3 ms·
The War on Crypto Terror
- plg 11y agoIf Apple doesn't hold the encryption keys for an iMessages chat (they reside on the participants' phones), they can't "hand over" the conversation. Well I guess they can hand over the encrypted conversation. What am I missing?
- noondip 11y agoPublic keys are fetched from Apple's servers; the entire key infrastructure is controlled by the fruit co. http://blog.quarkslab.com/static/resources/2013-10-17_imessage-privacy/slides/iMessage_privacy.pdf http://blog.quarkslab.com/static/resources/2013-10-17_imessa...
- plg 11y agoSure but private keys are on the device, no? Doesn't this mean that without access to the device, one can't decrypt messages?
- xyzzy123 11y agoApple could supply the user with a "fed key" and MITM, when user asks for their friend's key. This is the "public key distribution problem". It's ultimately a social problem (how do I identify that string of bits B corresponds with person P?) and can't be solved entirely in software. Some solutions: 1) Certificate authorities 2) Web of trust 3) Key transparency 4) Gossiping 5) Eschew automation, OOB manual verify There more, but ultimately all of them are ultimately trading off: a) Centralised versus decentralised trust b) Convenience versus security c) Opacity versus transparency And in particular, whether users need to understand what public keys are, and how to verify them.
- mike-cardwell 11y agoWhen you send a message to somebody, you need their public key. With iMessage, you're relying on Apple giving you the public key of the real recipient and not a public key belonging to themselves so they can decrypt, view it, encrypt with the recipients real public key and then forward on the message. Imagine if you were using PGP and every time you wanted to send an encrypted email to somebody you asked me for their public key and trusted whatever I gave you.
- plg 11y agoAhhhh man in the middle yes of course you're right That's different though than Apple "handing over the encryption key" to someone's conversation. ... that's Apple actively deceiving a user during a conversation ... Apple actively, intentionally, lying to users to say that their conversations are encrypted to Apple but in fact not. Assuming Apple is being honest and not doing this, what happens when the government asks Apple to "hand over the encryption keys"? Does this mean Apple has to agree to participate in a man in the middle attack?
- mike-cardwell 11y agoThe US government would just tell Apple to supply the plain text of any future messages going in and out of that particular account. How Apple goes about doing that is not their concern. Apple can do it if ordered to do so, so they must.
- deleted 11y ago[deleted]