Live data from Hacker News

Apple’s approach to privacy

apple.com

101–110 of 172 posts

Re: Apple’s approach to privacy

#101
post #64
post #62

Earlier quoted context omitted.

You don't have to. It just lets them better test and repair your device. If something is gorked up in your system files they can fix it using an admin account. I just dropped two laptops for repairs and didn't know an admin password on one. It wasn't a problem, though I suppose it might be more likely to come back with a wiped disk.

Why can't they just boot of an USB disk for testing?

They do boot over the network for hardware testing. That doesn't help them if the problem is in your software install.

Re: Apple’s approach to privacy

#102

Apple is in a good position in the market to do this, but it is just really hard to trust any US company. They say they will never give anyone access to their servers but how can they make that promise when they don't make the laws? As an aside I am finding it really difficult to delete my iCloud account, in fact it seems that is impossible.

Locating data outside the US is in no way a defense against US intelligence agencies. There are theoretically controls on domestic spying, and some possibility that Congress could make it illegal. They have a mandate to spy on foreign networks. If they haven't cracked your European email provider, then they're not doing what we pay and order them to do.

[flagged]

Re: Apple’s approach to privacy

#103

Apple is in a good position in the market to do this, but it is just really hard to trust any US company. They say they will never give anyone access to their servers but how can they make that promise when they don't make the laws? As an aside I am finding it really difficult to delete my iCloud account, in fact it seems that is impossible.

One doesn't need to give access to their servers in order to give access to their data. You just set up a hot spare and sync it over a leaky protocol, like FTP.

Ta-da! Both the marketing and the NSA are happy as clams.

Re: Apple’s approach to privacy

#104

Apple is in a good position in the market to do this, but it is just really hard to trust any US company. They say they will never give anyone access to their servers but how can they make that promise when they don't make the laws? As an aside I am finding it really difficult to delete my iCloud account, in fact it seems that is impossible.

Very well written text. I like the simple and comprehensible language.

Other companies should take this as an example. (Only problem: many other companies likely wouldn't want to tell in plain words how broad they are gathering and aggregating your (my) data)

Re: Apple’s approach to privacy

#105
post #66

Earlier quoted context omitted.

Genuine curiosity: which country would a company need to be in to be able to trust them?

Switzerland, Netherlands and Norway are a good starting point. I believe that now that privacy became a major concern, we will see countries with some legislative background and experience in other sectors that require secrecy above everything else (e.g. private banking), evolve in secure havens for servers.

The Netherlands is on its way to be removed from that short list. The new WIV20xx (charter for information and security services) gives it very broad powers against very little oversight. I have been unable to find a decent source in English, but among its provisions:

- allows for "reconnaissance" on external networks, including breaking encryption or forcing targets to divulge keys. This "reconnaissance" apparently includes installing sniffers or data probes.

- allows for untargeted data collection on wired networks (including cell phone towers)

- has provisions for forcing data transit stations (including ISP's, but also AMS-IX) to comply with requests.

Only English source I've been able to find with a quick search is https://blog.cyberwar.nl/2015/07/dutch-intelligence-bill-pro...

Re: Apple’s approach to privacy

#106
post #42

Apple is in a good position in the market to do this, but it is just really hard to trust any US company. They say they will never give anyone access to their servers but how can they make that promise when they don't make the laws? As an aside I am finding it really difficult to delete my iCloud account, in fact it seems that is impossible.

Changes in laws cannot provide access to data that was never gathered and stored in the first place. Similarly, laws cannot force a company to divulge encrypted data if the company does not hold the encryption keys. So as long as you trust the company, the country it's in is not relevant, at least for the situations outlined above.

Laws could, however, force the company to secretly push out an update that sends your keys to be held in escrow on government servers should the need arise to decrypt your stuff.

Re: Apple’s approach to privacy

#107

Earlier quoted context omitted.

Locating data outside the US is in no way a defense against US intelligence agencies. There are theoretically controls on domestic spying, and some possibility that Congress could make it illegal. They have a mandate to spy on foreign networks. If they haven't cracked your European email provider, then they're not doing what we pay and order them to do.

[flagged]

> I'd suggest you go 'deep inside you' and think again what should be the priorities to pay for. Thanks!

As you're perhaps aware, the US is a large country (in area and population), with a political system that depends on a sharply divided electorate. The things you seem to think are obvious issues to tackle are actually rather controversial, and prone to demagoguing by opportunistic politicians.

Congratulations on the ideal political process in your home country. Perhaps one day we'll attain the same level of enlightenment; or perhaps you'll gain a bit of maturity and understanding of the landscape here, and develop more realistic ideas about the US.

Thanks!

Re: Apple’s approach to privacy

#108
post #77
post #42

Earlier quoted context omitted.

Changes in laws cannot provide access to data that was never gathered and stored in the first place. Similarly, laws cannot force a company to divulge encrypted data if the company does not hold the encryption keys. So as long as you trust the company, the country it's in is not relevant, at least for the situations outlined above.

Whether or not they hold the keys at present, Apple is in a position of power with regard to the iOS environment. In a technical sense it would be fairly straightforward for them to acquire the keys. Trusting the company has nothing to do with it - they could be legally compelled to do so in a secret court, and gagged with a NSL to keep them from revealing such an order. Sadly that's the reality we now live in.

The reality is that they could always choose to do that and not tell you, no matter what they had promised.

Re: Apple’s approach to privacy

#109

Apple is in a good position in the market to do this, but it is just really hard to trust any US company. They say they will never give anyone access to their servers but how can they make that promise when they don't make the laws? As an aside I am finding it really difficult to delete my iCloud account, in fact it seems that is impossible.

Genuine curiosity: which country would a company need to be in to be able to trust them?

It depends on what you are trusting them to do. The NSA's not going to spy on you less just because you're not in the US. If anything, they'd spy on you more.
Post reply on HN