PQ3 HAS ARRIVED — iMessage gets a major makeover that puts it on equal footing with Signal How Kybers and ratcheting are boosting the resiliency of Apple’s messaging app.
Dan Goodin – Feb 22, 2024 12:37 am UTC EnlargeGetty Images reader comments 98
iMessage is getting a major makeover that makes it among the two messaging apps most prepared to withstand the coming advent of quantum computing, largely at parity with Signal or arguably incrementally more hardened.
On Wednesday, Apple said messages sent through iMessage will now be protected by two forms of end-to-end encryption (E2EE), whereas before, it had only one. The encryption being added, known as PQ3, is an implementation of a new algorithm called Kyber that, unlike the algorithms iMessage has used until now, cant be broken with quantum computing. Apple isnt replacing the older quantum-vulnerable algorithm with PQ3it’s augmenting it. That means, for the encryption to be broken, an attacker will have to crack both. Making E2EE future safe
Further ReadingThe Signal Protocol used by 1+ billion people is getting a post-quantum makeoverThe iMessage changes come five months after the Signal Foundation, maker of the Signal Protocol that encrypts messages sent by more than a billion people, updated the open standard so that it, too, is ready for post-quantum computing (PQC). Just like Apple, Signal added Kyber to X3DH, the algorithm it was using previously. Together, theyre known as PQXDH.
iMessage and Signal provide end-to-end encryption, a protection that makes it impossible for anyone other than the sender and recipient of a message to read it in decrypted form. iMessage began offering E2EE with its rollout in 2011. Signal became available in 2014. Advertisement
One of the biggest looming threats to many forms of encryption is quantum computing. The strength of the algorithms used in virtually all messaging apps relies on mathematical problems that are easy to solve in one direction and extremely hard to solve in the other. Unlike a traditional computer, a quantum computer with sufficient resources can solve these problems in considerably less time.
No one knows how soon that day will come. One common estimate is that a quantum computer with 20 million qubits (a basic unit of measurement) will be able to crack a single 2,048-bit RSA key in about eight hours. The biggest known quantum computer to date has 433 qubits.
Whenever that future arrives, cryptography engineers know its inevitable. They also know that its likely some adversaries will collect and stockpile as much encrypted data now and decrypt it once quantum advances allow for it. The moves by both Apple and Signal aim to defend against that eventuality using Kyber, one of several PQC algorithms currently endorsed by the National Institute of Standards and Technology. Since Kyber is still relatively new, both iMessage and Signal will continue using the more tested algorithms for the time being. Page: 1 2 Next → reader comments 98 Dan Goodin Dan Goodin is Senior Security Editor at Ars Technica, where he oversees coverage of malware, computer espionage, botnets, hardware hacking, encryption, and passwords. In his spare time, he enjoys gardening, cooking, and following the independent music scene. Advertisement Channel Ars Technica ← Previous story Next story → Related Stories Today on Ars
A woman casually walks into a convenience store and starts filling a bread crate with goods from one of the aisles.
A shop assistant tries to stop her, but she shrugs him off, undeterred. With the crate now full of items, she leaves without paying.
It is a scenario that is played out day in and day out across Britain, as retailers warn the surge in shoplifting is now “out of control”.
I’m sitting in the security office of a busy city centre shop and I’m watching as a schoolboy walks in and helps himself to a sandwich, stuffing it into his jacket.
Watching with me is shop worker Anton Mavroianu who positions himself by the main entrance waiting for the youngster to leave.
When the boy does leave, Anton demands the item back. Instead of being frozen with fear that he’s been caught, the boy laughs and walks off.
“All we can do is try to stop them,” Anton tells me. “But this is just another day for us.”
A few weeks earlier, when Anton tried to stop a shoplifter who had stolen from the store, the man pulled out a knife and tried to attack him.
This terrifying incident is an example of the very real threat posed to shop workers as they try to stem the tide of brazen thefts.
Advertisement
Shoplifting offences recorded by police in England and Wales have risen to the highest level in 20 years.
The British Retail Consortium (BRC) also reports that theft-related losses cost the retail sector millions each year, adding strain to an industry already grappling with post-pandemic recovery and economic uncertainty.
For small businesses, which lack the resources of larger chains, persistent theft can threaten their very survival.
Ricky Dougall owns a chain of convenience stores and says shoplifting cost his business around £100,000 last year.
“Shoplifting is a huge problem and it is what stops us from growing the business.
“People come in and help themselves like they own the place and when you call the police, most of the time, they don’t turn up.”
Mr Dougall says part of the problem is how this type of crime is classified.
Sentencing guidelines for thefts of under £200, so-called “low level shoplifting”, were relaxed in 2016. That is being blamed for the surge in cases.
An exclusive Sky News and Association of Convenience Stores survey shows that 80% of shopkeepers surveyed had an incident of retail crime in the past week.
The poll also found 94% of shopkeepers say that in their experience, shoplifting has got worse over the last year, with 83% not confident that the police will take action against the perpetrators of retail crime on their premises.
Paul Cheema from the Association of Convenience Stores says retailers are looking to Government to support them.
“I would say officials do not give a s*** about us retailers,” he tells me. “The losses are too big and I don’t think we can sustain that anymore.
“I would urge Keir Starmer to come and meet us and see up close the challenges that we are facing.”
Retailers have responded by investing heavily in security measures, from advanced surveillance systems to hiring more security staff.
But these investments come at a cost, often passed down to consumers through higher prices.
I get chatting to Matt Roberts, head of retail in the store I am in. He worries about shoplifting, but he worries about the staff more.
“I would imagine they dread coming to work because they’re always on tenterhooks wondering whether something is going to happen today, whether they are going to have to try and confront someone.
“It’s a horrible feeling. It’s out of control and we need help.”
The government has acknowledged the urgency of the issue. Home Secretary-led discussions with retail associations and law enforcement are underway to craft a comprehensive strategy.
In the King’s Speech, the government outlined details of a Crime and Policing Bill, which promised to “introduce stronger measures to tackle low level shoplifting”, as well as introducing a separate offence for assaulting a shop worker.
Children do not feel safe, a charity has warned, as a survey finds two-thirds of teens in England and Wales have a fear of violence.
The charity, which surveyed 10,000 children aged 13-17, found that 20% of teenagers have been victims of violence in the past 12 months.
“I think what shocked me most is how this is a problem that affects all of our children,” said Jon Yates, CEO of the Youth Endowment Fund.
“We found that two-thirds of all teenage children are afraid. And that fear is pretty real for a lot of them.”
He said it’s a fear so palpable that many teenage children are changing their patterns of behaviour, or have had it influence their daily decisions.
One third of teenage children – 33% – reported avoiding areas, whilst around 27% alter their travel routes or avoid public transport altogether to stay safe.
More worryingly, however, some say the fear of violence has led to mental health challenges, with 22% reporting difficulties sleeping, reduced appetite and concentrating in school.
More on Children
Related Topics:
Weapon carrying is also a concern for the charity, especially among vulnerable groups.
Please use Chrome browser for a more accessible video player
3:55
From September: Young gangs of Wolverhampton
In England and Wales, 5% of all 13-17 year olds reported carrying a weapon in the past year, but that figure jumps to 21% for those suspended from school and 36% for children who have been excluded from school.
Advertisement
But Mr Yates said “shockingly” only 12% of children who repeatedly commit violence get any sort of support.
“That’s madness,” he said.
Jay*, 23, from Birmingham said depending on your environment, sometimes violence is hard to avoid.
“I’ve had friends be shot, I’ve got friends who have been stabbed, I had a friend die last month to be fair,” Jay told Sky News.
He said it is “damaging” because you never really get the opportunity to “heal”. He is now being supported by the charity Project Lifeline, but says before then it was difficult to find any hope.
“If you don’t have hope,” Jay added, “you can’t really get anywhere. It’s about finding that hope.”
Mark Rodney, CEO of Lifeline Project, mentors at-risk young children and said he has learned that “not only the perpetrator carries the knife, the victim sometimes carries the knife”.
“And not only the perpetrator does the killing,” he added. “The victim sometimes does the killing, because that’s where we’re at.”
He said far too many families ask themselves “is my child safe going to school or coming home from school?” and adds the government must “actually start addressing people’s concerns”.
Please use Chrome browser for a more accessible video player
15:46
From September: Home Sec vows to halve knife crime
The report also found that in 93% of cases where teenage children repeatedly harm others, adults intervene with punishments such as school discipline or police involvement.
However, only 12% of these children are offered support aimed at addressing the root causes of violence and preventing further harm.
Mr Yates said: “They go to school, they do something violent. They get excluded.”
He added: “We need to be much better at saying, ‘we’re not going to lose that child. We’re going to keep providing support to them. We’re going to keep providing a mentor’.
“Instead, we let them fall through the cracks”.
A government spokesperson said: “Halving knife crime in a decade is a clear mission this government has set out.
“It is vital to protect vulnerable young people who are too often the victims or perpetrators of this crime.”
Corporate America is investing in clean energy at record levels, with tech giants taking the top spots for users of solar.
Meta, Google, and Amazon are leading the charge in solar and battery storage adoption, according to the Solar Energy Industries Association’s (SEIA’s) latest “Solar Means Business” report.
Meta continues to hold the title of the top solar user in corporate America, with nearly 5.2 gigawatts (GW) of solar capacity installed. Meanwhile, Google leads the way in energy storage, boasting 936 megawatt-hours (MWh) of installed battery capacity. Through the first quarter of 2024, these companies have added the most solar capacity to their electricity portfolios, with major players like General Motors, Toyota, and US Steel also climbing the ranks.
The report reveals that US businesses have installed nearly 40 GW of solar capacity both onsite and offsite through Q1 2024, and corporate storage use now exceeds 1.8 gigawatt-hours (GWh). Even more growth is coming: Companies have over 3 GWh of battery storage under contract that will come online in the next five years.
“Some of the largest industrial and data operations in the world continue turning to solar and storage as a reliable, low-cost way to power their operations,” said SEIA president and CEO Abigail Ross Hopper.
Technology companies are at the forefront of this shift as data center growth drives skyrocketing electricity demand. Amazon, for example, leads the US with 13.6 GW of solar procurements under contract, while Meta and Google each have nearly 6 GW under contract – pipelines over 10 times larger than the next company in the rankings.
Target remains the US’s leading onsite corporate solar user for the ninth year in a row, with Prologis, Walmart, Amazon, and Blackstone also making the top five. For the first time, the “Solar Means Business” report is also tracking corporate battery energy storage, with Google, Apple, Meta, Target, Walmart, Home Depot, and Kohl’s among the top 10 companies using storage to meet more of their energy needs in real-time.
Looking ahead, both offsite and onsite energy storage are expected to play a bigger role in corporate renewable energy strategies. Medical companies like Kaiser Permanente are already using batteries to power microgrids, making their facilities more resilient to outages.
Carolyn Campbell, Meta’s head of clean and renewable energy, East, highlighted the importance of expanding solar capacity to match the company’s global operations with 100% clean energy: “We’re thrilled to rank number one for corporate solar procurement in SEIA’s report this year, and we continue to find ways to grow the grid to benefit everyone.”
Target’s vice president of property management, Erin Tyler, said of Target’s 20-year-old solar program, “Through our commitment to solar, we’re well on our way to achieving our corporate goal of sourcing 100% of electricity from renewable sources by 2030.”
The “Solar Means Business” report also looks at the policies driving corporate America’s adoption of solar. Many companies are taking advantage of the Inflation Reduction Act’s long-term clean energy incentives. To further accelerate their renewable energy investments, businesses are calling for improvements in interconnection processes, new community solar legislation, and simpler tax credit monetization.
If you live in an area that has frequent natural disaster events, and are interested in making your home more resilient to power outages, consider going solar and adding a battery storage system. To make sure you find a trusted, reliable solar installer near you that offers competitive pricing, check out EnergySage, a free service that makes it easy for you to go solar. They have hundreds of pre-vetted solar installers competing for your business, ensuring you get high quality solutions and save 20-30% compared to going it alone. Plus, it’s free to use and you won’t get sales calls until you select an installer and share your phone number with them.
Your personalized solar quotes are easy to compare online and you’ll get access to unbiased Energy Advisers to help you every step of the way. Get started here. –trusted affiliate link*
FTC: We use income earning auto affiliate links.More.