Hacker News new | ask | show | jobs
by 486sx33 662 days ago
And now there is contact key verification, which I believe requires iMessage on iCloud to be enabled

https://support.apple.com/en-us/118246

This seems to eliminate the problem listed in the article. However each person on each side of the conversation has to enable contact key verification with the other person manually and be on software above Sonoma or iOS 17.2. But then it (apparently) makes it so Apple can’t read your messages. I assume this is some kind of back door on apples part to counter an NSA initiative

Note that an intel iMac19,1 (only model) can upgrade to Sonoma without a T2 chip , so it could be possible to use such a machine to extract secret keys or at least hack or spoof contact key verification key (maybe only for the specific user though not a global key)

1 comments

Contact key verification solves a different problem. Apple still retains the ability to decrypt your messages unless you and the person you are messaging both enable Advanced Data Protection or disable cloud backup entirely (sorry, no third party backup options allowed in the walled garden).