Live data from Hacker News

Apple’s approach to privacy

apple.com

71–80 of 172 posts

Re: Apple’s approach to privacy

#71
post #58
post #43

Earlier quoted context omitted.

>Does this mean they are capable of intercepting iMessage? You know what the best way is to see who cooperates with law enforcement and to what level? Court documents! I've been trawling court documents for the past few months (I'm writing a blog article on this) and I'm yet to find iMessage being used in court (unless the access to the conversation was given by one of the parties). iMessage really does seem secure f…

I'm also looking forward to your post. Whatsapp is supposed to be end-to-end encrypted with messages only stored on the phone, at least it has reportedly been like that since end of 2014. It would be extremely interesting and a big scandal if you found documents with Whatsapp messages in them dating from 2015.

Only from android to android. Other platforms don't have it implemented yet.

Re: Apple’s approach to privacy

#72
post #43

I was reading their guidelines for law enforcement requests: https://www.apple.com/privacy/docs/emeia_le_guidelines_final... Interesting note: "P. FaceTime FaceTime communications are end-to-end encrypted and Apple has no way to decrypt FaceTime data when it is in transit between devices. Apple cannot intercept FaceTime communications. Apple has FaceTime call invitation logs when a FaceTime call invitation is initiat…

>Does this mean they are capable of intercepting iMessage? You know what the best way is to see who cooperates with law enforcement and to what level? Court documents! I've been trawling court documents for the past few months (I'm writing a blog article on this) and I'm yet to find iMessage being used in court (unless the access to the conversation was given by one of the parties). iMessage really does seem secure f…

May I have a link to your blog?

Re: Apple’s approach to privacy

#73

So how will we ever know until it happens if the encryption on Apple devices is weakened by government demands? I understand they have a posted stance on privacy and such but the US government has shown it will threaten even those who divulge requests. It is to the point I don't upgrade i devices until weeks after just to be sure.

Isn't that problem solved by the 'canary in the coal mine' ? A company can have strong privacy language in their documentation. If any or part of that language disappears suddenly one day, you can know that a government forced the company to go against this language?

Sadly, Apple isn't on https://canarywatch.org/ Did I miss another way to know about that information (that does not involve parsing all Apple documentation by myself).

Re: Apple’s approach to privacy

#74

Apple is in a good position in the market to do this, but it is just really hard to trust any US company. They say they will never give anyone access to their servers but how can they make that promise when they don't make the laws? As an aside I am finding it really difficult to delete my iCloud account, in fact it seems that is impossible.

To paraphrase Spock, "Even laws must give way to mathematics".

Re: Apple’s approach to privacy

#75
No, I don't trust you. That trust is long gone, you will have a long way to go to earn it back. These are just words, and they can write whatever they want since there is no way to validate the claims.

Re: Apple’s approach to privacy

#76

I was reading their guidelines for law enforcement requests: https://www.apple.com/privacy/docs/emeia_le_guidelines_final... Interesting note: "P. FaceTime FaceTime communications are end-to-end encrypted and Apple has no way to decrypt FaceTime data when it is in transit between devices. Apple cannot intercept FaceTime communications. Apple has FaceTime call invitation logs when a FaceTime call invitation is initiat…

iMessage is discussed in great detail in https://www.apple.com/business/docs/iOS_Security_Guide.pdf

Re: Apple’s approach to privacy

#77
post #42

Apple is in a good position in the market to do this, but it is just really hard to trust any US company. They say they will never give anyone access to their servers but how can they make that promise when they don't make the laws? As an aside I am finding it really difficult to delete my iCloud account, in fact it seems that is impossible.

Changes in laws cannot provide access to data that was never gathered and stored in the first place. Similarly, laws cannot force a company to divulge encrypted data if the company does not hold the encryption keys. So as long as you trust the company, the country it's in is not relevant, at least for the situations outlined above.

Whether or not they hold the keys at present, Apple is in a position of power with regard to the iOS environment. In a technical sense it would be fairly straightforward for them to acquire the keys.

Trusting the company has nothing to do with it - they could be legally compelled to do so in a secret court, and gagged with a NSL to keep them from revealing such an order. Sadly that's the reality we now live in.

Re: Apple’s approach to privacy

#78
post #53

Earlier quoted context omitted.

When national security requests come with built-in gag orders, little-to-no oversight, and are probably easier to issue/get than warrants (no pesky judges or explaining to do) why would one ever use a warrant again?

If NSRs are so easy to get and so powerful, why does anyone still bother getting warrants?

[deleted]

Re: Apple’s approach to privacy

#79
post #42

Apple is in a good position in the market to do this, but it is just really hard to trust any US company. They say they will never give anyone access to their servers but how can they make that promise when they don't make the laws? As an aside I am finding it really difficult to delete my iCloud account, in fact it seems that is impossible.

Changes in laws cannot provide access to data that was never gathered and stored in the first place. Similarly, laws cannot force a company to divulge encrypted data if the company does not hold the encryption keys. So as long as you trust the company, the country it's in is not relevant, at least for the situations outlined above.

As far as I know you have very little rights to begin with as a non-US citizen outside of the US.

Re: Apple’s approach to privacy

#80

Apple is in a good position in the market to do this, but it is just really hard to trust any US company. They say they will never give anyone access to their servers but how can they make that promise when they don't make the laws? As an aside I am finding it really difficult to delete my iCloud account, in fact it seems that is impossible.

To paraphrase Spock, "Even laws must give way to mathematics".

But not to its application.
Post reply on HN