I go one step further and leave the SIM card out, which means the SMS vulnerability path is closed too.
I go one step further and leave the SIM card out, which means the SMS vulnerability path is closed too.
So in either case... turn off native messaging and use Signal or something if you are paranoid. You aren't really using the "phone" part anymore, so buy an iPod touch or something.
Also, iMessage is fully E2E if you disable iCloud Backup. Which can easily do in Settings.
If you are this paranoid, you shouldn't be carrying an electronic device.
I'm in the camp of pragmatic resistance to surveillance. I use browser plugins to block ads and cookies where it doesn't get in the way of reaching the content I want; I use Signal for messaging even though almost none of my recipients do; I disable location services except for things like Maps that actually need to know where I am; I turn off all the spyware I know about that's built into operating systems; etc. I'm not a tin-foil-hat-wearer; I'm not doing anything illegal that I need to hide; I'm just trying to push back in a small way against the erosion of privacy and rights that permeates everything electronic.
But the parent isn't paranoid. They really are watching. And we shouldn't be so complacent.
This person is so paranoid, that they believe that a cyberweapon developed by a private company in Israel that uses previously-unknown bugs in the most sandboxed messaging system you can get on a phone are going to be deployed against them, so they should not use the calling, texting, or any other "phone-like" functionalities of a phone.
They then distrust that the End to End Encryption is in-fact End to End, and then think that using Signal or something is more secure, when if a bug in a system more sandboxed than Signal was found (iMessage, which has BlastDoor which Signal does not have), it is more than likely that Signal has it's own zero-days in it, so you shouldn't be using that either.
That's paranoid, and if you are that paranoid (which, maybe you have a reason to be), your solution isn't well thought-through. You shouldn't be using a phone if you can help it.
Fun fact: having systemwide location services on, even if you don't enable it for any apps, means that your location is sent in realtime to Apple/Google at all times (via Wi-Fi triangulation data). It's not just passive GPS reception.
If you want actual location privacy, you'll want to leave location services off systemwide on your smartphone, and consider getting an offline GPS receiver device. Good car satnav devices from China are like $60 now, and include continent-wide maps, though you lose realtime traffic info, being offline.
- OpenCellID (offline): https://f-droid.org/en/packages/org.gfd.gsmlocation/
- Radiocells.org (optionally offline): https://f-droid.org/en/packages/org.openbmap.unifiedNlp/
- Déjà Vu (offline cache using Wi-Fi and cellular data): https://f-droid.org/en/packages/org.fitchfamily.android.deja...
- Mozilla Location Services (online): https://f-droid.org/en/packages/org.microg.nlp.backend.ichna...
UnifiedNlp is preinstalled on Android distributions that include microG. CalyxOS is the only one of these that supports relocking the bootloader with the developers' key:
There is a degree of rational fear, rational expectation of being tracked. Your degree of fear though is irrational unless you are, in fact, a journalist in an authoritarian state.
You are saying that you are so paranoid, you don't trust iMessage to be End-to-End Encrypted because it has zero-click exploits developed as part of a cyberweapon that is explicitly targeted against high-profile journalists. You then think using Signal or something is more secure, even though if this was pulled off in iMessage (more sandboxed than any other messenger security-wise), your other messengers probably are also flawed and you shouldn't use any of them.
In fact, you shouldn't use a mobile device. And maybe for your situation, that is right and rational. But for most people, it's not.
Just because someone want to be as secure as possible while using their electronic devices and you think they are being extreme doesn't mean that they are being paranoid. It has nothing to do with being paranoid. It could simply be because it is fun to try and secure your devices or to gather knowledge on how to do so in case you need to apply the skill-set at work or a thousand other reasons.
>you don't trust iMessage to be End-to-End Encrypted
I don't secure my devices as GP does but I also do not trust for a second that iMessage is securely E2EE. It is not something you hear rarely if talking about the topic, in fact it is very common argument on HN that iMessage messages are saved unencrypted to iCloud.
>this was pulled off in iMessage (more sandboxed than any other messenger security-wise)
That is almost the opposite opinion of iMessage than what was posted by researchers yesterday on HN (well, Twitter originally). In fact they stated:
>"BlastDoor is a great step, to be sure, but it's pretty lame to just slap sandboxing on iMessage and hope for the best. How about: "don't automatically run extremely complex and buggy parsing on data that strangers push to your phone?!"
In short, Paranoid is misused a lot like this. Just like Schizophrenia (it is often used about having multiple personalities or many opinions that clashes, but neither is correct usage).
It could be the case, absolutely. But the OP doesn't sound like their having fun, they are in earnest.
> do not trust for a second that iMessage is securely E2EE
Ask a security expert, and they will tell you it has been verified by just about everyone who has inspected it that this is, in fact, the case, including the EFF. But it is proprietary code, not open, which is a downfall.
> are saved unencrypted to iCloud
And can be turned off with the flip of a switch in Settings if that's something you are worried about. For most people who aren't OP-sec (like my Grandma), having all of her messages deleted because someone stole her phone isn't worth it.
> "buggy parsing on data that strangers push to your phone?!"
Yes... Except that every other secure messenger also does the exact same thing. And they don't have BlastDoor sandboxing like iMessage does. Yes, BlastDoor has flaws, but at least it's there unlike other messengers which don't sandbox.
You are putting words in OP's mouth. OP never said he was fearful, only that he didn't want to be tracked.
Someone friendly could follow me around in real life and watch what I'm doing - and keep suggesting products to me based on getting to know me. I'm not going to be afraid but I am going to be freaking annoyed, and feel like my privacy is violated when he says he isn't going away.
I'm trying to say his game-plan for not being tracked is immensely flawed. He thinks a nation-state weapon could be used against him, so switch to a third-party messenger which doesn't do the same degree of sandboxing for security. What could go wrong?
If you are worried about a threat that is that niche, and will almost certainly be patched soon, you shouldn't be using any messenger, logically speaking.
OP wasn't talking just about the pegasus attack, they were talking about the key escrow not being held under end to end encryption on iCloud. That's not going to be patched any time soon, and there are other messengers which don't do this.
If you just don't want to be watched, either by people or algorithms, and have a rational understanding of what tracking/surveillance you are under, and you are actually not paranoid.
You don't have to be interesting, you just need to exist to be caught up in the dragnet.
>you are using SMS
doesn't fit with this from GP
>leave the SIM card out
I know this because I used to carry an iPad Mini in my pants pocket.
Also, the whole point of disabling iMessage (in this thread) is to close the iMessage-related zero click exploits described in TFA.
And are you really sure that Signal or your preferred messengers don't also have Zero-Click exploits? After all, they aren't sandboxed to the degree iMessage is with BlastDoor.
Signal does not escrow endpoint keys in an iCloud Backup, so your first statement is incorrect.
Also, Signal putting your escrow keys in iCloud? I don't think you know what you are talking about. You can set iMessage to not put your keys in iCloud like I said above by turning off iCloud Backup which makes it fully End-to-End with your own key on your device, just like Signal.
If you are worried about the other party having their conversations being backed up, tell them to disable iCloud Backup. If you are this worried about the privacy of your communications, hopefully the other party would be as well.
And Signal and any other E2E messenger is absolutely storing copies of your key on the recipient's phone, just like iMessage would. If it didn't, there'd be no way to verify that a message was sent from the same sender.
"Fully" smells like a weasel word here. Either it is E2EE or it isn't. iMesssage isn't by default from what you are saying and if it requires the other end to also turn off icloud backup before it is E2EE then I'd go as far as stating that it is a completely useless attempt to be E2EE. In fact I'd argue Apple is full of sh*t if they actually ever stared that it is E2EE (but I have no idea if they did).
Comparing Signal to such a mess is... well at a minimum it is disingenuous.
The messages are fully end-to-end encrypted, we know that, the EFF has stated as such. However, iCloud Backup means copies of your messages that arrived after the end-to-end process are backed up online. For most people who buy iPhones, having their messages not be permanently lost if their phone is stolen is a fair trade. If you don't want copies of your messages backed up after they arrived through the end-to-end encryption process, then turn it off.
You might be thinking, "But what about the next message from Jim?" but that message is encrypted with a new key so the previous key isn't useful, your Signal works out what that key will be and remembers it until it receives a message from Jim.
It's a ratchet, you can go forwards but you can't go backwards, if I didn't keep the message Jim sent me last week then even though you've got the encrypted message, and I've still got a working key to receive new messages, we can't work back to decrypt the old message.
You might also be thinking, "There must be a long term identity key so that I can tell Jim and Steve apart?". Indeed there is. But Signal doesn't use this to sign messages since that's a huge security mistake, instead this long term identity key is used to sign a part of the initial keys other parties will use to communicate with you.
This design deliberately means you can't prove to anybody else, who sent you anything or what they sent. Sure, you can tell people. You can dish the dirt to your spouse, your friends, the Secret Police, but you can't prove any of it cryptographically.
That's true, and is a perfectly legitimate reason to use Signal.
I'm saying that the OP was dissing iMessage because of the Pegasus zero-click exploit, and was saying that switching to Signal gives zero guarantees of protecting you from that, because it likely has it's own zero-click exploits, especially because it doesn't attempt to sandbox unlike iMessage does with the flawed BlastDoor.
You will be forced to make compromises somewhere unless you want to live under a rock in the desert. You can't drive without a State ID, can't get a home loan without credit, can't work without a Social Security Number except under limited circumstances, can't make money without reporting to the IRS, and so on. It's entirely about what compromises you want to make, and the tradeoffs therein.
Something like 96% of human beings don't have a social security number. Many of them work.
The technicals are different, the point is the same.