based on the information we have available to us, paranoid to think your data isn't secure from hackers when it's stored properly in Apple's infrastructure. Your behavior is, by a gigantic margin, more likely to cause a compromise of your secure data than Apple is to cause a compromise of your secure data.
- sparker72678 5y agoAlso worth keeping in mind, this is true for any message you send that's received by someone else, regardless of your own hygiene. i.e. for true security all message participants must have iCloud Backoff off, etc.
- exabrial 5y agoAny system you don't have root access too, or don't fully comprehend the hardware design, can and will be used against you.
- meowtimemania 5y agoDo you fully comprehend your iPod from 2007? How was it used against you?
- ec109685 5y agoThis post is wrong. iCloud Backup is the only setting that matters. Whether you enable iCloud Messages or not has no baring on whether Apple can read your messages. With iCloud Message sync, Apple doesn’t store a decryption key on their servers.
- timmit 5y agoThese two toggle are funny. - back my encrypted data - back my encryption key (if back encryption key, the e2e does not make any sense) What the encryption key will be used to encrypt the e2e encryption key?
- setnone 5y agoAnother reminder that if you sign out of your device Apple will forcefully turn on all iCloud switches upon next log it. https://news.ycombinator.com/item?id=28285567 https://news.ycombinator.com/item?id=28285567
- ThinBold 5y agoDoesn't Apple simply happen to be both the chat provider and backup provider, so Apple-A does the E2E encryption and Apple-B sees your backup because you sort of want that? And people worrying about the other end of the chat... come on, you talked to them in the first place. They can forward anything, even if it's via Signal. The entire story is just hilarious and memeable. Users want backup; Apple open up the gate. Users want E2E; Apple shut up the gate. Users want iCloud recovery; Apple partially open the gate.
- beermonster 5y agoI’ve always disabled cloud backups. They don’t really serve much purpose anyway since it’s just settings and to me settings are less valuable than content. I can easily set my device up again from scratch - in fact I like to do that every now and then to get new defaults or see how UX has changed. If you connect your device locally you can, just using Finder, make an encrypted local backup which IMHO is much better. Even if Apple did say Cloud Backups were encrypted you’d have to take it at face value anyway. Always be in charge of your own data, and secure and back it up yourself.
- rswail 5y agoThis preoccupation with Apple maintaining your privacy from themselves is ridiculous. They commit to protecting your privacy from others and are clear on what they have access to themselves. If you want true E2E encryption and encryption at rest, then build your own infrastructure.
- utf_8x 5y agoThe post has been deleted, here's an archive link... https://web.archive.org/web/20210827045159/https://old.reddit.com/r/privacy/comments/pcb3ej/a_timely_reminder_that_apple_can_read_your/ https://web.archive.org/web/20210827045159/https://old.reddi...
- sirmike_ 5y agoIn the early days when iCloud was new it corrupted my decade long (at that point in time) bookmarks. I was devastated. I never recovered them all. But it taught me a lesson. Apple in the cloud brings nothing good to the user if you trust them. Since then I have never and will never use iCloud for anything important. I can see iCloud has become a vector for no privacy over the years.