9 ms·
iMessage Key Verification
- Humphrey 3y agoI wonder if the timing of this in response to Beeper Mini gaining access to the iMessage network?
- eclipxe 3y agoUnlikely.
- CodeWriter23 3y ago> Published Date: December 11, 2023
- deleted 3y ago[deleted]
- herpdyderp 3y agoAs mentioned in other comment, it was announced well before this month: https://www.macrumors.com/2022/12/07/new-imessage-apple-id-security-features/ https://www.macrumors.com/2022/12/07/new-imessage-apple-id-s...
- judge2020 3y agohttps://security.apple.com/blog/imessage-contact-key-verification/ https://security.apple.com/blog/imessage-contact-key-verific... is from October 27, 2023 though.
- danielraffel 3y agoit's been a few months since that post. looking forward to the complete technical walkthrough of their implementation.
- no_wizard 3y agoIts unlikely. They had pre-existing infrastructure for this via their Apple Messages For Business[0] program, which includes all the backbone to show that the account is verified (including the checkmark and info tab). This appears to be an extension of that for consumer accounts [0]: https://register.apple.com/resources/messages/messaging-documentation/ https://register.apple.com/resources/messages/messaging-docu...
- elteto 3y agoI think it would be hard to push out such a feature in such a short span. Beeper’s userbase is tiny and not an immediate security threat to Apple.
- ianlevesque 3y agoNor a distant security threat.
- fotta 3y agothis was announced a year ago https://www.macrumors.com/2022/12/07/new-imessage-apple-id-security-features/ https://www.macrumors.com/2022/12/07/new-imessage-apple-id-s...
- sib 3y agoNo, this feature has been in beta builds for quite a while.
- MuffinFlavored 3y ago> gaining access to the iMessage network? I wouldn't say they "gained access to iMessage network". They figured out a weakness in Apple's authentication that allowed a user with a fake serial # to authenticate. Apple is slowly making it more strict/checking the serial #s better (my opinion/guess).
- danShumway 3y agoThis seems somewhat similar to Matrix's (and other apps') approach of comparing keys to verify identity (plus with I guess some extra hardware requirements and attestation). I'm interested to see what the uptake is among users, because even though Matrix has done a fair amount to smooth this process, verification is still a pretty large source of friction from what I can tell, and I'm not completely sure how it could be made easier. I guess the idea here is that once you verify a contact that syncs to their other devices, but in theory Matrix also does that, and in practice I still see some friction. It's possible Apple's implementation will just be better, or that they'll rely on attestation to such a degree that they'll be able to skip some other friction points. But even with the public verification setup (which gets rid of the problem of needing to verify devices at the same time as the person you're talking to), I'm still slightly skeptical that users are going to copy and paste a code into their messaging app to verify contacts. My experience is that even popping up a button and saying, "do your friend and you see the same emoticons" is too much work for a lot of users. Maybe I'll be wrong. And I guess ideally if iOS users get used to doing this, they might be more tolerant of doing the same thing in other messengers too.
- seanieb 3y agoTrevor Perrin, who co-designed the Signal Protocol, made the point that most people don’t have to do this. If a few people do, an adversary won’t know if the target is verified or not. If they MITM they might be discovered instantly. Which gives the entire herd protection. - https://www.youtube.com/watch?t=2001&v=7WnwSovjYMs https://www.youtube.com/watch?t=2001&v=7WnwSovjYMs
- notpushkin 3y agoNot a great argument IMO. If only 0.1% people check the keys, the attacker may be just okay with the 0.1% chance of being discovered – especially if there's no consequences for them.
- viktorcode 3y agoOnly for mass attacks. A targeted attack will encounter the risk of the attacker being exposed. Think journalists, politicians, public figures
- deleted 3y ago[deleted]
- poorman 3y agoHow safe is the contact that is uploaded to the iCloud? How safe is the contact from being modified by some app on your iPhone? The contact containing the verification code seems to be one of the weaker link in this whole thing. If Mallory can change the verification code in the contact to their own, the communication between Alice and Bob is no longer protected.
- thamer 3y agoThey can't just change the verification code, and it's not based on the fields of the contact card. You can think of it as a fingerprint for their iMessage public key, the one used to encrypt messages end-to-end. If the key with which your phone encrypts iMessage payloads has changed, it indicates that the conversation is being intercepted. WhatsApp supports this too, see "Verify Security Code" on this page: https://faq.whatsapp.com/820124435853543 https://faq.whatsapp.com/820124435853543 So does Signal: https://support.signal.org/hc/en-us/articles/360007060632-What-is-a-safety-number-and-why-do-I-see-that-it-changed- https://support.signal.org/hc/en-us/articles/360007060632-Wh... So does Telegram: https://telegram.org/faq#q-what-is-this-39encryption-key-39-thing https://telegram.org/faq#q-what-is-this-39encryption-key-39-...
- grgar 3y agoBut the verification code is stored in the contact card, so the parent comment still stands. Anything that can access contacts, e.g. apps or iCloud (since Contacts are not part of Advanced Data Protection i.e. E2E encryption), can modify the verification code in the contact used by Messages for validation.
- fishcrackers 3y ago[dead]
- zaps 3y agoSo like is “sophisticated threats” a passive-aggressive way of saying “Beeper”?
- n2d4 3y agoI don't think this is related. This is just public key verification, the kind that other E2E messaging apps already had. I don't know about the specifics but as I understand, Beeper Mini could implement this too if they want to.
- dagmx 3y agoThis was announced last year, way before any of Beeper’s shenanigans. https://www.macrumors.com/2022/12/07/new-imessage-apple-id-security-features/ https://www.macrumors.com/2022/12/07/new-imessage-apple-id-s...
- lxgr 3y agoTheoretically the two are orthogonal. There's no reason why Beeper wouldn't be able to implement contact key verification; there's no hardware attestation component to it, as far as I can tell. Practically, the added complexity of having to integrate with iCloud Keychain certainly won't help.
- varenc 3y agoSeems like Apple is tacitly acknowledging that sophisticated actors have successfully been man-in-the-middling iMessage users. I wonder if they have clear evidence of that since I haven’t seen any coverage on this.
- dannyw 3y agoI don’t get that impression. Given that iMessage is such a high value target, I wouldn’t be surprised either way, but adding more security features is not a tacit admission of compromise.
- jrockway 3y agoThe attack is that anyone can make an iMessage account and pretend to be your friend ("new phone who this"); this feature is how you prevent that.
- dannyw 3y agoI don’t think that’s the attack this feature aims to prevent. Rather, it aims to prevent someone who compromised iMessage infrastructure, from pulling a dodgy around keys.
- varenc 3y agoAgreed with the sibling comment. To quote Apple, this feature can "detect sophisticated threats against iMessage servers". Essentially it's to protect against state-sponsored attacks MITMing you. Doing that also probably requires the attackers also have access to some root CA private keys so it's a very small pool.
- deleted 3y ago[deleted]
- AceJohnny2 3y agoOr! they're trying to get ahead of legislation (looking at the UK) by presenting a fait-accompli
- aaomidi 3y agoThere is a huge opportunity here for Apple to do a proper chain of trust. “You want to talk to Adam, but you haven’t verified their keys yet. However your contacts Anna and Derek have confirmed Adam’s identity”
- epolanski 3y agoI'm always confused by this. This merely validates that Anna at the time thought that was Adam's number, what else? Does not guarantee it's Adam reading.
- toomuchtodo 3y agoIf you have a cryptographic primitive and a robust system to protect it (secure hardware, biometric auth), if you can confirm digital identity in real life you can be reasonably assured Adam is reading. Chain of integrity.
- candiddevmike 3y agoJust like blockchain, meat space applications of digital chains of trust require too much benevolence. At the end of all the state of the art crypto is Grandma pushing a button.
- toomuchtodo 3y agoSpeaks to the robustness of the legal system, and code simply a crude layer on top of it.
- pyrophane 3y agoAt its best it verifies that "Adam" is using a device that was verified by a trusted 3rd party as being added to the network by Adam himself. So, it is more about trusting devices than individual interactions.
- jojobas 3y agoThis is such a privacy leak that I have a hard time thinking you're serious. “You want to talk to Family Lawyer D. Ivorstein, but you haven’t verified their keys yet. However your contact Wife has confirmed D. Ivorstein’s identity”
- tamimio 3y agoI think this feature is already in other chat apps like matrix or telegram, will see how’s Apple implementation compares, but great addition nonetheless.
- 0x0 3y agoSucks that it requires iCloud Keychain enabled, and also removing your appleid from any legacy macs and iphones. Wish they explained the reasons for this, because I'm having a hard time seeing one.
- teaearlgraycold 3y agoProbably requires a hardware-security-module for generating secure attestation keys.
- deleted 3y ago[deleted]
- cheeze 3y agoRemoving appleid from legacy mac and iphone because they don't have the hardware security module. So rather than having a broken imesssage experience on those devices, they decided its better for you to just unregister.
- comex 3y agoBecause iCloud Keychain sync is how each person can have one key for others to verify, rather than a separate key for every device they are logged into iMessage with. It’s described in more detail here: https://security.apple.com/blog/imessage-contact-key-verification/ https://security.apple.com/blog/imessage-contact-key-verific... (This is end-to-end encrypted, by the way; Apple can’t get at people’s private keys.) And this is a new protocol, so no surprise it doesn’t work with older operating systems. (It doesn’t say you have to remove your Apple ID completely, just log out of iMessage.)
- solardev 3y agoBeeper?
- aspenmayer 3y agoThe contact key verification feature preexists Beeper’s iMessage support.
- lxgr 3y agoQuite disappointingly, this requires being logged in with iCloud as well as iMessage on the same device, so I can't use it on my work computer (I have different Apple IDs at work and home). I don't really see why the two need to be tangled together.
- heywire 3y agoYou sign into your personal Apple accounts on your work computer? Seems like a very bad idea to mix work and personal.
- lxgr 3y agoThat's exactly what I'm not doing (iMessage is ok for me, all my iCloud data definitely not), hence no contact key verification for me.
- ezfe 3y agoI mean, you literally are - you've signed into iMessage with your personal account on a work device. I know it's not iCloud, but it's functionally the same as iCloud with all the checkboxes disabled.
- lxgr 3y agoHow are the two the same? iCloud automatically logs you into iMessage, but the reverse is not true. Getting more access beyond iMessage requires another authentication (it’s definitely not just “enabling more checkboxes), and most importantly iCloud Keychain won’t even be touched without the required second factor (usually another device’s passcode on the same iCloud account).
- makeitdouble 3y agoI think many people end up in that situation. An Apple account is required in many situations (e.g. you want to download something from the Mac Store, you want Find My Mac etc.), but Apple doesn't cleanly support multiple accounts on any of their devices (and they probably have no incentives to do so) It's also a PITA to have single devices with single accounts. For instance 2FA is a pain, you also can't use features like sidecar. All in all, Apple is really bad at this and makes you jump through hoops if you intend to have clean separation between your work and personal accounts.
- mjsweet 3y agoIt looks like I would need the following for this to work: To use iMessage Contact Key Verification, you’ll need: iOS 17.2, watchOS 9.2 and macOS 14.2 on all devices where you’ve signed in to iMessage with your Apple ID Unfortunately my work iMac isn’t on Sonoma, it’s on Monterey. I suppose I could log out on that machine, but still, a bit of a shame older versions aren’t supported. Am I reading the requirements correctly? Does this mean that for all devices to work with CKV, then all OS’s need to be updated, or will it not do CKV on any devices if even one device is not supported?
- captainoats 3y agoYep, I have an 2017 iMac at home and won’t be able to use CKV unless a sign out of iCloud on that machine.
- mjsweet 3y agoThat’s what I wondered!
- arthurcolle 3y agoIs this to kill off Beeper? EDIT: no, it wasn't. it was announced a year ago per other comments...
- SheinhardtWigCo 3y agoI wonder, why now? Smells like a warrant canary.
- GrabbinD33ze69 3y agoHow do you mean? As in Apple is requested to share info, & when they do so they modify data that would cause the key verification to fail, notifying any contacts of the suspected user via notification?
- SheinhardtWigCo 3y agoYes, and they are not allowed to disclose that, but they are allowed to ship new security features.
- kfreds 3y agoFor those interested, the underlying technology for this feature is transparency logs. Some technical details for iMessage's approach can be found here: https://security.apple.com/blog/imessage-contact-key-verification/ https://security.apple.com/blog/imessage-contact-key-verific... The same technology powers WhatsApp's key transparency: https://engineering.fb.com/2023/04/13/security/whatsapp-key-transparency/ https://engineering.fb.com/2023/04/13/security/whatsapp-key-... Less than a month ago the first workshop on "transparency systems" was held at ACM CCS: https://catsworkshop.dev https://catsworkshop.dev Shameless plug: I'm one of the designers of the Sigsum public transparency log, as well as System Transparency - a security architecture intended to bring transparency to the reachable state space of a remote running system.
- vinay_ys 3y agoWhy does Apple couple iMessage with rest of iCloud? Why is iCloud and iCloud Keychain being on a requirement for secure iMessage to function? That seems like a poor design choice to me. For someone who cares about their communication security deeply enough to do contact public key verification, they would likely want to turn off iCloud syncing iMessage across multiple devices. They are likely to not have same iCloud account on multiple devices. In such cases, what's the value of having iCloud Keychain being turned on?
- the_gipsy 3y agoMaybe it's a dark pattern, like safari downloads defaulting to iCloud instead of the phone.
- hnbear 3y agoGiven how hard it is to find your downloads locally on your phone, I think most users want sharing with other devices my default. Makes sense to download stuff and have it be in downloads on the laptop or iPad. I don’t think that’s really that dark.
- varenc 3y agoiMessage Key Verification does not require that you use 'iCloud for iMessage' (aka iCloud message syncing), it just requires that you're signed into iCloud and have iCloud Keychain enabled. Your critique is still valid but I think it's important to note that you're not required to store all your actual encrypted iMessage content in iCloud.
- flandish 3y agoDoesn’t sharing your pub code also kind of build a network of “proof” this is you? As in sure Billy knows its you but so will a court have that same evidence, making denial “thats a spoofed message” harder.