Remix.run Logo
staplers 2 days ago

  allows them to claim iMessage is e2ee while still escrowing keys in effective plaintext to Apple in the iCloud Backup
Does this also apply to their advanced data protection feature?
thewebguyd a day ago | parent | next [-]

I don' think so, but, even with advanced data protection on - if you communicate with someone via iMessage, for example, that does not use advanced data protection, and then they use iCloud backup, then it nullifies it essentially. Feds could get your messages via the recipients iCloud backup.

Advanced Data Protection needs to be turned on for both you, and everyone you communicate with if you want the full chain to be E2EE. Your communications are only ever as secure as its recipient.

intrasight 2 days ago | parent | prev [-]

My read is that it does not apply to ADP.

Also, what regular criminal, let alone terrorist, would leave iCloud backup turned on after all the hacks and leaks over the years. I assume that most in the HN community, like myself, have iCloud backup turned off.

sneak a day ago | parent [-]

Criminals (that get caught, or get put under surveillance) are generally criminals because they are stupid.

I would venture a guess that almost all criminals have iCloud Backup enabled, because that is the default setting.