Privacy? Who needs it, amirite? I mean, I'm not up to anything illegal, and I don't actually care about people seeing my stuff, BUT... the concept as a whole of "government should have access to everything all the time, regardless of reasoning" does not sit well with me.
Apple dropped plan for encrypting backups after FBI complained
51–60 of 734 posts
Re: Apple dropped plan for encrypting backups after FBI complained
#52Easy fix: back up your iPhone locally on your computer instead of using iCloud: https://support.apple.com/en-us/HT203977#computer The ambiguous position on true end-to-end encryption shows once again that Apple is in for the marketing (both to consumers—predatory and dangerous, and to engineering talent—dishonest). Same hypocrisy as on the China issue. Not that there is an easy solution when you are one of the bigges…
Second step: Delete old backups https://support.apple.com/en-us/HT204247#backups
Re: Apple dropped plan for encrypting backups after FBI complained
#53Apple already conceded to hosting Chinese iCloud data on Chinese servers, and that news came out about 2 years ago... which is also the timeframe reported for this decision to forego end-to-end encryption of iCloud backups.
I'm guessing here, but I think it's safe to assume that China was not going to permit such encryption (for the same reason they insist on hosting the data) and thus to provide it for the U.S., Apple would have had to fork iCloud. Add in the political risk in the U.S. and you have a recipe for "maybe not."
Re: Apple dropped plan for encrypting backups after FBI complained
#54Privacy? Who needs it, amirite? I mean, I'm not up to anything illegal, and I don't actually care about people seeing my stuff, BUT... the concept as a whole of "government should have access to everything all the time, regardless of reasoning" does not sit well with me.
Re: Apple dropped plan for encrypting backups after FBI complained
#55Earlier quoted context omitted.
Do they happen re-encrypt if I change my credentials a bunch of times or do they use my first ever password which was 123456?
The point of key derivation is that it can use a key to encrypt that is in turn protected by another key/password. So the amount necessary to re-encrypt when your password changes is just the encryption applied to the key. A similar technique is used in local disk encryption, where you don’t need to spend hours re-encrypting your hard drive just because you’ve changed your local account password...
Edit: or since it is "derived" and not really password which is used for encryption -- the derived thing could well be the hashed password. We are doomed. They might as well serial number their user and use that as key then. Never mind.
Re: Apple dropped plan for encrypting backups after FBI complained
#56What the... I was under the impression that iCloud backups are end-to-end encrypted. This is a HUGE problem.
The borg website is here:
https://borgbackup.readthedocs.io/en/stable/
and a good description of how it works and why you should use it is here:
Re: Apple dropped plan for encrypting backups after FBI complained
#57These are end to end:
Home data
Health data (requires iOS 12 or later)
iCloud Keychain (includes all of your saved accounts and passwords)
Payment information
QuickType Keyboard learned vocabulary (requires iOS 11 or later)
Screen Time
Siri information
Wi-Fi passwords
The messages also end to end but the backup contains the private key.
The moral of the story is that if you want real protection, do local backups.
Re: Apple dropped plan for encrypting backups after FBI complained
#58Privacy? Who needs it, amirite? I mean, I'm not up to anything illegal, and I don't actually care about people seeing my stuff, BUT... the concept as a whole of "government should have access to everything all the time, regardless of reasoning" does not sit well with me.
The point is, if someone from the law is interested in you, or suspects you of some grander illegal thing, a lot of us do illegal things that might just be a little less grand, and a lot of us have the digital equivalent of a broken taillight.
Re: Apple dropped plan for encrypting backups after FBI complained
#59Earlier quoted context omitted.
> it's unclear that it's in the best interests of humanity at large to make it easy for every individual to cipher their data in a way that no other human can ever access Unclear on what exactly? How much damage is done through encryption alone?
Arguably making it harder for enforcement agency to do their jobs. I believe this is their burden to bear and work with, since privacy for every citizens is also important.
And same goes for every other government. Why should the government can do whatever they want secretly?