38 ms·
Without open source, end to end encryption is useless. It's not hard to hide a piece of code that defeats the encryption in closed source code.
by crypto_throwa 1y ago
Without open source, end to end encryption is useless. It's not hard to hide a piece of code that defeats the encryption in closed source code.
- another_twist 1y agoCurious, is there a poc somewhere demonstrating an attack like this ?
- joaomacp 1y agoSure: plain_msg = decrypt(encrypted_msg) send_to_nsa(plain_msg)
- __spooky__ 1y agoiMessage is end to end encrypted. Although Apple says it secure and the courts and FBI seem to not be able to get it in, it is still closed source.
- rpdillon 1y agoJust don't back it up to iCloud!
- yamazakiwi 1y agoNot able to get into it legally or without consequence, it is not infallible.
- bigiain 1y agoI can't tell if I'm being paranoid or just realistic, when I suspect that FBI/Apple fights over decrypting/unlocking iPhones or iMessage are just part of Apple's security theater. If I were Evil-Tim-Cook, I'd have a deal with the FBI (and other agencies) where I'd hand over some user's data, in return for them keeping that secret and occasionally very publicly taking Apple to court demanding they expose a specific user and intentionally losing - to bolster Apple's privacy reputation.
- throw0101a 1y ago> If I were Evil-Tim-Cook, I'd have a deal with the FBI (and other agencies) where I'd hand over some user's data, in return for them keeping that secret and occasionally very publicly taking Apple to court demanding they expose a specific user and intentionally losing - to bolster Apple's privacy reputation. The FBI wants its investigations to go to court and lead to convictions. Any evidence gained in this way would be exposed as coming form Apple; notwithstanding parallel construction: * https://en.wikipedia.org/wiki/Parallel_construction https://en.wikipedia.org/wiki/Parallel_construction As for other agencies, I'm sure many have exploits to attack these devices and get spyware on them, and so may not need Apple's assistance.
- 14 1y agoI imagine if you have the information parallel construction becomes trivial.
- worthless-trash 1y agoThe killers app for ai.
- MangoToupe 1y agoMaybe. I think they'd have a hard time keeping that under wraps—governments aren't typically very careful (and the FBI is about as careful as a bull in a china shop) about not showing their hand when it comes to charging people. If you're strict about keeping certain info on certain channels, smart observers would notice if someone were snooping. For instance, if someone shared something incriminating in a group chat and got arrested, and that info was only shared in the group chat, they'd have to silence everyone in that group chat to ensure that the channel still seemed secure. I don't think at least our government is that competent or careful. But also, people wayyyy overhype how much apple tries to come off as privacy-forward. They sell ads and don't even allow you to deny apps access to the internet, and for the most part their phone security seems more focused on denying you control over your own phone rather than denying a third party access to it. I think they just don't want the hassle of complying with warrants. Stuff like pegasus would only be so easy to sell if you couldn't lean on the company to gain access, and I think it'd be difficult for hundreds of countries to conspire to obscure legal pressure. Finally Apple generally has little to gain from reading your data, unlike other tech giants with perverse incentives. Of course this is all speculation, but I do trust imessages much more than I trust anything coming out of meta, and most of what comes out of google.
- paulryanrogers 1y agoiMessage backups in the cloud are subject to warrants. Even if you don't use iCloud backups, can you be sure everyone you communicate with also abstains?
- stingraycharles 1y agoAren’t those encrypted with a key that lives on your device only?
- ants_everywhere 1y agohow would you restore if you lost your device?
- bri3d 1y agoBackups with Advanced Data Protection also enroll: * Recovery Keys * Recovery Contact (someone who holds your recovery key in key escrow)
- ants_everywhere 1y agoright, the ability to recover implies keys exist outside the device. even if they gossip keys to other devices you control, there are lots of people with only a single apple device.
- bri3d 1y agoOnly if you enable Advanced Data Protection, but in that case, yes, absolutely
- saagarjha 1y agoIt is actually quite difficult.