Do we have reason to believe iMessage and Whatsapp are more secure?
Do we have reason to believe iMessage and Whatsapp are more secure?
WeChat has been proven to be a heavily monitored and censored network. Whatever security failings iMessage and WhatsApp have, they pale in comparison to what's in place for WeChat.
What's dangerous is convincing yourself that proprietary systems won't betray your trust.
I thought it was clear those words came from my mouth.
All the westerners I know in China don't send sensitive information through Wechat. It's just good to have a low trust stance by default.
You say the security failings of iMessage and WhatsApp pale in comparison to WeChat; I agree with parent comment and ask - in light of PRISM etc. - on what grounds can you say we should not be just as suspicious?
I also, separately, think that in aggregate Apple has incentives to make iMessage secure. While Tencent has incentives to share WeChat data with CCP.
These are among many reasons why the comparison was false equivalence. The world is not just black and white “secure vs not secure.”
What basis do you have for this certainty?
But your question is by nature setting up a false comparison. There is no observed censorship apparatus in place in the US. You can always pose "what if" scenarios about super classified efforts, but functionally there is no active system in place.
Compare this to the vastly-resourced, all-encompassing one operated openly and enthusiastically by the CCP.
Given societal norms I think there is a strong expectation that my iMessages will not be censored in the near future either.
This means there is little incentive for NSA to train and develop an actionable automatic censorship application.
Again, this is true even if they intercept, decode, analyze, commit physical action on the basis of the analysis, and store every one of my messages.
I suppose there is not really the same kind of overt deployed censorship in the US like there is in China. I do personally think that the NSA somehow gets most messages sent in the US, but I have no idea what they would do with it or if that hypothesis is reasonable.
Would I prefer that access be held by the US Government, which for all its faults is extremely engaged with and integrated into the global system, beholden to Law and a robust court system which enforces a strict set of checks and balances on its behavior, and is philosophically rooted in individual liberty?
Or would I prefer the CCP, which does not even recognize the concept of individual liberty, is beholden to no one but itself and its own desires, and ruthlessly upholds its iron and unquestioned (unquestionable, at least in China) will upon the entire nation with absolutely 0 oversight?
Yeah, gonna go with the US here.
Uhm yeah but countries do nothing when Russia annexes Crimea, what do you think they’d do if the US simply spies on them? Absolutely nothing. It’s literally happening right now and it’s public knowledge and “it’s just a matter of national security.” Case closed.
Now, is China any better? Of course not, and the CCP has countless policies which are far worse to their own people than the US. But the key question is -- do you live in or have any connection to China? If not, then I would go with the CCP surveillance because there is no obvious mechanism for such surveillance to harm you directly. On the other hand, if you live in a 5-EYES country (as I do), any data obtained from US surveillance can be used in parallel construction (or other not-entirely-legal methods). Hell, here in Australia our mass surveillance systems have been used to punish minor infringements such as littering.
Obviously I'd prefer not to be surveilled at all, but between the two I'd choose the one that has the smallest threat of direct impact on my life.
they can spy on your business dealings and potentially find material to blackmail you
If you think you're marginally more likely to be arrested and prosecuted for littering because of super secret iMessage collection... why not consider the marginal effects of turning a blind eye to (and contributing to the economic expansion of) an illiberal, anti-democratic power that, in your words, does "far worse to their own people than the US"?
They seem to already be comfortable collecting your data as they please and influencing various levels of your government. What harm could it do to enthusiastically profile yourself for them?
It's a bit silly to require every comment which critises the US to also have to include a disclaimer that "yes, I also think China/Russia/other-enemy-of-the-US is bad".
> They seem to already be comfortable [...] and influencing various levels of your government.
I'm really not sure what you're referring to. If you're talking about the Australian government, I'm not aware of any substantial evidence that the CCP has actually influenced our government. Our government is friendly with China and does many things against the interests of the public as a result, but there is far more evidence of just ordinary domestic corruption.
I will also point out that there is strong evidence that the US (in particular, the CIA) effectively helped facilitate a soft-coup in Australia in 1975 (in response to Menzies' threat to close Pine Gap because the US lied about what it was used for). Oh, and the CIA offered $24m of laundered money to the Opposition for that election in order to help them win -- if only there was a word to describe that...
So if we're going to point-score about foreign influence in the Australian government -- the US literally replaced our prime minister in a (to quote Victor Marchetti, a former CIA officer) "kind of Chile coup". But I'd love it if nobody interfered with other countries' democratically-elected governments.
The United States is not the leader in this process. It’s a kind of follower because the first government that publicly declared that China has to be contained was Australia’s government.
The government of Australia in 2008 had already issued a white paper clearly stating that if we do not contain China, if our allies don’t contain China, then even Australia will become a Chinese colony.
So the Australian government had already taken a clear position. We have a choice: we either contain China or we become a Chinese colony.
Then, in 2011, just immediately after the tsunami and earthquake, [Australian] Prime Minister Gifford came to Tokyo. She made a little trip up to Fukushima when she arrived, just to show she is not afraid, and then she gave a speech in Tokyo, saying very clearly that Australia and the United States, Japan, have to cooperate to hold back China.
At that time, the prime minister was Mr. Kan, and Mr. Ichiro Ozawa was a very influential politician. Ozawa believed in containment.
So, the Australian prime minister comes to Tokyo and tells the Japanese: “Get up. Deal with this issue. Face China.”"[1]
I haven't vetted any of this but FYI.
[1]http://japan-forward.com/asias-next-page-india-japan-must-sh...
Why did the citizens reward and vote in the party who pulled those election tricks.
Why would you blame the US but not bother to change the laws? This can happen again.
It's one of their constitutional rights. Their purpose is to act as a surrogate for the Head of State (currently Queen Elizabeth II) and the role was designed to mirror the process of the UK's Head of State -- the Queen picks her ministers and in theory doesn't need to choose the leader of the party with the largest number of seats.
Do I think it's a system that should be changed? Yes, but this is complicated by the need for a mechanism for double-dissolution (which cannot be automatic because it could then just be gamed to re-trigger elections).
> Why did the citizens reward and vote in the party who pulled those election tricks.
As is usual, propaganda. The laundered $24m wouldn't have been used to buy toilet paper.
> Why would you blame the US but not bother to change the laws? This can happen again.
Given that the US triggered and orchestrated the constitutional crisis in order to further their own foreign policy (which was confirmed by President Jimmy Carter to have been the case when he vowed that the US wouldn't do it again), I think it's entirely fair to blame the US.
In order to change the role of Governor-General you'd need a constitutional amendment. To say that it's effectively impossible to get a constitutional amendment passed in Australia is an understatement (only 8 amendments have been passed, out of 44 attempts in the past ~120 years -- and most of those were passed soon after Federation). One of those failed amendments was to switch Australia to a republic model which would've replaced the Head of State and Governor-General with a President -- but the overall set of rights given to the President would've been the same.
It should also be noted the inclusion of double-dissolution in our Constitution was somewhat controversial at the conventions during drafting, but was eventually agreed to be vital if the Senate was to have the powers it currently has. So we would need some mechanism to avoid deadlocks, and the lack of obvious alternative solutions to this problem results in most proposals just keeping the existing system but changing how the Head of State and Governor-General are elected.
Tell that to the forcibly disappeared political dissidents, or to the Uyghurs who are being "re-educated" as we speak.
And remember, even if you're not connected to China now, that can always change in the future.
My point is that if you have a connection to the US (as all 5-EYES and allied countries do), then today that has a more direct impact on your life than any theoretical future risk that the CCP will be able to have a direct impact over your life. The premise of this discussion is that you have to choose one or the other. I am well aware of the massive threat that is retroactive surveillance, which is why I would choose neither (obviously).
> Tell that to the forcibly disappeared political dissidents, or to the Uyghurs who are being "re-educated" as we speak.
Those are all people who have direct connections to China in some respect, and what has been done to them are all horrific human rights abuses. However, I don't see what that has to do with what I said.
The point I'm trying to make is that you're not taking into account the fact that your use of CCP-backed services implicitly contributes to human rights and surveillance abuses within China. Once you consider this, I think minimizing the use of these products and services is worth incurring the added "risk" of being surveilled by the Five Eyes.
> In 2014, former CIA and NSA director Michael Hayden said in a public debate, “We kill people based on metadata.”
> According to multiple reports and leaks, death-by-metadata could be triggered, without even knowing the target’s name, if too many derogatory checks appear on their profile. “Armed military aged males” exhibiting suspicious behavior in the wrong place can become targets, as can someone “seen to be giving out orders.” Such mathematics-based assassinations have come to be known as “signature strikes.”
https://www.rollingstone.com/politics/politics-features/how-...
A implies B & C is not the same as asking whether B & C share the same qualities as A.
You actually created a strawman in order to say that your parent had a false equivalence.
It's not perfect but compared to the pretty much unlimited control the Chinese censors have over their companies it's a hell of a lot more trustworthy.
The security qualities of iMessage and WhatsApp is known. It’s not of WeChat.
More secure than WeChat? ABSA-FREAKING-LUTELY. And do I trust Apple to remain secure? Yes.
I'm mostly putting this here because I've heard people talking about security guarantees without considering tweaks in the supply chain or binary deliveries. Even Signal could get breached with enough effort from Google to push new bits and bypass certificate validation. (Though practically that is not going to happen.)
Clearly the only solution is to forage your own silicon for artisanal fabrication of your own chips.
https://www.archive.ece.cmu.edu/~ganger/712.fall02/papers/p7...
Though, my limited understanding of iMessage is that if you were to sniff the network traffic you could detect this.
This is not a secret, it's documented behavior. https://support.apple.com/en-us/HT202303 And it's not theoretical, because Apple does decrypt iMessage communications in response to law enforcement requests: https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...
Edit:
> Messages in iCloud also uses end-to-end encryption. If you have iCloud Backup turned on, your backup includes a copy of the key protecting your Messages. This ensures you can recover your Messages if you lose access to iCloud Keychain and your trusted devices. When you turn off iCloud Backup, a new key is generated on your device to protect future messages and isn't stored by Apple.
So Messages in iCloud is end-to-end encrypted, but if you enable iCloud Backup (a different product/feature), then your backup will include the key used to encrypt it.
I changed phones a while ago. Lost hundreds of thousands of messages. Didn't inconvenience me in the least. Anything important is on less ephemeral services like email or backed up manually.
A subpoena is another form of security, at least as far as a free society is concerned.
Except that there is no way to prove this. There is no way to prove that it isn't also sending a copy from the client back to the server. Whatsapp could deploy individualized specific clients to target users, perhaps at the behest of governments. The only full answer is totally open-source software with users able to cryptographically verify that they are downloading and running the same software as everyone else.
Absolutism isn't helpful IMHO, there is no true security in this world only degrees of trust and risk. You can always go one step further in securing a product but the first step still matters.
I think there's real value in companies implementing e2e (and it's hard! it's super hard politically to get this done when the business sees little value for the effort and I know this because I've successfully fought to get e2e into a product).
The reality from my point of view is that it takes idealists inside to convince a commercial entity to lock themselves out of value (commercial surveillance) they could capture. I find a company's stance on e2e to be a valuable signal.
https://faq.whatsapp.com/en/general/26000050
Something is being watched. I imagine they are hashing images and comparing them to a database.
Thank you.
What you want belongs as an operating system or app distribution mechanism concern. A third party OS extension might make sense. Even that's a bit fraught if there is any kind of dynamic code execution (aka code that appears at runtime, say, a web view).
How can Facebook/WhatsApp do this on Android or iPhone?