DeadlineX

joined 2 years ago
[–] [email protected] 1 points 2 years ago (1 children)

The public key doesn’t decrypt the information. The public key is used only for encryption. The private key is what is used for the decryption. Since the private key is on-device, there’s no way to get access to the decryption. It’s actually a bit more complicated than I wanted to go into for an already ridiculously long comment, but I’ll explain a bit more here.

With a hard drive, you have one key. This kind of encryption is called symmetric encryption. It uses a single private key, and that key can be used to decrypt at any time.

E2E encryption uses what is called asymmetric encryption. The key used to encrypt the information is actually the recipients public key. This is where some information is exposed to Apple (or anybody else who uses a directory lookup to find a public key). That lookup tells Apple who and how often you are messaging. This they will absolutely give to law enforcement with a warrant. It doesn’t tell a lot, but it does give information about your correspondence.

Once the information is encrypted, the matching private key is the only thing that can decrypt the content. This also places a vulnerability because if somebody sends a different public key, now the message is decryptable by the bad actor.

So because of the two key system, the private key for each individual is inaccessible to anyone except the individual. It’s actually a really cool concept. This is how HTTPS functions as well. TLS (it’s just the cryptographic protocol HTTPS uses) creates a secure connection using asymmetric encryption. The information it sends then uses symmetric encryption.

I’m a developer, and not an information security expert, so some of this may not be completely accurate, but it should be accurate for the most part. If you’re interested at all I would definitely suggest looking into it because I think it’s super neat.

Of course if you have any more questions I’m willing to talk as well.

[–] [email protected] 4 points 2 years ago

Honestly the biggest reason was that college kids are more likely to buy the accidental damage warranty or have parents that will.

[–] [email protected] 0 points 2 years ago

-doesn’t agree with/like what somebody else says: immediately jump to insults.

Come on. Let’s not insult people because we don’t like what they say. We can do better. We should do better. If people just got along with others who are different or have different interests, the whole world would be a better place.

Genuinely, I am asking you to reevaluate how you respond, and maybe just try to be a little nicer to others. It costs nothing and makes the world a little bit better every time.

[–] [email protected] 45 points 2 years ago (2 children)

I used to work at Microcenter for awhile. The best time to buy was always back to school. Holiday deals start at the beginning of November and are the exact same as Black Friday minus a few small door buster deals and maybe a special on a few models of pc. During back to school, pretty much everything is heavily discounted.

[–] [email protected] 2 points 2 years ago (4 children)

Yeah as the previous commenter said, e2e encryption just doesn’t allow anyone to access the data but the owner of the keys. E2E is prized because of this. There are two keys: public and private. If you and I are both using iMessage, you send a message to me that is encrypted on your device using your private key, and sent to my device using my public key. Only you and I can ever see those messages unless someone gets access to one of our phones.

Now, iCloud is backed up to apples servers. If you have iMessage backup enabled, it’s possible, and maybe even likely tbh, that Apple has access to recent messages. iMessage is also (potentially, but again in this case, I’d argue likely) susceptible to man-in-the-middle attacks. Because you need my public key for our communication to be decrypted, if you receive some else’s public key instead, they now have your messages and I don’t.

The DEA and FBI have both had documents leaked mentioning they can’t track or trace or unencrypt iMessage. The same is true for WhatsApp or any e2e messaging service.

Again, this is all contingent on not using iCloud backup. If you use iCloud backup, then the encryption keys used can be accessed with the proper authority. I assume (but haven’t looked into it) that Google is the same. If you don’t backup your e2e encrypted content, it cannot be decrypted without the private key only you have access to. Of course iCloud backup is enabled by default, so for the vast majority of Apple users, their messages and information are all available anyway so none of this matters.

In addition, iMessage uses a directory lookup to find the correct public key for your recipient. This information Apple does keep (I am unsure how long). What this means is that law enforcement (with a warrant) can see who and how often you are messaging. That alone is information we really don’t want people having.

So the moral is: if you don’t use backups for e2e encrypted communication, your content cannot be read externally. It’s just the way cryptography works.

This doesn’t mean that companies do not share information with law enforcement. There is a lot of unencrypted information Apple, Google, et al will share with government agencies when a warrant or subpoena is served. In addition to that, your phone provider will share information with them. In addition to that any SMS or MMS messages sent from any device will lack encryption and be easily discoverable.

Tl;dr: e2e encryption is secure, as long as you follow best practices and have an idea of how encryption works.

[–] [email protected] 7 points 2 years ago

Some of these additions are just silliness. That said, I could barely make it through the article, as it kept just randomly starting a new sentence halfway through a thought.

It also referenced somebody, but then didn’t finish the sentence before moving on to talk about someone else. I have been annoyed by all the “this article was written by an ai” comments I’ve been seeing lately. Having read this article I see what people mean.

[–] [email protected] 2 points 2 years ago

Thanks for the heads up!

[–] [email protected] 1 points 2 years ago

Yeah software is definitely more complex. But modern languages are easier and have more syntactic sugar. And being a junior dev is mostly boiler plating or copy and pasting. A lot of devs don’t even get into the real complicated stuff. I’m a mediocre dev with no degree and I’m constantly surprised at the terminology people who’ve been doing for years don’t understand.

[–] [email protected] 2 points 2 years ago* (last edited 2 years ago)

He’ll, kids shows have been essentially advertising platforms for decades. Shows and movies exist to sell toys and make profits.

[–] [email protected] 1 points 2 years ago

lol yeah it’s definitely Tesla! The Alaska looks amazing. I actually hadn’t seen that one but it definitely looks awesome. I looked it up and I think it was the nikola badger. The name doesn’t seem familiar but the look of it seems like what I was thinking.

Honestly I feel there have been a lot of ev startups that never deliver. I do think the rivian truck looks pretty nice as well.

[–] [email protected] 1 points 2 years ago

Oh man I didn’t even think about magic. Yeah that’s definitely a big on. I was lucky enough not to fall into that hobby.

[–] [email protected] 3 points 2 years ago (4 children)

I didn’t even know rivian had even made an actual vehicle until I saw one last month. I thought they were still vaporware. Wasn’t there another trunk company that was supposed to have made a truck like 6 years ago? Did they ever do that?

view more: ‹ prev next ›