Live data from Hacker News

Chinese authorities detain Apple employees suspected of selling customer data

hongkongfp.com

71–80 of 112 posts

Re: Chinese authorities detain Apple employees suspected of selling customer data

#71
post #66

So now after forcing Microsoft to have a Chinese version of Windows 10 without spyware, Blizzard forced to show the Overwatch loot boxes odds and this, we are living in a World where China, "Great Firewall" China is now the biggest advocate of users privacy. What is happening?

oh, they can just quit the Chinese market by following what google did almost 10 years ago. look at google's share price & revenues, surely you don't need the Chinese market to be successful.

fb is another good example.

Re: Chinese authorities detain Apple employees suspected of selling customer data

#72
post #41

Earlier quoted context omitted.

> Android, which is a privacy and security nightmare Only if your only source of information about Android is WWDC keynotes. But did Phil Schiller tell you about the Korean "malware" that was very quietly purged from App Store last week?

Only if your only source of information about Android is WWDC keynotes. Don't be silly. Google's own dashboard shows that the vast majority of devices are running old versions of Android with known security vulnerabilities: https://developer.android.com/about/dashboards/index.html Besides that, most likely >99% of the users are using a device with Google Play Services and other Google applications. It is no secret th…

So no issues then otherwise there would huge cry from android users like those from Windows users

Re: Chinese authorities detain Apple employees suspected of selling customer data

#73

Hoping comments can resist the urge to turn this into an apple bashing thread. Having someone purposefully steal your data from the inside doesn't mean you don't care about privacy. They likely won't reveal anything but I'm curious how they could get the info out of Apple systems. Most companies of Apple's size lock down work stations to the point of slowing down workers efficiency to keep customer data safe. Especia…

Interesting that you say that, because Google is constantly being bashed here for it's lack of privacy concerns (rightly so, IMO). When Apple makes the similar mistakes, I feel that they should also be bashed. I don't think of them as an "evil" company, like Google, but they do seem incompetent, or maybe more fairly: focused on the wrong things.

They've touted before that they are the company to use if you want your data to remain private and secure, but continue to act in direct violation of that. This seems highly problematic to me, and, IMO, they should be raked over the coals for this.

Re: Chinese authorities detain Apple employees suspected of selling customer data

#75

Is Apple storing everyone's data in China / do these 'bad apples' in China have access to every iCloud customers or is it just a local Chinese concern?

It does not make economical sense to store data in China

Re: Chinese authorities detain Apple employees suspected of selling customer data

#76

Don't all large companies have auto auditing of access to customer data?

lol

Sorry, but having worked for 3 large companies (not apple, or Google, or any in the same field), the auditing is purely just for show. They claim it publicly, but very little is actually done to ensure the safety of that data. When I started as an entry-level tech at 2 of them, I was given direct access after just a couple of days.

I'm sure there are plenty that do treat their customer data securely, but in my limited experience, that's not many of them.

Re: Chinese authorities detain Apple employees suspected of selling customer data

#77
post #33
post #24

Apple does not allow your iOS iCloud data to be encrypted in a manner where Apple cannot access it. As is alluded to in this article. Privacy advocates and privacy caring IT specialists have repeatedly asked Apple to offer such an option, but so far Apple has decided that regular people would turn such an option on, forget their password, then ask Apple for help and would be unhappy with their brand experience if App…

Given the way iCloud security works I'm not sure iCloud was breached at all [1]. Other reports seem to indicate that it was employees at Apple stores and third party resellers who had access to names, phone numbers and Apple IDs [2]. Presumably they would try to phish them later on. [1] https://youtu.be/BLGFriOKz6U?t=32m35s [2] http://www.foxbusiness.com/features/2017/06/07/chinas-new-cy...

It's almost as if people commenting here haven't even watched Ivan Krstić's Black Hat video...

Re: Chinese authorities detain Apple employees suspected of selling customer data

#78
post #3

Oh snap. And Apple has been touting itself as the champion of privacy in comparison with Google, Facebook and Microsoft... This doesn't look good for them

It's not Apple's policy to sell information. This is employees engaging in criminal behavior. Still not good for Apple, but it's correctable (firing and pressing charges as appropriate; institute stronger internal policies on both hiring and information access). Facebook and Google can't stop selling our information without going out of business (or a major pivot).

It kind of doesn't matter though. They are still the cause of a bunch of data being leaked through their actions. They should be held accountable for it whether it was intentional or not.

Your point is very valid, but the crime being committed against their customers is also very valid.

Re: Chinese authorities detain Apple employees suspected of selling customer data

#79

> Reporters successfully obtained a trove of material on one colleague — including flight history, hotel checkouts and property holdings — in exchange for a payment of 700 yuan (US$100). So it's not just email addresses / metadata from iCloud. This implies that 1) at least some iCloud data is stored unencrypted at rest, and 2) employees can query this data using internal tools. This seems pretty bad.

This does not necessarily imply that the data is unencrypted at rest. The query tool or the query backend could handle decryption seamlessly. S3 offers similar encryption at rest that is invisible to authorized requesters. If the story was that someone raided an Apple data center, stole hard drives, and leaked customer data, then we would have reason to assume that.

Always wondered that about encryption at rest as a feature in cloud services. The key is stored in the same system somewhere (or your app wouldn't function). A rogue employee can find the key if they want. So what is the practical benefit?

Re: Chinese authorities detain Apple employees suspected of selling customer data

#80
post #24

Apple does not allow your iOS iCloud data to be encrypted in a manner where Apple cannot access it. As is alluded to in this article. Privacy advocates and privacy caring IT specialists have repeatedly asked Apple to offer such an option, but so far Apple has decided that regular people would turn such an option on, forget their password, then ask Apple for help and would be unhappy with their brand experience if App…

>> Privacy advocates and privacy caring IT specialists have repeatedly asked Apple to offer such an option, but so far Apple has decided that regular people would turn such an option on, forget their password, then ask Apple for help and would be unhappy with their brand experience if Apple could not help them out. Were I an iCloud user, I would pay big $$$ for such a feature. But... they do have a point, and anyone…

>they do have a point, and anyone who's helped their friends and relatives with IT issues can confirm that.

I think it's a pretty common state of affairs when dealing with complaints about Apple's choices. It's not that they're (necessarily) malicious, or that they don't care about security etc. It's prioritising the user experience of an average user over the concerns of a relative minority.

I, personally, hope they never stop thinking about their products in that light.

Post reply on HN