Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

GP's point is sound: the weakness in public key crypto is key exchange. Unless you can independently verify that the keys you're getting from Apple belong to the intended recipient, the system doesn't work. You don't even have to add a key to the pool, you simply replace a key in the pool with a key generated by Apple, and when the message arrives on the server, it's decrypted and sent to anyone at all, and then re-encrypted with the recipient's key and sent along as normal. Even signatures aren't really a barrier in this case, since Apple can MITM your public key (used to verify the signature) to the recipient, as well.

Any crypto system whose security is predicated on a trusted server might as well be compromised. It's way too easy for servers to be subverted, either technologically or (il)legally.



If you have access to the private keys, which I'm assuming as I'm not talking about users trusting the system but rather researches identifying malicious use, then it's trivially easy to verify that the public keys being used are those, and only those, that correspond to the correct devices.

It's not a good system, but it's also not one that is impervious to detection of malicious activity.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: