Live data from Hacker News

Apple’s approach to privacy

apple.com

151–160 of 172 posts

Re: Apple’s approach to privacy

#151

Earlier quoted context omitted.

Locating data outside the US is in no way a defense against US intelligence agencies. There are theoretically controls on domestic spying, and some possibility that Congress could make it illegal. They have a mandate to spy on foreign networks. If they haven't cracked your European email provider, then they're not doing what we pay and order them to do.

> If they haven't cracked your European email provider... The difference is that European email providers are not cooperating, because they aren't obliged by your laws, whereas US companies are not only obliged to comply with requests, but they are also coerced to keep it a secret. > ... then they're not doing what we pay and order them to do That's a good thing to know, plus this is reason enough to pressure our gov…

The US does not worry about Europe because for all their strut and bellow concrete action is nonexistent.

Re: Apple’s approach to privacy

#152
post #86

I was reading their guidelines for law enforcement requests: https://www.apple.com/privacy/docs/emeia_le_guidelines_final... Interesting note: "P. FaceTime FaceTime communications are end-to-end encrypted and Apple has no way to decrypt FaceTime data when it is in transit between devices. Apple cannot intercept FaceTime communications. Apple has FaceTime call invitation logs when a FaceTime call invitation is initiat…

Knowing that most phone lines are essentially considered tapped by the NSA/FBI... So is privacy a good reason to use FaceTime Audio over say, a standard voice call?

I'd say yes, it's a lot harder to tap into than a cell phone call.

Re: Apple’s approach to privacy

#153

Earlier quoted context omitted.

Police use parallel construction when they don't want to reveal their methods. I seriously doubt law enforcement would engage in parallel construction if it had access to iMessage but Apple asked it to.

> I seriously doubt law enforcement would engage in parallel construction if it had access to iMessage but Apple asked it to. Why? They've been using parallel construction to avoid violating NDAs and giving up their capabilities for years. http://www.wired.com/2014/03/harris-stingray-nda/

That's exactly the case I was thinking about with my comment

1) Police don't care that APPLE doesn't want to reveal its methods, and 2) Unlike the Stingray, it wouldn't be illegal for them to use iMessage evidence in court if Apple provided it to them (especially with the use of a warrant!)

Re: Apple’s approach to privacy

#154
post #32
post #4

Earlier quoted context omitted.

Source?

Stuff like gotofail took a while to get patched (weeks?), and things like https://github.com/kpwn/tpwn has been around for a while which is still not patched in any public, non-beta release of OSX.

While it's definitely plausible, and probably likely, I was looking for a source to the specific statement that Apple is "voluntarily giving the NSA zero-day vulnerabilities months before they get fixed". Are they giving them to the NSA? Is this why they're holding out on fixing them? Do we have evidence that this is their intention?

Re: Apple’s approach to privacy

#155

Earlier quoted context omitted.

> to explicitly lie about it. Maybe I'm dense or naive, but I don't think there's any precedent for that. A gag order is one thing (and there are certainly places for it), but forcing someone to lie would hopefully violate the First Amendment.

> Maybe I'm dense or naive, but I don't think there's any precedent for that. It's well know about. https://en.wikipedia.org/wiki/National_security_letter https://www.eff.org/deeplinks/2014/04/warrant-canary-faq

It's strange that chainsaw10 is being downvoted for their comment. From the second link above, "Have courts upheld compelled false speech? No, and the cases on compelled speech have tended to rely on truth as a minimum requirement." That sounds more like there is not precedent to force people to tell explicit lies.

Re: Apple’s approach to privacy

#156

To my understanding, an NSL could mean "give me everything you have". And the NSLs have no disclosed accounts linked to them. Edit: Why the downvote? If my understanding is false, please indicate so.

Perhaps you could post the source for your understanding?

Re: Apple’s approach to privacy

#157

Earlier quoted context omitted.

> I seriously doubt law enforcement would engage in parallel construction if it had access to iMessage but Apple asked it to. Why? They've been using parallel construction to avoid violating NDAs and giving up their capabilities for years. http://www.wired.com/2014/03/harris-stingray-nda/

That's exactly the case I was thinking about with my comment 1) Police don't care that APPLE doesn't want to reveal its methods, and 2) Unlike the Stingray, it wouldn't be illegal for them to use iMessage evidence in court if Apple provided it to them (especially with the use of a warrant!)

I think it's more about the police not wanting the public to know that iMessage is owned; having trusted-but-broken communication services is a serious advantage for them.

Re: Apple’s approach to privacy

#159

Apple is in a good position in the market to do this, but it is just really hard to trust any US company. They say they will never give anyone access to their servers but how can they make that promise when they don't make the laws? As an aside I am finding it really difficult to delete my iCloud account, in fact it seems that is impossible.

Setting aside the fact that US intelligence agencies can and will subvert foreign servers with impunity, foreign intelligence agencies operate with less oversight within their own borders than the US agencies do within its borders AND they tend to cooperate with US agencies (or, worse, Russia's or China's).

Re: Apple’s approach to privacy

#160

https://commons.wikimedia.org/wiki/File:Prism_slide_5.jpg https://commons.wikimedia.org/wiki/File:PRISM_Collection_Det...

What describes the obvious discrepancy between what Tim Cook wrote and signed his name to, and the content on those slides?

> I want to be absolutely clear that we have never worked with any government agency from any country to create a backdoor in any of our products or services. We have also never allowed access to our servers. And we never will.

The slides imply Apple gives access to data on customers. Tim Cook says Apple does not give access to their servers. Is that really the point you're trying to make?

That's just semantics and weasel words, nothing more.

Post reply on HN