Live data from Hacker News

Chinese authorities detain Apple employees suspected of selling customer data

hongkongfp.com

61–70 of 112 posts

Re: Chinese authorities detain Apple employees suspected of selling customer data

#61
post #24

Apple does not allow your iOS iCloud data to be encrypted in a manner where Apple cannot access it. As is alluded to in this article. Privacy advocates and privacy caring IT specialists have repeatedly asked Apple to offer such an option, but so far Apple has decided that regular people would turn such an option on, forget their password, then ask Apple for help and would be unhappy with their brand experience if App…

Answers to likely responses: "just use a different cloud service": on iOS, for cloud backups, there are no alternatives: it's iCloud or nothing. Moreover, in the case of Apple this could actually be productive. They have been pushing the privacy angle. Let's not forget that this is the company that pushed out end-to-end encrypted chats to tens (hundreds?) of millions of users before Whatsapp did it. If Apple offered…

Genuinely trying to get an understanding of the pros and cons here, but is there any guarantee that this, or any other, data theft ring used iCloud? I mean, let's say I have an iCloud and it is encrypted in a completely secure fashion such that even Apple cannot access it. Well couldn't this ring have just collected my phone number, Apple ID etc etc from some other Apple database?

Maybe I'm misunderstanding the threat here, but it seems to me that this is not going to be fixed by simply encrypting iCloud. Sure, that would be part of a comprehensive response, but the main problem seems to be that these people had access to internal Apple databases. To my mind, "internal" means everything from retail POS data to iTunes. I guess I'm trying to understand why encrypting iCloud would prevent a ring of internal Apple employees from gathering a person's information and selling it?

And, to be frank, it's concerning because it's not just Apple. What stops a group of internal employees of any company from gathering a person's information and selling it?

What are needed are strong guarantees about data security internal to these companies. My background is in health care technology, so the analogy I would make is HIPAA. But we need HIPAA for everything instead of just for healthcare information. Right now if employees of enterprises outside healthcare access a person's information and they don't sell it, they're just checking on a friend, there is no liability for that. Under HIPAA you're fired at a minimum. That's what we need.

Re: Chinese authorities detain Apple employees suspected of selling customer data

#62
post #52
post #41

Earlier quoted context omitted.

> Android, which is a privacy and security nightmare Only if your only source of information about Android is WWDC keynotes. But did Phil Schiller tell you about the Korean "malware" that was very quietly purged from App Store last week?

I suspect most privacy problems come down to the apps on the users device for both platforms, but in terms of security Android is worse overall because of the abysmal rate of updates, and lack of widespread backing store encryption. That leaves a lot of Android devices open to shady apps and data loss after theft. Both platforms can always do better of course, and should learn from each other. But to pretend device s…

> lack of widespread backing store encryption

I am not sure what you mean.

Re: Chinese authorities detain Apple employees suspected of selling customer data

#63

Earlier quoted context omitted.

Just use different OS then

Like? On mobile, the only realistic alternative is Android, which is a privacy and security nightmare. On general purpose computers, Linux is better from the perspective of privacy. But for large parts of the general population, Windows is the only realistic alternative. And we know how important privacy is to Microsoft these days :(.

I recently discovered CopperheadOS [0], and I've been playing around with it on my old Nexus 5X. It's very barebones, but you can pick up good open alternatives to most closed software on F-droid. I'm still not ready to drop Google services completely, but it looks promising.

If you're willing to pay the premium, they sell the Pixel and Pixel XL with CopperheadOS loaded.

[0] https://copperhead.co/android/

Re: Chinese authorities detain Apple employees suspected of selling customer data

#64

Earlier quoted context omitted.

Just use different OS then

Like? On mobile, the only realistic alternative is Android, which is a privacy and security nightmare. On general purpose computers, Linux is better from the perspective of privacy. But for large parts of the general population, Windows is the only realistic alternative. And we know how important privacy is to Microsoft these days :(.

Yes, I was hinting towards Linux. If you worry about security then the answer is pretty clear - don't store anything valuable on mobile devices.

Re: Chinese authorities detain Apple employees suspected of selling customer data

#65

> Reporters successfully obtained a trove of material on one colleague — including flight history, hotel checkouts and property holdings — in exchange for a payment of 700 yuan (US$100). So it's not just email addresses / metadata from iCloud. This implies that 1) at least some iCloud data is stored unencrypted at rest, and 2) employees can query this data using internal tools. This seems pretty bad.

I have read a Chinese version of this news report in which none of the above is mentioned. I think this sentence refers to another privacy incident.

Re: Chinese authorities detain Apple employees suspected of selling customer data

#66
So now after forcing Microsoft to have a Chinese version of Windows 10 without spyware, Blizzard forced to show the Overwatch loot boxes odds and this, we are living in a World where China, "Great Firewall" China is now the biggest advocate of users privacy.

What is happening?

Re: Chinese authorities detain Apple employees suspected of selling customer data

#67
post #47
post #41

Earlier quoted context omitted.

> Android, which is a privacy and security nightmare Only if your only source of information about Android is WWDC keynotes. But did Phil Schiller tell you about the Korean "malware" that was very quietly purged from App Store last week?

How many of the Android devices are using the latest version and what's the option for the rest of them, excluding rooting? There are many advantages of Android, but this is not one of them.

> How many of the Android devices are using the latest version

This comes up every time security discussed. But it is not as black as white as you think:

1. Security patches are separate from OS upgrades [1]. Many vendors incorporate security patches without upgrading the OS.

2. Many core Android components are upgraded via the store.

3. Google scans and remove bad apps from your device no matter Android version [3]

--

[1] https://source.android.com/security/bulletin/2017-06-01

[2] https://www.howtogeek.com/179638/not-getting-android-os-upda...

[3] https://support.google.com/accounts/answer/2812853?hl=en

Re: Chinese authorities detain Apple employees suspected of selling customer data

#69
post #24

Apple does not allow your iOS iCloud data to be encrypted in a manner where Apple cannot access it. As is alluded to in this article. Privacy advocates and privacy caring IT specialists have repeatedly asked Apple to offer such an option, but so far Apple has decided that regular people would turn such an option on, forget their password, then ask Apple for help and would be unhappy with their brand experience if App…

There are other backup backup solutions. You can backup your camera roll to a Synology device in the background: https://www.synology.com/en-us/knowledgebase/Mobile/help/DSp...

Unfortunately, this still requires location services. I really wish Apple would allow true background photo sync.

From your link:

To upload photos in the background: iOS apps cannot perform background tasks for more than 3 to 10 minutes. Using geofences to add locations will trigger and resume upload tasks in the background for another 3 to 10 minutes whenever you leave or reenter the defined areas. Tap > Geofence > Create to add geofences.

Re: Chinese authorities detain Apple employees suspected of selling customer data

#70
post #66

So now after forcing Microsoft to have a Chinese version of Windows 10 without spyware, Blizzard forced to show the Overwatch loot boxes odds and this, we are living in a World where China, "Great Firewall" China is now the biggest advocate of users privacy. What is happening?

Small spiders meet a bigger spider.
Post reply on HN