Hacker News new | ask | show | jobs
by throwaway7767 3832 days ago
Apple can certainly read iMessage conversations and provide that data to goverments. They don't have the private keys, but they run the directory server that distributes the public keys used to encrypt to. So they can very easily provide you with the wrong public key for your recipient, decrypt that data and store/forward, and then re-encrypt on their end with the correct key and forward to the actual recipient.

"Secure" communications systems that rely on a trusted central third party to vouch for keys are no more secure than allowing that same third-party to implement key escrow.