6 ms·
Advanced encryption, until it comes time to text 70% of the phones in the world, in which case it defaults to a protocol released 32 years ago.
by lapetitejort 3y ago
Advanced encryption, until it comes time to text 70% of the phones in the world, in which case it defaults to a protocol released 32 years ago.
- tsunamifury 3y agoYes but that would have meant giving up sales in exchange for actually backing up their words. They aren’t even going to use the developed encrypted RCS protocol. Apple, when it comes to their values, is all lip service. I have intimate experience here with them both openly lying and purposefully deceiving their user base in this case.
- Jtsummers 3y agoWhat word? They never said they'd open iMessage. FaceTime is what they intended (or at least Jobs announced the intent) to open, and then that got caught up in a patent dispute.
- tsunamifury 3y agoNo, they could have shipped a product on android, or they could have used secure RCS, or several other things. FaceTime is not really true either. This was a convenient mistruth. There were several way to remedy that situation. Also your misremembering iMessage there was no such issue.
- matchbok 3y agoIt's not Apple's fault that the carriers/RCS/Google don't know how to make messaging work. RCS sucks, it pales in comparison to anything but SMS.
- detourdog 3y agoGoogle could have continued to support XMPP. If wishes were knishes doggies would eat.
- Jtsummers 3y agoYou wrote: > Yes but that would have meant giving up sales in exchange for actually backing up their words. What word did they not back up with respect to iMessage? When did they ever say they'd open it up?
- drcongo 3y agoFaceTime is definitely true. I've used it.
- 0x457 3y agoI remember them saying releasing iMessage as an open standard.
- Jtsummers 3y agoCan you point to a source for that outside your memory?
- layer8 3y agoThey’re confusing it with FaceTime: https://youtu.be/JOxf9tEXEKQ https://youtu.be/JOxf9tEXEKQ
- Jtsummers 3y agoI figured that was the case. I just wanted one of these folks that keep claiming it to cough up some evidence. It's a tired thing. There are lots of things to criticize Apple (and most companies) for, at least pick something that isn't imaginary.
- 0x457 3y agoI guess. But I swear I remember it was about iMessage. oh well, my bad.
- jxdxbx 3y agoThat was FaceTime, and it was because it was a peer-to-peer protocol. Then Apple was sued over a patent and had to implement a more normal design, where it pays for and runs the servers. Apple didn't want to run the servers for Android people to talk to each other.
- matthew-wegner 3y ago> They aren’t even going to use the developed encrypted RCS protocol. End-to-end RCS encryption is via proprietary Google extension and not even available to other Android RCS messaging apps.
- tsunamifury 3y agoIt was made available to Apple.
- zchrykng 3y agoDoesn't really help the argument that it is a proprietary Google technology. The fact that it had to be "made available" to Apple means that it isn't an open standard and requires trusting Google, which many of us don't.
- jxdxbx 3y agoEncrypted RCS should be a standard. When it is Google should adopt the standard, not its proprietary version. In the meantime I want Apple to implement standards, not proprietary Google technologies.
- GeekyBear 3y agoCitation? Beeper was explicitly told it was not available to others when they wanted to implement Google's encrypted RCS on their Android client. https://twitter.com/ericmigi/status/1557050351974420480 https://twitter.com/ericmigi/status/1557050351974420480
- brookst 3y agoUnder what terms, and with what promises? If Google's strategy was anything other than "get Apple to adopt, then screw them", Google would have contributed the enhancements back to the standard.
- GeekyBear 3y ago> the developed encrypted RCS protocol Google's proprietary closed source fork of RCS? > Google's version of RCS... is definitely proprietary, by the way. If this is supposed to be a standard, there's no way for a third-party to use Google's RCS APIs right now. Some messaging apps, like Beeper, have asked Google about integrating RCS and were told there's no public RCS API and no plans to build one. If you want to implement RCS, you'll need to run the messages through some kind of service, and who provides that server? It will probably be Google... So the pitch for Apple to adopt RCS isn't just this public-good nonsense about making texts with Android users better; it's also about running Apple's messages through Google servers. Google profits in both server fees and data acquisition. https://arstechnica.com/gadgets/2022/08/new-google-site-begs-apple-for-mercy-in-messaging-war/ https://arstechnica.com/gadgets/2022/08/new-google-site-begs...
- kergonath 3y ago> Yes but that would have meant giving up sales in exchange for actually backing up their words. I saw that you moved the goalposts in your reply, but anyway: which words? > They aren’t even going to use the developed encrypted RCS protocol. The protocol that was designed by Google and in which Google’s infrastructure is crucial? It’s not Apple’s fault that RCS does not have mandatory end-to-end encryption. > I have intimate experience here with them both openly lying and purposefully deceiving their user base in this case. Do you mean that they lied to you personnally? You should write about that, it sounds much more interesting.
- tsunamifury 3y agoI worked on several integration attempts between Apple and Google. They often presented specs that clearly showed security holes then simply would deny they were there or say “that’s secure”. It was a truly wild experience.
- kergonath 3y agoThis sounds fascinating, you really should write about this.
- tsunamifury 3y agoI'm following up here just because of your comment. I've thought about this often but I've run into a few problems: 1) This tier of work is roundly invisible to almost everyone in the field. Many in the field are so confident in their knowledge of 'how things work.' that they simply can't accept the real 'in the room' realities of whats going on. Often engineers most of all, who are often deceived by their executives on the real goals. Are you and eng? Have you ever had that feeling of being gaslit by your VP? Yea you probably were, and you didn't know why. 2) Even at that level, I had a limited picture and a good extrapolation of what was going on in other rooms, but nothing I can say fully factually 3) No one wants to know. People love the just-so stories of these companies and really genuinely seem to get hurt/be in denial when they are faced with the reality that they are made up of ultra-selfish, shark like people with very little invested in the consumer, the company, or really anyone else. It's a game played to win for personal satisfaction. I've found that most people, simply cannot accept this.
- para_parolu 3y agoWhy does 70% of world phones matter here? There are phones in the world that do not support any encryption when sending messages or doing calls.
- madeofpalk 3y agoSMS/RCS
- browningstreet 3y agoThe top 7 phones sold last year were all iPhones. https://www.macrumors.com/2024/02/21/iphones-top-7-best-selling-smartphones-2023/ https://www.macrumors.com/2024/02/21/iphones-top-7-best-sell... Too bad the other vendors don’t bother keeping up.
- not_a_real_56 3y agoThere is a flaw with your thinking. Any given year there are only 5-6 iPhones to choose from, where there are plenty of Android phones. This leads to "top phone sold" being iPhones because it is 5 phones against hundreds of Android phones that people get to choose from. You should instead look at Market share. https://www.statista.com/statistics/272698/global-market-share-held-by-mobile-operating-systems-since-2009/ https://www.statista.com/statistics/272698/global-market-sha...
- browningstreet 3y agoActually my point was companies-responsible-for-encryption development. You could argue it’s Google vs Apple on this front, but it could also be Apple vs Samsung, or Apple vs any of the other top tier android implementations. So you can either say Apple is reserving this development for a subset of the market, or Google is withholding it from a massive portion of the market share.
- danShumway 3y agoSamsung is not the reason why iMessages can't be sent to Android users or to Windows devices. Samsung does not decide which platforms Apple will and won't support. Coordination with even Google would not be necessary for Apple to offer encrypted conversations with users on other devices. There's no rule saying they need to use an open standard or a Google standard or be cross-compatible with another app. It's not that Apple is trying desperately to get iMessage onto other phones and failing because Google and Samsung just won't let them do it. Of course, Google has its own problems[0]. But the inability to use the Messages app to communicate securely with Android users[1], is solely 100% Apple's decision. Apple does not need to ask permission or coordinate with any other company to increase that security, they would just need to throw a messaging app up on the app store. Heck, they wouldn't need to support iMessage on Android. They could throw a messaging app up that had no encryption other than that it worked over HTTPS and data instead of SMS when messaging iOS users, changed nothing about the capabilities or features that they supported for non-iMessage users, and even only doing that -- if Android users could download it and set it as their default SMS client on Android then iPhone security would be better. ---- As a comparison here, if Signal dropped support for iOS tomorrow, would you blame Apple for not building support for Signal into iOS? No, that would be absurd to suggest. No one would claim that Apple had some obligation to support the Signal protocol or make Signal compatible with iMessage, or to build an open protocol -- we would all correctly point out that Signal decides where to make its app available. The same is true of Apple. The fact that you literally can't make many Messages conversations secure without completely abandoning the app and using a separate 3rd-party service for those conversations -- it is purely and entirely the result of a decision that Apple has made. ---- [0]: And in fact their proprietary encryption standard is no better than Apple's and they're pulling the exact same crap as Apple is for the same flimsy reasons. [1]: Note that I don't say non-Apple users, you can have an iMessages account through other devices and you still won't be able to use it with an Android phone number.
- Aaargh20318 3y agoThey have already announced they will add support for RCS this year (https://9to5mac.com/2023/11/16/apple-rcs-coming-to-iphone/ https://9to5mac.com/2023/11/16/apple-rcs-coming-to-iphone/), so not exactly a protocol released 32 years ago. It’s probably coming in iOS 18 Still unencrypted though, because the RCS standard does not include encryption.
- yackback 3y agoRCS is unencrypted unless you use Google's closed garden Google Messages' extensions. Apple is apparently working with GSMA to add encryption to the standard though. (They probably wouldn't add RCS otherwise.)
- astrange 3y agoThey would if a regulator made them. They're adding it because China requires it.
- danShumway 3y agoThis is getting downvoted, but it really does feel like a variant of the wrench problem: https://xkcd.com/538/ https://xkcd.com/538/ It's already incredibly hard to get people to use secure messaging systems. Downgrading to SMS isn't necessarily wrong (it's become harder to get people to use Signal now that it's dropped support for SMS), but it's a huge hole and effectively means that many customers will never have a significant number of their conversations encrypted. That's a boring security hole, sure. But at some point you have to think about UX as being a part of security, and a messaging system that isn't cross-platform is hard to call secure, because good luck trying to get your contacts to all use it. People get upset about this, but the reality is it does not matter what encryption scheme a messenger is using if it's impossible for you to get your contacts to use it. The same way that it does not matter how secure your 2FA system is if you can't get people to turn it on. I felt like on net Signal's support for SMS was a boon for security more than a hindrance because it made it easier for me to get people to sign up for Signal. In contrast, Signal's take was that having a secure and insecure service bundled up into the same messenger would on average make people more lax about security and would make it harder for them to make strong security guarantees. They viewed SMS support essentially as a security vulnerability. I do wish Signal had kept SMS and tried harder on the UX, I honestly feel somewhat strongly that removing support made secure messaging harder -- but while we can debate the security downsides and the onboarding downsides, I also have grown to kind of see their point? And iMessage falls very squarely into that problem, except with Signal I can at least tell my contacts how to get it. I don't know, it feels petty but like... if you have secure encryption but it doesn't get turned on for a bunch of messages, then that does seem like it has a security impact. I don't think that's a complicated or controversial thing to say, it's no different from calling out that some chat services require E2EE to be opt-in instead of opt-out. Good security requires thinking about that kind of stuff. It's the wrench problem. You're not going to get spied on by a quantum computer. You're going to get spied on because there's a decent chance that ~50% of your contacts or more aren't on iPhone and you'll be talking to them in plain text. And realistically for most users, switching to a cross-platform E2EE messenger that allows them to use one consistent service for all of their encrypted conversations is going to be meaningfully more secure even if it doesn't have quantum-resistant encryption. The most important problem for any secure messenger to solve is how to get people to use it. Sometimes that means compromising on other security standards, sometimes it means being harsher about security standards that would otherwise be optional. Sometimes it means caring about availability and onboarding, and not sending the majority of messages in an easily intercepted plain-text format.
- carstenhag 3y agoBarely anyone uses sms nowadays. People use WhatsApp, FB Messenger and co (outside of the USA).
- subtra3t 3y agoI think people who downvoted you did so after reading just your first sentence and not the entire comment. Outside of USA, I don't think anybody uses SMS for anything other than the occasional OTP or bank message. In India, nobody used anything other than WhatsApp till a few years ago. Now, teenagers use Instagram's chat feature and WhatsApp, and middle-aged adults use FB Messenger and WhatsApp.
- timeon 3y agoI do not use Meta apps. I use just SMS/iMessage and Signal. So most of the time it is SMS, since this is outside of USA and not many people use Signal. But even I send 'green bubble' from iPhone to iPhone sometimes. If there is no good internet coverage.