Live data from Hacker News

Apple’s approach to privacy

apple.com

51–60 of 172 posts

Re: Apple’s approach to privacy

#51
post #43

I was reading their guidelines for law enforcement requests: https://www.apple.com/privacy/docs/emeia_le_guidelines_final... Interesting note: "P. FaceTime FaceTime communications are end-to-end encrypted and Apple has no way to decrypt FaceTime data when it is in transit between devices. Apple cannot intercept FaceTime communications. Apple has FaceTime call invitation logs when a FaceTime call invitation is initiat…

>Does this mean they are capable of intercepting iMessage? You know what the best way is to see who cooperates with law enforcement and to what level? Court documents! I've been trawling court documents for the past few months (I'm writing a blog article on this) and I'm yet to find iMessage being used in court (unless the access to the conversation was given by one of the parties). iMessage really does seem secure f…

“Parallel construction is a law enforcement process of building a parallel - or separate - evidentiary basis for a criminal investigation in order to conceal how the investigation actually began.”

https://en.wikipedia.org/wiki/Parallel_construction

Re: Apple’s approach to privacy

#52
Nice but recently I was asked to enter the admin password of my MBP into a webform at an Apple reseller, it was a requirement for getting the GPU repaired (as part of a recall.) Isn't that very strange?

Re: Apple’s approach to privacy

#53
post #2

I guess I should have expected a number this high, but I didn't. 750-999 national security requests in half a year? Not warrants, but national security requests. That just seems insane to me.

When national security requests come with built-in gag orders, little-to-no oversight, and are probably easier to issue/get than warrants (no pesky judges or explaining to do) why would one ever use a warrant again?

If NSRs are so easy to get and so powerful, why does anyone still bother getting warrants?

Re: Apple’s approach to privacy

#54
So how will we ever know until it happens if the encryption on Apple devices is weakened by government demands? I understand they have a posted stance on privacy and such but the US government has shown it will threaten even those who divulge requests.

It is to the point I don't upgrade i devices until weeks after just to be sure.

Re: Apple’s approach to privacy

#56
post #42

Apple is in a good position in the market to do this, but it is just really hard to trust any US company. They say they will never give anyone access to their servers but how can they make that promise when they don't make the laws? As an aside I am finding it really difficult to delete my iCloud account, in fact it seems that is impossible.

Changes in laws cannot provide access to data that was never gathered and stored in the first place. Similarly, laws cannot force a company to divulge encrypted data if the company does not hold the encryption keys. So as long as you trust the company, the country it's in is not relevant, at least for the situations outlined above.

> Changes in laws cannot provide access to data that was never gathered and stored in the first place.

Laws can and have been written that require companies to gather data.

> Similarly, laws cannot force a company to divulge encrypted data if the company does not hold the encryption keys.

Laws can and have been written that require companies to use weaker or broken encryption.

Re: Apple’s approach to privacy

#57
post #46
post #45

Earlier quoted context omitted.

It's half a google away. https://www.google.com/search?q=disable+spotlight+queries+se...

Doesn't really address iOS 9 which changed things around a bit, and to even find anything about iOS at all you have to start looking at the 4th or 5th result on some random domain. And - even then - there are multiple odd places in the settings you need to check and verify, some of which are hidden in a long list of other apps.

It's detailed in the help page, the link to which is on the same settings screen that contains the switches to turn off.

Likewise on MacOS, there's a 'About Spotlight Suggestions & Privacy' button on the Spotlight settings page. Again, it's on the same screen that contains the switches to turn off the feature.

You don't need internet access to find these options, and I can't think of a better place to put the help. Knowing that these options exist in the first place is another problem though...

Re: Apple’s approach to privacy

#58
post #43

I was reading their guidelines for law enforcement requests: https://www.apple.com/privacy/docs/emeia_le_guidelines_final... Interesting note: "P. FaceTime FaceTime communications are end-to-end encrypted and Apple has no way to decrypt FaceTime data when it is in transit between devices. Apple cannot intercept FaceTime communications. Apple has FaceTime call invitation logs when a FaceTime call invitation is initiat…

>Does this mean they are capable of intercepting iMessage? You know what the best way is to see who cooperates with law enforcement and to what level? Court documents! I've been trawling court documents for the past few months (I'm writing a blog article on this) and I'm yet to find iMessage being used in court (unless the access to the conversation was given by one of the parties). iMessage really does seem secure f…

I'm also looking forward to your post. Whatsapp is supposed to be end-to-end encrypted with messages only stored on the phone, at least it has reportedly been like that since end of 2014. It would be extremely interesting and a big scandal if you found documents with Whatsapp messages in them dating from 2015.

Re: Apple’s approach to privacy

#59
post #2

I guess I should have expected a number this high, but I didn't. 750-999 national security requests in half a year? Not warrants, but national security requests. That just seems insane to me.

I suppose the question is - What is the scope of an NSL? Can it cover all subscriber data in a single request?

Re: Apple’s approach to privacy

#60
post #42

Earlier quoted context omitted.

Changes in laws cannot provide access to data that was never gathered and stored in the first place. Similarly, laws cannot force a company to divulge encrypted data if the company does not hold the encryption keys. So as long as you trust the company, the country it's in is not relevant, at least for the situations outlined above.

> Changes in laws cannot provide access to data that was never gathered and stored in the first place. Laws can and have been written that require companies to gather data. > Similarly, laws cannot force a company to divulge encrypted data if the company does not hold the encryption keys. Laws can and have been written that require companies to use weaker or broken encryption.

True, of course. But we would presumably know about these laws, in advance, and we would have the ability to make choices based on this knowledge.

Apple has thus far been steadfast in resisting this sort of activity and in advocating against any such laws.

So for me at least, this is behavior that is worthy of trust.

Post reply on HN