Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It is E2EE, and the backups on Apple's servers are encrypted. However, if you also have iCloud Backup turned on, the encryption key is backed up plain-text [1][2], so the effect ("Apple is able to access them when subpeonaed" sic.) remains the same in those cases, but it can be configured/avoided.

[1]: https://support.apple.com/en-us/HT202303 [2]: https://www.reddit.com/r/apple/comments/8nbgyu/messages_in_i...



Do you use imessage in any groups were there isn't at least one member that has iCloud Backup turned off? I don't know a single person with it off.


Yes, several, they mostly all work in security and actually read the Platform Security Guide and made a decision the inconveniences were outweighed by the strengths of not storing that key.

Remember also that subpoenas rarely permit “fishing expeditions”, so if they want your iMessages, can convince the judiciary you have potentially committed a crime, your key not being stored and the E2EE nature doesn’t always mean a judge is going to let LE go after Bob, Joe, Bill and everyone you have messaged with and demand Apple hand over all their iMessages (if they have backups enabled).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: