Live data from Hacker News

Apple dropped plan for encrypting backups after FBI complained

reuters.com

51–60 of 734 posts

Re: Apple dropped plan for encrypting backups after FBI complained

#51

Privacy? Who needs it, amirite? I mean, I'm not up to anything illegal, and I don't actually care about people seeing my stuff, BUT... the concept as a whole of "government should have access to everything all the time, regardless of reasoning" does not sit well with me.

Nourong

Re: Apple dropped plan for encrypting backups after FBI complained

#52

Easy fix: back up your iPhone locally on your computer instead of using iCloud: https://support.apple.com/en-us/HT203977#computer The ambiguous position on true end-to-end encryption shows once again that Apple is in for the marketing (both to consumers—predatory and dangerous, and to engineering talent—dishonest). Same hypocrisy as on the China issue. Not that there is an easy solution when you are one of the bigges…

Second step: Delete old backups https://support.apple.com/en-us/HT204247#backups

Eh, maybe, maybe not. What guarantees are there that the backups actually get deleted? Storage is cheap these days...

Re: Apple dropped plan for encrypting backups after FBI complained

#53
I will not be surprised if further reporting points a finger at the influence of China as well.

Apple already conceded to hosting Chinese iCloud data on Chinese servers, and that news came out about 2 years ago... which is also the timeframe reported for this decision to forego end-to-end encryption of iCloud backups.

I'm guessing here, but I think it's safe to assume that China was not going to permit such encryption (for the same reason they insist on hosting the data) and thus to provide it for the U.S., Apple would have had to fork iCloud. Add in the political risk in the U.S. and you have a recipe for "maybe not."

Re: Apple dropped plan for encrypting backups after FBI complained

#54

Privacy? Who needs it, amirite? I mean, I'm not up to anything illegal, and I don't actually care about people seeing my stuff, BUT... the concept as a whole of "government should have access to everything all the time, regardless of reasoning" does not sit well with me.

What happens when what is considered legal gets changed in the future?

Re: Apple dropped plan for encrypting backups after FBI complained

#55

Earlier quoted context omitted.

Do they happen re-encrypt if I change my credentials a bunch of times or do they use my first ever password which was 123456?

The point of key derivation is that it can use a key to encrypt that is in turn protected by another key/password. So the amount necessary to re-encrypt when your password changes is just the encryption applied to the key. A similar technique is used in local disk encryption, where you don’t need to spend hours re-encrypting your hard drive just because you’ve changed your local account password...

Then it must need my password to decrypt the key which was used to encrypt the raw data? What if I do not tell them my password, (assuming my password is one way hashed and stored) would that brick the key and in turn brick the data? Clearly I am missing something here..

Edit: or since it is "derived" and not really password which is used for encryption -- the derived thing could well be the hashed password. We are doomed. They might as well serial number their user and use that as key then. Never mind.

Re: Apple dropped plan for encrypting backups after FBI complained

#56

What the... I was under the impression that iCloud backups are end-to-end encrypted. This is a HUGE problem.

You should look into the 'borg' backup tool - it has become the de facto standard for remote backups because it does everything that rsync does (efficient, changes only backups) but also produces strongly encrypted remote backup sets that only you have a key to ... your cloud provider has no access to the data.

The borg website is here:

https://borgbackup.readthedocs.io/en/stable/

and a good description of how it works and why you should use it is here:

https://www.stavros.io/posts/holy-grail-backups/

Re: Apple dropped plan for encrypting backups after FBI complained

#57
Apple has a list for that: https://support.apple.com/en-us/HT202303

These are end to end:

Home data

Health data (requires iOS 12 or later)

iCloud Keychain (includes all of your saved accounts and passwords)

Payment information

QuickType Keyboard learned vocabulary (requires iOS 11 or later)

Screen Time

Siri information

Wi-Fi passwords

The messages also end to end but the backup contains the private key.

The moral of the story is that if you want real protection, do local backups.

Re: Apple dropped plan for encrypting backups after FBI complained

#58

Privacy? Who needs it, amirite? I mean, I'm not up to anything illegal, and I don't actually care about people seeing my stuff, BUT... the concept as a whole of "government should have access to everything all the time, regardless of reasoning" does not sit well with me.

You don't even, for instance, torrent? Movies, music? (You don't have to answer that. :P ) Ever pirate apps, even just to try before you buy?

The point is, if someone from the law is interested in you, or suspects you of some grander illegal thing, a lot of us do illegal things that might just be a little less grand, and a lot of us have the digital equivalent of a broken taillight.

Re: Apple dropped plan for encrypting backups after FBI complained

#59
post #25

Earlier quoted context omitted.

> it's unclear that it's in the best interests of humanity at large to make it easy for every individual to cipher their data in a way that no other human can ever access Unclear on what exactly? How much damage is done through encryption alone?

Arguably making it harder for enforcement agency to do their jobs. I believe this is their burden to bear and work with, since privacy for every citizens is also important.

Tell you what. The minute the entire government and FBI start recording their activities openly on an immutable blockchain, or at least every police officer wears a bodycam on-duty, we can talk about handing over keys for all citizen data being open to said government. But still hard to search and index en masse.

And same goes for every other government. Why should the government can do whatever they want secretly?

Post reply on HN