Apple can read your iMessages (even though they’re E2E encrypted)
old.reddit.com
old.reddit.com
Reality - there was a period where the icloud backups created backups that apple did not have access to. Critically, this mean that if you had any of a wide variety of things happen - unless you were very good about key management - your content was lost for good. ALL your photos (which could be heartbreaking) etc.
It turns out this is NOT what people want. They want apple to have access to their content, so when they have a device stolen and don't have a super long recovery key properly saved, they are not hosed.
Same issue BTW with bitlocker on windows. People DO NOT save those recovery keys, even if they should. Microsoft added a way to force a backup into an account admins and others would have access to, thank goodness, because otherwise users there would be hosed as well.
Whenever someone loses their account the first thing they do is run to the vendor and flip their shit when the vendor is unable to do anything.
I imagine from a business perspective it’s just better to keep access to data, sometimes without nefarious reasons like advertising, rather just keeping customers happy.
They had records of my folks purchasing the laptop, but they argued that state ID's and credit cards can be faked and stolen, and were thus inadequate for their internal security purposes.
And so you can still use the computer just not keep your data.
Those cards are easily forged and there is nothing you can realistically do to prove the laptop is yours without also allowing thieves/criminals to prove it's theirs. And so they have to err on the side of caution.
The onus lies on you to keep backups.
Also, Apple eventually unlocked the laptop.
In this case you are wanting to keep the data as well.
Regardless of the reasoning, if you have this ability, you can and will be compelled to give up that information. Therefore, it is best to not have that information or STFU about being concerned about privacy.
They certainly turn to Apple for help, but I think it's sometimes simply despair and not flipping their shit.
E.g. I was once in an Apple store and the Genius was trying to help someone who, for some inexplicable reason, did everything in the Guest account of her laptop.
The laptop rebooted for some reason (maybe she said OK to install updates?), and she lost the contents of Guest. Which means she lost everything.
Vendors like Apple need to be prepared for all sorts of data loss scenarios. Ordinary users simply don't think about computers the same way as engineers do.
Also, calling this "E2EE" is against the unwritten rules of the profession.
0: https://www.macworld.com/article/234693/apple-id-adds-recove...
This is surely true no matter how strong the encryption scheme, though. If you share your content with anyone else, then your security is only as strong as theirs.
You have to explicitly enable it.
Apple's documentation needs to be a little clearer on this but the system is basically designed with the accurate notion that the biggest footgun for 90% of users is not "the government was able to access my messages with a warrant" but rather "I lost access to my end to end encrypted messages".
Bit of a broad stroke anyway.
If it's the latter then yes, you can (almost) always choose not to use a service or website. That's a poor argument to defend bad privacy practices.
If it's the former then just disabling iCloud backup does not result in E2E storage of other iCloud data. iCloud photos, drive, etc. are still not E2E.
b) End to end encryption has always meant transport encryption not encryption at rest.
If you think the word "blame" is too morally hot, then we can always go with causal attribution.
b) this is just false; whether the data is at rest or not has nothing to do with the definition of the term. And it is misleading in any case.
b) The etymology of the term has been blurred by WhatsApp referring to it as both transport and encryption at rest. But historically it has not included the latter part.
No, it's not because it is another instance. Someone can have one thing right and another thing wrong. And whatever the true meaning of "E2EE", its use in this case is misleading at best, so I'm pretty sure that the profession does not approve of it.
The user is being used as an excuse: "we compromise your privacy because that user over there wants it". This is not blame in the obvious sense of "it's that user's fault that they lost their data", but it is blame: "the responsibility for this thing isn't ours, the people who wrote the code, but yours."
Sure, but if someone in the middle wants to store, then they don’t have anything unencrypted to store. Ultimately it all depends what one defines the “ends” as. In general for backup, both ends are the user. For chat, the sender and recipient. Apple is not an end, but a provider in the middle.
User B screenshots all of those messages and uploads them unencrypted to a random FTP server.
Now replace the random FTP server with iCloud. Or Google Drive. Does that change the nature of the messaging between User A and User B? I would say it doesn't. In fact, WhatsApp does basically the same.
People are certainly choosing convenience over privacy in that any backup is preferable to no backup.
However, Apple does not give the option to choose E2E or not so users cannot make that choice of privacy vs convenience. You're assuming that people choosing iCloud over not-iCloud means people do not want E2E. It may be the case that people prefer E2E but this is not evidence of it.
Furthermore, I don't believe iCloud backups were ever E2E and that it was a feature that was removed. Apple states which iCloud services are E2E[0] and these services I'd argue are pretty straightforward to setup and not lose. Most of the time you don't need a recovery key, just to be logged in on another device.
Even if it is the case that most users do not want E2E, there's certainly a large audience (outside of just the HN bubble) that do want it. They could make it optional.
There's a heck of a lot here which generally feels like a problem where the user isn't ever adequately briefed on what's happening and why, and isn't given reasonable options. People are very familiar with the idea of giving a house key to a friend, but for some reason we don't offer the substantially better options we have in this regard when it comes to encryption.
If my memory serves me correct iCloud Backup was designed as such since Day 1 ( iOS 5 ) so Apple could help its customer when they loss their phone. Is there any links to suggest Apple changed their Backup access?
I don't think whoknowswhat11's account (that there was a period where backups were encrypted but it was removed because users didn't want it) is accurate.
I had seen more than a dozen iTunes Backup corruption where the backup is completely useless. And this problem exist even today. And it seems the chances of happening is higher on Windows PC. iCloud isn't without flaws I have seen three iCloud Backup suggesting it is corrupted. But there is often a backup from previous days as iCloud dont overwrite backup. Given the lower chances of happening I had to use iCloud.
I make the odd encrypted local backup just as a recovery point but my RTO is measured in years TBH.
I know someone that got a drive recovered once and they had no idea what BitLocker is. They were pretty happy to have the key saved in their MS account.
It’s not possible to give up that which you do not have. And the convenience isn’t for the users
However I agree, I heavily use iMessage, it’s convenient because when I used signal I didn’t get notifications.
However, Apple has had the decryption keys server side for ages, and I believe the reason they don’t have E2EE is purely because users don’t store their backup keys, and kick off when they loose all their life that’s stored in iCloud, and it’s just not worth the hassle to the support team, my family is the same with 1Password, they don’t backup their secret key thing, so I have to either store it or restore their account.
Bitlocker doesn’t help in this regard either, you can bypass the mandatory saving section by using print to PDF to store the recovery file to the encrypted drive, essentially locking a safe with the key inside.
There is zero guarantee from any E2EE system that the data is encrypted at rest by the sender and receiver. In fact in most cases, the data is not encrypted at rest because people want to do silly things like read messages.
The exact same vulnerability exists on every platform that's automatically backing up local data to the cloud. Even if you disable cloud backups you're still stuck if whoever you're messaging has left them enabled.
The only meaningful way around this hole when it comes to messaging apps is row-level encryption on the backing store. This has a lot of problems of its own and potential holes when it comes to indexing and searching.
* iMessage, which does use true E2E encryption in transit.
* iCloud backup, which backs up the contents of your device (including your unencrypted at-rest iMessage data), and does NOT support E2E encryption.
Technically if you (and all your friends) use iMessage and don’t use iCloud backup, then it is impossible for Apple to read your messages.
In reality, the alternatives to iCloud backup are too risky and/or cumbersome, so most people use it, with the result that Apple can read your iMessages once they’ve been sent/received and your phone has performed a backup.
They are providing E2EE with iMessage. E2EE only provides security for data in transit. It ensures that only the endpoints can decrypt the communication. That is it. There's absolutely no promises of encryption at rest on those endpoints.
Not only is Apple actually doing E2EE but the tech press (and apparently HN posters) seem to think E2EE means something that it does not.
When you sign into Messages on a device it generates a key pair and sends the public key to Apple. When you first send someone a message your device gets their list of device public keys. Messages are encrypted with session keys that are encrypted with the public keys. Each recipient device gets a copy of the message and uses its device private key to decrypt the message. The sender and receiver will receive copies on all their signed in devices.
The encryption "hole" with Messages is when the local device database is backed up to iCloud. This is the same hole that exists for any messenger app that has its local database backed up to iCloud. iCloud backups are encrypted at rest on Apple's servers but with keys they can access.
Apple was apparently going to close this loophole, but decided not to. They probably received negative feedback from the three letter acronym agencies.
On the other hand the government could certainly find a specific individual they know you've messaged with, and execute a warrant specifically for their conversations with you.
Perhaps we need a new term, other than E2E encrypted, to close the door on 'loopholes' such as the provider managing your keys.
In this case Apple can do anything they want with the keys since it's a locked down and closed platform.
You can't trust anything unless you built it yourself [0]. Just because I tell you that binary is built from the source code does not mean it's not backdoored.
[0] Theoretically, reproducible builds provide the same security, but in the end you need to build it yourself to get the hash, at which point you just replace one `cp` with two `sha256sum`.
With closed systems, the best you can hope for is to treat it like a black box that can and will change out from under you.
99.999% of open source projects rely on Github Actions, Circle CI, Travis CI etc to build their code. Those are all proprietary so unless you are running your own CI/CD stack then you can't trust the code.
And of course every open source project relies on libraries. So you need to make sure this applies equally to them as well.
Security comes in layers, and with open systems, if you want to, and if you have the resources, you can audit and verify those layers depending on your level of paranoia and your potential adversaries.
You might throw your hands up in the air because security isn't assured and go all in on closed, black box systems, but there is value in open systems when it comes to security.
[1] https://www.cs.cmu.edu/~rdriley/487/papers/Thompson_1984_Ref...
It's like if you're trying to figure out how a magician does a trick, "he must have a collaborator in the audience" is a reasonable guess. "Everyone in the audience other than me is a collaborator" is usually not.
As "Reflections on trusting trust" (https://www.cs.cmu.edu/~rdriley/487/papers/Thompson_1984_Ref...) points out, you can't trust anything including if you built it yourself, at least assuming you mean 'build' in the software sense. Even in the hardware sense, it's probably beyond the reach of anyone, let alone any individual actor, to build a modern computing machine from bare metal in a way that involves no trust of a third party.
It’s silly not to call it E2E, since e2e just means that no eavesdropper in the middle can intercept it.
If you don’t trust the person who wrote the software you are using, that is a different issue. Just as serious, but it has nothing to do with either it is E2E or not.
You know where the ends are. As I said, you always have something between you and the ‘end’, and you always have to trust someone.
Whether something is E2E or not is completely independent from whether you trust your software.
In which case Apple is no different to every other cloud company which scans for CSAM.
Apple's ads will age fine since they invest far more effort in keeping your data private than every other OEM. Even their CSAM effort which blew up is far better than other companies who are doing server-side scanning.
Especially in China... Apple's privacy claim sounds silly, knowing that they gave up on protecting users data where it truly matters - against the government abuse and focus mostly on the least dangerous threat (if threat at all) - online advertising.
It doesn’t seem worthwhile to enumerate the ways this can be abused to someone who is bought into slippery slope theories.
https://web.archive.org/web/20210827045159/https://old.reddi...
But honestly you don’t need it. Even though iMessage is end to end encrypted, Apple mediates the key exchange. It’d be trivial for them to do a man in the middle attack by saying the other guy has a new key.
It’s about iCloud backups containing the decryption keys. iMessages are backed up encrypted.
If Messages is not toggled in iCloud, then as long as iCloud backup is toggled, it will directly back up the raw messages - encrypting with an Apple stored key just as for any other non end to end encrypted data.
And people worrying about the other end of the chat... come on, you talked to them in the first place. They can forward anything, even if it's via Signal.
The entire story is just hilarious and memeable. Users want backup; Apple open up the gate. Users want E2E; Apple shut up the gate. Users want iCloud recovery; Apple partially open the gate.
If the government wants to look at my data, and has gone through the proper channels to do so, I believe that, generally, that system will protect me from a consequential privacy intrusion. It's not a perfect system, but I believe the benefits of the power of subpoena are worth the costs, so I'm happy to participate in it.
Do you really believe that only nation states can get into Apple's machines? I'd agree that Apple is pretty far up there in security reputation, but if there was a headline tomorrow of "iMessage Backups of 2 Million Users For Sale On Tor" would it really surprise you?
I don't even trust _myself_. I self-host my family's Matrix server, and we still encrypt all our conversations.
Hacking isn't a magic wand, where bad guys cast spells and good guys just look foolish. I've worked in cybersecurity for ~10 years, and I know generally what the reputations are of various large tech companies. Apple has a good reputation for protecting properly secured data.
It is currently, based on the information we have available to us, paranoid to think your data isn't secure from hackers when it's stored properly in Apple's infrastructure. Your behavior is, by a gigantic margin, more likely to cause a compromise of your secure data than Apple is to cause a compromise of your secure data.
If you connect your device locally you can, just using Finder, make an encrypted local backup which IMHO is much better.
Even if Apple did say Cloud Backups were encrypted you’d have to take it at face value anyway. Always be in charge of your own data, and secure and back it up yourself.
- back my encrypted data - back my encryption key (if back encryption key, the e2e does not make any sense)
What the encryption key will be used to encrypt the e2e encryption key?
Although you’re relying on your recipient disabling it too. So really you have to use something else. Signal, etc.
With that said, I still think an iPhone with iCloud disabled is better than other phones on the market privacy-wise. And for the average consumer, iPhones offer a good tradeoff between privacy and usability.
I was devastated. I never recovered them all. But it taught me a lesson.
Apple in the cloud brings nothing good to the user if you trust them.
Since then I have never and will never use iCloud for anything important. I can see iCloud has become a vector for no privacy over the years.
i.e. for true security all message participants must have iCloud Backoff off, etc.
If they just added that, it would be so incredibly useful. I'm sure they won't though, because that might mean that people could access iMessages from non-Apple hardware (the HORROR).
If you want true E2E encryption and encryption at rest, then build your own infrastructure.
Why is guesswork like that acceptable in a privacy tool? Furthermore, who actually believed that Apple couldn't read their messages? 'End-to-end' means very little when both ends are Apple-controlled.
It’s pretty simple. iMessage is relatively secure and most criminals, nation states etc, won’t be able to access your messages unless they have a legal means to do so.
If you need protection from a nation state that can force Apple to divulge content, such as the US, use something else such as signal.
See https://support.apple.com/en-us/HT207428, https://support.apple.com/en-us/HT208532, https://support.apple.com/guide/security/security-of-icloud-..., and https://support.apple.com/en-us/HT202303