AT&T Breach Shows Why RCS Can't Be Trusted
daringfireball.net
daringfireball.net
Is the author's point, simplified, "any centralized collection of communications data, unencrypted, is vulnerable?" They mention E2EE, but even some of those still present centralized, unencrypted metadata.
Gruber has had several moments where he's stridently defended Apple and denied issues only for it later to be revealed that there absolutely was an issue.
The last straw for me was the LassPass App Store issue a few months ago (where a scam app was approved and took the top spot in the store, over the official app).
Gruber, on this:
> > Instead, the scam LassPass app tries to steer you to creating a “pro” account subscription for $2/month, $10/year, or a $50 lifetime purchase. Those are actually low prices for a scam app — a lot of scammy apps try to charge like $10/week.
Emphasis mine, but are you kidding me? He actually tries to downplay the issue by saying "Well, at least you wouldn't be scammed out of that much money".
And then doubles down, by claiming, with absolutely no knowledge whatsoever:
> It doesn't look like the app was intended to steal credentials.
Why do you think that is plausible reasoning? To me, the credentials are what you're intending to steal with the scam app. You might make some money from the IAPs, but that's a cherry on the top (and likely the actual reason why the amounts were low, so it didn't raise more red flags).
I've seen yoga practitioners who can't contort themselves as much as Gruber can when trying to defend/promote Apple and their interests.
That’s a ridiculously uncharitable take on a simple statement of fact that you yourself even seem to accept later in your comment.
So no, I stand by it. If by his belief, not mine, that the app was purely a financial scam, he literally downplayed it, effectively, as "even if you're being scammed, you could have been scammed more elsewhere", and most of the rest of his writing was implying people are being overly critical of Apple.
As for an uncharitable take? Were it Gruber's first forays into defending Apple in the face of evidence, maybe. After screen staining, batterygate, butterflygate, logic board issues, and several more (hell, he even defended "You're holding it wrong"), all of which Gruber insisted these were all user issues, non-issues or random events, several of which ended up resulting in warranty extensions and/or recalls, I'm less inclined to be ... 'charitable'.
Unless you are the only holder of the key, encryption is typically useless in a hack.
Go ask every healthcare breach and they will tell you the data was encrypted...
If RCS was encrypted there is a 99% chance att would have the keys easily accessible.
1. Mobile internet access.
2. Messaging.
I don't like tying communications to phone numbers either because that means you need phone service to communicate, but that ship has sailed, and there are many people who barely use email at all.
“SMS and traditional telephone voice calls lack any encryption at all, but they’re firmly established. Just like email. But anything new should only be supported if it’s fundamentally based on E2EE.”
“Perhaps, someday, the RCS spec will support an open standard for E2EE. I’m not holding my breath for that. For one thing, industry consortiums tend not to produce good solutions to hard problems, and an open standard for E2EE messaging is a very hard problem.”
So, they argue
- new communication standards must be end-to-end encrypted
- that open end-to-end encrypted standards cannot be developed
If both are true any new communication standards must be proprietary.
I don’t think that’s a conclusion shared by society.
1: https://datatracker.ietf.org/doc/rfc9420/
2: https://matrix.org/blog/2023/07/a-giant-leap-with-mls
3: https://security.googleblog.com/2023/07/an-important-step-to...
4: https://www.androidauthority.com/google-mls-e2ee-messages-34...
Meanwhile the proprietary networks that literally billions of people already use have had E2E for 10+ years.