Live data from Hacker News

Chinese authorities detain Apple employees suspected of selling customer data

hongkongfp.com

41–50 of 112 posts

Re: Chinese authorities detain Apple employees suspected of selling customer data

#41

Earlier quoted context omitted.

Just use different OS then

Like? On mobile, the only realistic alternative is Android, which is a privacy and security nightmare. On general purpose computers, Linux is better from the perspective of privacy. But for large parts of the general population, Windows is the only realistic alternative. And we know how important privacy is to Microsoft these days :(.

> Android, which is a privacy and security nightmare

Only if your only source of information about Android is WWDC keynotes.

But did Phil Schiller tell you about the Korean "malware" that was very quietly purged from App Store last week?

Re: Chinese authorities detain Apple employees suspected of selling customer data

#42

> Reporters successfully obtained a trove of material on one colleague — including flight history, hotel checkouts and property holdings — in exchange for a payment of 700 yuan (US$100). So it's not just email addresses / metadata from iCloud. This implies that 1) at least some iCloud data is stored unencrypted at rest, and 2) employees can query this data using internal tools. This seems pretty bad.

This does not necessarily imply that the data is unencrypted at rest. The query tool or the query backend could handle decryption seamlessly. S3 offers similar encryption at rest that is invisible to authorized requesters. If the story was that someone raided an Apple data center, stole hard drives, and leaked customer data, then we would have reason to assume that.

I assumed "encrypted at rest" to mean encrypted with the user's passcode, meaning it could only be decrypted from a properly authorized user session, not some internal apple tool.

Re: Chinese authorities detain Apple employees suspected of selling customer data

#43
post #18

Earlier quoted context omitted.

Caring about peoples privacy, and technological negligence that results in that privacy being impinged upon, are in fact the same issue.

It's not technological negligence to allow customers the means to access their own data if they forget their password. it's common sense.

It's technological negligence if you set out to protect customers privacy, but your employees decide to steal it anyway, because they can.

Re: Chinese authorities detain Apple employees suspected of selling customer data

#44
post #40

This is always the argument that makes my friends and family call be paranoid in data privacy discussions: "Even if the company has good intentions when they collect your data, there's no telling who else might end up with access to it in the future." Obviously this is bad overall, but at least now I can point to a specific example of this happening.

The example I previously used was this old case: Google Engineer Allegedly Fired For Accessing Private User Information To Stalk Teens Source: http://www.businessinsider.com/google-engineer-stalked-teens...

and microsoft accessed a hotmail account to investigate a leak https://arstechnica.com/tech-policy/2014/03/microsoft-will-n....

One perspective is that every company gets to screw this up once and then has to get serious about privacy.

But it's possible this is happening all the time, victims don't know their saas vendor was complicit in releasing their information. If the companies ever catch the perps, they're quietly fired in exchange for a non-disclosure agreement that serves the interests of all parties (except the consumer).

Re: Chinese authorities detain Apple employees suspected of selling customer data

#45
post #26

Can confirm. I've had someone contact me on snapchat and show me screenshots of Apple's internal tools and offer to run queries for $$$. He was willing turn off 2FA, change the email, and reset the password (thus, giving me access) for $$$$. He told me that he texts a friend who calls and pretends to be the customer in question, and texts him all the verification questions he has to ask as part of SOP. Many AppleCare…

Did you report that?

I emailed security@apple.com and never received a response.

Generally, when I need to get the attention of big tech corporations I talk to a friend who works there. Unfortunately, I don't really know anyone who works at Apple.

Re: Chinese authorities detain Apple employees suspected of selling customer data

#46
post #24

Apple does not allow your iOS iCloud data to be encrypted in a manner where Apple cannot access it. As is alluded to in this article. Privacy advocates and privacy caring IT specialists have repeatedly asked Apple to offer such an option, but so far Apple has decided that regular people would turn such an option on, forget their password, then ask Apple for help and would be unhappy with their brand experience if App…

"Answers to likely responses: "just use a different cloud service": on iOS, for cloud backups, there are no alternatives: it's iCloud or nothing."

That makes me unhappy with the brand experience.

Re: Chinese authorities detain Apple employees suspected of selling customer data

#47
post #41

Earlier quoted context omitted.

Like? On mobile, the only realistic alternative is Android, which is a privacy and security nightmare. On general purpose computers, Linux is better from the perspective of privacy. But for large parts of the general population, Windows is the only realistic alternative. And we know how important privacy is to Microsoft these days :(.

> Android, which is a privacy and security nightmare Only if your only source of information about Android is WWDC keynotes. But did Phil Schiller tell you about the Korean "malware" that was very quietly purged from App Store last week?

How many of the Android devices are using the latest version and what's the option for the rest of them, excluding rooting? There are many advantages of Android, but this is not one of them.

Re: Chinese authorities detain Apple employees suspected of selling customer data

#48
post #24

Apple does not allow your iOS iCloud data to be encrypted in a manner where Apple cannot access it. As is alluded to in this article. Privacy advocates and privacy caring IT specialists have repeatedly asked Apple to offer such an option, but so far Apple has decided that regular people would turn such an option on, forget their password, then ask Apple for help and would be unhappy with their brand experience if App…

There are other backup backup solutions. You can backup your camera roll to a Synology device in the background: https://www.synology.com/en-us/knowledgebase/Mobile/help/DSp...

Re: Chinese authorities detain Apple employees suspected of selling customer data

#49
post #24

Apple does not allow your iOS iCloud data to be encrypted in a manner where Apple cannot access it. As is alluded to in this article. Privacy advocates and privacy caring IT specialists have repeatedly asked Apple to offer such an option, but so far Apple has decided that regular people would turn such an option on, forget their password, then ask Apple for help and would be unhappy with their brand experience if App…

>> Privacy advocates and privacy caring IT specialists have repeatedly asked Apple to offer such an option, but so far Apple has decided that regular people would turn such an option on, forget their password, then ask Apple for help and would be unhappy with their brand experience if Apple could not help them out.

Were I an iCloud user, I would pay big $$$ for such a feature. But... they do have a point, and anyone who's helped their friends and relatives with IT issues can confirm that.

Re: Chinese authorities detain Apple employees suspected of selling customer data

#50
post #37

Hoping comments can resist the urge to turn this into an apple bashing thread. Having someone purposefully steal your data from the inside doesn't mean you don't care about privacy. They likely won't reveal anything but I'm curious how they could get the info out of Apple systems. Most companies of Apple's size lock down work stations to the point of slowing down workers efficiency to keep customer data safe. Especia…

Hum. No one is giving some slack to a bank for having rogue employees. Part of the job of being a large organisation is ensuring your employees do not misbehave. In this case at the very least ensure they have minimum access to users data.

Or setting up the technology so nobody at apple can even access the unencrypted data. Much more effective than policies that you expect people to follow.

I work at a fairly security conscious company, and the only data I can't access is that encrypted at the consumer's end.

Post reply on HN