Post-quantum iMessage

Martin Shelton

Principal Researcher

Blue lattice behind three ornate keys
Electronic Frontier Foundation (CC BY 2.0)

It’s the Digital Security Training team at Freedom of the Press Foundation (FPF), with security news that keeps you, your sources, and your devices safe. If someone has shared this newsletter with you, please subscribe here.

In the news

Both in the U.S. and abroad, governments are capturing encrypted connections that pass over the public internet and saving them for later use. Such “harvest now, decrypt later” attacks are no longer the thing of science fiction, thanks to post-quantum computers that could meaningfully shorten the amount of time required to unscramble encryption, allowing attackers to read previously private messages. 

Such attacks could be more viable within years or decades, so a growing number of organizations are preparing for them with post-quantum encryption. In its recent iOS and iPadOS 17.4 updates, Apple has joined Signal and other online services in offering post-quantum encryption to resist these attacks. Learn more here.

Get Notified. Take Action.

What you can do

  • Download your updates! New security features like this underscore the importance of keeping your devices up to date. Check out our guide on the story inside your software updates.
  • Note that iMessage is only encrypted between iMessage users, meaning if you are having a “green bubble” conversation with someone on Android, it’s likely using SMS, which is much less secure. And if you or your conversational partner have iMessage backups enabled using iCloud, Apple may have a copy of your messages, with or without these new security features. If these are concerns for you, you and your pals should try out Signal. Read our beginner-friendly guide to Signal.

Updates from my team

  • To conclude our spree of guide updates to include Signal’s new username features, we have made some changes to our guide on “Security considerations for confidential tip pages.” Check it out.
  • A couple of teammates and I will be at NICAR in Baltimore this week. If you’re around March 7-10, come say hi and get a few FPF stickers!

We are always ready to assist journalists with digital security concerns. Reach out here, and stay safe and secure out there.

Best,
Martin

Donate to support press freedom

Your support is more important than ever.

Read more about Digital Security Digest

Google backtracks on ad privacy plan

Google has a habit of hitting the brakes on products and features β€” so much so that it’s become something of a meme to be β€œkilled by Google.” This time it decided to backtrack on its long-standing plan to replace traditional tracking in its Chrome browser.

Beware fraudulent CrowdStrike emails

Last Friday, computer systems worldwide were taken down by a defective update from enterprise cybersecurity vendor CrowdStrike. In the wake of the outage, the U.S. Cybersecurity and Infrastructure Agency is warning of phishing emails, with attackers posing as CrowdStrike customer support.

What to do about AT&T breach

Around 110 million AT&T subscribers were affected by a data breach from May 1 to Oct. 31, 2022, TechCrunch reported.