7 ms·
Full text: https://pdf.yt/d/1dKWAxs03AvnYqkt https://pdf.yt/d/1dKWAxs03AvnYqkt
by jug5 12y ago
Full text: https://pdf.yt/d/1dKWAxs03AvnYqkt https://pdf.yt/d/1dKWAxs03AvnYqkt
- testuser12345 12y agoThanks for sharing!
- ejr 12y agoMods, please change the article URL to this.
- chmars 12y agoThe URL should IMHO be http://www.zdziarski.com/blog/?p=3441 http://www.zdziarski.com/blog/?p=3441 (primary source) or even directly http://www.zdziarski.com/blog/wp-content/uploads/2014/07/iOS_Backdoors_Attack_Points_Surveillance_Mechanisms.pdf http://www.zdziarski.com/blog/wp-content/uploads/2014/07/iOS....
- dang 12y agoI agree. We changed the url to that second link from http://www.sciencedirect.com/science/article/pii/S1742287614000036 http://www.sciencedirect.com/science/article/pii/S1742287614.... Linking directly to the pdf would go against what the author says he wants there.
- higherpurpose 12y ago> In October 2013, Quarkslab exposed design flaws(iMessage privacy) in Apple’s iMessage protocol demonstrating that Apple does, despite its vehement denial,have the technical capability to intercept private iMessage traffic if they so desired, or were coerced to under a court order. The iMessage protocol is touted to use end-to-end encryption, however Quarkslab revealed in their research that the asymmetric keys generated to perform this encryption are exchanged through key directory servers centrally managed by Apple, which allow for substitute keys to be injected to allow eavesdropping to be performed. Similarly, the group revealed that certificate pinning, a very common and easy-to-implement certificate chain security mechanism, was not implemented in iMessage, potentially allowing malicious parties to perform MiTM attacks against iMessage in the same fashion. So much for iMessage security. Also, ProtonMail works much in the same way (central key management), for anyone wondering, so it should be vulnerable to the same type of attacks.
- deleted 12y ago[deleted]
- newaccountfool 12y agoYcombinator and all users and people who accessed this page will be getting their front doors kicked in.