8 ms·
iMessage, explained
- bgorman 3y agoMy prediction is that Apple will start to use attestation (device check) to lock down iMessage. The problem is that this would require a software update for older devices.
- ocdtrekkie 3y agoApple already provides security updates to all iOS devices made in the last 5ish years at least, so it would probably take a pretty trivial number of years for them to have an update deployed to nearly all iOS devices that see active use.
- gafage 3y agoThe iPhone 5s (released ten years ago) received an update earlier this year.
- uf00lme 3y agoI think that is how BBM worked, but I could be wrong. I'd be surprised if it is part of the over arching OS security. Sounds like something that should be in their lockdown mode at the very least.
- kotaKat 3y agoThey already partially do. > Warning: In order to generate the “validation data”, pieces of information about the device such as its serial number, model, and disk UUID are used. This means that not all validation data can be treated equivalently: just like with Hackintoshes, the account age and “score” determine if an invalid serial can be used, or if you get the “customer code” error. The "customer code" error is a prompt from Apple, basically an attestation failure -- you have to contact Apple Support to get your Apple ID unlocked once you've tripped the failure. Legitimate customers will breeze right through (eg, just approving your login from your legit device), but Hackintosh users use crafty means to fake their way through the process.[1] [1]https://old.reddit.com/r/hackintosh/comments/gij9rt/getting_imessage_to_work_with_customer_code/ https://old.reddit.com/r/hackintosh/comments/gij9rt/getting_...
- blibble 3y agoremote attestation would mean it's not possible to pull out the binary and run it externally you'd need the key from the TPM/secure enclave too, which is much much harder to extract
- SpaghettiCthulu 3y agoIt's only a matter of time until a company starts selling TPM dumps, right?
- blibble 3y agomaybe, but for a task like this it doesn't really scale Apple aren't going to allow one phone to attest 5000 new iMessage clients
- kotaKat 3y agoThat's... amusingly, also a thing in Chinese marketplaces, for a similar purpose. iCloud Activation Lock, on non-cellular devices (eg, Wi-Fi only iPads), relies on the device's serial number, Wi-Fi MAC, and Bluetooth MAC addresses as the three identifiers required to clear the Activation Lock check. Via special debug cables (eg, a "DCSD cable") there are ways to write in new SysCfg data to the flash to change those variables. This can also be done to Apple Watches (pre-Series 6) with a special dock also sold on the Chinese market. You can (sort of easily) get your hands on a "clean" serial/MACs set for under $10-15 or so on the market.
- Eriksrocks 3y agoInteresting. I assume this is mostly used to "wash" stolen devices to make them appear legitimate for resale? I'm surprised Apple designed the hardware to allow this without any sort of authentication.
- Eriksrocks 3y agoYou can't "dump" a TPM. That's the whole point. They are designed such that the cryptographic secrets they hold (including ones loaded at manufacturing) are unrecoverable without an electron microscope and nation-state level resources (and even then, it would be extremely difficult if not impossible on modern process nodes).
- WD40forRust42 3y ago[dead]
- cavisne 3y agoIt would require a hardware update for older devices I believe, ie any that don’t have TPMs
- thomasahle 3y agoMaybe, but they also just announced RCS support: https://9to5mac.com/2023/11/16/apple-rcs-coming-to-iphone/ https://9to5mac.com/2023/11/16/apple-rcs-coming-to-iphone/ so maybe they've just decided that this is a good opportunity to take the charge opening things up.
- whynot-123 3y agoI would like to point out how awesome it is that someone in high school is making this caliber of a post. I've thought at least a dozen times over the last 20 years how i would like to understand macOS internals, and this person is deconstructing it. well done!
- apetresc 3y agoFully agree, but you're even burying the lede here. He didn't just write the blog post, he wrote pypush itself.
- nicolas_17 3y agoI have confirmed with him that he hadn't been born yet when Steve Jobs announced the first iPhone. I feel old.
- deleted 3y ago[deleted]
- dbuxton 3y agoGenuine question - can a topic really be `opertunistic` or is that author typo? I love these `referer`-type misspellings that become fossilized over generations
- projektfu 3y agoThe code doesn't seem to use it, but I think it would be a misspelling by the author, as it's probably an integer code.
- nicolas_17 3y agoAt the protocol level, they are indeed just integers: https://theapplewiki.com/wiki/Apple_Push_Notification_Service#09_Push_Topics https://theapplewiki.com/wiki/Apple_Push_Notification_Servic...
- jjtech 3y agoUnfortunately, there are many typos in my code :P On the other hand, I'm not sure if this is a typo on Apple's part, but it certainly is weird: you must use "WindowSerial" here[1], not "WindowsSerial" with the extra s [1] https://github.com/JJTech0130/pypush/blob/8b33c0ee5d540d8ac7237a081a1f1f35b7621656/albert.py#L62C16-L62C16 https://github.com/JJTech0130/pypush/blob/8b33c0ee5d540d8ac7...
- girvo 3y agoThat "missing plural S in PascalCased (or camelCased) names" is something I see semi-often! Congratulations on this amazing work :)
- catlover76 3y agoI just got an iPhone for the first time, and it is a noticeably better device than my previous Android phones. One downside is that I can't use iMessage on my Windows and Linux computers. Will look into pypush Honestly, the iPhone is nudging me further to giving a Macbook/OSX a try one day, but the major blocker to me is the poor state of gaming on Macs.
- selykg 3y agoPersonally, the approach I took to this was just to game on consoles. In my personal experience, the upgrade cycle is far far better for me. I don't feel like I've missed anything as a result either.
- crossroadsguy 3y agoPersonally, for communication I never use a device platform specific/locked app/service. Maybe you could keep using the app(s) whatever you were.
- frizlab 3y agoI’m curious, what do you use then?
- gumby 3y agoThere are lots of choices depending on your community and desired feature set: whatsapp, fb messenger, instagram messenger, telegram, signal, discord, or the direct messaging features of other programs like Slack. imessage is an outlier in that it also has a bidirectional link with SMS. I just read today that FB messenger used to have this (who knew?) but no longer does. My reading of the EU's complaint is that if imessage didn't have this feature they would not be in trouble since they'd be no different from the other services in being a silo. Weird!
- frizlab 3y agoUnless I’m mistaken literally all of these services are locked down too, and few have E2E encryption… iMessage is indeed “Apple-only” but the rest is on “all” platforms only for purely economical reasons, as much as iMessage is on Apple platforms only for the same reason. At least iMessage falls back to SMS (soon RCS) when available, which is much more ubiquitous than the rest tbh… If you truly want to avoid a lock down you should host your own messaging solution.
- benoror 3y agoMore on this: https://news.ycombinator.com/item?id=38531759 https://news.ycombinator.com/item?id=38531759
- lxe 3y agoThis is phenomenal work. You should write a little on how you got into this whole field. There are high school and college kids all over reddit struggling how to excel at technical stuff, learn programming, get a job in tech, and I feel like they can really benefit from your perspective.
- tomashubelbauer 3y agoI don't disagree with what you say, but I would be surprised if it was any sort of secret sauce and not "just" an incredible amount of grinding, the seemingly zero-cost energy reservoir you can tap into as a young adult if you really like what you're doing and possibly an enlightened parent or a role model.
- terminous 3y ago> possibly an enlightened parent or a role model This is typically the 'secret sauce'.
- bexsella 3y agoI was once asked how I got to where I am, where others in my situation might not have, my response was: “Parents that gave a damn”. It wasn’t about pressuring me, it was about recognising my interest in computers, and fostering that interest as much as was financially possible given our circumstances (which were often dire). My parents aren’t technical, but they did what they could, and I wouldn’t be the engineer I am without that.
- drekipus 3y agoI grew up with a foster mother that actively "suppressed" what I did on the computer, banning me for a month if I didn't get changed immediately after school. Now I've become a senior engineer, but I'm kinda shotty at it, chaotic good in solving problems, but issues with authority and process. Who knows, maybe I would've became a "run of the mill" engineer if she helped.
- geospatialover 3y agothe fact that you're in high school is incredible. keep it up!
- phero_cnstrcts 3y agoNot many make it that far!
- xg15 3y ago> When making an IDS registration request, a binary blob called “validation data” is required. This is essentially Apple’s verification mechanism to make sure that non-Apple devices cannot use iMessage. I wonder, will this be in violation of the EU's DSA and/or DMA once they are in force?
- Longhanks 3y agoDSA and DMA do not magically grant you the permission to do whatever you want with Apple's servers, nor force they Apple into having to serve any particular valid response to the requests you make. In whatever way Apple is going to comply with DSA and DMA, this ain't it.
- xg15 3y agoI don't know the legal text, but improving interop specifically between messaging services seems to be a goal of the DMA, according to the EU parliament [1]: > Interoperability between messaging platforms will improve - users of small or big platforms will be able to exchange messages, send files or make video calls across messaging apps. Lock-in mechanisms like the above would at least run counter to that goal. I also think that enforcing device restrictions on a messaging service is more problematic than on some random API: Messengers are subject to the network effect and usually you can't freely choose which messenger you want to use - it depends on which one the people you want to talk with are on. In an extreme case, some person or business could choose to exclusively communicate using iMessage. Then you'd have to buy an iPhone just to be able to reach them. This seems like exactly the kind of interop problem the EU is concerned about. [1] https://www.europarl.europa.eu/news/en/headlines/society/20211209STO19124/eu-digital-markets-act-and-digital-services-act-explained https://www.europarl.europa.eu/news/en/headlines/society/202...
- turquoisevar 3y agoEuropean regulations work on a policy level not on a technical level. In other words, Apple having technical limitations isn’t illegal per se, Apple refusing to facilitate interoperability might be illegal (although future RCS adoption will meet the requirements). The above assumes that iMessage meets the regulations threshold, which it currently doesn’t according to Apple based on user numbers, but that’s a different debate.
- bentt 3y agoOMG I love this. Go get em! Also, this is perfect material for Hack Club. You should join! https://hackclub.com/ https://hackclub.com/
- cynicalsecurity 3y ago> In order to generate the “validation data”, pieces of information about the device such as its serial number, model, and disk UUID are used. Sadly, this is a clear sign the project is going to stop working eventually. At some point, the Apple is simply going to pull the plug. I remember doing similar tricks when I was a kid. Nowadays I simply won't even care trying. The problem clearly isn't supposed to be solved this way. I'm not even sure if it's a good exercise in programming either. Software development is about doing the things the right way, not exercising in futility. A better experience would be writing your own message delivery solution, superior to iMessage.
- jowea 3y agoI get it and it may be true in this case that Apple can too easily pull the plug, adversarial interoperability has a long history: https://www.eff.org/deeplinks/2019/06/adversarial-interoperability-reviving-elegant-weapon-more-civilized-age-slay https://www.eff.org/deeplinks/2019/06/adversarial-interopera...
- ianlevesque 3y agoThe messaging space also had the amazing Adium client during the last round of messaging wars, and less amazing Trillian as reverse engineered clients distributed or sold. I for one am excited to see this space heating back up.
- selykg 3y agoTrillian used to be amazing. It is up there in my memory as about as life changing as Winamp was for me personally.
- joshmanders 3y agoI remember being jealous I couldn't use Trillian because I didn't have a way to pay for it. Running AIM, ICQ and MSN all at the same time.
- jamesdepp 3y agopypush, the open source project behind today’s developments in the iMessage reversing news, is licensed under MongoDB’s Server Side Public License and owned by Beeper (JJTech sold the rights to Beeper, per discord). Although this library is fantastic, I do think that the extremely copyleft license could have implications on where we see this used.
- wmf 3y agoTime for some reverse reverse engineering.
- dinobones 3y agoReverse engineering iMessage has been touted as some holy grail meme for what... 10+ years now? So proud that a high school student was the one to finally figure it out. In a world of 100s of thousands of software engineers, "Cybersecurtiy professionals", and so on. A kid with almost no credentials out-innovates everyone because they have talent and focus. Literally HackerNews! My favorite kind of news.
- deleted 3y ago[deleted]
- Thoreandan 3y agoSo… anyone gonna make a libpurple plug-in?
- DANmode 3y agoIf you receive no replies, will you? =]
- deleted 3y ago[deleted]
- brcmthrowaway 3y ago[flagged]
- maqp 3y agoGonna repeat myself since iMessage hasn't improved one bit after four years. I also added some edits since attacks and Signal have improved. iMessage has several problems: 1. iMessage uses RSA instead of Diffie-Hellman. This means there is no forward secrecy. If the endpoint is compromised at any point, it allows the adversary who has a) been collecting messages in transit from the backbone, or b) in cases where clients talk to server over forward secret connection, who has been collecting messages from the IM server to retroactively decrypt all messages encrypted with the corresponding RSA private key. With iMessage the RSA key lasts practically forever, so one key can decrypt years worth of communication. I've often heard people say "you're wrong, iMessage uses unique per-message key and AES which is unbreakable!" Both of these are true, but the unique AES-key is delivered right next to the message, encrypted with the public RSA-key. It's like transport of safe where the key to that safe sits in a glass box that's strapped against the safe. 2. The RSA key strength is only 1280 bits. This is dangerously close to what has been publicly broken. On Feb 28 2023, Boudet et. al broke a 829-bit key. To compare these key sizes, we use https://www.keylength.com/en/2/ https://www.keylength.com/en/2/ 1280-bit RSA key has 79 bits of symmetric security. 829-bit RSA key has ~68 bits of symmetric security. So compared to what has publicly been broken, iMessage RSA key is only 11 bits, or, 2048 times stronger. The same site estimates that in an optimistic scenario, intelligence agencies can only factor about 1507-bit RSA keys in 2024. The conservative (security-consious) estimate assumes they can break 1708-bit RSA keys at the moment. (Sidenote: Even the optimistic scenario is very close to 1536-bit DH-keys OTR-plugin uses, you might want to switch to OMEMO/Signal protocol ASAP). Under e.g. keylength.com, no recommendation suggest using anything less than 2048 bits for RSA or classical Diffie-Hellman. iMessage is badly, badly outdated in this respect. 3. iMessage uses digital signatures instead of MACs. This means that each sender of message generates irrefutable proof that they, and only could have authored the message. The standard practice since 2004 when OTR was released, has been to use Message Authentication Codes (MACs) that provide deniability by using a symmetric secret, shared over Diffie-Hellman. This means that Alice who talks to Bob can be sure received messages came from Bob, because she knows it wasn't her. But it also means she can't show the message from Bob to a third party and prove Bob wrote it, because she also has the symmetric key that in addition to verifying the message, could have been used to sign it. So Bob can deny he wrote the message. Now, this most likely does not mean anything in court, but that is no reason not to use best practices, always. 4. The digital signature algorithm is ECDSA, based on NIST P-256 curve, which according to https://safecurves.cr.yp.to/ https://safecurves.cr.yp.to/ is not cryptographically safe. Most notably, it is not fully rigid, but manipulable: "the coefficients of the curve have been generated by hashing the unexplained seed c49d3608 86e70493 6a6678e1 139d26b7 819f7e90". 5. iMessage is proprietary: You can't be sure it doesn't contain a backdoor that allows retrieval of messages or private keys with some secret control packet from Apple server 6. iMessage allows undetectable man-in-the-middle attack. Even if we assume there is no backdoor that allows private key / plaintext retrieval from endpoint, it's impossible to ensure the communication is secure. Yes, the private key never leaves the device, but if you encrypt the message with a wrong public key (that you by definition need to receive over the Internet), you might be encrypting messages to wrong party. You can NOT verify this by e.g. sitting on a park bench with your buddy, and seeing that they receive the message seemingly immediately. It's not like the attack requires that some NSA agent hears their eavesdropping phone 1 beep, and once they have read the message, they type it to eavesdropping phone 2 that then forwards the message to the recipient. The attack can be trivially automated, and is instantaneous. So with iMessage the problem is, Apple chooses the public key for you. It sends it to your device and says: "Hey Alice, this is Bob's public key. If you send a message encrypted with this public key, only Bob can read it. Pinky promise!" Proper messaging applications use what are called public key fingerprints that allow you to verify off-band, that the messages your phone outputs, are end-to-end encrypted with the correct public key, i.e. the one that matches the private key of your buddy's device. 7. iMessage allows undetectable key insertion attacks. EDIT: This has actually has some improvements made a month ago! Please see the discussion in replies. When your buddy buys a new iDevice like laptop, they can use iMessage on that device. You won't get a notification about this, but what happens on the background is, that new device of your buddy generates an RSA key pair, and sends the public part to Apple's key management server. Apple will then forward the public key to your device, and when you send a message to that buddy, your device will first encrypt the message with the AES key, and it will then encrypt the AES key with public RSA key of each device of your buddy. The encrypted message and the encrypted AES-keys are then passed to Apple's message server where they sit until the buddy fetches new messages for some device. Like I said, you will never get a notification like "Hey Alice, looks like Bob has a brand new cool laptop, I'm adding the iMessage public keys for it so they can read iMessages you send them from that device too". This means that the government who issues a FISA court national security request (stronger form of NSL), or any attacker who hacks iMessage key management server, or any attacker that breaks the TLS-connection between you and the key management server, can send your device a packet that contains RSA-public key of the attacker, and claim that it belongs to some iDevice Bob has. You could possibly detect this by asking Bob how many iDevices they have, and by stripping down TLS from iMessage and seeing how many encrypted AES-keys are being output. But it's also possible Apple can remove keys from your device too to keep iMessage snappy: they can very possibly replace keys in your device. Even if they can't do that, they can wait until your buddy buys a new iDevice, and only then perform the man-in-the-middle attack against that key. To sum it up, like Matthew Green said[1]: "Fundamentally the mantra of iMessage is “keep it simple, stupid”. It’s not really designed to be an encryption system as much as it is a text message system that happens to include encryption." Apple has great security design in many parts of its ecosystem. However, iMessage is EXTREMELY bad design, and should not be used under any circumstances that require verifiable privacy. In comparison, Signal * Uses Diffie Hellman + Kyber, not RSA * Uses Curve25519 that is a safe curve with 128-bits of symmetric security, not 79 bits like iMessage. * Uses Kyber key exchange for post quantum security * Uses MACs instead of digital signatures * Is not just free and open source software, but has reproducible builds so you can be sure your binary matches the source code * Features public key fingerprints (called safety numbers) that allows verification that there is no MITM attack taking place * Does not allow key insertion attacks under any circumstances: You always get a notification that the encryption key changed. If you've verified the safety numbers and marked the safety numbers "verified", you won't even be able to accidentally use the inserted key without manually approving the new keys. So do yourself a favor and switch to Signal ASAP. [1] https://blog.cryptographyengineering.com/2015/09/09/lets-tal https://blog.cryptographyengineering.com/2015/09/09/lets-tal...
- edweis 3y agoMore and more often, I see titles that are not capitalized. Is it a new trend ?
- walteweiss 3y agoI guess most of the people never knew the titles are different.
- ChrisMarshallNY 3y agoI just got done adding APNs to one of my dashboard apps. It's a wicked pain in the butt, but I finally got it. The trickiest part was the backend server, which I implemented in ... gasp PHP. I didn't want to load in a whole SaaS, in order to do a very simple push notification, so I had to learn to do it from scratch. In the process, I learned that there's a lot of wrong information out there, and I had do quite a bit of trial and error. But it works, and the code is actually wicked simple.
- nicolas_17 3y agoThe protocol between your backend server and Apple, and between Apple and the phone, are completely different. So this comment seems almost off-topic...
- ChrisMarshallNY 3y agoNo, it’s not off-topic. I’m not claiming to have reverse-engineered that stuff (I have successfully reverse-engineered internal Apple tech in the past, and it hasn’t ended well. I’ve been writing Apple software, sometimes, at a fairly low level, for quite a while). I suspect there may be other reasons for the downvotes. It isn’t really something I’m losing much sleep over. It’s just a fairly typical type of HN comment. I literally, like, yesterday, got it going, and it was a less-than-linear process. My own experience, in hacking the system, has taught me to try to stay inside the lines –something that is increasingly difficult, these days. This article (which is excellent, and quite worthy of HN) made me think of it. Also, even doing what I did, has its challenges. I didn’t want to distract from the OP, by going into any detail. Maybe, one day, I’ll write it up (I’m fairly good at that kind of thing), but that is something for another day.
- devaiops9001 3y ago[flagged]
- local_crmdgeon 3y agoWhat
- autoexec 3y agoI was hoping this would explain why iMessage allows invisible messages and attachments. I really can't think of any reason why Apple would want to implement something like that, but they've been predictably used to infect devices.
- yalogin 3y agoThis has nothing to do with the iMessage protocol itself. Invisible messages looks like a bug, as it depends on the current UI and rendering repercussions. May be if you file a bug on them they may respond.
- kccqzy 3y agoIf you are talking about malware, then there's no need for Apple to implement something like invisible messages. Malware essentially just exploits the parser, takes over execution, and never executes the code to display messages or puts them into the chat history.
- nyreed 3y agoHuh. So Android's push notification service is built on their instant messenger (GTalk), and Apple's instant messenger is built on their push notification service. How cute.
- tech234a 3y agoNote: Android doesn’t use GTalk for notifications anymore, and the GTalk servers don’t exist any more [1]. [1]: https://arstechnica.com/gadgets/2021/08/a-decade-and-a-half-of-instability-the-history-of-google-messaging-apps/2/#h2 https://arstechnica.com/gadgets/2021/08/a-decade-and-a-half-...
- CTmystery 3y agoLearning the contract is great, thank you for the work! How about the infra stack used by imessages? Does anyone have intel on that? The scale is incredible, which always makes me wonder how it can be so good while other apple web services (forums, dev portals, etc) can be so buggy and half baked
- nicolas_17 3y agoThe actual mind-blowing scale is that Apple's push notification service isn't just carrying iMessages. It's also carrying push notifications for every third-party messaging app. And the non-messaging apps with notifications too. And the silent internal notifications. You added a meeting to your calendar on your Mac? Push notification to your iPhone to tell it that the iCloud data changed and it needs to update. Changed a file on iCloud Drive? Push notification to sync your other devices. Got a phone call, and it starts ringing on your Mac too via Continuity? Push notification (encrypted like an iMessage). Just how many messages are going through that service every second?!
- d4rkp4ttern 3y agoIt’s 2023 and I’m still really shocked how hard it is to download all your iMessages and archive or search through them.
- lxgr 3y agoAbsolutely amazing work. Just one nit: Per the article, > While the pair format is much more documented and easier to implement, it does not provide forward secrecy using “pre-keys” (similar to Signal) as the new pair-ec format does. Is there any indication that (modern, i.e. ECIES-using) iMessage really uses pre-keys? As far as I can tell, it only uses a drop-in replacement of ECIES instead of RSA for the encryption (and maybe signature?) part, but that alone does not yield forward secrecy. If there isn't, I believe this might be a misinterpretation of how RSA, Elliptic Curves, and forward secrecy relate. The Wikipedia article on iMessage seems to propagate the same mistake: > The post also noted that iMessage uses RSA key exchange. This means that, as opposed to what EFF's scorecard claims, iMessage does not feature forward secrecy. (The quoted reference actually makes no such claim.)
- joshavant 3y agoLooking at the Beeper Mini announcement [1], they clearly state that a user doesn't need an Apple ID to register their phone number and send/receive iMessages. Also, they describe direct, device-to-Apple interactions. However, this article says: > IDS is used as a keyserver for iMessage... > The first step in registering for IDS is getting an authentication token. This requires giving the API your Apple ID Username and Password. > After registering with IDS, you will receive an “identity keypair”. This keypair can then be used to perform public key lookups. So how does the Beeper Mini app take an arbitrary Android phone number, register public keys for it with IDS, and perform public key lookup of recipients... all without ever using an Apple ID? [1] https://blog.beeper.com/i/139416474/security-and-privacy https://blog.beeper.com/i/139416474/security-and-privacy EDIT - It looks like the answer here is the 'SMS Gateway' which is virtually undescribed in the OP article or anywhere on [1]. Guess that's the secret sauce.
- jjeaff 3y agoI just downloaded Beeper Mini on my android phone and after giving me a fail error when trying to send an SMS to Apple to register my phone, it then popped up asking for my apple id.
- swiftlyTyped 3y agoA few days later, seems apple has begun locking down iMessage further
- onlyhumans 3y agoThis is good. This iMessage back door would have allowed spoofing of phone numbers, hijacking sms from non iMessage users, and lots of spam