Live data from Hacker News

Chinese authorities detain Apple employees suspected of selling customer data

hongkongfp.com

31–40 of 112 posts

Re: Chinese authorities detain Apple employees suspected of selling customer data

#31
post #24

Apple does not allow your iOS iCloud data to be encrypted in a manner where Apple cannot access it. As is alluded to in this article. Privacy advocates and privacy caring IT specialists have repeatedly asked Apple to offer such an option, but so far Apple has decided that regular people would turn such an option on, forget their password, then ask Apple for help and would be unhappy with their brand experience if App…

Just use different OS then

Like?

On mobile, the only realistic alternative is Android, which is a privacy and security nightmare.

On general purpose computers, Linux is better from the perspective of privacy. But for large parts of the general population, Windows is the only realistic alternative. And we know how important privacy is to Microsoft these days :(.

Re: Chinese authorities detain Apple employees suspected of selling customer data

#32

> Reporters successfully obtained a trove of material on one colleague — including flight history, hotel checkouts and property holdings — in exchange for a payment of 700 yuan (US$100). So it's not just email addresses / metadata from iCloud. This implies that 1) at least some iCloud data is stored unencrypted at rest, and 2) employees can query this data using internal tools. This seems pretty bad.

This does not necessarily imply that the data is unencrypted at rest. The query tool or the query backend could handle decryption seamlessly. S3 offers similar encryption at rest that is invisible to authorized requesters. If the story was that someone raided an Apple data center, stole hard drives, and leaked customer data, then we would have reason to assume that.

Re: Chinese authorities detain Apple employees suspected of selling customer data

#33
post #24

Apple does not allow your iOS iCloud data to be encrypted in a manner where Apple cannot access it. As is alluded to in this article. Privacy advocates and privacy caring IT specialists have repeatedly asked Apple to offer such an option, but so far Apple has decided that regular people would turn such an option on, forget their password, then ask Apple for help and would be unhappy with their brand experience if App…

Given the way iCloud security works I'm not sure iCloud was breached at all [1]. Other reports seem to indicate that it was employees at Apple stores and third party resellers who had access to names, phone numbers and Apple IDs [2]. Presumably they would try to phish them later on.

[1] https://youtu.be/BLGFriOKz6U?t=32m35s

[2] http://www.foxbusiness.com/features/2017/06/07/chinas-new-cy...

Re: Chinese authorities detain Apple employees suspected of selling customer data

#34
post #18

Earlier quoted context omitted.

Being the victim of criminal behaviour, and not caring about other people's privacy are two very different things.

Caring about peoples privacy, and technological negligence that results in that privacy being impinged upon, are in fact the same issue.

It's not technological negligence to allow customers the means to access their own data if they forget their password. it's common sense.

Re: Chinese authorities detain Apple employees suspected of selling customer data

#35
This being the Chinese government it could also mean they try to discredit a strong foreign platform that is really hard to control in terms of privacy and security. No doubt Apple is giving all governments headaches not only the US.

If people believe they still can be hacked or tracked while using Apple equipment less people might be tempted to use it.

Not telling the sale of data didn't ever happen. I think if it's true that Apple should one up their security even more.

Re: Chinese authorities detain Apple employees suspected of selling customer data

#36
post #24

Apple does not allow your iOS iCloud data to be encrypted in a manner where Apple cannot access it. As is alluded to in this article. Privacy advocates and privacy caring IT specialists have repeatedly asked Apple to offer such an option, but so far Apple has decided that regular people would turn such an option on, forget their password, then ask Apple for help and would be unhappy with their brand experience if App…

Answers to likely responses: "just use a different cloud service": on iOS, for cloud backups, there are no alternatives: it's iCloud or nothing. Moreover, in the case of Apple this could actually be productive. They have been pushing the privacy angle. Let's not forget that this is the company that pushed out end-to-end encrypted chats to tens (hundreds?) of millions of users before Whatsapp did it. If Apple offered…

Apple could utilize their newer devices' capabilities of finger print recognition. If you don't have a device capable of this, you don't get encryption. Sound very Apple™.

Re: Chinese authorities detain Apple employees suspected of selling customer data

#37

Hoping comments can resist the urge to turn this into an apple bashing thread. Having someone purposefully steal your data from the inside doesn't mean you don't care about privacy. They likely won't reveal anything but I'm curious how they could get the info out of Apple systems. Most companies of Apple's size lock down work stations to the point of slowing down workers efficiency to keep customer data safe. Especia…

Hum. No one is giving some slack to a bank for having rogue employees. Part of the job of being a large organisation is ensuring your employees do not misbehave. In this case at the very least ensure they have minimum access to users data.

Re: Chinese authorities detain Apple employees suspected of selling customer data

#38

> Reporters successfully obtained a trove of material on one colleague — including flight history, hotel checkouts and property holdings — in exchange for a payment of 700 yuan (US$100). So it's not just email addresses / metadata from iCloud. This implies that 1) at least some iCloud data is stored unencrypted at rest, and 2) employees can query this data using internal tools. This seems pretty bad.

The preceding sentence seems to indicate that is referring to black market information from government databases, which is its own problem, but isn't related to iCloud.

Re: Chinese authorities detain Apple employees suspected of selling customer data

#40

This is always the argument that makes my friends and family call be paranoid in data privacy discussions: "Even if the company has good intentions when they collect your data, there's no telling who else might end up with access to it in the future." Obviously this is bad overall, but at least now I can point to a specific example of this happening.

The example I previously used was this old case:

Google Engineer Allegedly Fired For Accessing Private User Information To Stalk Teens

Source: http://www.businessinsider.com/google-engineer-stalked-teens...

Post reply on HN