So, if you think you are a likely target of a state sponsored attack, best thing you can do on an Apple device is to turn on lockdown mode, turn off iCloud and iMessage, stop using keychain, use only a yubikey for all authentication, and restrict yourself to a limited number of essential apps on your primary device and use a dedicated burner device for all your throwaway browsing and communications, and erase/reset that device after every session. And still, assume everything you say and do online is fully compromised, because there are always system vulnerabilities that haven't been made known yet ('zero-day' attacks) and are being used to compromise highly targeted individuals. In the end, it is a very convoluted cat and mouse game.
This is the way.
This is such a bizarre comment to make, because OP never suggested that Facebook is "totally okay". You replied to them after their edit window passed, so they didn't say that and then edit it out either.
FB Messenger is simply an alternative. I haven't paid attention to it, but maybe the Threads fediverse integration will piss me off just as much.
I am noticing, the social circle I am currently in has now largely moved to Telegram, whereas in other places it's 100% WhatsApp.
imessage and rcs (and arguably mms, although that started as cost cutting) are backdoors for the legal protections on mining telephony provider metadata for marketing. with those two "opt in" (lol) techs, all safeguards are off.
Apple can read approximately everyone’s iMessages out of their backups. It’s not private or secure, and claiming it is end to end encrypted is misleading almost to the point of being actually false.
This can be changed by opting in to the e2ee iCloud data service “Advanced Data Protection.”
iMessages are backed up in duplicate - once on the sender and once on the receiver. You can only control e2ee for half of it, so your conversations are still under surveillance unless everyone you message with has also turned on ADP.
By your terminology, all iOS devices are “compromised” by default from having non-e2ee iCloud Backup enabled by default.
Signal chats on iOS are stored in a storage class that cannot be backed up or exported from the device.
https://en.m.wikipedia.org/wiki/PRISM
From the front page of the Times today, they are renewing the law that says they have to do it without a warrant (FISA Section 702, aka PRISM).
https://www.nytimes.com/2024/04/12/us/politics/surveillance-...
You’ll note that this is regularly and frequently used by the FBI against domestic users (such as BLM protesters). Apple processes these FISA demands on over 70,000 user accounts every year, and the number is increasing. (That’s just the count for the warrantless FISA stuff - search warrants are a different (larger) figure.)
They also expanded it to allow them to search Apple’s data on people entering the US as visitors.
> The House also passed several other significant amendments. They included allowing the Section 702 program to be used to gather intelligence on foreign narcotics trafficking organizations and to vet potential foreign visitors to the United States; empowering certain congressional leaders to observe classified hearings before a court that oversees national-security surveillance; and expanding the types of companies with access to foreign communications that can be required to participate in the program.
Apple makes privacy claims about iMessage including 'Apple can’t decrypt the data.', which is notably false in this (common) scenario, and requires a large asterisk on those claims, IMO bordering on making them unethical, period.