Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

I believe that this application actually does connect to Apple's servers from the phone, but it doesn't then interpret the protocol on the device. Instead, it ferries the data to the third-party developer's server, parses everything remotely, figures out what to do with the data, and sends everything back to the client decoded along with responses to send back to Apple.

Doing it this way means that Apple can't just block them by IP address, it avoids them having to distribute their "secret sauce" (understanding the iMessage protocol is clearly very valuable), and it potentially allows them to use actual Apple code on their servers (in case they haven't spent the time to fully break the fairplay obfuscation that Apple is using for some of their keys).

Here's what I'm seeing: every time I send it a message, I get a packet from Apple, and then immediately the app sends a packet of almost exactly the same size to 222.77.191.206 (which is listed in this application's APK as "ServerIp"). It then gets back two packets from the Chinese server, the first of which I'm presuming is the decoded result and the second packet being a response to send Apple (as immediately a packet is sent back to Apple with about the same size).

Additionally, if you read the reviews of this application, the author is making some very weird responses to people with login issues: he's asking for their Apple ID, as apparently that's enough for him to debug their issue. That shouldn't be possible if the application is just directly talking to Apple the entire time.

[edit: The more I stare at this, the more confident I am in this analysis; specifically, the packets that are "about" and "almost exactly" the same size are very deterministic: the packets to/from Apple are precisely 7 bytes larger than the corresponding packets to/from the Chinese server.]

[edit: It also occurred to me to verify the other direction: in fact, if you go to send a message, first the client sends something to the developer's server, which then returns a packet which, along with again the exactly 7 extra bytes, is sent to Apple's server.]



Not that this needs pointing out, but this also means the mysterious Chinese server also gets to read all your iMessages. This is some kind of quasi-MITM, and for that alone Apple would be in the right to block this kind of thing from ever working.


Why is it any worse than only Apple server reading all you messages? You trust one third party with proven track record of spying on its customers, but somehow you are upset that someone else also has access to you messages, thought that someone didn't (yet) do anything wrong with them.

If you are American, you don't have to fear from Chinese espionage, and US agencies already have your data. If you are European, it's more or less the same. If you are from China, well, at least you can prove that you are not doing anything behind the government back ;)


Surely you're joking. I don't doubt you can understand the difference between a government law enforcement agency reading your messages and some guy off the street reading your messages.

Neither Apple nor the NSA will, for example, immediately rack up a string of fraudulent charges on every credit card number that it sees come through its system. Some random guy in China? I'd say there's a pretty high chance that's exactly the reason this app is in the app store.


>> "I don't doubt you can understand the difference between a government law enforcement agency reading your messages and some guy off the street reading your messages."

I'd feel more secure with just some guy off the street reading my messages. Fortunately I don't ever send CC#'s through messaging services so there's very little else he could do.


where is your proof that the guy off the street in this case isn't the chinese government?


I didn't mention this case I was speaking more generally. And I'd personally be more worried with what the US government knows about me than the Chinese. I have many more interactions with American people and businesses and I like to visit there. I don't have much if any interaction with China so it doesn't bother me as much.


That still makes no sense. Your information has been leaked to one party, so you're okay with it leaking to others as well? Also, it's not just what they know, it's what they do with that knowledge. And it seems pretty absurd to make the claim that the US has had worse precedence in this regard than China.


Worry about it when you're important enough for the Chinese government to care what you do? I'm certainly not.


No, it is not a joke. iMessage is not a secure communications channel. With this app in the wild, it is pretty clear it is not a secure communications channel. You should not post CC information along an insecure communications channel.

You may be right that there is more risk involved now, but it is nice to get the point out in the open.


People know who Apple is. Apple has a reputation. Sure they're compromised by NSA, but every communications medium in the world is compromised by NSA.

I don't know who's running this server in China. But unless it's the NSA, you're much worse off using this app than native iMessage, because now in addition to NSA seeing everything, so does this guy--who has no reputation at risk. Adding more eavesdroppers makes communications additively less secure.

How exactly do I have nothing to fear from the Chinese? At least the NSA is unlikely to have any real interest in communications between Americans in America because it's outside their mission, which is not true for Chinese or Russian intelligence.


> Sure they're compromised by NSA, but every communications medium in the world is compromised by NSA.

I do not think that this statement is accurate. The NSA has specifically targeted the largest players.

Also: "encryption works. Properly implemented strong crypto systems are reliable" - Edward Snowden.


Yes but you do have to sacrifice quite a bit to be outside of the NSA's realm of observability. Is iMessage securely encrypted? Wasn't the DEA caught red-handed with a false memo claiming they couldn't MITM iMessage communication?


> Yes but you do have to sacrifice quite a bit to be outside of the NSA's realm of observability.

Very true. That's a consequence of the largest players in winner-take-all markets being targeted.


By MITM you think a guy with a hard drive sitting in the middle of the Apple HQ siphoning data directly to NSA? Yes, I could imagine that.


"In Snowden we trust" - the internet

It's sad that the NSA and government has lost the faith of Americans to the point that the word of one man is taken without question.


Well, Mr "nsashill42334", account under 24 hours old, I don't think that Mr Snowden should be trusted without question. However it seems unlikely that he is setting out to dupe people into using encryption for some reason or other.


Sure they're compromised by NSA, but every communications medium in the world is compromised by NSA.

scary baseling like this


> Why is it any worse than only Apple server reading all you messages?

Not. This. Again.

Because one person can read your messages, it doesn't mean that the whole world should be able to. One happening doesn't mean the other is okay.


Uh... as I read it the point of this app is the the whole world is able to read your messages. This app is just the existence proof that all that is required is access to the raw packet data.

Clearly most people are going to "trust" Apple Computer more than this app vendor. But the point is that such trust isn't worth anything. The data is hanging out there already.


Huh? So, does the existence of an open-source reimplementation of early versions of SSL also imply that if you had access to the raw packets you can read anyone else's SSL stream? How about if we first require the data to be sent in the clear to someone who refuses to tell us how DES works, but is willing to provide a web service that implements it? This app is not by any stretch of imagination proof that the protocol on the wire is not encrypted. Yes, that might be the case, and we might learn some interesting things at pod2g's talk on iMessage at HITB (I'm definitely looking forward to that), but that would be totally unrelated to the existence or possibility of this app.


You seem to misunderstand the OP concerns.

It is not only one person, it is not only Apple servers reading all your messages. It is in fact the whole world. Through Apple gives it to NSA which hands it over to various other agencies, GHCQ, FRA, your data ends up in Israel. Your data is already a goods traded with on the international market.

Why not increase the competitiveness of this Chinese actor, you will get better service in the future? More competitive - better service.


Let me give you an example.

Apple, NSA saw CC number in your chat log, but Apple, NSA, GHCQ, FRA or Israeli Intelligence won't steal your CC and use it.

However, the Chinese vendor could intercept CC info and sell it to blackmarket.


You seem to be confused.

The NSA has already sold your CC on the black market. Its just that the buyer hasnt used it, because they cant use it without getting penalties. Penalties which this Chinese vendor would succumb to as well.

Now are you going to say you trust Israel more than the Chinese, they wont misuse your CC, and if they did, its still better than trusting a Russian vendor?


If you are American, you don't have to fear from Chinese espionage

Citation needed. There are numerous stories (unconfirmed of course, but that's the way these things always are) of Chinese hackers breaking into companies and stealing trade secrets. They aren't just after super spies, you know.

And you don't work in an industry the Chinese would be interested in? Good for you. But do you know anyone that is? This hack might quite possibly allow them to send messages as you to whoever they want.

"The NSA has my information so hey, screw it" isn't really an appropriate reaction.


My server logs suggest I need to fear Chinese espionage. You'd need a hell of a citation to beat that.


Attack surface. When you increase the number of parties capable of decrypting your data, you increase the risk of an exposure.


The Apple server cannot read your messages because it is encrypted client-side. https://www.schneier.com/blog/archives/2013/04/apples_imessa...


If it were a proper "Silicon Valley kid" who did that, you would applause loudly. Does it happen to you that there are talented geeks and developers in China. For one: http://agentzh.org/


What the hell are you on about? I don't care about the nationality of this anonymous person trying to MITM my iMessages, only that some anonymous person is trying to MITM my iMessages.


I agree. The way a couple folks are throwing around their words shows prejudice.


It shows a grounding in reality.

This guy may well be a perfectly responsible entrepreneur, but the fact is that common Chinese business practices can be pretty shocking. My wife in Chinese, her sister works for a bank over there and her husband is a cop. I could tell your stories that would make your hair stand on end, but I don't want to put anyone off ever going there again. I love China, but doing business over there's not for the faint hearted and it's just good sense to be realistic about it.


Current version need server,because Apple have same limits. but in new version , i will not use server. Thanks.


Do you know if iMessages are encrypted to more than one key (i.e. not just with the recipient key)?


How the f* did you made this if you can't even speak English decently? No offense.


> did you made this

Seriously? You're going to complain about his English?


Perhaps he's a non-English speaking coder who is expressing admiration and incredulity? What makes you think he's complaining? He goes so far as to explicitly state "no offence".


There's a boundary between playing devil's advocate and taking the piss outright.


When is "no offense" ever attached to a compliment?


Because he is able to not only master his native tongue but also acquire some fluency in English. You people born with English as native language wouldn't know how hard it is to keep switching between 3-4 languages constantly.


Chances are you're better than him at English... and he's better at programming.


I think you got exactly what they are doing. In fact if you see their "icloud sdk" looks also exactly what you mentioned.

https://github.com/huluwateam/icloud

[edit: maybe this is more simple to decrypt https://github.com/huluwateam/icloud/blob/master/DataSyncSDK...]


Ahhh good ol' github. Shows the author email and everything. Finally I can ask the author for his secret ingredients.


And Apple's lawyers can find out how to reach him too.

Not saying that's a good thing, just that it's a likely thing.


In China. Good luck with that.


It's a fair point, though it may depend whether there is any "official support" for his actions.

If it's just someone acting on their own for fun, the amount of money Apple invest in China might suggest that they have some sway should they choose to use it.


the code there makes no mention of the iMessage protocol. everything there can be done using other publicly avaiable API's such as the CalDAV/CardDAV api.


Really, can you have direct access to things like photostream?


That makes sense with my very limited experience messing with the iMessage protocol. Stands to reason that passwords are being ferried back to them though, there's got to be some financial reason for going to all this trouble.

ED: Their obfuscation isn't actually that severe once you get used to it.


I came to the same conclusion as Saurik, (though didn't go as far as looking up the Server and seeing it was from China).

I had hoped that I could decompile it, get the special sauce, and make a client for Qt-based OSes and also Windows Phone. Looks like I won't make any progress today


You likely won't be able to do anything at all, as the client is fairly dumb. It just takes requests from Apple's server, encrypts with CTR AES and a static key, then fires them off to the Chinese server for actual processing. Unless you want to use their server in your own application, you're just as snookered as before; you still need the secret sauce.


I'm aware of that, hence why I said I won't be making any progress. I've tried using the Mac version and iOS versions, no luck either way.

I'll try BBM too once its on Android. Trying to get it off my Z10 has proven just as difficult


However since this protocol is really strong:

1) They are using a workaround like a vm running osx where a program add the requested account on Message.app and then send back the I/O.

2) Second solution they got from an insider the protocol description and decryption.


I would be surprised if #1 was the case. Given the amount of volume of traffic that this app will generate, the traffic for identifying a rapidly signing in Message.app will be pretty unique and easily blockable by Apple.

Additionally, I know that recent efforts in the hackintosh community had problems with Message.app because the latest protocols incorporate being able to access the serial number of your machine (or something along those lines). Apple goes through some extensive hoops verifying that access to OS X -only and iOS-only services really does come from their devices.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: