http://blog.cryptographyengineering.com/2013/06/can-apple-re...
http://arstechnica.com/security/2013/06/can-apple-read-your-...
http://www.zdnet.com/apples-imessage-encryption-claims-refut...
According to Apple, each device's private key is generated locally and never leaves the device, making it impossible to MITM your messages.
From page 20: "For each key pair, the private keys are saved in the device’s keychain and the public keys are sent to Apple’s directory service (IDS), where they are associated with the user’s phone number or email address, along with the device’s APNs address."
[1] http://images.apple.com/iphone/business/docs/iOS_Security_Fe...
When I ask for nardi's public key, they can give me theirs, I encrypt it with that key and send it. They use their private key to decrypt it, store it, and then encrypt it with your actual public key and forward it along, neither of us any the wiser.
Couldn't you say the same thing about Signal? Both parties claim to use end-to-end encryption.
"The audio/video contents of FaceTime calls are protected by end-to-end encryption, so no one but the sender and receiver can access them. Apple cannot decrypt the data."
https://ssl.apple.com/iphone/business/docs/iOS_Security_Feb1...
> And you can only do that between iPhone/Mac users.
Ah yeah, I thought Signal was only for iPhone, based on the title. Should have read the first paragraph more closely.
It appears to interoperate with RedPhone, an Android app by the same authors.
"Apple does not log messages or attachments, and their contents are protected by end-to-end encryption so no one but the sender and receiver can access them. Apple cannot decrypt the data."
Which has been refuted several times.
[1] https://ssl.apple.com/iphone/business/docs/iOS_Security_Feb1...