4 ms·
Apple: it's impossible because of the encryption Regulator: what are the others using? Apple: something very similar but slightly different Regulator: and it
by arlcode 4y ago
Apple: it's impossible because of the encryption
Regulator: what are the others using?
Apple: something very similar but slightly different
Regulator: and it's impossible to develop an open standard thet allows p2p encryption to be maintained?
Apple: Yes obviously in this specific field of technology that's not possible at all.
(Not the) Regulator: Sounds legit
- runako 4y agoThis facile response ignores that Apple Messages is a system, not just an encryption algorithm. Of particular concern is key management: who manages the keys that allow the messages to be decrypted? Currently, it's Apple. What this Act says is that Apple Messages must interop with any other messaging system. If you spin up a VM running an iMessage-compatible server on Hetzner, Apple Messages must interop with you and cannot privilege Messages (e.g. by continuing to use blue bubbles as a differentiator). That VM may be malicious (for ex: it may log who communicated with whom when), but the Act still requires that it be placed on an even footing with Messages. Similarly, the Act essentially says that once implemented, anyone using a phone can unintentionally be sending all of their messages to Facebook Messenger, which by law must have seamless interop with Messages. Any group chat could be logged by Facebook by virtue of one person in the chat choosing Facebook Messenger as their default messaging app. This requirement materially changes the security posture of a billion devices currently in use. You may believe the tradeoff is worthwhile, but it's still not a free tradeoff.
- lstodd 4y agoThat only means that the Apple Messages model is outdated and a replacement is hereby being required. If Apple prefers lock-in over innovation, it's their problem, not the users'.
- ko27 4y agoSome of the comments you posted on this thread are completely false, like EU forcing Apple to change bubble color or forcing them to handover encryption keys. Neither of that is even remotely true. If Apple doesn't want other companies to have encryption keys they can (and should) provide an E2E API. They can document their own protocol, or implement an existing open one, like Signal's.