iMessage's 'End-To-End' Encryption Hardly Any Better Than TLS, Say Cryptography Researchers

Apple’s iMessage has long been lauded as being the first mainstream chat application to use end-to-end encryption. However, cryptography professor Matthew Green and his team of students at Johns Hopkins University discovered that the iMessage's encryption is actually hardly any better than regular TLS network encryption.

Latest Videos FromTom's Hardware
Contributor

Lucian Armasu is a Contributing Writer for Tom's Hardware US. He covers software news and the issues surrounding privacy and security.

  • mrbofus
    "iMessage's 'End-To-End' Encryption Hardly Any Better Than TLS, Say Cryptography Researchers"

    Why is "end-to-end" in quotes? Isn't iMessage's encryption end-to-end? The quotes, particularly in the headline, imply that it's not...?
    Reply
  • Darkk
    "Ever since Edward Snowden released the NSA documents, an encryption mechanism called “forward secrecy” has significantly increased in popularity with service providers. The mechanism essentially automatically rotates the encryption keys at regular intervals, and once it switches to a new key, past data can’t be decrypted anymore."

    Not entirely accurate. Using "forward secrecy" simply protects a session in transit. There are several sessions over a short period of time. Only that session gets compromised if the attacker figured out the session encryption key.

    The attacker can capture all those sessions and do offline brute force which will take huge amount of resources and time to do it. NSA might be able to do this in parallel which is beyond reach for most of us.
    Reply