5 ms·
So if I get this right, the vulnerability is that Apple could sit in between you and your friend, impersonating each to the other while relaying and reading you
by stellar678 13y ago
So if I get this right, the vulnerability is that Apple could sit in between you and your friend, impersonating each to the other while relaying and reading your messages.
This seems about as vulnerable as the certificate authority/public key infrastructure system used for SSL, code signing, etc... We're always delegating to another party the responsibility of authenticating the person on the other side of our messages/web browser/signed software that we run. In the case of iMessage, Apple is responsible for authenticating your friend. In the SSL or signed code case, the certificate authorities are responsible. Seems that both Apple and CA companies might be subject to the same legal pressures to eavesdrop on people.
- fsckin 13y agoNot quite. A CA signs your public key. You never give anyone the private key, because... well, it's private.
- agwa 13y agoYou're not giving anyone your private key here, either. stellar678 is basically correct - Apple, like a CA, is vouching for the authenticity of users' public keys. The only difference is superficial: a SSL CA signs a certificate and the validation is done without needing to contact the CA, whereas with iChat the public key is validated by virtue of coming from Apple. Just as a CA can sign a malicious certificate, Apple can send you a malicious public key.
- hrjet 13y agoI wouldn't call that a superficial difference. Sending a malicious public key from a central server is easier than injecting a public key into a network stream. The former requires just a single entity to be compromised. The latter requires a compromise in the network in addition to a compromise in the CA.
- fsckin 13y agoExcept in the iMessage scenario, Apple generates (and keeps) a copy of the private key so you can recover a lost device by signing into iCloud on a new phone.
- agwa 13y agoThat's not what these researchers found. They found that each device has a distinct private key, and that the sender of an IM actually sends a separate message to each device, encrypted with the appropriate key. Do you have a source for your claim?
- mikehotel 13y agoWhile Apple boasts of "end-to-end encryption" it's pretty clear that Apple itself holds the key -- because if you boot up a brand new iOS device, you automatically get access to your old messages. That means that (a) Apple is storing those messages in the cloud and (b) it can decrypt them if it needs to. From http://www.techdirt.com/articles/20130405/01485922590/dea-accused-leaking-misleading-info-falsely-implying-that-it-cant-read-apple-imessages.shtml http://www.techdirt.com/articles/20130405/01485922590/dea-ac...