

This is an interesting time for secure messaging. Apple says it has patched those vulnerabilities in iOS 15, but it was damaging, nonetheless. While this doesn't technically breach end-to-end encryption, it does open a backdoor to outside interference within the overall secure messaging enclave and has been heavily criticized by security and privacy advocates as a result.Īnd let’s not forget Pegasus gate, where an iMessage compromise was implicated in zero-click attacks on Apple users reportedly perpetrated using NSO technology.

Second, Apple has also misstepped with its decision to add an on-device AI classifier to iMessage to warn minors sending or receiving explicit imagery.

This is fairly pitiful as a token gesture for cross-platform interoperability, but it makes the point. Google has been gently pressing Apple to get onboard this SMS v2 upgrade, and we saw more of that recently with a Google Messages update that translates the emoticon iMessage responses to something similar on an Android device. It means that Apple users messaging Android contacts, or vice versa, have to revert to a third-party platform like WhatsApp or will default to non-secure SMS, a crazy situation for 2021. The storage of encryption keys in accessible backups is one mistake, but it has made two others as well, both of which significantly reduce the security and privacy of iMessage.įirst, Apple’s decision to steer clear of Google’s now coordinated RCS rollout across Android is a bad move for users. This has not been a good year for Apple and its iMessage platform.

If you’re an Android user, you can set Signal as your default messenger, such that it handles SMS as well-that’s a great option to have. You should definitely use Signal where your contacts also have the app. If you want to keep your messaging private, my advice is to use WhatsApp as your daily, just given its scale, but make sure you use encrypted backups and don’t have the iCloud backup option enabled. “Signal doesn’t have access to your messages your chat list your groups your contacts your stickers your profile name or avatar or even the GIFs you search for.” “It’s impossible to turn over data that we never had access to in the first place,” Signal says.
