Apple is in a good position in the market to do this, but it is just really hard to trust any US company. They say they will never give anyone access to their servers but how can they make that promise when they don't make the laws? As an aside I am finding it really difficult to delete my iCloud account, in fact it seems that is impossible.
To paraphrase Spock, "Even laws must give way to mathematics".
Apple’s approach to privacy
111–120 of 172 posts
Re: Apple’s approach to privacy
#112Apple says "Less than 0.00673% of customers have been affected by government information requests." That's approximately 1 out of every 14,000 -- seems like a lot to me!
It also says that 94% of requests are "Device requests - Law enforcement seeking a stolen device."
Re: Apple’s approach to privacy
#113I am still skeptical about any company in a hypothetical case where private information of its customers is sought by governments like China. BTW, I am living and going to live in China in future.
Re: Apple’s approach to privacy
#114Earlier quoted context omitted.
Changes in laws cannot provide access to data that was never gathered and stored in the first place. Similarly, laws cannot force a company to divulge encrypted data if the company does not hold the encryption keys. So as long as you trust the company, the country it's in is not relevant, at least for the situations outlined above.
Whether or not they hold the keys at present, Apple is in a position of power with regard to the iOS environment. In a technical sense it would be fairly straightforward for them to acquire the keys. Trusting the company has nothing to do with it - they could be legally compelled to do so in a secret court, and gagged with a NSL to keep them from revealing such an order. Sadly that's the reality we now live in.
In theory Apple could modify iMessage to MITM the key distribution server and enable eavesdropping. The only way to protect against that is to provide in-person validation mechanisms so users can directly compare keys. I hope they add such a thing, not that 99.99999% of their users would ever use it.
As far as the US legal system goes you'd need positive law to enforce wiretapping requirements. Courts (as a general rule) can't issue orders to force Apple to write new code or modify their silicon design to support something the government wishes it could have. Given the way SCOTUS has been approaching cell phone privacy I'm not sure such a law would pass muster.
Re: Apple’s approach to privacy
#115Earlier quoted context omitted.
Changes in laws cannot provide access to data that was never gathered and stored in the first place. Similarly, laws cannot force a company to divulge encrypted data if the company does not hold the encryption keys. So as long as you trust the company, the country it's in is not relevant, at least for the situations outlined above.
> Changes in laws cannot provide access to data that was never gathered and stored in the first place. Laws can and have been written that require companies to gather data. > Similarly, laws cannot force a company to divulge encrypted data if the company does not hold the encryption keys. Laws can and have been written that require companies to use weaker or broken encryption.
Not just that. Laws can (and probably have been) written that require companies to gather data and to explicitly lie about it.
Re: Apple’s approach to privacy
#116 * They were truly, actively committed to defending a user's privacy.
* They allowed using your own domains (I currently have around 30 domains pointed to the same GMail account).
If both of the above were true, I'd ditch my Cyanogenmod-running HTC One M8 and buy an iPhone today. My privacy is worth more to me than the ability to install whatever music player, keyboard, etc that I want or drop to a command line (though I do love having that ability and would miss it).Re: Apple’s approach to privacy
#117Earlier quoted context omitted.
Genuine curiosity: which country would a company need to be in to be able to trust them?
It depends on what you are trusting them to do. The NSA's not going to spy on you less just because you're not in the US. If anything, they'd spy on you more.
Re: Apple’s approach to privacy
#118As a long time Linux user and a long time Google product user, I'd be willing to go all in on Apple if: * They were truly, actively committed to defending a user's privacy. * They allowed using your own domains (I currently have around 30 domains pointed to the same GMail account). If both of the above were true, I'd ditch my Cyanogenmod-running HTC One M8 and buy an iPhone today. My privacy is worth more to me than…
Re: Apple’s approach to privacy
#119Apple is in a good position in the market to do this, but it is just really hard to trust any US company. They say they will never give anyone access to their servers but how can they make that promise when they don't make the laws? As an aside I am finding it really difficult to delete my iCloud account, in fact it seems that is impossible.
I agree, like Lavabit... Lavabit had all the best intentions but in the end the law screwed them over anyway.
Of course Apple has a lot more power than Lavabit, so it's nice they are taking this standpoint and being resistant. Hopefully they can contribute to a positive change.. Anyways at least they are trying, something i haven't seen from other big companies, like Google https://en.wikipedia.org/wiki/Criticism_of_Google#Privacy
Re: Apple’s approach to privacy
#120As a long time Linux user and a long time Google product user, I'd be willing to go all in on Apple if: * They were truly, actively committed to defending a user's privacy. * They allowed using your own domains (I currently have around 30 domains pointed to the same GMail account). If both of the above were true, I'd ditch my Cyanogenmod-running HTC One M8 and buy an iPhone today. My privacy is worth more to me than…
Nope. Just nope. I'll stick with choice and privacy over promises of privacy by a for-profit.
Combine that with GMail. I pay for the business version, yet the privacy policy is still hard to understand and I still get suspicious ads popping up which seem to have come from no where else but my email. Could be wrong, but it's uncanny.
I have a hard time trusting Google.