[Infowarrior] - Dear Apple: Please set iMessage free
Richard Forno
rforno at infowarrior.org
Mon Aug 20 07:17:06 CDT 2012
Saturday, August 18, 2012
Dear Apple: Please set iMessage free
http://blog.cryptographyengineering.com/2012/08/dear-apple-please-set-imessage-free.html
Normally I avoid complaining about Apple because (a) there are plenty of other people carrying that flag, and (b) I honestly like Apple and own numerous lovely iProducts. I'm even using one to write this post.
Moroever, from a security point of view, there isn't that much to complain about. Sure, Apple has a few irritating habits -- shipping old, broken versions of libraries in its software, for example. But on the continuum of security crimes this stuff is at best a misdemeanor, maybe a half-step above 'improper baby naming'. Everyone's software sucks, news at 11.
There is, however, one thing that drives me absolutely nuts about Apple's security posture. You see, starting about a year ago Apple began operating one of the most widely deployed encrypted text message services in the history of mankind. So far so good. The problem is that they still won't properly explain how it works.
And nobody seems to care.
< -- >
To me, the disconcerting thing about iMessage is how rapidly it's gone from no deployment to securing billions of text messages for millions of users. And this despite the fact that the full protocol has never been published by Apple or (to my knowledge) vetted by security experts. (Note: if I'm wrong about this, let me know and I'll eat my words.)
---
Just because i'm near the punchbowl doesn't mean I'm also drinking from it.
More information about the Infowarrior
mailing list