DOJ sues Apple, spotlighting iMessage

Martin Shelton

Principal Researcher

Screenshot from iMessage. (Freedom of the Press Foundation, CC BY 4.0)

It’s the Digital Security Training team at Freedom of the Press Foundation (FPF), with security news that keeps you, your sources, and your devices safe. If someone has shared this newsletter with you, please subscribe here.

In the news

The U.S. Department of Justice filed an antitrust lawsuit against Apple, claiming the company engages in monopolistic practices over the smartphone market, preventing competitors by degrading the experience of communicating with non-Apple users in its products. iMessage features prominently in the suit, with the DOJ alleging consumers are disincentivized to leave its “walled garden” and so miss out on unique features built into the iMessage protocol, including end-to-end encryption between Apple users. Read more here.

Get Notified. Take Action.

What you can do

Because iMessage offers end-to-end encryption, preventing even Apple from snooping on its users' conversations by default, it works just fine when used with your fellow “blue bubble” Apple contacts. However, when speaking to Android users, iMessage falls back to standard SMS messages, which are far less secure. This is another reason we often encourage using Signal for end-to-end encrypted messaging, since it offers similar safety guarantees on both iPhones and Android phones. Read our guide to getting started with Signal or, if you already use it, read our guide to locking down Signal.

Updates from my team

We are always ready to assist journalists with digital security concerns. Reach out here, and stay safe and secure out there.

Best,
Martin

Donate to support press freedom

Your support is more important than ever.

Read more about Digital Security Digest

Google backtracks on ad privacy plan

Google has a habit of hitting the brakes on products and features — so much so that it’s become something of a meme to be “killed by Google.” This time it decided to backtrack on its long-standing plan to replace traditional tracking in its Chrome browser.

Beware fraudulent CrowdStrike emails

Last Friday, computer systems worldwide were taken down by a defective update from enterprise cybersecurity vendor CrowdStrike. In the wake of the outage, the U.S. Cybersecurity and Infrastructure Agency is warning of phishing emails, with attackers posing as CrowdStrike customer support.

What to do about AT&T breach

Around 110 million AT&T subscribers were affected by a data breach from May 1 to Oct. 31, 2022, TechCrunch reported.