Skip to main content

Despite FBI whining, iMessage isn’t invincible after all, researcher claims

how to save text messages
Kritchanut/Shutterstock
FBI director James Comey has been campaigning against Apple and Google’s decision to introduce “end-to-end” encryption on the companies’ respective smartphones since they announced it last fall. Most recently, Comey testified before the Senate Judiciary Committee about the dangers of encryption and asked Senators to pressure tech companies into rolling it back so that the contents of smartphones would be accessible to law enforcement. Comey argued that criminals are “going dark,” hiding evidence of their wrongdoing behind encryption that his agency cannot break.

However, Comey’s arguments about encryption don’t align with how iPhone encryption actually works, claims computer-security researcher Nicholas Weaver. In a post on the blog Lawfare on Tuesday, Weaver points out that, even if encryption protects the contents of your iMessages, the FBI can still obtain plenty of information about you from your iPhone — for instance, your location data and your iMessage metadata would both be accessible to law enforcement with a warrant.

Recommended Videos

Crucially, Weaver also points out that iPhone users who enable iCloud backups would be vulnerable to a FBI search warrant. iCloud backs up the contents of messages to Apple’s servers, making the messages themselves easily accessible — a far cry from the inaccessibility described by Comey before the Senate Judiciary Committee.

“Finally, there is iMessage, whose ‘end-to-end’ nature, despite FBI complaints, contains some significant weaknesses and deserves scare-quotes,” Weaver explains. Even though Apple CEO Tim Cook has claimed that there is no way for the company to read users’ iMessages, Weaver points out that it is possible to compromise the cryptography used to encrypt these messages.

Some encryption systems use a public keyserver, where users can look up and independently verify each other’s keys. However, Apple’s keyserver is private, so users have no way to independently verify each other’s keys. Apple could collaborate with law enforcement to provide a false key, thereby intercepting a specific user’s messages, and the user would be none the wiser. Weaver writes, “There remains a critical flaw: There is no user interface for Alice to discover (and therefore independently confirm) Bob’s keys.  Without this feature, there is no way for Alice to detect that an Apple keyserver gave her a different set of keys for Bob.  Without such an interface, iMessage is ‘backdoor enabled’ by design: The keyserver itself provides the backdoor.” Weaver says this vulnerability could also be used to tap into FaceTime calls.

“If one desires confidentiality, I think the only role for iMessage is instructing someone how to use Signal [an open-source encrypted messaging app],” Weaver concludes.

Kate Conger
Former Digital Trends Contributor
Kate is a freelance writer who covers digital security. She has also written about police misconduct, nail polish, DARPA…
I love Apple, but it’s totally wrong about iMessage and RCS
An iPhone 15 Pro showing the main iMessage screen.

I’ve been using an iPhone ever since 2008, starting with the original and then every generation since. For several years, the iPhone was only capable of SMS texting, with MMS support arriving with iOS 3 in 2009.

But in 2011, Apple created something new: iMessage. It first arrived on iOS and then went to the Mac in 2012 to replace iChat. iMessage is basically an instant messaging service that is exclusive to all Apple products: iPhone, iPad, Apple Watch, and Mac. You can send text, images and video, documents, rich preview links, stickers, and more between one another. You can also see if a message is delivered, send read receipts (if you want), and everything is encrypted. With iOS 16, you can even edit and unsend messages within a certain time frame.

Read more
The iPhone’s futuristic satellite tech isn’t coming to Android any time soon
The Google Pixel 8's screen.

It could take a while before Android phones allow satellite connectivity to assist users in emergency scenarios, thanks in no part to Qualcomm canceling its ambitious Snapdragon Satellite plans. Apple introduced satellite SOS support last year with the iPhone 14 series, with the intention of helping people when they are out of cellular or broadband coverage range.

The feature allows you to text emergency responders, share locations, and request roadside assistance. But not long after, hope emerged for Android phones. Earlier this year, Qualcomm announced Snapdragon Satellite, with the goal of aping Apple’s initiative for Android phones.

Read more
An iPhone that isn’t the iPhone 15 is selling fast in Japan
Apple's logo on an iPhone.

Apple released the iPhone 15 last month, with the new device offering two screen sizes of 6.1 inches and 6.7 inches.

The arrival of the latest iteration of the tech giant's popular handset saw the company banish from its online store the iPhone 13 Mini, which, as its name suggests, offers a smaller 5.4-inch display.

Read more