3 ms·
When you craft a push notification server-side, it contains the payload in plaintext. Now, that is probably encrypted in Apple-land, but my point is that the go
by akouri 5y ago
When you craft a push notification server-side, it contains the payload in plaintext. Now, that is probably encrypted in Apple-land, but my point is that the gov't probably has sunk its teeth into Apple already. So, yea signal's encryption may be open source and proven, but I doubt Apple's doesn't have a backdoor.
- MrKristopher 5y agoNot sure if Signal is doing this, but they could send a notification with title "New message" and encrypted payload. The payload can be processed by a client-side notification extension which decrypts the payload and chooses what notification text the user will see.
- ylk 5y agoI mean Apple themselves is telling devs to not send sensitive data in the actual notification > [...] never include sensitive data or data that can be retrieved by other means in your payload. Instead, use notifications to alert the user to new information or as a signal that your app has data waiting for it. https://developer.apple.com/library/archive/documentation/NetworkingInternet/Conceptual/RemoteNotificationsPG/CreatingtheNotificationPayload.html https://developer.apple.com/library/archive/documentation/Ne...
- egberts1 5y agothat’s why Signal sends an empty notification then uses their own EE2E for notification wordings.
- diebeforei485 5y agoNot true. The server can send encrypted (not plaintext) payload. The client can then use a NotificationExtension to decrypt the payload as it comes in. https://developer.apple.com/documentation/usernotifications/unnotificationserviceextension https://developer.apple.com/documentation/usernotifications/...