TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Apple can read your iMessages (even though they’re E2E encrypted)

304 pointsby decryptover 3 years ago

24 comments

whoknowswhat11over 3 years ago
A better headline - users willing to give up privacy for convenience.<p>Reality - there was a period where the icloud backups created backups that apple did not have access to. Critically, this mean that if you had any of a wide variety of things happen - unless you were very good about key management - your content was lost for good. ALL your photos (which could be heartbreaking) etc.<p>It turns out this is NOT what people want. They want apple to have access to their content, so when they have a device stolen and don&#x27;t have a super long recovery key properly saved, they are not hosed.<p>Same issue BTW with bitlocker on windows. People DO NOT save those recovery keys, even if they should. Microsoft added a way to force a backup into an account admins and others would have access to, thank goodness, because otherwise users there would be hosed as well.
评论 #28341417 未加载
评论 #28342258 未加载
评论 #28341113 未加载
评论 #28343065 未加载
评论 #28343092 未加载
评论 #28348126 未加载
评论 #28341916 未加载
评论 #28342628 未加载
评论 #28344414 未加载
评论 #28342339 未加载
评论 #28341223 未加载
giantrobotover 3 years ago
I&#x27;m continually surprised that people can&#x27;t seem to understand E2EE. For whatever reason they assume it means a message is encrypted forever and unreadable by anyone.<p>There is zero guarantee from <i>any</i> E2EE system that the data is encrypted at rest by the sender and receiver. In fact in most cases, the data is <i>not</i> encrypted at rest because people want to do silly things like read messages.<p>The exact same vulnerability exists on every platform that&#x27;s automatically backing up local data to <i>the cloud</i>. Even if <i>you</i> disable cloud backups you&#x27;re still stuck if whoever you&#x27;re messaging has left them enabled.<p>The only meaningful way around this hole when it comes to messaging apps is row-level encryption on the backing store. This has a lot of problems of its own and potential holes when it comes to indexing and searching.
评论 #28343795 未加载
nostromoover 3 years ago
… if you back up your device to iCloud. (Of course, almost everyone does.)<p>Apple was apparently going to close this loophole, but decided not to. They probably received negative feedback from the three letter acronym agencies.
评论 #28340685 未加载
评论 #28341320 未加载
评论 #28340706 未加载
评论 #28340684 未加载
评论 #28340821 未加载
MaxBarracloughover 3 years ago
Similar discussion 9 days ago on the thread <i>Apple urged to drop plans to scan iMessages, images for sex abuse</i>: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=28233200" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=28233200</a><p>Perhaps we need a new term, other than <i>E2E encrypted</i>, to close the door on &#x27;loopholes&#x27; such as the provider managing your keys.
评论 #28340848 未加载
评论 #28341038 未加载
评论 #28343808 未加载
评论 #28345158 未加载
sschuellerover 3 years ago
These Apple privacy ads [1] are not aging well and they aren&#x27;t even old.<p>[1] <a href="https:&#x2F;&#x2F;youtu.be&#x2F;lHcf9ZkJ28o" rel="nofollow">https:&#x2F;&#x2F;youtu.be&#x2F;lHcf9ZkJ28o</a>
评论 #28341763 未加载
评论 #28341128 未加载
utf_8xover 3 years ago
The post has been deleted, here&#x27;s an archive link...<p><a href="https:&#x2F;&#x2F;web.archive.org&#x2F;web&#x2F;20210827045159&#x2F;https:&#x2F;&#x2F;old.reddit.com&#x2F;r&#x2F;privacy&#x2F;comments&#x2F;pcb3ej&#x2F;a_timely_reminder_that_apple_can_read_your&#x2F;" rel="nofollow">https:&#x2F;&#x2F;web.archive.org&#x2F;web&#x2F;20210827045159&#x2F;https:&#x2F;&#x2F;old.reddi...</a>
ummonkover 3 years ago
Without reading the post I assume it&#x27;s talking about iCloud backup (which is on by default) backing up your raw messages with just an Apple encryption key? That&#x27;s well documented and makes sense as a default functionality - average users would be too prone to losing their data if data weren&#x27;t backed up without E2EE.
评论 #28341039 未加载
评论 #28340921 未加载
评论 #28340852 未加载
评论 #28341139 未加载
ThinBoldover 3 years ago
Doesn&#x27;t Apple simply happen to be both the chat provider and backup provider, so Apple-A does the E2E encryption and Apple-B sees your backup because you sort of want that?<p>And people worrying about the other end of the chat... come on, you talked to them in the first place. They can forward anything, even if it&#x27;s via Signal.<p>The entire story is just hilarious and memeable. Users want backup; Apple open up the gate. Users want E2E; Apple shut up the gate. Users want iCloud recovery; Apple partially open the gate.
orastorover 3 years ago
Apple can also silently create a stealthy virtual device that will get all messages as your phone does
评论 #28341591 未加载
TameAntelopeover 3 years ago
I find this acceptable. My threat model includes pickpockets and nosy siblings. It doesn&#x27;t include nation states and highly sophisticated attacks.<p>If the government wants to look at my data, and has gone through the proper channels to do so, I believe that, generally, that system will protect me from a consequential privacy intrusion. It&#x27;s not a perfect system, but I believe the benefits of the power of subpoena are worth the costs, so I&#x27;m happy to participate in it.
评论 #28343823 未加载
setnoneover 3 years ago
Another reminder that if you sign out of your device Apple will forcefully turn on all iCloud switches upon next log it. <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=28285567" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=28285567</a>
beermonsterover 3 years ago
I’ve always disabled cloud backups. They don’t really serve much purpose anyway since it’s just settings and to me settings are less valuable than content. I can easily set my device up again from scratch - in fact I like to do that every now and then to get new defaults or see how UX has changed.<p>If you connect your device locally you can, just using Finder, make an <i>encrypted</i> local backup which IMHO is much better.<p>Even if Apple did say Cloud Backups were encrypted you’d have to take it at face value anyway. Always be in charge of your own data, and secure and back it up yourself.
timmitover 3 years ago
These two toggle are funny.<p>- back my encrypted data - back my encryption key (if back encryption key, the e2e does not make any sense)<p>What the encryption key will be used to encrypt the e2e encryption key?
jpxwover 3 years ago
Yet another reason to disable iCloud, if you’re privacy conscious.<p>Although you’re relying on your recipient disabling it too. So really you have to use something else. Signal, etc.<p>With that said, I still think an iPhone with iCloud disabled is better than other phones on the market privacy-wise. And for the average consumer, iPhones offer a good tradeoff between privacy and usability.
nimbiusover 3 years ago
Patiently awaiting the obligatory HN &#x27;iPhone considered harmful&#x27; thread at this point with complementary link to a medium article. Seriously though after the San Bernardino shooter fiasco and the ongoing us government regulation demands it was basically all but guaranteed apple would pull all the stops to get Sam off their back.
sirmike_over 3 years ago
In the early days when iCloud was new it corrupted my decade long (at that point in time) bookmarks.<p>I was devastated. I never recovered them all. But it taught me a lesson.<p>Apple in the cloud brings nothing good to the user if you trust them.<p>Since then I have never and will never use iCloud for anything important. I can see iCloud has become a vector for no privacy over the years.
makachover 3 years ago
E2E encryption != Encryption at rest.
ec109685over 3 years ago
This post is wrong. iCloud Backup is the only setting that matters. Whether you enable iCloud Messages or not has no baring on whether Apple can read your messages. With iCloud Message sync, Apple doesn’t store a decryption key on their servers.
sparker72678over 3 years ago
Also worth keeping in mind, this is true for any message you send that&#x27;s received by someone else, regardless of your own hygiene.<p>i.e. for true security <i>all</i> message participants must have iCloud Backoff off, etc.
exabrialover 3 years ago
Any system you don&#x27;t have root access too, or don&#x27;t fully comprehend the hardware design, can and will be used against you.
评论 #28344801 未加载
warning26over 3 years ago
If they can do this, surely this evaporates any security-related rationale for not providing a web-accessible version of iMessages.<p>If they just added <i>that</i>, it would be so incredibly useful. I&#x27;m sure they won&#x27;t though, because that might mean that people could access iMessages from non-Apple hardware (the HORROR).
marto1over 3 years ago
Aren&#x27;t they required by law to be able to do that ? (PATRIOT act, etc.)
评论 #28342012 未加载
rswailover 3 years ago
This preoccupation with Apple maintaining your privacy from <i>themselves</i> is ridiculous. They commit to protecting your privacy from <i>others</i> and are clear on what they have access to themselves.<p>If you want true E2E encryption and encryption at rest, then build your own infrastructure.
smoldesuover 3 years ago
Edward Snowden&#x27;s article earlier this week posited that some 80% of iPhone users leave auto-sync on for iCloud, meaning that there&#x27;s about a 20% chance that the next thing you send over iMessage isn&#x27;t encrypted.<p>Why is guesswork like that acceptable in a <i>privacy</i> tool? Furthermore, who actually believed that Apple <i>couldn&#x27;t</i> read their messages? &#x27;End-to-end&#x27; means very little when both ends are Apple-controlled.
评论 #28341187 未加载
评论 #28341347 未加载
评论 #28342110 未加载