Trill News

Well done is better than well said. — Benjamin Franklin
STEM

Apple Hardens iMessage Against Quantum Computing Threats

Apple Hardens iMessage Against Quantum Computing Threats
Measuring a qubit leaves no room for error by FMNLab (CC BY 4.0)
Apple announced PQ3, a new post quantum encryption protocol for iMessage designed to protect conversations from future quantum computing attacks, on February 21, 2024.

The protocol layers post quantum cryptography, including the Kyber algorithm, on top of iMessage's existing elliptic curve encryption, and Apple described the result as Level 3 security, the strongest claimed by any messaging platform at the time.

Rather than replacing its encryption wholesale, Apple designed PQ3 to refresh session keys continuously so a single compromised key cannot unlock an entire conversation history.

The design targets harvest now, decrypt later attacks, in which adversaries collect encrypted messages today and wait for quantum computers powerful enough to break them.

Two academic research teams evaluated the PQ3 standard before launch, though real world testing remains impossible because quantum machines capable of breaking current encryption are not yet available.

The upgrade rolled out with iOS 17.4, iPadOS 17.4, macOS 14.4, and watchOS 10.4, following Signal's earlier post quantum move and Meta's push to encrypt Messenger and Instagram, and it placed iMessage among the most quantum resistant consumer messaging platforms in the world.
Apple declared iMessage the most quantum-secure messaging protocol at scale in February 2024, and the claim was precise enough to age fast. PQ3 layers Kyber onto elliptic curve cryptography and refreshes keys roughly every 50 messages, capping what any single stolen key can unlockApple. NIST ratified the underlying bet six months later, renaming Kyber as the ML-KEM standard in August 2024. Signal closed the gap in October 2025 with its SPQR ratchet, matching the continuous post-quantum protection that made PQ3 distinctive, and Apple answered by extending post-quantum crypto to TLS, SSH and Watch connections in its 2026 systemsSignal. Next: Signal’s pledge that every message it sends will carry this protection too.

Read the original reporting at TechCrunch.

Read Full Story at TechCrunch →

FIND A BOOK ON BOOKSHOP.ORG