4 ms·
If the secret part of an asymmetric key is generated on a device and it lives and dies on that device, Apple doesn't have it -- the device does. Messages encryp
by defap 13y ago
If the secret part of an asymmetric key is generated on a device and it lives and dies on that device, Apple doesn't have it -- the device does. Messages encrypted using the public part of that key can only be decrypted with a device that has the key.
But he wasn't describing a technique for decoding messages that have already been sent. He's only claiming an attack on future messages.
With control of the CA, the attacker can just advertise a bogus public key for the victim in the key server, giving him access to future messages. He can now intercept and relay.
- cclogg 13y agoOn the theme of iMessage, do you guys recommend using it over regular SMS? Are there pros/cons as far as privacy go? (genuinely wondering)
- szc 13y agoFuture messages would need to be encrypted using the new key. If the protocol announces when a new key is added to the "encryption set" how can you get away with that? (when you add a new device to iMessage all the other devices "see" the new device being added and tell you about it). It would be great to see a comparison between OTR and iMessage.
- fpgeek 13y ago> (when you add a new device to iMessage all the other devices "see" the new device being added and tell you about it) And who writes the software on those devices that tells you about the new key again? Based on what I'm reading, absent physical access to one of the devices authorized for using iMessage at the time, past iMessages should be safe. But, given the apparent ease of adding new authorized devices, tapping future iMessages sounds like it wouldn't be hard.