6 ms·
Remember this Pre-Snowden disinformation? 'US DEA upset it can't break Apple's iMessage encryption' http://appleinsider.com/articles/13/04/04/us-dea-upset-it-
by mooredinty 11y ago
Remember this Pre-Snowden disinformation?
'US DEA upset it can't break Apple's iMessage encryption'
http://appleinsider.com/articles/13/04/04/us-dea-upset-it-cant-break-apples-imessage-encryption http://appleinsider.com/articles/13/04/04/us-dea-upset-it-ca...
I still can't believe so many people fell for that.
- andreyf 11y agoDid I miss something? Why do you think the DEA can break iMessage encryption?
- nitrogen 11y agoOne doesn't need to break any encryption if one has other means of accessing the plaintext. There's a difference between disinformation and misinformation. Even the truth, told selectively, can be disinformative.
- kylek 11y agohttps://en.wikipedia.org/wiki/Limited_hangout https://en.wikipedia.org/wiki/Limited_hangout
- andreyf 11y agoOne should be careful not to live in or spread in paranoia where everything is a plot to deceive. For anyone looking at the source material and judging reasonably, there was no deception. Perhaps some journalists got a little carried away, but I'd blame that on the pressures of their industry, not malice. The original DEA slide that was leaked says something very simple: traditional interception techniques do not work on end-to-end encrypted message services (e.g. iMessage). They can't just ask (or get a judge to ask) a law-enforcement-friendly cellular provider to tap the line and CC them on anything someone does. This is true for BBM and WebRTC and many other ways of communicating, as well.
- throwaway7767 11y agoThey can surely force by legal means Apple to give you the wrong key for a recipient, thereby defeating the end-to-end protection. This is the danger of the new wave of security tools that want to "solve" the hard problems (such as key verification) of secure messaging. The hard problems are still there, they're usually just bypassed by centralising trust, which creates a very tempting target for government legal pressure.
- Karunamon 11y agoThat implies some kind of evidence has come out to suggest that this article is false. Could you point to such evidence, please?
- eyeareque 11y agoThey were bothered that their "stingray" like devices could not capture the messages. But fear not, they can still get it from Prism or Xkeyscore (or whatever they call it).
- andreyf 11y agoFalse and false. The article linked complaints that traditional legal interception means do not work. Those are the ones where they nicely ask the cellular providers for the data. It's not about "stingray like devices", it's about sending a letter and getting the data. End-to-end encryption protects against that, be it iMessage or BBM. Prism collects data directly from companies that participate, and Apple has said they do not have access to iMessages contents. There was some speculation about courts being able to force Apple to abuse their authority as the iMessage certificate swapper, but I've seen no evidence or convincing argument for that to be the case. Xkeyscore does not collect any data, but searches it.
- task_queue 11y agoApple is still subject to NSLs, and like Lavabit, can be coerced into operating in such a way that they're able to provide message contents to authorities while advertising that they are in fact secure.
- LLWM 11y agoIt's much simpler than that. Their marketing team gets their material from the R&D team, and neither group knows about the NSLs, because why would they? Only compliance and a few people on legal know, and everyone hates them already anyway.
- im3w1l 11y agoYou can't use the super secret laser snooper on small fish. So even if it exists, it's still reasonable to have other venues.