Affiliate Disclosure
If you buy through our links, we may get a commission. Read our ethics policy.

Researchers, Apple collaborate to fix iMessage security hole with today's release of iOS 9.3

A bug has been discovered in Apple's iMessage encryption by security researchers at Johns Hopkins University, who have collaborated with the company to help patch the issue in the upcoming iOS 9.3 software update, set to be released to the public today.

Johns Hopkins will withhold publishing the details of flaw until after iOS 9.3 is released to the public, according to The Washington Post. Researchers claim that the security hole could allow hackers to decrypt photos and videos sent via iMessage.

Apple issued a statement on the team's findings, saying the problem was partially fixed with iOS 9. Today's release of iOS 9.3, expected after the company's "iPhone SE" media event, will apparently fully resolve the issue.

"Apple works hard to make our software more secure with every release," the statement reads. "We appreciate the team of researchers that identified this bug and brought it to our attention so we could patch the vulnerability."

The head of the research team, Matthew D. Green, said the flaw likely wouldn't have helped the FBI in its investigation of the San Bernardino shooter's iPhone 5c. But the team also stands by Apple in its encryption battle with the U.S. government, saying the flaw only serves to highlight the fact that there are other ways the government could break into mobile devices without forcing Apple to make a backdoor.

"Even Apple, with all their skills — and they have terrific cryptographers — wasn't able to quite get this right," Green said. "So it scares me that we're having this conversation about adding back doors to encryption when we can't even get basic encryption right."

Security researchers have repeatedly praised Apple's iMessage protocol for being highly secure, sometimes to the ">chagrin of law enforcement. But the research by Johns Hopkins shows that even the most robust encryption can have serious flaws.

iMessages are encrypted messages that can be sent between Apple devices, including iPhones, iPads and even Macs running the OS X platform. The service launched with iOS 5 back in 2011.



16 Comments

6Sgoldfish 108 comments · 9 Years

Is the use of an iPhone 5S mockup meant to loop us in? ;) 

wood1208 2938 comments · 10 Years

While fixing this bug, Apple can also add able to create/save multiple draft text/message before send option in iMessage App. Missing since it’s inception against android stock message app. iPhone users say create multiple draft using Notes App and cut/paste into imessage when ready to send your text. I say why ? why not build into imessage/text app like android stock text app. Even every email app on every platform does it when you leave draft, it automatically saves.

wood1208 2938 comments · 10 Years

lkrupp said:
wood1208 said:
While fixing this bug, Apple can also add able to create/save multiple draft text/message before send option in iMessage App. Missing since it’s inception against android stock message app. iPhone users say create multiple draft using Notes App and cut/paste into imessage when ready to send your text. I say why ? why not build into imessage/text app like android stock text app. Even email does it when you leave draft, it automatically saves.
Switch to Android then if iOS is so rudimentary and behind the times.

Wov ! Is this your recommendation as apple fan ? Shame on you. My family might have more Apple gadgets than you and not recently but since the day of early Macs. And forgot to add. I guarantee, I have more Apple stocks than you do.

matrix077 868 comments · 9 Years

wood1208 said:
While fixing this bug, Apple can also add able to create/save multiple draft text/message before send option in iMessage App. Missing since it’s inception against android stock message app. iPhone users say create multiple draft using Notes App and cut/paste into imessage when ready to send your text. I say why ? why not build into imessage/text app like android stock text app. Even every email app on every platform does it when you leave draft, it automatically saves.

A month ago my maid was just confused by her Android phone on this issue. She didn't understand what "draft" was.

I say I prefer the way iMessage handle it. Send or not send. No draft. That's simpler.