Live data from Hacker News

Apple’s approach to privacy

apple.com

81–90 of 172 posts

Re: Apple’s approach to privacy

#81

Wasn't the Fappening because of a iCloud hole?

The images in The Fappening came from a variety of cloud services, including iCloud. I think the hackers were getting access primarily via social engineering.

There was an iCloud hole that was discovered around the same time as The Fappening, but no evidence that it was used by them before it was patched by apple.

Re: Apple’s approach to privacy

#82

Earlier quoted context omitted.

No, it was because celebrities are normal people and tended to use the same password for multiple services. One service was compromised, which compromised every other one because the passwords were the same.

Source? Most of my google has netted the blame on Apple and a conspiracy throy of this beng a PR scandal.

Really? It seems to me that most articles conclude that it wasn’t iCloud that was hacked but the celebrities.

Apple also released a press release[1] saying that they “have discovered that certain celebrity accounts were compromised by a very targeted attack on user names, passwords and security questions, a practice that has become all too common on the Internet. None of the cases we have investigated has resulted from any breach in any of Apple’s systems including iCloud® or Find my iPhone.”

[1]: http://www.apple.com/pr/library/2014/09/02Apple-Media-Adviso...

Re: Apple’s approach to privacy

#83

We’re going to make sure you get updates here about privacy at Apple at least once a year and whenever there are significant changes to our policies. Translation: We set up this page to reference for the inevitable future articles and critcisms of our policies. Not saying it's a bad idea, but it's very lawerly to me. Like this one: We don’t build a profile based on your email content or web browsing habits to sell to…

I was going to suggest that this page was meant to serve as a warrant canary but it looks like Apple had a warrant canary but it's gone now (Explanation of a warrant canary for the uninitiated in link): http://apple.slashdot.org/story/14/09/18/2216222/apples-warr...

Re: Apple’s approach to privacy

#84
post #42

Earlier quoted context omitted.

Changes in laws cannot provide access to data that was never gathered and stored in the first place. Similarly, laws cannot force a company to divulge encrypted data if the company does not hold the encryption keys. So as long as you trust the company, the country it's in is not relevant, at least for the situations outlined above.

> Changes in laws cannot provide access to data that was never gathered and stored in the first place. Laws can and have been written that require companies to gather data. > Similarly, laws cannot force a company to divulge encrypted data if the company does not hold the encryption keys. Laws can and have been written that require companies to use weaker or broken encryption.

>Laws can and have been written that require companies to use weaker or broken encryption.

Source? Example? I don't know an example of this. (At least in the US)

Re: Apple’s approach to privacy

#85
post #17

> Apple has never worked with any government agency from any country to create a “backdoor” in any of our products or services. We have also never allowed any government access to our servers. And we never will. Did Apple ever provide any insight into what access the Prism program had? They denied knowing about it[1], so either they are lying or it was a mole. Did they ever follow up with an investigation or conclusi…

Under a strict interpretation, Apple hasn't given the NSA "access to [their] servers" (not root access, not physical access, etc.). They've given them a means to access some user data. (Edit: Or just request it, see snowwrestler's comment below.)

To answer what access the NSA has, the best case would be merely access to iCloud email, iTunes Store purchase records and other things Apple can't encrypt. The worst case is everything.

Re: Apple’s approach to privacy

#86

I was reading their guidelines for law enforcement requests: https://www.apple.com/privacy/docs/emeia_le_guidelines_final... Interesting note: "P. FaceTime FaceTime communications are end-to-end encrypted and Apple has no way to decrypt FaceTime data when it is in transit between devices. Apple cannot intercept FaceTime communications. Apple has FaceTime call invitation logs when a FaceTime call invitation is initiat…

Knowing that most phone lines are essentially considered tapped by the NSA/FBI...

So is privacy a good reason to use FaceTime Audio over say, a standard voice call?

Re: Apple’s approach to privacy

#87
post #60

Earlier quoted context omitted.

True, of course. But we would presumably know about these laws, in advance, and we would have the ability to make choices based on this knowledge. Apple has thus far been steadfast in resisting this sort of activity and in advocating against any such laws. So for me at least, this is behavior that is worthy of trust.

> But we would presumably know about these laws, in advance Court rulings and legal authorisations to conduct surveilance can and have ... you guessed it ... been kept secret

Also true. But we know from the Snowden revelations and other sources that Apple has been backing up its promises. So we have at least some level of assurance that Apple is a good actor.

Re: Apple’s approach to privacy

#88

I use Apple products, including the MBP on which I am typing this post. I paid big bucks and my expectation is Apple should respect my privacy. Services like Google I use them for free, and as such, monetization is fair. Not for Apple, and I hope it won't let me down.

This seems to me like a rational approach. You get what you pay for. Or to put it another way, if you don't pay for the product, then you are the product.

Re: Apple’s approach to privacy

#90
post #84

Earlier quoted context omitted.

> Changes in laws cannot provide access to data that was never gathered and stored in the first place. Laws can and have been written that require companies to gather data. > Similarly, laws cannot force a company to divulge encrypted data if the company does not hold the encryption keys. Laws can and have been written that require companies to use weaker or broken encryption.

>Laws can and have been written that require companies to use weaker or broken encryption. Source? Example? I don't know an example of this. (At least in the US)

https://en.wikipedia.org/wiki/40-bit_encryption was the most secure thing it was legal to export. The Netscape browser, in particular, had a lot of hoops you had to go through in order to get the 56 bit version meant for US audiences. Therefore, even most Americans with internet access at the time had the crippled international version.
Post reply on HN