Is your secure iMessage conversation actually secure?
Apple introduced iMessage within Messages in 2011 as its house-brand, end-to-end encrypted messaging product. The promise of iMessage is that posts are always encrypted, using servers and technology developed by Apple and controlled by it.…
Apple launched iMessage in 2011 as its proprietary end-to-end encrypted messaging service within the Messages app. The encryption keys remain on the user's device, inaccessible to Apple or third parties. Despite past exploits, the core protocol has never been breached. Apple continuously enhances iMessage's encryption while adding features like Contact Key Verification for conversation integrity.
After researching these apps, the reporter discovered that users might be deceived into believing iMessage is always secure. The report outlines four communication types, with iMessage always encrypted while other methods like RCS, SMS, and MMS may not. RCS encryption depends on both the sender and recipient's devices supporting it. The reporter noticed that when iMessage stops working within a conversation, there's no clear warning or signal to indicate the downgrade to RCS or other unencrypted methods.
To verify the current encryption status, users can check the Info pane at the bottom of a conversation. However, this information is not emphasized enough, as the app continues to display that all iMessage conversations are securely encrypted end-to-end. This lack of clear warnings or notifications when iMessage degrades to less secure methods can lead users to feel a false sense of security, even as their conversations become vulnerable.
Written by urgent.news from Six Colors's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.