3 ms·
I think it’s “provably secure” in the same sense that end to end chat apps can be provably secure. You can compare codes in the apps to prove that your conversa
by MarkSweep 2y ago
I think it’s “provably secure” in the same sense that end to end chat apps can be provably secure. You can compare codes in the apps to prove that your conversation are noting man-in-the-middles. You still have to trust the software running on both ends to be doing the right thing.
Apple goes further than standard end-to-end encryption messaging by adding a software attestation component to the hand shake. And they say they will publish the server side software for researchers to poke at. And there is a certificate security style log so you can be sure that the server side software is published.
I’m not saying the system is good or works, I’m just saying don’t totally discount the idea of designing a system that has provable security properties.
- AlexErrant 2y agoI'm engaging in pedantry here, but computer science has proofs. When we have hardware level security vulnerabilities, I trust my device as far as I can throw it. Proofs are only sound and valid in maths. https://securityintelligence.com/news/apple-m-series-chips-hardware-flaw/ https://securityintelligence.com/news/apple-m-series-chips-h... Everything Apple's done yields verifiable security - but it's not "provably secure". The two are distinct, and when you try to sell to me with bad language I get squinty-eyed. Especially since "confidential computing" already exists on x86/AWS, and I struggle to see the difference. It just sounds like Apple marketing to me. > don’t totally discount the idea of designing a system that has provable security properties They're only as provable as your assumptions/givens. Given a hardware vuln, where is your security now?
- shusson 2y agoAgreed, I think a lot of people do not appreciate the complexity of software systems. If we could prove software, we wouldn't have bugs. https://wiki.c2.com/?ProofsCantProveTheAbsenceOfBugs https://wiki.c2.com/?ProofsCantProveTheAbsenceOfBugs
- MarkSweep 2y agoThanks for this reply, it was more informative than the original "dunking" one.