You don't even need "backdoors" in encryption. Existing lawful-intercept on Slack, Discord, Facebook, Google and all the wireless carriers will net just about anything you could ever want to know.
You don't even need "backdoors" in encryption. Existing lawful-intercept on Slack, Discord, Facebook, Google and all the wireless carriers will net just about anything you could ever want to know.
The last time I saw this matter being discussed here, tptacek was getting pretty upset at people who were suggesting that baseband processors presented a security threat. He's a security expert with a reputation to uphold so I expect he's probably right, but I would still like to see a detailed explanation of why he's right.
For a reason I don't understand, this topic seems to illicit a lot of insults, when calmly assuaging fears would doubtlessly be more effective.
I was under the impression that iMessage was end-end encrypted. So unless Apple has a secret backdoor built into their systems, nobody should be able to access those messages correct? Wireless carriers are just sending my encrypted messages over their networks.
What am I missing?
Do you believe my cell service provider could decrypt my HTTPS connections to my bank?
Since cellphones have a BMC that isn't user owned, which does have access to the full system memory (rather than being an isolated peripheral modem), and since OTA firmware updates can be pushed by the "infrastructure" (including fake 'towers' setup by TLAs, criminal hackers of other sorts, and hobbyists) containing code to compromise and silently ex-filtrate any data (including those keys, or even just the conversation directly); it is an inherently insecure environment.
This needs to be from the PCB traces, all of the component tolerances, all of the chips, all of the firmware (even the ROMs that are actually baked in ROMs on the chips), the bootloader, OS, and entire userland.
This is required not just for the host system but also the human interfaces and peripherals.
I hope we will be able to reach that point with a RISKV system at some point; but the various proprietary interfaces that require licences for implementation/etc might make this problematic. I am for standards, preferably completely free, but FRAND and non-restrictive on meeting the above goals might be good enough. The platform has to be fully open-book, but some of that book can be covered by reproduction limitations for a limited time. (I'd prefer standard patent duration at most, as this stuff NEEDS to become the digital version of paper at some point; and within my lifetime would be nice.)
If you can read your message history from an iPhone, Apple is just one silent update away from reading it as well.
To answer to that. Maybe the problem is in those hardwares and operating systems that do not have backdoors?
I don't think you understand what end-to-end means.
So he's right theres no such thing as true end to end on common cell phones.
Hardly the only application though, is it?
That's kind of what HDCP is, so it could be done on an embedded display too.
I do not find that this comment proven, neither in your profile, nor in the context of this thread.