TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

iMessage Key Verification

239 点作者 simpleintheory超过 1 年前

15 条评论

danShumway超过 1 年前
This seems somewhat similar to Matrix&#x27;s (and other apps&#x27;) approach of comparing keys to verify identity (plus with I guess some extra hardware requirements and attestation).<p>I&#x27;m interested to see what the uptake is among users, because even though Matrix has done a fair amount to smooth this process, verification is still a pretty large source of friction from what I can tell, and I&#x27;m not completely sure how it could be made easier. I guess the idea here is that once you verify a contact that syncs to their other devices, but in theory Matrix also does that, and in practice I still see some friction.<p>It&#x27;s possible Apple&#x27;s implementation will just be better, or that they&#x27;ll rely on attestation to such a degree that they&#x27;ll be able to skip some other friction points. But even with the public verification setup (which gets rid of the problem of needing to verify devices at the same time as the person you&#x27;re talking to), I&#x27;m still slightly skeptical that users are going to copy and paste a code into their messaging app to verify contacts. My experience is that even popping up a button and saying, &quot;do your friend and you see the same emoticons&quot; is too much work for a lot of users.<p>Maybe I&#x27;ll be wrong. And I guess ideally if iOS users get used to doing this, they might be more tolerant of doing the same thing in other messengers too.
评论 #38715157 未加载
评论 #38715417 未加载
评论 #38716427 未加载
评论 #38715735 未加载
kfreds超过 1 年前
For those interested, the underlying technology for this feature is transparency logs. Some technical details for iMessage&#x27;s approach can be found here:<p><a href="https:&#x2F;&#x2F;security.apple.com&#x2F;blog&#x2F;imessage-contact-key-verification&#x2F;" rel="nofollow noreferrer">https:&#x2F;&#x2F;security.apple.com&#x2F;blog&#x2F;imessage-contact-key-verific...</a><p>The same technology powers WhatsApp&#x27;s key transparency:<p><a href="https:&#x2F;&#x2F;engineering.fb.com&#x2F;2023&#x2F;04&#x2F;13&#x2F;security&#x2F;whatsapp-key-transparency&#x2F;" rel="nofollow noreferrer">https:&#x2F;&#x2F;engineering.fb.com&#x2F;2023&#x2F;04&#x2F;13&#x2F;security&#x2F;whatsapp-key-...</a><p>Less than a month ago the first workshop on &quot;transparency systems&quot; was held at ACM CCS:<p><a href="https:&#x2F;&#x2F;catsworkshop.dev" rel="nofollow noreferrer">https:&#x2F;&#x2F;catsworkshop.dev</a><p>Shameless plug: I&#x27;m one of the designers of the Sigsum public transparency log, as well as System Transparency - a security architecture intended to bring transparency to the reachable state space of a remote running system.
arthurcolle超过 1 年前
Is this to kill off Beeper?<p>EDIT: no, it wasn&#x27;t. it was announced a year ago per other comments...
tamimio超过 1 年前
I think this feature is already in other chat apps like matrix or telegram, will see how’s Apple implementation compares, but great addition nonetheless.
vinay_ys超过 1 年前
Why does Apple couple iMessage with rest of iCloud? Why is iCloud and iCloud Keychain being on a requirement for secure iMessage to function? That seems like a poor design choice to me.<p>For someone who cares about their communication security deeply enough to do contact public key verification, they would likely want to turn off iCloud syncing iMessage across multiple devices. They are likely to not have same iCloud account on multiple devices. In such cases, what&#x27;s the value of having iCloud Keychain being turned on?
评论 #38727765 未加载
评论 #38718250 未加载
poorman超过 1 年前
How safe is the contact that is uploaded to the iCloud? How safe is the contact from being modified by some app on your iPhone? The contact containing the verification code seems to be one of the weaker link in this whole thing.<p>If Mallory can change the verification code in the contact to their own, the communication between Alice and Bob is no longer protected.
评论 #38715344 未加载
评论 #38715949 未加载
flandish超过 1 年前
Doesn’t sharing your pub code also kind of build a network of “proof” this is you? As in sure Billy knows its you but so will a court have that same evidence, making denial “thats a spoofed message” harder.
mjsweet超过 1 年前
It looks like I would need the following for this to work:<p>To use iMessage Contact Key Verification, you’ll need: iOS 17.2, watchOS 9.2 and macOS 14.2 on all devices where you’ve signed in to iMessage with your Apple ID<p>Unfortunately my work iMac isn’t on Sonoma, it’s on Monterey. I suppose I could log out on that machine, but still, a bit of a shame older versions aren’t supported.<p>Am I reading the requirements correctly? Does this mean that for all devices to work with CKV, then all OS’s need to be updated, or will it not do CKV on any devices if even one device is not supported?
评论 #38716523 未加载
aaomidi超过 1 年前
There is a huge opportunity here for Apple to do a proper chain of trust.<p>“You want to talk to Adam, but you haven’t verified their keys yet. However your contacts Anna and Derek have confirmed Adam’s identity”
评论 #38716251 未加载
评论 #38715826 未加载
lxgr超过 1 年前
Quite disappointingly, this requires being logged in with iCloud as well as iMessage on the same device, so I can&#x27;t use it on my work computer (I have different Apple IDs at work and home). I don&#x27;t really see why the two need to be tangled together.
评论 #38716669 未加载
评论 #38716519 未加载
Humphrey超过 1 年前
I wonder if the timing of this in response to Beeper Mini gaining access to the iMessage network?
评论 #38715037 未加载
评论 #38715011 未加载
评论 #38715067 未加载
评论 #38715956 未加载
评论 #38715004 未加载
评论 #38714957 未加载
SheinhardtWigCo超过 1 年前
I wonder, why now? Smells like a warrant canary.
评论 #38716892 未加载
varenc超过 1 年前
Seems like Apple is tacitly acknowledging that sophisticated actors have successfully been man-in-the-middling iMessage users. I wonder if they have clear evidence of that since I haven’t seen any coverage on this.
评论 #38716447 未加载
评论 #38716058 未加载
评论 #38715693 未加载
评论 #38715703 未加载
0x0超过 1 年前
Sucks that it requires iCloud Keychain enabled, and also removing your appleid from any legacy macs and iphones. Wish they explained the reasons for this, because I&#x27;m having a hard time seeing one.
评论 #38715899 未加载
评论 #38715814 未加载
评论 #38715893 未加载
评论 #38715902 未加载
zaps超过 1 年前
So like is “sophisticated threats” a passive-aggressive way of saying “Beeper”?
评论 #38715656 未加载
评论 #38715600 未加载
评论 #38716477 未加载