5 ms·
The problem here is that you need to know the other person's encryption key. Since I'm not warned whenever you get a new device, I have no idea how many keys ar
by mrmaddog 13y ago
The problem here is that you need to know the other person's encryption key. Since I'm not warned whenever you get a new device, I have no idea how many keys are assigned to you. Hence, the key distribution problem still remains.
- pilif 13y agoOh I agree with you. The public key directory thing breaks the whole system. No question there. I totally agree with the original article. I just wanted to highlight the fact that devices DO inform the user when a new key gets added. So if the directory didn't serve fake public keys and if the devices didn't have code to not warn if certain keys were added, then you would have the guarantee to only talk to me. Sure: I could add more devices, but I have the full control over them, so it doesn't matter to you how many devices your client encrypts the message for because I have the full control over what devices I authorize or not. That of course would be the perfect world, when in fact, Appke probably adds surveillance keys to the directory server and doesn't warn the user as such keys are added. Don't use iMessages for anything you would not want Apple or the NSA or any other law enforcement agency to read. But then again, don't use any of email (envelope in the clear), SMS (your carrier can read it), any other IM service (same issue as iMessage), snail mail (can be read by the post office and anybody opening your letter box when you aren't there).
- sneak 13y ago> I just wanted to highlight the fact that devices DO inform the user when a new key gets added. This is totally false. When you are sending iMessages to someone, you get no UI indication at all when they buy new devices and add them to their Apple ID. You are confusing it with adding devices to your own account. We're talking about RECIPIENT keys.
- msh 13y agoI would not want the sender of messages to me to be notified about my devices.
- sneak 13y agoWell, they are now—if they MITM their connection to the APNS. Messages they send get encrypted to all the devices associated with your iMessage account. The data's available to them from Apple, though there is no UI for it.