Apple's iMessage encryption trips up feds' surveillance
news.cnet.com
news.cnet.com
Er
For one, why assume he cares at all about US gov agencies? HN is international. There are people here who could not care less about US agencies. Not to mention there are people who despise their abuses and privacy breaches, including lots of Americans.
Second, not everything is a "conspiracy theory". And not every "conspiracy theory" is laughable (e.g about aliens or illuminati). Real-life conspiracies (people, agencies etc, conspiring to do some stuff in secret to gain something) happen all the time. Actually conspiracy (covertly trying to spread misinformation or to gain state information or to steal trade secrets etc) is the very thing secret agencies do.
As for your misguided surprise about how an agency could ever use the press to spread misinformation, you might want to read on this: http://en.wikipedia.org/wiki/Operation_Mockingbird
E.g.:
The DEA can break iMessage encryption
Obviously they can't, and they want you to shy away from using iMessage! The DEA can't break iMessage encryption
Obviously they can, and they want you to keep/start using it!I mean, in your example there are 3 cases:
1) Obviously that can't, and they want you to shy away from using iMessage! 2) Obviously they can, and they want you to keep/start using it! 3) They can't and they are frank about it.
It could be either of the three.
We cannot say that it can only be (3) because "(1) and (2) are conspiracies".
We cannot even say that (3) is more possible because it doesn't involve a conspiracy.
It depends on more information and context to decide. Some situations we know quite well that are unlikely to involve conspiracies ("Jack said he went to Spain for holidays").
Other situations, we know quite well that are more likely to involve conspiracies ("The other 2 co-founders of my startup had a private meeting with a VC without informing me").
Now, something involving state agencies, I'd say is quite likely to involve some kind of conspiracy.
Sure, there are real life conspiracies, but understand this, just because we can define a conspiracy as 'the very thing secret agencies do' does not prove that the DAE is conspiring to release PR articles to spread disinformation.
There's no evidence of what the OP suggested but there is a whole lot of paranoia and emotions running wild and it doesn't befit this place.
My point, made jokingly, is that it's hard to tell between "real reporting of the DEA being flustered" from "planted reporting to get criminals to use iMessage and get busted". Hopefully encouraging critical inquiry of news sources befits this place.
* regular SMS/MMS messages sent from the Messaging app on Android, in which case: No, of course not. Those go directly to the cellular modem in the device. Or
* messages sent/received using Google Voice, in which case: Probably. These are scraps of data that live on Google's servers, just like data within Gmail/GTalk/et al. They have mp3 audio and text transcriptions of all your incoming voicemail that comes in through GV.
And replace the stock system with Cyanogen mod or similar and have a smartphone that won't be taking commands from the mothership.
But shortly thereafter, you started hearing about countries collaborating with BlackBerry to decrypt messages... first in palces like Saudi Arabia and Dubai, then in places like the UK. That tends to support the assertion that BBM was difficult/impossible to intercept.
Please use iMessage more, we promise we definitely can't read your messages.
Lots of love,
Feds
xxx
You could go high-tinfoil and claim they would rather people iMessaged than using whatsapp or some other free message service? But anyone thinking about avoiding federal intercepts would use neither of these things rendering this piece worthless.
So what do they actually have to gain?
It seems more likely to me that this is a real problem than a PR piece.
Encrypting text messages with iMessage or a similar service simply makes my life more difficult. And remember Apple has been lobbying against a law that would extend CALEA to iMessage.
You don't mean that a reputable tech news site would ever use 'Apple' and 'iSomething' in a headline for SEO bate?
Or the whole thing is a CIA/FBI ruse to encourage people to use a service they have a secret door into, i.e., see Nrsolis's comments, https://news.ycombinator.com/item?id=5492994.
If they actualy can or can not read the messages is left as an excercize to the reader.
What I can say with certainty is that the communications are not as secure as the article make them look like. Apple can still get you, and they can still get Apple...
I think I might actually side with the tin-foils on this one. In any case, iMessage isn't a (well-)documented protocols implementation, so I wouldn't rely on it for security.
Edit: Public scrutiny seems to back up the SA's claim [1].
The article links to the iMessage examination, but where does it back up your TLA associate's claim that end-to-end is a lie?
http://www.apple.com/pr/library/2011/06/06New-Version-of-iOS...
From the URL:
"iMessage also features delivery and read receipts,
typing indication and secure end-to-end encryption."
And thanks for the link!And even more importantly, impossible with a warrantless wiretap as well.
This new wide-spread adoption of encryption is law enforcements new enemy.
"(3) Encryption A telecommunications carrier shall not be responsible for decrypting, or ensuring the government’s ability to decrypt, any communication encrypted by a subscriber or customer, unless the encryption was provided by the carrier and the carrier possesses the information necessary to decrypt the communication."
More info: http://paranoia.dubfire.net/2011/02/deconstructing-calea-hea...
Also, declan, I was in the room during meetings with the FBI when I worked for a large telecommunications carrier. I integrated the CALEA mediation platform with the IP network and I'm well aware of what is required and not required to be present in the network regarding CALEA.
IANAL, but you would be wise to consider that the FBI considers the former "information service providers" to be "telecommunications providers" to the extent that they can convince a judge that they are acting as one. I wouldn't think I was safe because I was using any kind of messaging where I couldn't control the keys, the software that uses them, and the distribution and verification of said keys.
But Apple, Google, Facebook, Twitter, etc. are simply not telecommunications carriers. That's the whole point. CALEA as enacted in 1994 doesn't apply to them, and even the FCC didn't try to apply CALEA to them when subsequently expanding the law. This is why both the FBI director and the FBI general counsel said in the last two weeks they want Congress to rewrite the law to cover those companies.
CALEA applies to "facilities-based broadband Internet access providers and providers of interconnected Voice over Internet Protocol (VoIP)." Pure TCP/IP services are not "interconnected." See page #2 of the FCC's order: http://hraunfoss.fcc.gov/edocs_public/attachmatch/FCC-06-56A...
If you're saying that the FBI sometimes gets judges and companies to go beyond what the law allows, you may be right. On the other hand, companies are under no obligation to comply, as we see in this new lawsuit: http://news.cnet.com/8301-13578_3-57577958-38/google-fights-...
It's not a stretch to imagine an situation where a company decides to fight and loses, thus looping in a huge number of companies that might imagine that they aren't telecom providers, but a court decides they are.
There is a very fine line between SMS and iMessage. Apple provides servers that store and forward messages, and it'd be hard to argue with a straight face that a court should "think different" when comparing AT&T and Apple. Judges aren't dumb and they will pay close attention to the "substance test" when deciding if a company is providing a "telecommunications service" in a ruling.
... I guess CALEA could be made to force them to MITM anyone doing key exchanges. Damn.
...is the key phrase. Does Apple have that ability or not w.r.t. iMessage?
Even if the claim is correct, there is no guarantee that the implementation that does use the key material can use it in a way that doesn't reveal the key in another way.
Other supposedly secure key storage mechanisms have had disappointingly little luck against determined attackers. Ask any cryptographer about attacks that reveal key info in deployed and implemented crypto-systems.
If I can copy-paste an iMessage, it's getting turned into plain text at some point...
It's implied a bit that it is encrypted end-to-end and that Apple can't get the contents... but it doesn't seem to actually say that anywhere. This comment on StackExchange says the encryption is only from sender to Apple and Apple to recipient, so Apple has the plaintext: http://security.stackexchange.com/questions/18908/the-inner-...
Also, wouldn't the same issues have come up with BBM?
That's based on Apple press releases from 2011 and 2012. See, for example:
http://www.apple.com/pr/library/2011/06/06New-Version-of-iOS... "secure end-to-end encryption"
I think there are at least a few engineers at Apple capable of implementing this correctly. Not that I assume it's unbreakable, I'm just not as pessimistic.
That's not quite true, right? If encryption was successfully broken, then you wouldn't need an audit. Even if it wasn't broken, there's still things like this: http://pthree.org/2012/02/17/ecb-vs-cbc-encryption/
I presume Apple has the ability to send a backdoored update to iMessage to any user they want, and probably to obfuscate it well enough to not tip anyone off. Therefore, if DEA can get a warrant requiring Apple to provide technical assistance, Apple has at least one route to get message plaintext.
I've been using keys with both Jabber and e-mail for a long time ... what we really need is the clients to use encryption as their default mode.
Apple appears to act as a certificate authority for IMessage [0]. At the very least Apple could man-in-the-middle any (and scarily) all their traffic. The article implies that they'd have to do this before the first message is ever sent between to parties. Presumably, we'd hope Apple has the ability to re-key the service since phones get stolen and lost, so they can forge that process to insert the bogus key. We'd probably also hope that your key is not shared across all of your devices, so it might(though its not as likely as the rekey protocol) also be possible to add a device as that is "the feds"
Yes, both of these would require active work on Apple/ law enforcement's part to forward the messages to their intended recipient. However, this isn't that much work and 2) for actual wiretaps you typically need someone to monitor the tap so you don't record information not covered by the tap(we see this in The Wire).
Lastly, there is precedent (all be it Canadian) for companies being forced to exploit vulnerabilities in their system. [1]
Also, this ignores the fact that apple has device backups of most people's devices and can probably extract keys from them ( even for the encrypted ones, its likely with a poor password)
[0]http://blog.cryptographyengineering.com/2012/08/dear-apple-p... [1] http://www.wired.com/threatlevel/2007/11/encrypted-e-mai/
Due to his confidentiality agreements he couldn't provide specifics about the NSA's capabilities, he only would share his own personal security practices. After that discussion I concluded that if the US Government wanted to know something about you they could find out. Not only by technical means, but by any channel you could likely imagine. These guys are smart, the idiots you hear about in the media are field agents, not the back office folks conducting the real security work.
Since that time I've also assumed that the US has encryption technology that is at least 5 years ahead of public research. Today, I assume that means the US has access to a functional quantum computer and anything using today's encryption standards are left insecure if the right 3 letter agency wants to know.
As I understand iMessage, when you attempt to text a number a background thread fires and checks with Apple's iMessage servers to see whether or not the number is associated with an iMessage account, then returns the end-user account details to your device so it may send a digital message addressed to that user to Apple's iMessage servers.
Replace that digital ID with a public key. Private keys are generated and kept only on your iDevice. iMessage servers are your CA. Each iDevice has a unique public key.
At this point you have a very secure, end-to-end encryption scheme. No warrantless snooping is possible, and even Apple is unaware of your message contents.
Now depending on whether you want your design to be CALEA-compatible or not, Apple can issue a new private key to the government and add it to "your" list of public keys on their CA to allow the government to intercept future messages after they have obtained a warrant. If you think you can go toe-to-toe with the FBI and exempt yourself from CALEA by claiming the design of your infrastructure does not permit for message interception, you can tweak the CA around a bit. Only one public key per user, pass private key symmetrically encrypted with a password only the user knows from one device to the other via a "secure" side channel when adding new iDevice to user's iMessage account or other workaround.
I'm absolutely not a security person, and none of what I say should be taken except as some ramblings that might have some hint of an idea beneath them. I already can think of a dozen weaknesses in this system, this kinda works only if you assume you can trust Apple to play within the rules of the framework they're making, i.e. not to try to intercept your private key, log your keystrokes, automatically add a second public key recipient to your messages, etc. Fact of the matter is, you are at their mercy. tptacek, please be gentle in gutting me.
Edit: Thanks for that link, daniel. It is comforting to know that there is indeed some base level of security. If CALEA-compliance is achieved by adding the fed's public key to a list of destination public keys for a message, that implies you should actually be able to find out whether or not you're being monitored by simply checking for new/unknown/unexpected additions to your list of public keys. Of course, there are other methods of doing this that wouldn't be as easy to detect, e.g. maybe there is an out-of-band request for additional public keys to send to, maybe the fed's public key is already embedded in the device and is being used invisibly every time, etc. etc. etc.
Edit2: For people wondering if syncing of old iMessages between devices means iMessage doesn't work like this, I don't think that's the case. I believe that's done via iCloud (i.e. backup of previously decrypted messages), as when you add a new Apple ID to iMessages on OS X, you don't get the old messages for that account, only new ones. So it's another attack vector, but not inherent weakness in the iMessage design.
Source? How can I add a new device (e.g. Messages on OSX) and get all the messages between my phone and friends?
The protocol hasn't been completely reverse engineered but enough to know it's likely decentralized like this, just MITM it (quite a bit is documented on the wiki I linked), Apple is the CA and the piping but it appears to be rather strong and decentralized in terms of chain-of-trust. Apple has put itself, probably without coincidence, in a position where they may not even be able to execute a court order to spy on a user.
The Apple security white-papers detail their hardware level certificates, I've dealt with this a lot as a Apple MDM developer.
When I have A, and want to add B, A ships its private key to B so it can decrypt the messages too? (and vise versa, obviously)
Or does A get B's public key, and A then re-encrypts and re-sends messages it receives to B?
Or is it something completely different?
Someone who actually knows should weigh in, though. GP's understanding seems a bit murky to me.
When someone sends me an iMessage, their client sends as many copies as I have devices?
Generally how this works is that the sender encrypts the message with a symmetric encryption algorithm (like AES) and then encrypts the randomly-generated AES key with RSA with each of the receivers' private keys. So you only send out a single message, but it can be decrypted by any of the intended recipients.
WINDMILLS DO NOT WORK THAT WAY.
I have a feeling they could manage.
I really had thought, that this would have happened long ago, for everybody, and so on. Would not have thought, that this was a problem for law enforcement, as it was with i.e. skype.
Nobody iMessaging me gets any indication when I get a new iPad and add it to my account, despite all their messages to me now encrypting (on their device) to n+1 of my devices now.
You can find more info here. Encryption and Data Protection section should be a good place to start.
[1]http://en.wikipedia.org/wiki/Communications_Assistance_for_L...
The choice is odd because the FCC deregulated the internet to make ISPs "information services" not "common carriers". So there is precedent for expansion that makes no logical sense.
Made me chuckle. Given that zero day are mostly available in black markets how can they justify to give money to criminals ?
> VUPEN Exploits for Offensive Security As the world leader in vulnerability research, VUPEN provides extremely sophisticated and government-grade exploits specifically designed for the Intelligence and LEA community to help them achieve their offensive missions using tailored and unique codes created in-house by VUPEN for exclusive and undisclosed vulnerabilities discovered by VUPEN researchers.
Access to this service is restricted to organizations from countries members or partners of NATO, ANZUS and ASEAN.
http://www.vupen.com/english/services/lea-index.php
completely legitimate company
There. Fixed that for you.
Easy: they're both criminals.
But then you have to trust that 'they' are law abiding. Extraordinary rendition is both reassuring and alarming. 'They' will jump through hoops to look like they're obeying laws, but the end result is still people being water-boarded.
The Hushmail thing shows that some companies will happily roll over when given valid law enforcement documentation. (Fair enough, I'm not sure what else they should do.)
Companies could design products that do not give them the ability to cooperate in that manner. Hushmail, for example, could have designed a system where customers were sold smartcards and not actually run the mail transport, so that Hushmail itself had no ability to access encrypted messages. While this would have made Hushmail a bit less convenient, it would also have made it many times more secure.
Unfortunately, in the current right-wing political climate, there are few incentives for companies to actually develop or deploy such systems.
Really though, if you are only going to use PGP from a single computer and you are not going to download your encryption software every time you use it, what advantage is there to using Hushmail? Thunderbird with Enigmail, Evolution, Claws-mail/Sylpheed, and numerous other email programs can encrypt and sign messages. Hushmail's only draw is that it is webmail, which is only useful if you want to check your email from arbitrary other computers.
It is also generally bad practice to leave your secret keys on some server somewhere, even if you are sure your passphrase is strong. I would not be surprised if a lot of Hushmail users have very weak passphrases that can be easily guessed.
Hushmail takes all that difficulty away, with the drawbacks you mention of insecurity from people trusting it too much.
Other classes of mail (priority, parcel post) can be opened by postal inpectors at their discretion. Mail entering or leaving the country can be inspected by US Customs. My dad used to correspond with HAM operators all over the world, and letters from soviet bloc or certain third world countries were routinely opened.
The problem with using the mail to deprive another of property or "honest services" is that it is a serious crime, a criminal (which can be defined very loosely under the "honest services" umbrella) can be fined up to $1M or jailed for 30 years. Politicians filing ethics financial disclosure forms always file these in person, as inaccurate information can result in a slam dunk case for the US Attorney.
So for your normal correspondence, 1st class mail is as safe as you can get.
Assuming this to be the case, you wouldn't normally choose to use iMessage. It just happens if it can.
If further penalty were to be considered, I expect the prosecutor would have to prove that the user intentionally took action to ensure iMessage was used for the delivery of messages instead of SMS. I suspect that would be hard to demonstrate.
Messaging is superfluous on the internet. Everything has it from Words With Friends to World of Warcraft. I understand that not all messaging systems are encrypted but being required to put in a backdoor for a government agency to spy on messages is a fair amount of work. Would you have to log all messaging too and for how long?
It's a modern version of the Ultra intercepts/Coventry blitz (now called into question). The NSA might risk revealing its methods if it would stop the next 9/11. To put a meth dealer in jail? Not a chance.
I think the government would need to be in mortal peril otherwise before they reveal they broke RSA, assuming that they have. To stop a 9/11-type attack they would probably fake some information leak from the other side.
The real danger from NSA decryption would be in their storage facilities. What you say now could come back to haunt you in the future depending on the political climate (e.g. the US falls into a police state where political prisoners are taken, etc).
If yes, then legal and technical frameworks are needed where service providers outside the traditional telcos can respond. This is the gap that has been widening since the introduction of the smartphone.
It's not a huge problem right now since most criminal communication that police are interested in is still done over traditional voice, SMS, and email (where these providers are already interfaced with law enforcement).