Cryptography Experts Recommend Apple Replace its iMessage Encryption

IMessage_IconApple has implemented a series of short- and long-term defenses to its iMessage protocol after several issues were discovered by a team of researchers at Johns Hopkins University, according to a report published today (via PatentlyApple).

This attack is different to the one Johns Hopkins researchers discovered in March, which allowed an attacker to decrypt photos and videos sent over iMessage.

The technical paper details how another method known as a "ciphertext attack" allowed them to retrospectively decrypt certain types of payloads and attachments when either the sender or receiver is still online.

The scenario requires that the attacker intercepts messages using stolen TLS certificates or by gaining access to Apple's servers. While the attack takes a high level of technical expertise to be successful, the researchers note that it would be well within the means of state-sponsored actors.

Overall, our determination is that while iMessage’s end-to-end encryption protocol is an improvement over systems that use encryption on network traffic only (e.g., Google Hangouts), messages sent through iMessage may not be secure against sophisticated adversaries.

The team also discovered that Apple doesn't rotate encryption keys at regular intervals, in the way that modern encryption protocols such as OTR and Signal do. This means that the same attack can be used on iMessage historical data, which is often backed up inside iCloud. In theory, law enforcement could issue a court order forcing Apple to provide access to their servers and then use the attack to decrypt the data.

The researchers believe the attack could also be used on other protocols that use the same encryption format, such as Apple's Handoff feature, which transfers data between devices via Bluetooth. OpenPGP encryption (as implemented by GnuPGP) may be vulnerable to similar attacks when used in instant messaging applications, the paper noted.

Apple was notified of the issue as early as November 2015 and patched the iMessage protocol in iOS 9.3 and OS X 10.11.4 as a result. Since that time, the company has been pushing out further mitigations recommended by the researchers through monthly updates to several of its products.

However, the team's long-term recommendation is that Apple should replace the iMessage encryption mechanism with one that eliminates weaknesses in the protocol's core distribution mechanism.

The paper detailing the security issue is called Dancing on the Lip of the Volcano: Chosen Ciphertext Attacks on Apple iMessage, and was published as part of the USENIX Security Symposium, which took place in Austin, Texas. You can read the full paper here.

Top Rated Comments

joe-h2o Avatar
77 months ago
John Hopkins is a renowned medical school in Baltimore. What makes them the experts on cryptography?
It's more than just a medical school.

Jesus ****ing christ on a stick we're less than three comments in and 2/3 of them are dismissing this out of hand because it's not a 100% positive Apple story but a constructive criticism of how they can improve weaknesses in their cryptography.
Score: 40 Votes (Like | Disagree)
Telos101 Avatar
77 months ago
John Hopkins is a renowned medical school in Baltimore. What makes them the experts on cryptography?
They have an Information Security Institute. Professor Matthew Green was part of the research team.

Green is part of the group which developed Zerocoin ('https://en.wikipedia.org/wiki/Zerocoin'), an anonymous cryptocurrency ('https://en.wikipedia.org/wiki/Cryptocurrency'). His research team has exposed flaws in more than one third of SSL/TLS ('https://en.wikipedia.org/wiki/Transport_Layer_Security') encrypted web sites as well as vulnerabilities in encryption technologies, including RSA BSAFE ('https://en.wikipedia.org/wiki/RSA_BSAFE'), Exxon/Mobil Speedpass ('https://en.wikipedia.org/wiki/Speedpass'), E-ZPass ('https://en.wikipedia.org/wiki/E-ZPass'), and automotive security systems. In 2015, Green was a member of the research team that identified the Logjam ('https://en.wikipedia.org/wiki/Logjam_(computer_security)') vulnerability in the TLS protocol.

Green is a member of the technical advisory board for the Linux Foundation Core Infrastructure Initiative, formed to address critical Internet security concerns in the wake of the Heartbleed ('https://en.wikipedia.org/wiki/Heartbleed') security bug disclosed in April 2014 in the OpenSSL ('https://en.wikipedia.org/wiki/OpenSSL') cryptography library.

He sits on the technical advisory boards for CipherCloud ('https://en.wikipedia.org/wiki/CipherCloud'), Overnest and Mozilla Cybersecurity Delphi. Green co-founded and serves on the Board for Directors of the Open Crypto Audit Project (OCAP), which undertook a security audit ('https://en.wikipedia.org/wiki/Security_audit') of the TrueCrypt ('https://en.wikipedia.org/wiki/TrueCrypt') software.

https://en.wikipedia.org/wiki/Matthew_D._Green
Score: 35 Votes (Like | Disagree)
voxtro Avatar
77 months ago
John Hopkins is a renowned medical school in Baltimore. What makes them the experts on cryptography?
Comments like these annoy me quite a bit (unless I'm missing some type of sarcasm). As an Apple user and someone with a background in cryptography who has actually read the entire paper, you don't need to have a MIT or Stanford paper to make a cryptanalysis. In cryptography papers are heavily peer reviewed and skepticism is part of the process the whole time. At the end of the day it boils down to mathematics and computer science and these are provable things, so it's not hypothesis. The paper includes examples of how the attacks can be carried out and under specific conditions. It explains the protocols and the exact mechanisms used to extract the payloads in their settings. All the caveats are stated. Also, it does state that Apple implemented a lot of their recommendations in later versions of iOS and OS X/macOS (their paper references iOS 9.3 and OS X 10.11.4 or later)
Score: 31 Votes (Like | Disagree)
joe-h2o Avatar
77 months ago
I think I read this on news.google.com.au.... sounds like a beat up to me. Next....
You have to read more than just the title before you can make an informed comment.
Score: 19 Votes (Like | Disagree)
aplnub Avatar
77 months ago
I think I read this on news.google.com.au.... sounds like a beat up to me. Next....
Doesn't sound like a beat up to me. Sounds like good advice and it seems Apple has been favorable at receiving advice in the past. Hopefully, they address the concerns for all our sakes.
Score: 13 Votes (Like | Disagree)
aplnub Avatar
77 months ago
John Hopkins is a renowned medical school in Baltimore. What makes them the experts on cryptography?
A school cannot be great at more than one field?
Score: 11 Votes (Like | Disagree)

Popular Stories

maxresdefault

M2 13-Inch MacBook Pro With 256GB SSD Appears Slower Than Equivalent M1 in Real-World Speed Tests

Monday June 27, 2022 1:57 pm PDT by
Benchmark testing has indicated that the 256GB variant of the 13-inch MacBook Pro with M2 chip offers slower SSD performance than its M1 equivalent, and now real-world stress testing by YouTuber Max Yuryev of Max Tech suggests that the 256GB SSD in the 13-inch MacBook Pro is also underperforming in day-to day-usage. The M2 MacBook Pro with 256GB SSD and 8GB RAM was slower than the M1 MacBook ...
M2 Pro and Max Feature

Apple's Upcoming M2 Pro Chip for High-End MacBook Pro and Mac Mini Will Reportedly Be 3nm

Monday June 27, 2022 7:31 am PDT by
TSMC will manufacture Apple's upcoming "M2 Pro" and "M3" chips based on its 3nm process, according to Taiwanese industry publication DigiTimes. "Apple reportedly has booked TSMC capacity for its upcoming 3nm M3 and M2 Pro processors," said DigiTimes, in a report focused on competition between chipmakers like TSMC and Samsung to secure 3nm chip orders. As expected, the report said TSMC will...
iPhone 11 Pro vs iPhone 14 Pro

iPhone 11 Pro vs. 14 Pro: New Features to Expect if You've Waited to Upgrade

Monday June 27, 2022 11:22 am PDT by
With many customers choosing to upgrade their iPhone every two or three years nowadays, there are lots of iPhone 11 Pro users who might be interested in upgrading to the iPhone 14 Pro later this year. Those people are in for a treat, as three years of iPhone generations equals a long list of new features and changes to look forward to. Below, we've put together a list of new features and...
original iphone 2007

15 Years Ago Today, the iPhone Went On Sale

Wednesday June 29, 2022 4:43 am PDT by
Fifteen years ago to this day, the iPhone, the revolutionary device presented to the world by the late Steve Jobs, officially went on sale. The first iPhone was announced by Steve Jobs on January 9, 2007, and went on sale on June 29, 2007. "An iPod, a phone, an internet mobile communicator... these are not three separate devices," Jobs famously said. "Today, Apple is going to reinvent the...
tesla carplay hack

Tesla Apple CarPlay Hack Updated to Work With Any Tesla Model

Monday June 27, 2022 3:38 am PDT by
Polish developer Michał Gapiński has released a new and improved version of his "Tesla Android Project" which brings Apple's CarPlay experience to more Tesla vehicles than ever before. According to Gapiński, version 2022.25.1 provides "100% functional CarPlay integration for any Tesla," and comes with several new features and bug fixes. The project now supports DRM video playback so that...
13 inch macbook pro m2 mock feature 2

Base 13-Inch MacBook Pro With M2 Chip Has Significantly Slower SSD Speeds

Sunday June 26, 2022 2:52 pm PDT by
Following the launch of Apple's new 13-inch MacBook Pro with the M2 chip, it has been discovered that the $1,299 base model with 256GB of storage has significantly slower SSD read/write speeds compared to the equivalent previous-generation model. YouTube channels such as Max Tech and Created Tech tested the 256GB model with Blackmagic's Disk Speed Test app and found that the SSD's read and...
maxresdefault

Video Comparison: M2 MacBook Pro vs. M1 MacBook Pro

Tuesday June 28, 2022 2:45 pm PDT by
Apple last week launched an updated version of the 13-inch MacBook Pro, and it is the first Mac that is equipped with an updated M2 chip. As it's using a brand new chip, we thought we'd pick up the M2 MacBook Pro and compare it to the prior-generation M1 MacBook Pro to see just what's new. Subscribe to the MacRumors YouTube channel for more videos. For the video comparison, we're using the...
iPhone vs Galaxy Larger

Apple Executive Says Samsung Copied the iPhone and Simply 'Put a Bigger Screen Around It'

Tuesday June 28, 2022 8:59 am PDT by
The Wall Street Journal's Joanna Stern today shared a new documentary about the evolution of the iPhone ahead of the 15th anniversary of the device launching on June 29, 2007. The documentary includes an interview with Apple's marketing chief Greg Joswiak, iPhone co-creator Tony Fadell, and a family of iPhone users. One segment of the interview reflects on Android smartphones gaining larger...
widgets ios 16 feature

Gurman: iPhone 14 Pro to Feature Always-On Display Showing iOS 16's New Lock Screen Widgets

Sunday June 26, 2022 7:36 am PDT by
iPhone 14 Pro models are widely expected to feature always-on displays that allow users to view glanceable information without having to tap to wake the screen. In the latest edition of his Power On newsletter for Bloomberg, Mark Gurman said the feature will include support for iOS 16's new Lock screen widgets for weather, fitness, and more. "Like the Apple Watch, the iPhone 14 Pro will be...