> In October 2013, Quarkslab exposed design flaws(iMessage privacy) in Apple’s iMessage protocol demonstrating that Apple does, despite its vehement denial,have the technical capability to intercept private iMessage traffic if they so desired, or were coerced to under a court order. The iMessage protocol is touted to use end-to-end encryption, however Quarkslab revealed in their research that the asymmetric keys generated to perform this encryption are exchanged through key directory servers centrally managed by Apple, which allow for substitute keys to be injected to allow eavesdropping to be performed. Similarly, the group revealed that certificate pinning, a very common and easy-to-implement certificate chain security mechanism, was not implemented in iMessage, potentially allowing malicious parties to perform MiTM attacks against iMessage in the same fashion.
So much for iMessage security. Also, ProtonMail works much in the same way (central key management), for anyone wondering, so it should be vulnerable to the same type of attacks.