Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> If you’re using an up-to-date iPhone to send a text message to another iPhone user, and the little bubble containing your message is blue, then neither Apple, nor your ISP, nor any law enforcement agency tapping into the transmission line is likely able to read the contents of the message.

That is incorrect and dangerous advice to give users.

As has been discussed before, as long as Apple controls the public key exchange process, they have the capability to intercept and decrypt your messages if they wish, or are compelled to do so.



Apple also controls the OS on both sides, and could silently push a "special" update to virtually anyone. If e.g. Abu Bakr al Baghdadi had an iPhone and was communicating with operations, and that phone could be identified, it'd be a race at NSA/TAO between compelling or technically subverting Apple to push such an update (if there is no other better solution), and the incoming Hellfire missile from CIA.

That said, iMessage in design and even implementation is utterly amazing compared to the normal quality of such systems from big companies. It is by far the most secure large-scale easy to use communications system available today. I think WhatsApp/Moxie-enhanced will probably surpass it when available, but that's an add-on application. iMessage is an out of the box default.


No matter how good iMessage may be, it's still a walled garden. It only provides privacy for the relatively privileged owners of iOS devices.


> Abu Bakr al Baghdadi had an iPhone and was communicating with operations,

I don't know what is more stunning; the blatant racism, or the fact that nobody seems to care about it.


I don't know what is more stunning, that you don't know who the man is OR how to use a semicolon OR that nobody else seems to care about neither.


How is that racist?


Anonbanker doesn't know who Abu Bakr al Baghdadi. So, if you think it's just some made up name it does come across as racist.


DanBC speaks truth, and I stand with egg on my face for playing the racism card, when it turned out I was actually the racist one for assuming the name was a joke.


Yeah, it's the name of the leader of Islamic State. That NSA and CIA are competing to kill him is just a statement of fact (which he'd gladly repeat if asked); it's not particularly racist, and doesn't even say anything about agreeing with the targeting decision.


When Apple's Privacy policy updated recently, the warrant canary was removed. Reading between the lines it looks bad :)


I'd never heard that term before. Here's the wikipedia article for anyone interested:

https://en.wikipedia.org/wiki/Warrant_canary

That's a really interesting concept thanks for bringing it to my attention.

If anyone's interested here's the first article I found discussing Apple removing their warrant canary:

https://gigaom.com/2014/09/18/apples-warrant-canary-disappea...


There's also the fact that iCloud backups are encrypted with keys that Apple controls. So even if messages are securely end-to-end encrypted, Apple can produce available iCloud backups.


As I understand it, Apple can subvert the privacy of future messages by silently adding themselves as another "device" for your messages, but this does not allow them to intercept and decrypt messages that have already been generated (i.e. before they add themselves). Correct?


I think the "silently" part is not possible with the current iOS codebase. They could patch that, but it's probably not even necessary since I occasionally have my desktop pop up as a "new device" again.

It loses auth for whatever reason (a bug? an os update?), has me sign in again, and then a "new device" message with my desktop name pops up on all of my mobile devices. I really have no way of telling if it is a reauth from my desktop or a third party that happened to know my desktop name.


What advice could one give that wasn't dangerous?


Assume that everything you send via iMessage can be intercepted [1]

[1] At least by an adversary with sufficient resources, leverage, and impunity (NSA, GCHQ, etc.)


Nobody has something that would fulfill your caveat, with the possible exception of a few larger countries. If you are the named target of the NSA, they will find a way into your communications.

This war really has little to do with find the way into a named person's communications; it has much more to do with finding the names of people whose communications they want to see.

For that, iMessage is devastating (assuming it is implemented and behaves as marketed, a pretty big assumption).


> If you are the named target of the NSA, they will find a way into your communications.

This is completely false. Use good cryptography properly, and make sure your system isn't hackable. PGP + Tails is a popular combination for Glenn Greenwald and others like him.


"isn't hackable" isn't feasible to the layman, and I'd argue for even security professionals. You can take measures to make it difficult to hack, but to say you can make a system unhackable through those means is false as well.

There are just too many layers of abstraction to exploit to say a system isn't hackable.


Greenwald also used cryptocat at a time when its crypto could have been broken by an NSA intern in an afternoon. "Greenwald uses this" is perhaps not a ringing endorsement of a product's security.


Until an intelligence agency manages to bug your home or image your machine like it seems they sneakily did with Ross Ulbricht (by stealing his laptop).

And in a lot of countries you are automatically jailed for not handing over your encryption keys when asked.


Could you provide a citation for "automatically jailed for not handing over your encryption keys" - I have not heard that before.



RIP Act in UK. Certainly detained (witness what happened to GG's partner in LHR).

Not automatically jailed, but can be jailed when they want the key and not turned over.


Tails is definitely hackable through the browser.


slightly less hi falutin: adversary with access to a relevant apple employee?




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: