4 ms·
ADP is a total joke if it doesn't also disable plaintext backups for the people you're talking to
by xvector 1y ago
ADP is a total joke if it doesn't also disable plaintext backups for the people you're talking to
- Jtsummers 1y ago> ADP is a total joke if it doesn't also disable plaintext backups for the people you're talking to Do you consider all security to be a joke then? If you send me a message, how will you actually guarantee that I do not make a copy of it once it's on my own computer?
- modeless 1y agoThere's no guarantee, but some apps intended for security actually make at least a minimal effort to be excluded from plaintext backups, rather than intentionally sending their encryption keys to the backup service that just happens to be run by the same company...
- Jtsummers 1y agoOk. So you concede that there is no way for you to ensure that messages you send me, that I can decrypt, are left unreadable by anyone but me. So what secure communication system should we be using given that none of them can guarantee that the recipient doesn't leak information to another country by choosing to use a compromised version of the client?
- modeless 1y agoMy complaint is not about guarantees, it's about defaults. Default non-e2e-encrypted backups of message encryption keys are the problem here. No system can guarantee absolute security, but that doesn't mean they're all equivalently bad. Some are definitely more secure than others, and defaults have a lot to do with it!
- Jtsummers 1y ago> Some are definitely more secure than others, and defaults have a lot to do with it! That's great, naming those would have been better though since it would have actually answered the question.
- fmajid 1y agoYou are attacking a straw man. The risk is the your correspondent does not have ADP enabled, as it is not on by default, and not even offered in some authoritarian countries like the U.K., so even without their cooperation they can still get their key. I don’t know if iMessage implements Perfect Forward Secrecy, but at the very least they will be able to read all your messages moving forward.
- j16sdiz 1y agohttps://support.apple.com/en-us/102651 https://support.apple.com/en-us/102651 > With Advanced Data Protection, the number of data categories that use end-to-end encryption rises to 25 and includes your iCloud Backup,... > iCloud Backup (including device and Messages backup) (3) > (3) .... Advanced Data Protection: iCloud Backup and everything inside it is end-to-end encrypted, including the Messages in iCloud encryption key.
- modeless 1y agoYes, your backup is e2e encrypted after you enable the off-by-default ADP. But some of your friends probably didn't enable ADP, and the keys to decrypt your messages to them are stored in their backups which Apple can read at will.
- unloader6118 1y agoThere are some fundamental different between two ecosystems. On Google, the Google Drive and Photo are encrypted to a key owned by google. On iCloud, the iCloud Drive and Photo are encrypted to your account key. In which, without ADP, this key is shared with Apple. When ADP is enabled, Apple does not store this key. iCloud Backup is stored with the same technology as iCloud Drive. When it comes to lost password account recovery: - Google can just reset your password, and your drive and photo are still accessible. All barrier are procedural, not technical. - iCloud (with ADP), they can still reset your password, but then your icloud drive and icloud photo are loss forever. There are some trade off ..: - Lost password recovery experience. _Some_ user will lost their password anyway. How high should the bar be? - Cloud first? or local device first with cloud backup? - Are you giving the cloud data same protection as local device? In google's solution, they put the google drive data at risk... In apple's solution, it need extra steps to ensure you have proper account recovery flow covered.
- modeless 1y agoThat's all fine, but tangential to my complaint, which is about iMessage specifically. iMessage, as a system that strongly promotes e2ee as a core feature, should not be backing up its encryption keys to non-e2ee iCloud backup in any scenario. Messages should fall in the same category as keychain passwords and (yes!) Memoji, backups of which are always end-to-end encrypted even when ADP is not enabled. In fact I would say calling iMessage an e2ee system is false advertising until this is corrected. Reasonable people would assume that an Apple system advertised as e2ee would make an effort to prevent Apple servers from having the keys to decrypt most iMessages, while the reality is with these defaults it's likely that a large majority of iMessages can be decrypted by Apple servers at will.