4 ms·
>(if I understand it correctly) the cryptography is solid The issue is that iMessage outright ignores a long understood challenge in the APPLICATION of cryptog
by mapgrep 13y ago
>(if I understand it correctly) the cryptography is solid
The issue is that iMessage outright ignores a long understood challenge in the APPLICATION of cryptography, namely knowing when to trust that someone is REALLY giving you their public key rather than being man-in-the-middled.
While this is a thorny challenge there are well understood, if imperfect, ways of addressing it that have been around for decades. At minimum it works like ssh, where you get a warning when an unfamiliar new key is presented and decide whether to trust it or not. More sophisticated is the certificate infrastructure around TLS/SSL where some effort is made to bring semi-trusted third parties into play.
These are all flawed solutions, the problem remains essentially unsolved. But any truly secure system based around public keys has some mechanism that addresses this challenge.
The issue with iMessage is that 1. Apple did not attempt to address the key exchange problem, which would maybe be fair enough on an "easy" consumer product with weak security claims but then 2. Apple made strong security claims very publicly and 3. even said a counterfactual, that it had no capability to intercept messages.
THAT is what is disingenuous: Apple implements public key cryptography, which since its inception and at its very heart raises difficult challenges around key exchange; Apple chooses to ignore these challenges; Apple then claims strong public key security. Either attempt to address the challenges like everyone else, or don't make the security claim, you can't do both.
- Spooky23 13y agoI disagree. The flawed systems are SMS and predecessor systems like alphanumeric pagers, where your messages are archived indefinitely in a database by the carrier. Remember the Wikileaks release of all of the pager traffic in lower Manhattan on 9/11? In my mind, the NSA/PRISM stuff is a meta-problem that is just something that is hanging out in the background. I work in enterprise IT, I'm not a dissident, drug dealer or whistleblower, so I'm more worried about incompetent carriers and other hostile parties than the NSA. So iMessage gives me encrypted message content that may be readable retrospectively by the NSA, and is almost certainly "tappable" by normal law enforcement. The reality is, that's about as good as you are going to get outside of a defined community of interest. My employer has highly secure voice and text solutions available for key personnel, for instance. Perfectly secure communications won't be available to the masses, because the operators of those systems face liability.
- bloopletech 13y agoWhats the liability difference between the systems at work and the systems for the general public? Strong crypto is, and should be, available to everyone.
- Spooky23 13y agoThe law. Common carriers are required to to have "tappable" systems if the system is deemed to replace phone conversations.
- kabouseng 13y agoThe biggest difference is ease of use. The more secure a system, the less user friendly it tends to get, and that is the cause why the general public don't get secret and top secret cryptographic products...
- mapgrep 13y agoThis ignores the context of the system, which is everything in this controversy. Apple did not say, "Here's iMessage, it is much more secure than SMS." Apple said (in essence), "Here's iMessage, we couldn't tap it if we tried." THAT is false, and all of the nice things you point out about iMessage aren't in dispute and don't have anything to do with the glaring inaccuracy of Apple's claim.
- Spooky23 13y agoThey didn't say that. Previously they said: "no one but the sender and receiver can see or read [FaceTime calls and iMessages]. Apple cannot decrypt that data." Now, they are saying "iMessage is not architected to allow Apple to read messages". They key message is: Apple cannot decrypt or read your data. That's all they said. They didn't say "Apple will not lawfully provide iMessage encryption keys to the government" nor "Apple will not provide the secret key for the iPhone CA to the government upon request/demand" nor "Apple will not provide iMessage data to the police." When a secret court compels you to remain silent, what isn't said is critical.