What iMessage actually keeps private — and what it doesn't
A plain-English read on the iMessage threat model — what Apple sees, what your provider sees, what survives a phone search, and where steganography fits.
iMessage is end-to-end encrypted. People hear that and round it to “safe”. The actual picture is more interesting, and worth knowing before you decide what to send through it.
What’s actually encrypted
The message body — the text, the attachments, the stickers — leaves your device encrypted with a key only the recipient can decrypt. Apple’s servers relay the ciphertext but cannot read it. Your carrier sees less than that: just an iMessage-shaped blob over Apple’s network.
This is real protection. A network-level adversary can’t read your texts. A breach of Apple’s relay servers wouldn’t either.
What Apple still knows
Encryption protects the contents, not the envelope. Apple, in normal operation, knows:
- Who you talk to, and when. Sender, recipient, timestamp.
- The size and rough shape of each message.
- Your account metadata — phone number, Apple Account, device list.
- Push delivery — every message goes through Apple’s push system, which knows which device received what, when.
That’s “metadata” in the technical sense, and metadata is enough for most investigations. The famous quote — “we kill people based on metadata” — was about phone records, not messages, but the principle holds.
What survives if your phone is taken
This is where it gets uncomfortable.
If someone compels you to unlock your phone — at a border, in a search, or in a hostile interview — the encryption stops mattering. The Messages app opens, and there’s your full history. Apple’s encryption doesn’t protect you from yourself; it protects you from the network.
Even without the phone, there’s iCloud. Apple’s own security overview says iCloud Backup includes Messages, and when backup is on, it also holds a copy of the Messages in iCloud encryption key — protected with keys Apple keeps, unless you’ve turned on Advanced Data Protection. Someone who gets into your Apple Account, or compels Apple, can reach more than the network ever could.
So the real questions for an iMessage user, in order:
- Who has my Apple Account credentials?
- Is iCloud Backup of Messages on?
- Is Advanced Data Protection on?
- Could someone make me unlock this phone?
What recompression and screenshots do
Two side effects worth knowing.
iMessage can recompress images and video on some paths — group chats, forwarding, saving to Photos and sharing again. The recipient gets a smaller, lower-quality version. For ordinary photos this is fine. For anything that depends on exact pixel data — including some kinds of steganography — recompression destroys the hidden payload silently.
Screenshots, similarly, are just images. They lose any pixel-level data that wasn’t already visible. This is good news for steganographic carriers: a screenshot of a Stiger sticker is just a sticker, with no recoverable hidden text.
Where steganography fits
End-to-end encryption hides what you said. Steganography hides that you said anything. They solve different problems and stack well.
In a country where iMessage works but Telegram doesn’t, a Stiger sticker looks like an ordinary sticker to someone scrolling your chat, and its text doesn’t show up in a keyword search of your phone. Apple and your carrier see an image going from you to someone, as with any photo.
What it won’t survive is a forensic look. The sticker arrives as an image attachment rather than a native iMessage sticker, and trained steganalysis tools can tell that an image carries hidden data — not what the data says. Stiger raises the cost of noticing; it doesn’t make noticing impossible.
This isn’t a replacement for Signal where Signal works. It’s the right tool when the act of using a privacy tool is the threat.
The honest summary
iMessage is good for “I don’t want my carrier reading my texts.” It’s adequate for “I don’t want a casual snoop reading my texts.” It’s not sufficient on its own when:
- you’re worried about your own device being inspected,
- you’re worried about Apple Account compromise,
- you’re worried about being identified as someone who uses encrypted messaging at all.
For each of those, the right answer is some combination of: turn on Advanced Data Protection, audit iCloud Backup of Messages, and — for the third one — use a carrier that doesn’t look like a privacy tool. That last part is what Stiger is for.
Read more on the threat model: THREAT_MODEL.md.