Live data from Hacker News

Apple’s approach to privacy

apple.com

121–130 of 172 posts

Re: Apple’s approach to privacy

#121
post #84

Earlier quoted context omitted.

> Changes in laws cannot provide access to data that was never gathered and stored in the first place. Laws can and have been written that require companies to gather data. > Similarly, laws cannot force a company to divulge encrypted data if the company does not hold the encryption keys. Laws can and have been written that require companies to use weaker or broken encryption.

>Laws can and have been written that require companies to use weaker or broken encryption. Source? Example? I don't know an example of this. (At least in the US)

I would also consider the NSA meddling with Bitlocker and RSA behind the curtain to be conceptually equivalent.

https://www.schneier.com/blog/archives/2015/03/can_the_nsa_b...

http://gizmodo.com/nsa-paid-security-firm-10-million-bribe-t...

Re: Apple’s approach to privacy

#122
post #30

Earlier quoted context omitted.

It also says that 94% of requests are "Device requests - Law enforcement seeking a stolen device."

The trick is telling the difference between that and: "Device requests - Law enforcement seeking a device they claim is stolen."

well, put a number on it. Of the "Device request" class, clearly at least some of them really are stolen. So that can't be zero. In fact, I'd bet the vast majority of those claims are indeed stolen phones.

I'll give you P(spy) = .01, which feels plausible, around 140 incidents, but we have zero evidence. For something like P(spy) = .1, 1400 requests, I'd want more evidence. It dosn't need to be particularly good evidence, because i don't hold the NSA side to be particularly good.

But, you know, still more than vague comments about the state oppressing a vast number of people with undocumented shady tactics. They've been proven to use undocumented shady tactics in the past, but they also seem pretty bad at keeping that stuff secret for long.

Re: Apple’s approach to privacy

#123
post #115

Earlier quoted context omitted.

> Changes in laws cannot provide access to data that was never gathered and stored in the first place. Laws can and have been written that require companies to gather data. > Similarly, laws cannot force a company to divulge encrypted data if the company does not hold the encryption keys. Laws can and have been written that require companies to use weaker or broken encryption.

> Laws can and have been written that require companies to gather data. Not just that. Laws can (and probably have been) written that require companies to gather data and to explicitly lie about it.

> to explicitly lie about it.

Maybe I'm dense or naive, but I don't think there's any precedent for that. A gag order is one thing (and there are certainly places for it), but forcing someone to lie would hopefully violate the First Amendment.

Re: Apple’s approach to privacy

#124

Apple is in a good position in the market to do this, but it is just really hard to trust any US company. They say they will never give anyone access to their servers but how can they make that promise when they don't make the laws? As an aside I am finding it really difficult to delete my iCloud account, in fact it seems that is impossible.

Locating data outside the US is in no way a defense against US intelligence agencies. There are theoretically controls on domestic spying, and some possibility that Congress could make it illegal. They have a mandate to spy on foreign networks. If they haven't cracked your European email provider, then they're not doing what we pay and order them to do.

> If they haven't cracked your European email provider...

The difference is that European email providers are not cooperating, because they aren't obliged by your laws, whereas US companies are not only obliged to comply with requests, but they are also coerced to keep it a secret.

> ... then they're not doing what we pay and order them to do

That's a good thing to know, plus this is reason enough to pressure our governments and companies to not buy into US products or services. And in case you haven't noticed, this has tangible effects already, as fear of industrial espionage is spreading in big companies like fire and I've noticed this first hand in the German companies I'm in contact with. On the negative side, the US is positioned as the steward of the Internet and because your government fucked things up so badly, this is the perfect opportunity for the other countries to balkanize the Internet, to build firewalls, etc.

So I hope you're happy about how your taxes are being spent.

Re: Apple’s approach to privacy

#126

https://commons.wikimedia.org/wiki/File:Prism_slide_5.jpg https://commons.wikimedia.org/wiki/File:PRISM_Collection_Det...

Does anyone else have the suspicion that Prism was named prism because instead of getting companies to co-operate with the program they were siphoning off data like they did to google by tapping their fiber lines?

That would fit more in line with what we have heard about the tapping stations/rooms at AT&T/Verizon over the years.

I mean if they were really involved with back dooring the individual servers of google/apple/facebook that would involve hundreds of employees at each company to make that happen. Someone would have spoken out by now with some evidence to prove it.

To my knowledge that hasn't happened. Just this shitty looking powerpoint outlining when the data was starting to come in...

Re: Apple’s approach to privacy

#127

I was reading their guidelines for law enforcement requests: https://www.apple.com/privacy/docs/emeia_le_guidelines_final... Interesting note: "P. FaceTime FaceTime communications are end-to-end encrypted and Apple has no way to decrypt FaceTime data when it is in transit between devices. Apple cannot intercept FaceTime communications. Apple has FaceTime call invitation logs when a FaceTime call invitation is initiat…

iMessage is discussed in great detail in https://www.apple.com/business/docs/iOS_Security_Guide.pdf

Most relevant excerpt (page 34):

How iMessage sends and receives messages

Users start a new iMessage conversation by entering an address or name. If they enter a phone number or email address, the device contacts the IDS to retrieve the public keys and APNs addresses for all of the devices associated with the addressee. If the user enters a name, the device first utilizes the user’s Contacts app to gather the phone numbers and email addresses associated with that name, then gets the public keys and APNs addresses from the IDS.

The user’s outgoing message is individually encrypted for each of the receiver’s devices. The public RSA encryption keys of the receiving devices are retrieved from IDS. For each receiving device, the sending device generates a random 128-bit key and encrypts the message with it using AES in CTR mode. This per-message AES key is encrypted using RSA-OAEP to the public key of the receiving device. The combination of the encrypted message text and the encrypted message key is then hashed with SHA-1, and the hash is signed with ECDSA using the sending device’s private signing key. The resulting messages, one for each receiving device, consist of the encrypted message text, the encrypted message key, and the sender’s digital signature. They are then dispatched to the APNs for delivery. Metadata, such as the timestamp and APNs routing information, is not encrypted. Communication with APNs is encrypted using a forward-secret TLS channel.

Re: Apple’s approach to privacy

#128
post #121
post #84

Earlier quoted context omitted.

>Laws can and have been written that require companies to use weaker or broken encryption. Source? Example? I don't know an example of this. (At least in the US)

I would also consider the NSA meddling with Bitlocker and RSA behind the curtain to be conceptually equivalent. https://www.schneier.com/blog/archives/2015/03/can_the_nsa_b... http://gizmodo.com/nsa-paid-security-firm-10-million-bribe-t...

That's saying that agencies can break TPM chips and get Bitlocker keys. Which is obviously true, as even a private individual has done so to a TPM.

Re: Apple’s approach to privacy

#129

Earlier quoted context omitted.

Locating data outside the US is in no way a defense against US intelligence agencies. There are theoretically controls on domestic spying, and some possibility that Congress could make it illegal. They have a mandate to spy on foreign networks. If they haven't cracked your European email provider, then they're not doing what we pay and order them to do.

> If they haven't cracked your European email provider... The difference is that European email providers are not cooperating, because they aren't obliged by your laws, whereas US companies are not only obliged to comply with requests, but they are also coerced to keep it a secret. > ... then they're not doing what we pay and order them to do That's a good thing to know, plus this is reason enough to pressure our gov…

>European email providers are not cooperating

The NSA doesn't need cooperation. It can pwn sysadmins, plant covert operatives, and backdoor equipment in transit (including foreign-made equipment, so long as US intelligence can influence the shipping carrier, for example by recruiting employees or hacking ancient legacy software). If it can't, then it can pwn the other side of the conversation, or watch the SMTP in cleartext through a submarine-tapped undersea cable.

Disband the NSA and some other agency, some other country, will do the same thing.

You're bikeshedding. End-to-end encryption with HSMs and trusted execution environments everywhere, always. Verifiable, deterministic builds. A genuinely trustworthy, decentralized PKI. Better software engineering security practices, a professional barrier to entry, and an ethical system (ala the Bar or medical boards) with teeth that will reliably eviscerate people and companies who write and run irresponsibly sloppy code.

The cat's not going back in the bag because you avoid the US. Fighting over which service providers you send cleartext through, whose hard drives your unencrypted data sits on, who has the power to MITM you, is a waste of time and a distraction from the real challenge of developing and adopting security systems and practices that make doing what the NSA is doing actually difficult.

Re: Apple’s approach to privacy

#130

Earlier quoted context omitted.

It depends on what you are trusting them to do. The NSA's not going to spy on you less just because you're not in the US. If anything, they'd spy on you more.

Sure, but they'll have more trouble getting cooperation from non-US companies you're using.

They would no longer need to ask for cooperation. Personally, I'd call that less safe.

At least in theory, the NSA could allow a compliant US business to be secure. If the NSA could not get data from a foreign business the easy way, I'm sure they would get it the hard way.

Post reply on HN