▲ 132 ▼ ChatGPT access to Apple Messages is dangerous and irresponsible (paulfwalsh.substack.com) submitted 2 days ago by QuadernoFigurati@lemmy.ml to c/privacy@lemmy.ml 28 comments fedilink hide all child comments
[–] JiveTurkey@lemmy.world 31 points 2 days ago (2 children) So is trusting apple messages. permalink fedilink source hideshow 4 child comments replies: [–] umbrella@lemmy.ml 17 points 2 days ago (1 child) or apple at all in the first place permalink fedilink source parent hideshow 2 child comments replies: [–] bigbangdangler@reddthat.com 8 points 1 day ago But they're different! They're so privacy focused! They care about their customers more than the other guy! ...and other such silliness I have heard on certain forums. permalink fedilink source parent [–] Kevlar21@piefed.social 9 points 2 days ago (2 children) Not trying to be contrarian or argumentative with this, but apple claims that imessage is end to end encrypted and therefore not readable even by them. Do you have evidence to the contrary? Or am I missing some other aspect? permalink fedilink source parent hideshow 4 child comments replies: [–] speckofrust@lemmy.dbzer0.com 10 points 2 days ago (1 child) From the article… I want to make one technical point absolutely clear because several people have misunderstood my argument: The encryption still works. OpenAl hasn't cracked or mathematically broken iMessage encryption. An iMessage remains encrypted between endpoints. The privacy problem occurs at the endpoint. Once the message has been decrypted on the recipient's Mac, that recipient can authorise third party software to access the readable conversation. The encryption worked exactly as designed. It simply can't protect message content from software authorised to access it before or after decryption. That's what I mean when I say this integration undermines the purpose of end to end encryption. permalink fedilink source parent hideshow 2 child comments replies: [–] EncryptKeeper@lemmy.world 2 points 1 day ago* (1 child) But it doesn’t undermine the purpose of end to end encryption? End to end encryption means it’s encrypted on one end and is decrypted on the other end, as opposed to being decrypted somewhere in the middle. This problem doesn’t for anything to undermine end to end encryption at all? With E2EE you still have to trust the other end. If the person who is the other end installs a plugin that reads the texts you send them, that’s not really a technology problem it’s an OpSec problem. permalink fedilink source parent hideshow 2 child comments replies: [–] speckofrust@lemmy.dbzer0.com 1 point 1 day ago (1 child) I agree. It definitely does undermine the purpose of E2EE. I just wanted to let it be known that ChatGPT hasn’t actually broken the encryption algo. Still, fuck Open AI, and any friend who would ever use AI to scan our Signal chats (if such a plugin is ever created) will be immediately cut off from chat comms. permalink fedilink source parent hideshow 2 child comments replies: [–] EncryptKeeper@lemmy.world 2 points 1 day ago (1 child) It definitely does undermine the purpose of E2EE It doesn’t undermine it at all is what I’m saying. The problem is just entirely unrelated to E2EE permalink fedilink source parent hideshow 2 child comments replies: [–] speckofrust@lemmy.dbzer0.com 0 points 5 hours ago (1 child) It doesn’t break the encryption, you’re right, though insofar as it makes the encryption irrelevant, I’d say it’s being undermined, but that’s just wordplay. The point is, fuck Open AI. permalink fedilink source parent hideshow 2 child comments replies: [–] EncryptKeeper@lemmy.world 1 point 5 hours ago* It doesn’t make the encryption irrelevant nor is it undermined in any way. The person on the other end that you’re choosing to communicate with is the weak link. It has nothing to do with encryption at all. They could do the exact same thing whether encrypted or not. E2EE is simply not a factor here at all permalink fedilink source parent [–] Auli@lemmy.ca 2 points 1 day ago (1 child) The problem is Apple controls the keys. permalink fedilink source parent hideshow 2 child comments replies: [–] EncryptKeeper@lemmy.world 2 points 1 day ago You can enable Advanced Data Protection and Apple will no longer store the keys, however this is off by default and for something like an iMessage conversation both users would have to enable it for it to mean anything permalink fedilink source parent
[–] umbrella@lemmy.ml 17 points 2 days ago (1 child) or apple at all in the first place permalink fedilink source parent hideshow 2 child comments replies: [–] bigbangdangler@reddthat.com 8 points 1 day ago But they're different! They're so privacy focused! They care about their customers more than the other guy! ...and other such silliness I have heard on certain forums. permalink fedilink source parent
[–] bigbangdangler@reddthat.com 8 points 1 day ago But they're different! They're so privacy focused! They care about their customers more than the other guy! ...and other such silliness I have heard on certain forums. permalink fedilink source parent
[–] Kevlar21@piefed.social 9 points 2 days ago (2 children) Not trying to be contrarian or argumentative with this, but apple claims that imessage is end to end encrypted and therefore not readable even by them. Do you have evidence to the contrary? Or am I missing some other aspect? permalink fedilink source parent hideshow 4 child comments replies: [–] speckofrust@lemmy.dbzer0.com 10 points 2 days ago (1 child) From the article… I want to make one technical point absolutely clear because several people have misunderstood my argument: The encryption still works. OpenAl hasn't cracked or mathematically broken iMessage encryption. An iMessage remains encrypted between endpoints. The privacy problem occurs at the endpoint. Once the message has been decrypted on the recipient's Mac, that recipient can authorise third party software to access the readable conversation. The encryption worked exactly as designed. It simply can't protect message content from software authorised to access it before or after decryption. That's what I mean when I say this integration undermines the purpose of end to end encryption. permalink fedilink source parent hideshow 2 child comments replies: [–] EncryptKeeper@lemmy.world 2 points 1 day ago* (1 child) But it doesn’t undermine the purpose of end to end encryption? End to end encryption means it’s encrypted on one end and is decrypted on the other end, as opposed to being decrypted somewhere in the middle. This problem doesn’t for anything to undermine end to end encryption at all? With E2EE you still have to trust the other end. If the person who is the other end installs a plugin that reads the texts you send them, that’s not really a technology problem it’s an OpSec problem. permalink fedilink source parent hideshow 2 child comments replies: [–] speckofrust@lemmy.dbzer0.com 1 point 1 day ago (1 child) I agree. It definitely does undermine the purpose of E2EE. I just wanted to let it be known that ChatGPT hasn’t actually broken the encryption algo. Still, fuck Open AI, and any friend who would ever use AI to scan our Signal chats (if such a plugin is ever created) will be immediately cut off from chat comms. permalink fedilink source parent hideshow 2 child comments replies: [–] EncryptKeeper@lemmy.world 2 points 1 day ago (1 child) It definitely does undermine the purpose of E2EE It doesn’t undermine it at all is what I’m saying. The problem is just entirely unrelated to E2EE permalink fedilink source parent hideshow 2 child comments replies: [–] speckofrust@lemmy.dbzer0.com 0 points 5 hours ago (1 child) It doesn’t break the encryption, you’re right, though insofar as it makes the encryption irrelevant, I’d say it’s being undermined, but that’s just wordplay. The point is, fuck Open AI. permalink fedilink source parent hideshow 2 child comments replies: [–] EncryptKeeper@lemmy.world 1 point 5 hours ago* It doesn’t make the encryption irrelevant nor is it undermined in any way. The person on the other end that you’re choosing to communicate with is the weak link. It has nothing to do with encryption at all. They could do the exact same thing whether encrypted or not. E2EE is simply not a factor here at all permalink fedilink source parent [–] Auli@lemmy.ca 2 points 1 day ago (1 child) The problem is Apple controls the keys. permalink fedilink source parent hideshow 2 child comments replies: [–] EncryptKeeper@lemmy.world 2 points 1 day ago You can enable Advanced Data Protection and Apple will no longer store the keys, however this is off by default and for something like an iMessage conversation both users would have to enable it for it to mean anything permalink fedilink source parent
[–] speckofrust@lemmy.dbzer0.com 10 points 2 days ago (1 child) From the article… I want to make one technical point absolutely clear because several people have misunderstood my argument: The encryption still works. OpenAl hasn't cracked or mathematically broken iMessage encryption. An iMessage remains encrypted between endpoints. The privacy problem occurs at the endpoint. Once the message has been decrypted on the recipient's Mac, that recipient can authorise third party software to access the readable conversation. The encryption worked exactly as designed. It simply can't protect message content from software authorised to access it before or after decryption. That's what I mean when I say this integration undermines the purpose of end to end encryption. permalink fedilink source parent hideshow 2 child comments replies: [–] EncryptKeeper@lemmy.world 2 points 1 day ago* (1 child) But it doesn’t undermine the purpose of end to end encryption? End to end encryption means it’s encrypted on one end and is decrypted on the other end, as opposed to being decrypted somewhere in the middle. This problem doesn’t for anything to undermine end to end encryption at all? With E2EE you still have to trust the other end. If the person who is the other end installs a plugin that reads the texts you send them, that’s not really a technology problem it’s an OpSec problem. permalink fedilink source parent hideshow 2 child comments replies: [–] speckofrust@lemmy.dbzer0.com 1 point 1 day ago (1 child) I agree. It definitely does undermine the purpose of E2EE. I just wanted to let it be known that ChatGPT hasn’t actually broken the encryption algo. Still, fuck Open AI, and any friend who would ever use AI to scan our Signal chats (if such a plugin is ever created) will be immediately cut off from chat comms. permalink fedilink source parent hideshow 2 child comments replies: [–] EncryptKeeper@lemmy.world 2 points 1 day ago (1 child) It definitely does undermine the purpose of E2EE It doesn’t undermine it at all is what I’m saying. The problem is just entirely unrelated to E2EE permalink fedilink source parent hideshow 2 child comments replies: [–] speckofrust@lemmy.dbzer0.com 0 points 5 hours ago (1 child) It doesn’t break the encryption, you’re right, though insofar as it makes the encryption irrelevant, I’d say it’s being undermined, but that’s just wordplay. The point is, fuck Open AI. permalink fedilink source parent hideshow 2 child comments replies: [–] EncryptKeeper@lemmy.world 1 point 5 hours ago* It doesn’t make the encryption irrelevant nor is it undermined in any way. The person on the other end that you’re choosing to communicate with is the weak link. It has nothing to do with encryption at all. They could do the exact same thing whether encrypted or not. E2EE is simply not a factor here at all permalink fedilink source parent
[–] EncryptKeeper@lemmy.world 2 points 1 day ago* (1 child) But it doesn’t undermine the purpose of end to end encryption? End to end encryption means it’s encrypted on one end and is decrypted on the other end, as opposed to being decrypted somewhere in the middle. This problem doesn’t for anything to undermine end to end encryption at all? With E2EE you still have to trust the other end. If the person who is the other end installs a plugin that reads the texts you send them, that’s not really a technology problem it’s an OpSec problem. permalink fedilink source parent hideshow 2 child comments replies: [–] speckofrust@lemmy.dbzer0.com 1 point 1 day ago (1 child) I agree. It definitely does undermine the purpose of E2EE. I just wanted to let it be known that ChatGPT hasn’t actually broken the encryption algo. Still, fuck Open AI, and any friend who would ever use AI to scan our Signal chats (if such a plugin is ever created) will be immediately cut off from chat comms. permalink fedilink source parent hideshow 2 child comments replies: [–] EncryptKeeper@lemmy.world 2 points 1 day ago (1 child) It definitely does undermine the purpose of E2EE It doesn’t undermine it at all is what I’m saying. The problem is just entirely unrelated to E2EE permalink fedilink source parent hideshow 2 child comments replies: [–] speckofrust@lemmy.dbzer0.com 0 points 5 hours ago (1 child) It doesn’t break the encryption, you’re right, though insofar as it makes the encryption irrelevant, I’d say it’s being undermined, but that’s just wordplay. The point is, fuck Open AI. permalink fedilink source parent hideshow 2 child comments replies: [–] EncryptKeeper@lemmy.world 1 point 5 hours ago* It doesn’t make the encryption irrelevant nor is it undermined in any way. The person on the other end that you’re choosing to communicate with is the weak link. It has nothing to do with encryption at all. They could do the exact same thing whether encrypted or not. E2EE is simply not a factor here at all permalink fedilink source parent
[–] speckofrust@lemmy.dbzer0.com 1 point 1 day ago (1 child) I agree. It definitely does undermine the purpose of E2EE. I just wanted to let it be known that ChatGPT hasn’t actually broken the encryption algo. Still, fuck Open AI, and any friend who would ever use AI to scan our Signal chats (if such a plugin is ever created) will be immediately cut off from chat comms. permalink fedilink source parent hideshow 2 child comments replies: [–] EncryptKeeper@lemmy.world 2 points 1 day ago (1 child) It definitely does undermine the purpose of E2EE It doesn’t undermine it at all is what I’m saying. The problem is just entirely unrelated to E2EE permalink fedilink source parent hideshow 2 child comments replies: [–] speckofrust@lemmy.dbzer0.com 0 points 5 hours ago (1 child) It doesn’t break the encryption, you’re right, though insofar as it makes the encryption irrelevant, I’d say it’s being undermined, but that’s just wordplay. The point is, fuck Open AI. permalink fedilink source parent hideshow 2 child comments replies: [–] EncryptKeeper@lemmy.world 1 point 5 hours ago* It doesn’t make the encryption irrelevant nor is it undermined in any way. The person on the other end that you’re choosing to communicate with is the weak link. It has nothing to do with encryption at all. They could do the exact same thing whether encrypted or not. E2EE is simply not a factor here at all permalink fedilink source parent
[–] EncryptKeeper@lemmy.world 2 points 1 day ago (1 child) It definitely does undermine the purpose of E2EE It doesn’t undermine it at all is what I’m saying. The problem is just entirely unrelated to E2EE permalink fedilink source parent hideshow 2 child comments replies: [–] speckofrust@lemmy.dbzer0.com 0 points 5 hours ago (1 child) It doesn’t break the encryption, you’re right, though insofar as it makes the encryption irrelevant, I’d say it’s being undermined, but that’s just wordplay. The point is, fuck Open AI. permalink fedilink source parent hideshow 2 child comments replies: [–] EncryptKeeper@lemmy.world 1 point 5 hours ago* It doesn’t make the encryption irrelevant nor is it undermined in any way. The person on the other end that you’re choosing to communicate with is the weak link. It has nothing to do with encryption at all. They could do the exact same thing whether encrypted or not. E2EE is simply not a factor here at all permalink fedilink source parent
[–] speckofrust@lemmy.dbzer0.com 0 points 5 hours ago (1 child) It doesn’t break the encryption, you’re right, though insofar as it makes the encryption irrelevant, I’d say it’s being undermined, but that’s just wordplay. The point is, fuck Open AI. permalink fedilink source parent hideshow 2 child comments replies: [–] EncryptKeeper@lemmy.world 1 point 5 hours ago* It doesn’t make the encryption irrelevant nor is it undermined in any way. The person on the other end that you’re choosing to communicate with is the weak link. It has nothing to do with encryption at all. They could do the exact same thing whether encrypted or not. E2EE is simply not a factor here at all permalink fedilink source parent
[–] EncryptKeeper@lemmy.world 1 point 5 hours ago* It doesn’t make the encryption irrelevant nor is it undermined in any way. The person on the other end that you’re choosing to communicate with is the weak link. It has nothing to do with encryption at all. They could do the exact same thing whether encrypted or not. E2EE is simply not a factor here at all permalink fedilink source parent
[–] Auli@lemmy.ca 2 points 1 day ago (1 child) The problem is Apple controls the keys. permalink fedilink source parent hideshow 2 child comments replies: [–] EncryptKeeper@lemmy.world 2 points 1 day ago You can enable Advanced Data Protection and Apple will no longer store the keys, however this is off by default and for something like an iMessage conversation both users would have to enable it for it to mean anything permalink fedilink source parent
[–] EncryptKeeper@lemmy.world 2 points 1 day ago You can enable Advanced Data Protection and Apple will no longer store the keys, however this is off by default and for something like an iMessage conversation both users would have to enable it for it to mean anything permalink fedilink source parent