Two corrections to your comment...
ANY system where code can be deployed at will and the owner of the device is not in full control of the device will have this same level of vulnerability. Saying that a system is insecure because you could change the system doesn't tell you anything interesting about the system.
1. The NSA vacuums up network traffic. Meaning they use man-in-the-middle attacks. Sometimes they do force businesses to deploy a malicious program, as you describe, to gather a user's password. This is called a Pen Register, or Trap Trace Device: https://ssd.eff.org/wire/govt/pen-registers However, this is the exception, not the norm.
Defending against man-in-the-middle attacks is a bare minimum requirement for any system that purports to be "secure". Defending against Pen Registers is an unsolved problem, but it's unrelated to the attack presented here.
If I understand it correctly, they are saying that the messages are encrypted using an RSA key unique to the sender, and that this is not secure because Apple could, if they wanted to or were ordered to, replace the certificates with ones that were not secret. [...] What is misleading here is that (if I understand it correctly) the cryptography is solid, it is the implementation being owned by Apple that raises the doubt. But this is NOT a statement about the cryptography used on the iMessages, it is a statement about the fact that Apple effectively has "root access" to their phones.
2. From http://blog.quarkslab.com/static/resources/2013-10-17_imessa... page 36:
- All iMessages are encrypted and signed using
asymmetric cryptography
- Thus, there has to be a key directory
- iMessage client retrieves recipient’s public keys by
querying Apple’s ESS server
It's that last point which is the most important. When someone sends you an iMessage, their device queries an Apple-controlled server for the recipient's public key. The server returns a "Public Keys Buffer". The buffer contains an RSA public key (1280-bit) to encrypt
messages for the remote device.
Apple controls that server. They can send you whatever public key they want.
In other words, while I wouldn't say it's "trivial," it's at least "realistic" for the government to be able to order Apple to serve up an MITM'd public key. Combined with a copy of the network traffic, they can then decrypt all iMessages. And the government isn't the only adversary to worry about, either.
The point of cryptography is that you should be able to trust who you choose to trust. Apple is saying we can trust their claim of not being able to decrypt iMessages. But that claim rests on Apple to serving up the proper public keys through Apple-controlled servers. This is called the key exchange problem, and it's why their iMessage claim can be accurately described as "completely bogus." They don't even attempt to address key exchange security.
The takeaway is: iMessage shouldn't be trusted.