4 ms·
Re-read what I wrote, and think about what it means. I think it means you have a false belief about the limits of the system. If there were any additional
by embolism 13y ago
Re-read what I wrote, and think about what it means.
I think it means you have a false belief about the limits of the system.
If there were any additional barrier preventing Apple from provisioning iMessage entpoints, iPhone users would not be able to activate iMessage with only their Apple ID.
Wrong. Apple doesn't have your password. Only a hash. Verifying against the hash allows apple to add another device to the backend but does not unlock the keys to the message history. Only the password does that.
There is some understanding about how the protocol works here: https://news.ycombinator.com/item?id=5493514 https://news.ycombinator.com/item?id=5493514
There are other sources around the net that you can refer to to understand more about how such a protocol can be built, but I don't have a lot of faith in you as a conversation partner now that you've demonstrated that you can't be bothered to inform yourself before responding incorrectly with condescending certainty.
- jmillikin 13y ago> Verifying against the hash allows apple to add another > device to the backend but does not unlock the keys to > the message history Isn't this what I've been claiming? If Apple can provision additional endpoints, they can provision a virtual endpoint which receives messages and forwards them to third parties.
- embolism 13y agoDoing that wouldn't provide access to the history. Unless they always do this for every single device, there is no mountain of data to analyze. The point we are discussing is not whether iMessage provides perfect security. The point is that iMessage doesn't give Apple a stockpile of personal data that can be indiscriminately targeted at any time the way GMail can. I'm not saying it's a panacea or arguing in favor of Apple. iMessage proves that Google could engineer a system to protect users privacy by not stockpiling data if they wanted to, which you have incorrectly denied.
- jmillikin 13y ago> iMessage proves that Google could engineer a system > to protect users privacy iMessage does not protect privacy, because Apple is capable of intercepting your messages messages and sending them to third parties. To be a private communications medium, it should be considered impossible for messages to be intercepted. The only thing worse than a product that doesn't offer privacy is a product which claims to, but actually doesn't. IMO, Apple's claim that iMessage is private is irresponsible because it endangers people who take that claim at face value.
- LoganCale 13y agoAny evidence of this? I had read and posted about the same, but more recently found an older discussion on HN (which, absurdly, I cannot find now) which explains in more detail how the end to end encryption actually works and does so in a way that Apple almost definitely cannot intercept the plaintext messages.
- jmillikin 13y agoSee my first post in this thread. Short version: Users can enable iMessage on their devices by signing in to their Apple account. Therefore, Apple is capable by themselves of configuring which devices receive messages from particular accounts. Therefore, Apple is capable of configuring a device you do not control to receive your messages.
- embolism 13y agoYou are pretending that this is equivalent to asserting that they have access to arbitrary message histories, which they in fact do not.
- jmillikin 13y agoNo, I'm not. At no point have I ever claimed that being able to intercept messages is equivalent to having access to previous messages.