iMessage's 'End-To-End' Encryption Hardly Better Than TLS
tomshardware.com
tomshardware.com
Abstract:
> Apple’s iMessage is one of the most widely-deployed end-to-end encrypted messaging protocols. Despite its broad deployment, the encryption protocols used by iMessage have never been subjected to rigorous cryptanalysis. In this paper, we conduct a thorough analysis of iMessage to determine the security of the protocol against a variety of attacks. Our analysis shows that iMessage has significant vulnerabilities that can be exploited by a sophisticated attacker. In particular, we outline a novel chosen ciphertext attack on Huffman compressed data, which allows retrospective decryption of some iMessage payloads in less than 218 queries. The practical implication of these attacks is that any party who gains access to iMessage ciphertexts may potentially decrypt them remotely and after the fact. We additionally describe mitigations that will prevent these attacks on the protocol, without breaking backwards compatibility. Apple has deployed our mitigations in the latest iOS and OS X releases.
Paper (PDF): https://www.usenix.org/system/files/conference/usenixsecurit...
And in a side note, that's why I dislike that journalists have been trained to remove so many words from headline copy by default.
The underlying problems have not been fixed. They added some band aids to prevent the specific attack Green found, yet the protocol is still a big mess, an ad-hoc design that is doing a couple of things that every cryptographer who knows a thing about modern crypto designs knows to avoid.
If that's the "fix" you can see why it hasn't been done and we instead have several mitigations instead.
Signal is definitely moving things in the right direction but I wish there was more research in this "signal integration" space. Do you know of any research here?
http://blog.cryptographyengineering.com/2016/03/attack-of-we...
but basically totally broken by design.
http://www.interworx.com/community/is-ssl-tls-broken/
further tls:sender,recipient and server can read the message
end to end:only sender and reciever can read the messages even though a sever facilitates connecting them to each other.
> but basically totally broken by design.
> http://www.interworx.com/community/is-ssl-tls-broken/
Can you please excerpt some quotes from that article which support that claim?"Secondly, there’s the implementation. This is a bit more tricky because there’s plenty of scope for influencing either the software implementations or the standards upon which that implementation is based." vs. http://www.theregister.co.uk/2015/09/15/still_200k_iot_heart...
And if you think the vulnerabilities of the shocking state of openssl stop at heartbleed (which is as obvious as backdoors get), you've obviously not given the code even a cursory glance over.
https obviously greater than http But if you trust it with your life you wont have a life. It's as simple as that. (and tls is basic compared to tor, and even that we have seen is broken to hell and back, or silkroad would still be running.)
Signal and especially OTR are the current state of the art. Apple went the security by obscurity route and once again proved it's inferior.
iMessage was advertised to protect the user's message in such a way that even Apple couldnt't read them, even if they stage a man-in-the-middle attack.
(disclosure: I have not read the article)
https://github.com/WhisperSystems/libsignal-protocol-java
Edit: Some more pointers for those interested: https://whispersystems.org/blog/signal-inside-and-out/
> In this work we analyze the iMessage protocol and identify several weaknesses that an attacker may use to decrypt iMessages and attachments. While these flaws do not render iMessage completely insecure, some flaws reduce the level of security to that of the TLS encryption used to secure communications between end- user devices and Apple’s servers.
A good end-to-end encryption should guarantee that as long as both clients have good intentions, nothing can reveal their communication. This is a much higher level of expectation.
And I don't care if pointing that out costs me mod points. Its seems on these types of conversations negative points are a mark of honesty.