Not trying to be contrarian or argumentative with this, but apple claims that imessage is end to end encrypted and therefore not readable even by them. Do you have evidence to the contrary? Or am I missing some other aspect?
I want to make one technical point absolutely clear because several people have misunderstood my argument:
The encryption still works.
OpenAl hasn't cracked or mathematically broken iMessage encryption. An iMessage remains encrypted between endpoints.
The privacy problem occurs at the endpoint.
Once the message has been decrypted on the recipient's Mac, that recipient can authorise third party software to access the readable conversation.
The encryption worked exactly as designed. It simply can't protect message content from software authorised to access it before or after decryption.
That's what I mean when I say this integration undermines the purpose of end to end encryption.
But it doesn’t undermine the purpose of end to end encryption? End to end encryption means it’s encrypted on one end and is decrypted on the other end, as opposed to being decrypted somewhere in the middle.
This problem doesn’t for anything to undermine end to end encryption at all? With E2EE you still have to trust the other end. If the person who is the other end installs a plugin that reads the texts you send them, that’s not really a technology problem it’s an OpSec problem.
I agree. It definitely does undermine the purpose of E2EE. I just wanted to let it be known that ChatGPT hasn’t actually broken the encryption algo.
Still, fuck Open AI, and any friend who would ever use AI to scan our Signal chats (if such a plugin is ever created) will be immediately cut off from chat comms.
It doesn’t break the encryption, you’re right, though insofar as it makes the encryption irrelevant, I’d say it’s being undermined, but that’s just wordplay. The point is, fuck Open AI.
It doesn’t make the encryption irrelevant nor is it undermined in any way.
The person on the other end that you’re choosing to communicate with is the weak link. It has nothing to do with encryption at all. They could do the exact same thing whether encrypted or not. E2EE is simply not a factor here at all
You can enable Advanced Data Protection and Apple will no longer store the keys, however this is off by default and for something like an iMessage conversation both users would have to enable it for it to mean anything
This is a rage bait headline. OpenAI has a plugin that you can give access to your messages. The claim that this is somehow different from any other use, or breaks some implied secrecy because it was encrypted, is nonsense. You never have control over what the person at the other end of a conversation does with that conversation and encryption was never meant to address that.
The claim that this is somehow different from any other use
You never have control over what the person at the other end of a conversation does
encryption was never meant to address that
I wonder why Apple stans never bring this up when calling it the most private operating system that "cares" about user "privacy" and "security" when they can just hand over your E2EE messages after it's decrypted, if a company has a "plugin".
Convenient, isn't it?
And if Apple has a plugin for OpenAI, think of what "plugins" the government has behind closed doors.
But stans never stop repeating the same "encryption", "privacy", "security" talking points when defending it.
I wonder why Apple stans never bring this up when calling it the most private operating system that "cares" about user "privacy" and "security" when they can just hand over your E2EE messages after it's decrypted, if a company has a "plugin".
I don’t really understand what the point is you’re trying to make here.
What does Apple have to do with what somebody you’re sending texts to does with the texts you sent them? What is any company supposed to do about that?
Why would they do that? That wouldn’t stop the person you’re texting from just copying and pasting your texts into ChatGPT directly, which is your actual problem. If you text somebody, no matter how “private” it is, you have to trust the person you’re texting because you’re giving them those texts and they can do whatever they want with them.
No… the blame is shifted to the person for sharing their private texts in this scenario. The blame is on the person, who made the decision of sharing the texts…
What bullshit in the UK. Be specific and informative. You mean they discontinued the Advanced Data Protection, yeah it sucks. But the alternative was the UK government forcing them to create a back door, as part of Investigatory Powers Act of 2016, which they rejected.
26 Comments
JiveTurkey@lemmy.world · 32 pts · 16d
So is trusting apple messages.
umbrella@lemmy.ml · 17 pts · 16d
bigbangdangler@reddthat.com · 8 pts · 16d
But they're different! They're so privacy focused! They care about their customers more than the other guy!
...and other such silliness I have heard on certain forums.
Kevlar21@piefed.social · 9 pts · 16d
Not trying to be contrarian or argumentative with this, but apple claims that imessage is end to end encrypted and therefore not readable even by them. Do you have evidence to the contrary? Or am I missing some other aspect?
speckofrust@lemmy.dbzer0.com · 10 pts · 16d
From the article…
I want to make one technical point absolutely clear because several people have misunderstood my argument:
The encryption still works. OpenAl hasn't cracked or mathematically broken iMessage encryption. An iMessage remains encrypted between endpoints. The privacy problem occurs at the endpoint.
Once the message has been decrypted on the recipient's Mac, that recipient can authorise third party software to access the readable conversation. The encryption worked exactly as designed. It simply can't protect message content from software authorised to access it before or after decryption.
That's what I mean when I say this integration undermines the purpose of end to end encryption.
EncryptKeeper@lemmy.world · 2 pts · 16d
But it doesn’t undermine the purpose of end to end encryption? End to end encryption means it’s encrypted on one end and is decrypted on the other end, as opposed to being decrypted somewhere in the middle.
This problem doesn’t for anything to undermine end to end encryption at all? With E2EE you still have to trust the other end. If the person who is the other end installs a plugin that reads the texts you send them, that’s not really a technology problem it’s an OpSec problem.
speckofrust@lemmy.dbzer0.com · 1 pts · 16d
I agree. It definitely does undermine the purpose of E2EE. I just wanted to let it be known that ChatGPT hasn’t actually broken the encryption algo.
Still, fuck Open AI, and any friend who would ever use AI to scan our Signal chats (if such a plugin is ever created) will be immediately cut off from chat comms.
EncryptKeeper@lemmy.world · 2 pts · 16d
It doesn’t undermine it at all is what I’m saying. The problem is just entirely unrelated to E2EE
speckofrust@lemmy.dbzer0.com · 0 pts · 14d
It doesn’t break the encryption, you’re right, though insofar as it makes the encryption irrelevant, I’d say it’s being undermined, but that’s just wordplay. The point is, fuck Open AI.
EncryptKeeper@lemmy.world · 1 pts · 14d
It doesn’t make the encryption irrelevant nor is it undermined in any way.
The person on the other end that you’re choosing to communicate with is the weak link. It has nothing to do with encryption at all. They could do the exact same thing whether encrypted or not. E2EE is simply not a factor here at all
Auli@lemmy.ca · 2 pts · 16d
The problem is Apple controls the keys.
EncryptKeeper@lemmy.world · 2 pts · 16d
You can enable Advanced Data Protection and Apple will no longer store the keys, however this is off by default and for something like an iMessage conversation both users would have to enable it for it to mean anything
Jacob93@sh.itjust.works · 22 pts · 16d
This is a rage bait headline. OpenAI has a plugin that you can give access to your messages. The claim that this is somehow different from any other use, or breaks some implied secrecy because it was encrypted, is nonsense. You never have control over what the person at the other end of a conversation does with that conversation and encryption was never meant to address that.
0_o7@lemmy.dbzer0.com · 0 pts · 16d
Yes, it is.
I wonder why Apple stans never bring this up when calling it the most private operating system that "cares" about user "privacy" and "security" when they can just hand over your E2EE messages after it's decrypted, if a company has a "plugin".
Convenient, isn't it?
And if Apple has a plugin for OpenAI, think of what "plugins" the government has behind closed doors.
But stans never stop repeating the same "encryption", "privacy", "security" talking points when defending it.
EncryptKeeper@lemmy.world · 3 pts · 16d
I don’t really understand what the point is you’re trying to make here.
What does Apple have to do with what somebody you’re sending texts to does with the texts you sent them? What is any company supposed to do about that?
Goodlucksil@lemmy.dbzer0.com · -2 pts · 16d
Apple makes iOS updates. It isn't hard to block chatgpt from accessing those supposedly "private" messages.
EncryptKeeper@lemmy.world · 4 pts · 16d
Why would they do that? That wouldn’t stop the person you’re texting from just copying and pasting your texts into ChatGPT directly, which is your actual problem. If you text somebody, no matter how “private” it is, you have to trust the person you’re texting because you’re giving them those texts and they can do whatever they want with them.
Goodlucksil@lemmy.dbzer0.com · 0 pts · 15d
The blame is shifted to the person for airing their private texts then if they copy-paste the messages into ChatGPT.
Otherwise, the blame is on Apple, who made the decision of sharing the texts.
EncryptKeeper@lemmy.world · 2 pts · 15d
No… the blame is shifted to the person for sharing their private texts in this scenario. The blame is on the person, who made the decision of sharing the texts…
Apple is uninvolved in the decision
partofthevoice@lemmy.zip · 2 pts · 16d
But has Apple ever allowed a third party cloud service to integrate with your text messages at the request of your best friend on their phone?
E2EE solves the Two Generals Problem. There’s also the issue of flat out letting the bad guys in.
eremophila@lemmy.zip · 17 pts · 16d
chatgpt
apple
what could go wrong?
ThatGuyNamedZeus@feddit.org · 4 pts · 16d
using apple devices is dangerous and irresponsible and I don't know how they're still in business after that bullshit they pulled in the UK
elastichamster@lemmy.world · 1 pts · 16d
What bullshit in the UK. Be specific and informative. You mean they discontinued the Advanced Data Protection, yeah it sucks. But the alternative was the UK government forcing them to create a back door, as part of Investigatory Powers Act of 2016, which they rejected.
ThatGuyNamedZeus@feddit.org · 3 pts · 16d
No, the age verification that they weren't actually obligated to do
EncryptKeeper@lemmy.world · 1 pts · 16d
Because the only viable alternative is Google, who are objectively worse.
sudoer777@lemmy.ml · 3 pts · 16d
Depends on your threat model IMO, but I wouldn't use either of those services in particular
HiddenLayer555@lemmy.ml · 1 pts · 16d
Untamed_Star@lemmy.blahaj.zone · 1 pts · 16d
[REDACTED] indeed