4 ms·
It's really impressive that a high school student [1] has managed to reverse engineer iMessage. What I'm wondering is: 1. How stable is it; would it be trivial
by happyhardcore 3y ago
It's really impressive that a high school student [1] has managed to reverse engineer iMessage. What I'm wondering is:
1. How stable is it; would it be trivial for Apple to patch this?
2. If it's as simple as reverse engineering the protocols, how has it taken this long?
[1] https://github.com/JJTech0130 https://github.com/JJTech0130
- Obscurity4340 3y agoIts more a commentary on how amateur it is in my respectful view. iMessage is a fundamentally unserious "product" in search of enough collateral flaws to harm those foolish enough to depend on it for anything.
- happyhardcore 3y agoHow so? Other than the security issues that get exploited by NSO group from time to time (that appear to be mitigated fairly well by lockdown mode if that's something that's important to you) or the obvious flaw that you can't talk to anyone that doesn't have an iPhone it seems to be a perfectly good platform. The alternatives either have worse encryption (Telegram, RCS), worse privacy (WhatsApp), or the same platform lock-in as iMessage (Google's RCS).
- Obscurity4340 3y agoiMessage is the LastPass of messaging apps. This has been endlessly discussed and I want people to use their curiosity to help direct them to why I would comment in this way. In practice (not whitepaper or the ideal implementation), it is no more secure than sms (actually worse)
- nickpeterson 3y agoThe joke will be when they increase iMessage security to prevent these solutions from working well ;)
- Obscurity4340 3y agoThat's the thing tho: it will never be secure because its the skeleton key. It was never truly intended to be secure. Same reason why only WebKit's allowed on all billion+ iPhones. Access is only guranteed if its monocultural.
- saagarjha 3y agoThis is absolutely not true. iMessage is a full E2E implementation; it’s nothing like SMS.
- modeless 3y ago"E2E" is a joke when Apple holds the encryption keys to the vast majority of all messages, and uses them to respond to law enforcement requests. (It's how iCloud backup works by default and we know people don't change defaults. This is documented by Apple, not a conspiracy theory.)
- jwells89 3y agoIt’s still a substantial upgrade over SMS or unencrypted (non-Google) RCS, where anybody can snoop on conversations with little effort.
- Obscurity4340 3y agoLast time I checked, everyone knows SMS is cleartext and can't take over your phone in the profound way built-in 1st party apps/services you emphatically cannot remove (only toggle) can seize the means of production so to speak.
- jwells89 3y ago“Everyone” may be overly broad… just about everybody with any technical inclination knows yes, but for many years now the overwhelming majority of smartphone users have not been particularly technically inclined, and as such I would not expect most of them to be aware of the security and privacy implications that come with use of the various messaging services. With that in mind, I’d say that most messaging apps don’t go far enough to make that distinction clear. Any app handling SMS or any other unencrypted messages should have ever-present, readily visible warnings when conversations aren’t encrypted.
- Obscurity4340 3y ago
- standardUser 3y ago> the obvious flaw that you can't talk to anyone that doesn't have an iPhone That's because iMessage is a first and foremost a marketing tool that Apple compels users to rely on.
- foobiekr 3y agoDo you somehow think complexity is the opposite of amateur - that is, complex = professional? Because I have bad news for you. If iMessage is simple that means literally the opposite of what you think it means.
- deleted 3y ago[deleted]