Live data from Hacker News

Chinese authorities detain Apple employees suspected of selling customer data

hongkongfp.com

91–100 of 112 posts

Re: Chinese authorities detain Apple employees suspected of selling customer data

#91
Apple's focus on privacy has always been a splinter in the eye of Chinese authorities.

I strongly believe that this is an excuse Chinese authorities had been looking for that will use to pressure Apple in China at the same time create the illusion to the general public to not trust Apple.

I find it especially suspecious that the Chinese media put so much emphasis the privacy concern of this event and in modern Chinese culture, privacy is much less regarded as compared to western countries.

Anyone remember the propaganda while Google was being driven out of China? Straight up false info about Google were broadcasted on CCTV-1, the prime time national channel. A lot of my friends in China became very patriotic and viewed Google as some sort of evil corporation trying to undermine Chinese culture.

Re: Chinese authorities detain Apple employees suspected of selling customer data

#92

Earlier quoted context omitted.

I emailed security@apple.com and never received a response. Generally, when I need to get the attention of big tech corporations I talk to a friend who works there. Unfortunately, I don't really know anyone who works at Apple.

You don't have any contact details in your profile; check mine and send me any details you can. I'll ping the appropriate people.

Also, we need your ss# and your keys

Re: Chinese authorities detain Apple employees suspected of selling customer data

#93
post #24

Apple does not allow your iOS iCloud data to be encrypted in a manner where Apple cannot access it. As is alluded to in this article. Privacy advocates and privacy caring IT specialists have repeatedly asked Apple to offer such an option, but so far Apple has decided that regular people would turn such an option on, forget their password, then ask Apple for help and would be unhappy with their brand experience if App…

Correct me if I'm wrong but isn't this the same thing as turning iCloud backups off and doing local encrypted backups instead? It seems like a reasonable choice to me, if you don't want to store in iCloud you can keep it locally with a different encryption model.

Yes but only iCloud backups can happen automatically and wirelessly every night. For local backups you need to attach the phone to your laptop using your usb cable and click "back up" in iTunes manually every time.

Re: Chinese authorities detain Apple employees suspected of selling customer data

#94
post #91

Apple's focus on privacy has always been a splinter in the eye of Chinese authorities. I strongly believe that this is an excuse Chinese authorities had been looking for that will use to pressure Apple in China at the same time create the illusion to the general public to not trust Apple. I find it especially suspecious that the Chinese media put so much emphasis the privacy concern of this event and in modern Chines…

> Apple's focus on privacy has always been a splinter in the eye of Chinese authorities.

So was UK authorities, US authorities, and lots of other authorities, there is no need to single out China in this case.

> I strongly believe that this is an excuse Chinese authorities had been looking for that will use to pressure Apple in China at the same time create the illusion to the general public to not trust Apple.

Yes, it could be the excuse for Chinese authorities, but this case could have happened anywhere else in the world given the way Apple stores information, and similar incidents have happened before for other companies like mentioned in other comments. So I don't see a strong evidence that this particular incident is related to some ulterior motive of Chinese government.

> I find it especially suspecious that the Chinese media put so much emphasis the privacy concern of this event and in modern Chinese culture, privacy is much less regarded as compared to western countries.

The entire incident is about privacy issues, what else do you expect the media to talk about? New iPhone colors?

> Anyone remember the propaganda while Google was being driven out of China? Straight up false info about Google were broadcasted on CCTV-1, the prime time national channel. A lot of my friends in China became very patriotic and viewed Google as some sort of evil corporation trying to undermine Chinese culture.

As far as I remember, Google did not want to comply with Chinese regulations on censorship, so it was not allowed to operate in China, simple as that. I don't think people had that bad of an impression about Google, more like they felt bad losing a good search engine or simple just don't really care.

Re: Chinese authorities detain Apple employees suspected of selling customer data

#95

Earlier quoted context omitted.

This does not necessarily imply that the data is unencrypted at rest. The query tool or the query backend could handle decryption seamlessly. S3 offers similar encryption at rest that is invisible to authorized requesters. If the story was that someone raided an Apple data center, stole hard drives, and leaked customer data, then we would have reason to assume that.

Always wondered that about encryption at rest as a feature in cloud services. The key is stored in the same system somewhere (or your app wouldn't function). A rogue employee can find the key if they want. So what is the practical benefit?

AFAIK, encryption at rest protects against a very specific threat. That is, someone goes into the data center, turns off your server, and steals the hard drive.

Re: Chinese authorities detain Apple employees suspected of selling customer data

#96
post #33
post #24

Apple does not allow your iOS iCloud data to be encrypted in a manner where Apple cannot access it. As is alluded to in this article. Privacy advocates and privacy caring IT specialists have repeatedly asked Apple to offer such an option, but so far Apple has decided that regular people would turn such an option on, forget their password, then ask Apple for help and would be unhappy with their brand experience if App…

Given the way iCloud security works I'm not sure iCloud was breached at all [1]. Other reports seem to indicate that it was employees at Apple stores and third party resellers who had access to names, phone numbers and Apple IDs [2]. Presumably they would try to phish them later on. [1] https://youtu.be/BLGFriOKz6U?t=32m35s [2] http://www.foxbusiness.com/features/2017/06/07/chinas-new-cy...

Given that with 2FA enabled Apple can't even reset your password (which has caught the tech press out before https://thenextweb.com/apple/2014/12/08/lost-apple-id-learnt...) I agree that iCloud itself is unlikely the source.

It's probably a marketing or support database that contains basic data. Annoying but not a serious breach.

Re: Chinese authorities detain Apple employees suspected of selling customer data

#97
i have seen hn commenters praise apple for "taking a stand on privacy". but how can anyone believe that when they collect so much personal data about the people who purchase their hardware? the old apple did not do this.

1. collecting data on users for months and years after purchase, 2. storing it electronically on remote computers, 3. some connected to the internet. yes, this surely points to a company is concerned about user privacy.

if something goes wrong can you sue apple?

we should expect every hardware vendor from laptop mfrs to the rpi foundation to be silently collecting data from their customers long after the merchandise is purchased. they need to do this, because...

wtf?

1. collecting data on consumers and 2. storing it online.

#1 is incompatible with a pro-consumer stance on user privacy.

#2 is a guarantee that others besides the company are going to get that data, whether the consumer is told about the breach or not.

Re: Chinese authorities detain Apple employees suspected of selling customer data

#99

Don't all large companies have auto auditing of access to customer data?

This is common for large law firms. My employer has software that enforces ethical requirements and monitors users to detect suspicious activity.

Re: Chinese authorities detain Apple employees suspected of selling customer data

#100

Earlier quoted context omitted.

This does not necessarily imply that the data is unencrypted at rest. The query tool or the query backend could handle decryption seamlessly. S3 offers similar encryption at rest that is invisible to authorized requesters. If the story was that someone raided an Apple data center, stole hard drives, and leaked customer data, then we would have reason to assume that.

I assumed "encrypted at rest" to mean encrypted with the user's passcode, meaning it could only be decrypted from a properly authorized user session, not some internal apple tool.

> Privacy advocates and privacy caring IT specialists have repeatedly asked Apple to offer such an option, but so far Apple has decided that regular people would turn such an option on, forget their password, then ask Apple for help and would be unhappy with their brand experience if Apple could not help them out.

From Darthy's comment 30 minutes ago https://news.ycombinator.com/item?id=14513803

Post reply on HN