← Back to context

Comment by sneak

6 years ago

I was in exactly this same boat for a long time. I bought maybe a dozen iPhones through the years to upgrade friends and partners from Android just so I could iMessage them.

Turns out, most of iCloud is not e2e encrypted, critically, notes and pictures and contacts and backups. Apple (and by extension, US military intelligence and FBI/DHS) can read your private notes and see your nudes, and review your address book and message history. I knew I was going to need to switch eventually.

* iCloud device backup is on by default. This syncs all of your unencrypted iMessage history to Apple. It also syncs all of your conversation partners’ message histories, from their phones, to Apple. It is not e2e encrypted so it suffers from the Zoom Problem: Apple has the keys and can decrypt it, for themselves or the government via the illegal PRISM program.

* iMessage (despite being e2e) can be arbitrarily wiretapped by injecting a surveillance key because the client trusts the key list from the server blindly, with no UI notifications for the sender on key changes/amendments.

* I can’t run the client on half of my computers

* Signal works on ios/android and has desktop clients for all major platforms... and critically now supports iPads. It also has the nice property of being e2e without implicit trust in the server, although hopefully the TOFU model can be improved.

I switched. I am now signed out of iMessage on all my computers, and it’s great.

If I can do it, anyone can. I was in as far as one can go.