Cryptography Experts Recommend Apple Replace its iMessage Encryption

IMessage_IconApple has implemented a series of short- and long-term defenses to its iMessage protocol after several issues were discovered by a team of researchers at Johns Hopkins University, according to a report published today (via PatentlyApple).

This attack is different to the one Johns Hopkins researchers discovered in March, which allowed an attacker to decrypt photos and videos sent over iMessage.

The technical paper details how another method known as a "ciphertext attack" allowed them to retrospectively decrypt certain types of payloads and attachments when either the sender or receiver is still online.

The scenario requires that the attacker intercepts messages using stolen TLS certificates or by gaining access to Apple's servers. While the attack takes a high level of technical expertise to be successful, the researchers note that it would be well within the means of state-sponsored actors.

Overall, our determination is that while iMessage’s end-to-end encryption protocol is an improvement over systems that use encryption on network traffic only (e.g., Google Hangouts), messages sent through iMessage may not be secure against sophisticated adversaries.

The team also discovered that Apple doesn't rotate encryption keys at regular intervals, in the way that modern encryption protocols such as OTR and Signal do. This means that the same attack can be used on iMessage historical data, which is often backed up inside iCloud. In theory, law enforcement could issue a court order forcing Apple to provide access to their servers and then use the attack to decrypt the data.

The researchers believe the attack could also be used on other protocols that use the same encryption format, such as Apple's Handoff feature, which transfers data between devices via Bluetooth. OpenPGP encryption (as implemented by GnuPGP) may be vulnerable to similar attacks when used in instant messaging applications, the paper noted.

Apple was notified of the issue as early as November 2015 and patched the iMessage protocol in iOS 9.3 and OS X 10.11.4 as a result. Since that time, the company has been pushing out further mitigations recommended by the researchers through monthly updates to several of its products.

However, the team's long-term recommendation is that Apple should replace the iMessage encryption mechanism with one that eliminates weaknesses in the protocol's core distribution mechanism.

The paper detailing the security issue is called Dancing on the Lip of the Volcano: Chosen Ciphertext Attacks on Apple iMessage, and was published as part of the USENIX Security Symposium, which took place in Austin, Texas. You can read the full paper here.

Popular Stories

iPhone SE 4 Thumb 1

iPhone SE 4 With Apple's Own 5G Modem 'Confirmed' to Launch in March

Tuesday November 19, 2024 12:12 pm PST by
Barclays analyst Tom O'Malley and his colleagues recently traveled to Asia to meet with various electronics manufacturers and suppliers. In a research note this week, outlining key takeaways from the trip, the analysts said they have "confirmed" that a fourth-generation iPhone SE with an Apple-designed 5G modem is slated to launch towards the end of the first quarter next year. In line with previo...
airtag purple

AirTag 2 Rumored to Launch Next Year With These New Features

Sunday November 17, 2024 5:18 am PST by
Apple released the AirTag in April 2021, so it is now three over and a half years old. While the AirTag has not received any hardware updates since then, a new version of the item tracking accessory is rumored to be in development. Below, we recap rumors about a second-generation AirTag. Timing Apple is aiming to release a new AirTag in mid-2025, according to Bloomberg's Mark Gurman....
Magic Mouse Next to Keyboard

No, Apple CEO Tim Cook Didn't Say He Prefers Logitech's MX Master 3 Over the Magic Mouse

Sunday November 17, 2024 3:03 pm PST by
While the Logitech MX Master 3 is a terrific mouse for the Mac, reports claiming that Apple CEO Tim Cook prefers that mouse over the Magic Mouse are false. The Wall Street Journal last month published an interview with Cook, in which he said he uses every Apple product every day. Soon after, The Verge's Wes Davis attempted to replicate using every Apple product in a single day. During that...
Generic iOS 18 Feature Real Mock

Apple Releases iOS 18.1.1 and iPadOS 18.1.1 With Security Fixes

Tuesday November 19, 2024 10:10 am PST by
Apple today released iOS 18.1.1 and iPadOS 18.1.1, minor updates to the iOS 18 and iPadOS 18 operating systems that debuted earlier in September. iOS 18.1.1 and iPadOS 18.1.1 come three weeks after the launch of iOS 18.1. The new software can be downloaded on eligible iPhones and iPads over-the-air by going to Settings > General > Software Update. Apple has also released iOS 17.7.2 for...
at t turbo indicator iphone 16 pro max v0 8hrh7w5f3w1e1

AT&T Turbo Indicator Showing Up in iPhone Status Bar for Subscribers

Wednesday November 20, 2024 3:42 am PST by
AT&T has begun displaying "Turbo" in the iPhone carrier label for customers subscribed to its premium network prioritization service, according to reports on Reddit. The new indicator seems to have started appearing after users updated to iOS 18.1.1, but that could be just coincidence. Image credit: Reddit user No_Highlight7476 The Turbo feature provides enhanced network performance through ...
iPhone 17 Slim Feature Single Camera 1 Redux

'iPhone 17 Air' Rumored to Surpass iPhone 6 as Thinnest iPhone Ever

Monday November 18, 2024 1:07 pm PST by
In a research note with Hong Kong-based investment bank Haitong today, obtained by MacRumors, Apple analyst Jeff Pu said he agrees with a recent rumor claiming that the so-called "iPhone 17 Air" will be around 6mm thick. "We agreed with the recent chatter of an 6mm thickness ultra-slim design of the iPhone 17 Slim model," he wrote. If that measurement proves to be accurate, there would be ...
bug security vulnerability issue fix larry

Make Sure to Update: iOS 18.1.1 and macOS Sequoia 15.1.1 Fix Actively Exploited Vulnerabilities

Tuesday November 19, 2024 10:52 am PST by
The iOS 18.1.1, iPadOS 18.1.1, and macOS Sequoia 15.1.1 updates that Apple released today address JavaScriptCore and WebKit vulnerabilities that Apple says have been actively exploited on some devices. With the JavaScriptCore vulnerability, processing maliciously crafted web content could lead to arbitrary code execution. The WebKit vulnerability had the same issue with maliciously crafted...

Top Rated Comments

joe-h2o Avatar
108 months ago
John Hopkins is a renowned medical school in Baltimore. What makes them the experts on cryptography?
It's more than just a medical school.

Jesus ****ing christ on a stick we're less than three comments in and 2/3 of them are dismissing this out of hand because it's not a 100% positive Apple story but a constructive criticism of how they can improve weaknesses in their cryptography.
Score: 40 Votes (Like | Disagree)
Telos101 Avatar
108 months ago
John Hopkins is a renowned medical school in Baltimore. What makes them the experts on cryptography?
They have an Information Security Institute. Professor Matthew Green was part of the research team.

Green is part of the group which developed Zerocoin ('https://en.wikipedia.org/wiki/Zerocoin'), an anonymous cryptocurrency ('https://en.wikipedia.org/wiki/Cryptocurrency'). His research team has exposed flaws in more than one third of SSL/TLS ('https://en.wikipedia.org/wiki/Transport_Layer_Security') encrypted web sites as well as vulnerabilities in encryption technologies, including RSA BSAFE ('https://en.wikipedia.org/wiki/RSA_BSAFE'), Exxon/Mobil Speedpass ('https://en.wikipedia.org/wiki/Speedpass'), E-ZPass ('https://en.wikipedia.org/wiki/E-ZPass'), and automotive security systems. In 2015, Green was a member of the research team that identified the Logjam ('https://en.wikipedia.org/wiki/Logjam_(computer_security)') vulnerability in the TLS protocol.

Green is a member of the technical advisory board for the Linux Foundation Core Infrastructure Initiative, formed to address critical Internet security concerns in the wake of the Heartbleed ('https://en.wikipedia.org/wiki/Heartbleed') security bug disclosed in April 2014 in the OpenSSL ('https://en.wikipedia.org/wiki/OpenSSL') cryptography library.

He sits on the technical advisory boards for CipherCloud ('https://en.wikipedia.org/wiki/CipherCloud'), Overnest and Mozilla Cybersecurity Delphi. Green co-founded and serves on the Board for Directors of the Open Crypto Audit Project (OCAP), which undertook a security audit ('https://en.wikipedia.org/wiki/Security_audit') of the TrueCrypt ('https://en.wikipedia.org/wiki/TrueCrypt') software.

https://en.wikipedia.org/wiki/Matthew_D._Green
Score: 35 Votes (Like | Disagree)
voxtro Avatar
108 months ago
John Hopkins is a renowned medical school in Baltimore. What makes them the experts on cryptography?
Comments like these annoy me quite a bit (unless I'm missing some type of sarcasm). As an Apple user and someone with a background in cryptography who has actually read the entire paper, you don't need to have a MIT or Stanford paper to make a cryptanalysis. In cryptography papers are heavily peer reviewed and skepticism is part of the process the whole time. At the end of the day it boils down to mathematics and computer science and these are provable things, so it's not hypothesis. The paper includes examples of how the attacks can be carried out and under specific conditions. It explains the protocols and the exact mechanisms used to extract the payloads in their settings. All the caveats are stated. Also, it does state that Apple implemented a lot of their recommendations in later versions of iOS and OS X/macOS (their paper references iOS 9.3 and OS X 10.11.4 or later)
Score: 31 Votes (Like | Disagree)
joe-h2o Avatar
108 months ago
I think I read this on news.google.com.au.... sounds like a beat up to me. Next....
You have to read more than just the title before you can make an informed comment.
Score: 19 Votes (Like | Disagree)
aplnub Avatar
108 months ago
I think I read this on news.google.com.au.... sounds like a beat up to me. Next....
Doesn't sound like a beat up to me. Sounds like good advice and it seems Apple has been favorable at receiving advice in the past. Hopefully, they address the concerns for all our sakes.
Score: 13 Votes (Like | Disagree)
aplnub Avatar
108 months ago
John Hopkins is a renowned medical school in Baltimore. What makes them the experts on cryptography?
A school cannot be great at more than one field?
Score: 11 Votes (Like | Disagree)