How secure are your messages really?

messages

Tbtech looks into the recent discovery that not all encrypted messages are as safe as everyone thought, and the methods users can take to maintain privacy.

Tech users want to know that their information is kept private, and this is a large selling point for end-to-end encrypted message services. For many years now, iMessage and WhatsApp have competed to be the best and most well-known in the communications sector, each claiming to be the most secure messaging system available. Both companies have done well to champion cybersecurity trust, but recently, a significant flaw has revealed a crack in this trust. 

The news came via a release by Property of the People, a non-profit organization that explained its motives as being ‘devoted to governmental transparency’ on Twitter. This showed an official FBI training document detailing different messenger services and the ability to gain information on a suspect via legal means through that service.

iMessage, the exclusive Apple messenger service, was placed at the top of this list as the most easily accessible messaging service for gaining access to private information. On this file, it listed that those who access iMessage can recover message history and contact details. The flaw in the system is the cloud backup system; all the messages are encrypted as promised and secure while being sent; however, once the message history is backed up to the cloud, they are accessible. This is due to the encryption keys being backed up to the same file; not the most brilliant move by Apple.

WhatsApp, the well-known message service owned by Meta Platforms, only allows access to a list of contacts created within the app. Much less information than potentially incriminating messages but still not as secure as people were made to believe.

Of course, all access requires a legal subpoena first; however, if one person has been in contact with someone being investigated (even in passing), all of their messages would be legally included in a subpoena. This is avoidable by simply turning off your automatic backup (shown below). This does mean if you lose your device, your old messages will not be recoverable when syncing a new phone or tablet.

Apple has not commented on this flaw and it’s not surprising after its year of PR nightmares, including the August announcement that images being sent in this messenger service would be screened by an AI in order to determine if they are sexual in nature, which brought on tremendous backlash.

It is interesting that the news of this FBI document came to light only two months after WhatsApp struck out against Apple for its message security. As mentioned before, it is more reassuring to know that there is no access to message content for WhatsApp users, however the FBI has been quoted saying it can request contact lists and metadata “sent every 15 minutes”. WhatsApp did release an update to fix this error, including a user warning advising them to remove the iCloud back-up during a step-by-step setup process in September.

Presently, Apple’s public image is suffering, not only due to encryption errors but also because of its struggles with the ongoing Malware issue known as Pegasus (created by NSO Group, the Israeli spyware company). This malware reportedly gains access to your phone in an attempt to ‘investigate terrorism’.

When asked about the situation, head of Apple security engineering and architecture, Ivan Krstic stated “Apple runs one of the most sophisticated security engineering operations in the world, and we will continue to work tirelessly to protect our users from abusive state-sponsored actors like NSO Group.”

In a rebuttal statement, a spokesperson from NSO commented that “thousands of lives were saved around the world thanks to NSO Group’s technologies used by its customers.” This shows NSO sees themselves as providing a service to the community, begging the question, when is full privacy allowed, and when is breaking it acceptable?

Interestingly, the NSO Group was sued for the same malware issue by WhatsApp owners Meta, (formerly Facebook) back in 2019, which means it has taken Apple two years to jump to action on this issue. While filing the lawsuit they did make a statement that “to prevent further abuse and harm to its users, Apple is also seeking a permanent injunction to ban NSO Group from using any Apple software, services, or devices.”

Read More:

Google has been on the move to surpass Apple and make Android the new secure go-to device that Apple has always been known for. Google’s new global RCS—Rich Communication Services release is much stricter than iMessage’s previous end-to-end encryption as it does not allow any group chats or use of multiple devices. The only thing allowed (to ensure security) is 1:1 messages between two people. Apple has considered joining this system and becoming a cross-platform messenger previously, allowing an Android phone to use Apple-exclusive apps. However, just like then it has now again refused to join, clearly due to its resistance to break away from the closed ecosystem Apple is known for. Google have since taunted Apple and the feud over who is the most secure continues.

The issue at the end of this is that users can not feel comfortable on any messaging service as new reports constantly come in of security breaches (mostly propaganda based it seems). The companies behind the messaging services refuse to work together to solve this problem and it is the users that suffer in the long run.

Click here to discover more of our podcasts

For more news from Top Business Tech, don’t forget to subscribe to our daily bulletin!

Follow us on LinkedIn and Twitter

Erin Laurenson

Multimedia Content Producer for TBTech

Tech and Business Outlook: US Confident, European Sentiment Mixed

Viva Technology • 11th February 2025

The VivaTech Confidence Barometer, now in its second edition, reveals strong confidence among tech executives regarding the impact of emerging technologies on business competitiveness, particularly AI, which is expected to have the most significant impact in the near future. Surveying tech leaders from Europe and North America, 81% recognize their companies as competitive internationally, with...

How smart labels are transforming supply chains

Sharath Muddaiah • 27th January 2025

As e-commerce continues to rise globally, the impact of just-in-time manufacturing and rising consumer expectations mean the need for real-time visibility has never been greater. Smart labels directly address this demand, offering solutions to long-standing challenges like shipment delays, theft, and the lack of traceability. With the smart label market projected to grow from $14.1...

The rise of loyalty apps

Sue Azari • 17th January 2025

Increased choice and a consumer more price sensitive than ever before, has made customers far more likely to shop around for the best deals. Price is now the number one factor in brand consideration. In an effort to bag a bargain, loyalty programs have become increasingly popular with consumers, with nine out of ten in...

Rocket launch challenges Elon Musk’s space dominance

Professor Sultan Mahmud • 16th January 2025

Amazon founder Jeff Bezos’s space company has blasted its first rocket into orbit in a bid to challenge the dominance of Elon Musk’s SpaceX. The New Glenn rocket launched from Cape Canaveral Space Force Station in Florida at 02:02 local time (07:02 GMT). It firmly pits the world’s two richest men against each other in...

Giesecke+Devrient launches new Smart Label at CES 2025

Giesecke Devrient • 06th January 2025

G+D has today launched the G+D Smart Label, its innovative tracking solution that transforms any package into an IoT device. Ultra-thin and only slightly larger than a credit card, the new Smart Label proposition has been jointly developed by G+D in conjunction with its hardware partner, Sensos to enable cost-effective, accurate location tracking for a...

Choose an AI solution to transform beyond technology

Kit Cox • 09th December 2024

The first step is knowing exactly what your business wants to achieve with AI; think faster, smarter and more efficient. Once you know what you are working towards, you can start looking for a solution that can help you make it a reality. AI integration can feel like a daunting task at the beginning, so...

A Roadmap to Security and Privacy Compliance

John Lynch Director of Kiteworks • 04th December 2024

Only by understanding the current regulatory environment and implementing robust data protection measures, can organisations enhance their security posture, ensure compliance, and build resilience against the latest cyber threats. This article provides a comprehensive roadmap of how to do it.