Live data from Hacker News

Apple dropped plan for encrypting backups after FBI complained

reuters.com

71–80 of 734 posts

Re: Apple dropped plan for encrypting backups after FBI complained

#71
post #35

Earlier quoted context omitted.

It's mostly marketing bullshit. Apple and Microsoft both tried to build ad businesses, but when they weren't as successful as Google, they turned lemons into lemonade by launching data privacy PR campaigns against Google. Meanwhile, Apple and Microsoft quietly censor their products in China, surrender data to Chinese authorities, and now we find Apple is intentionally leaving iCloud data insecure. Presumably Google w…

"Apple is intentionally leaving iCloud data insecure" ... if you'd done some research you would know that iCloud backups are not end-to-end encrypted. That means you have a choice: backup to iCloud for the convenience and give up some privacy, or turn off the iCloud backup. It would be nice if Apple was more forthcoming with that fact but there is some onus on the customer these days to understand what's private and…

Doesn’t that page show everything as end-to-end encrypted, except email messages on the server?

If “backup”, photos, messages, contacts, calendars, iCloud Drive, notes, and safari data (and a few more) are end-to-end encrypted what else is there?

Re: Apple dropped plan for encrypting backups after FBI complained

#72
post #35

Reminds me of WhatsApp claiming it had encryption everywhere and then this [0] dropped. Except, in this case, I'm actually surprised. Didn't Apple publicly claim that it wouldn't bow down to any demands from the agencies? [0]: https://www.theinquirer.net/inquirer/news/3061660/whatsapp-i...

It's mostly marketing bullshit. Apple and Microsoft both tried to build ad businesses, but when they weren't as successful as Google, they turned lemons into lemonade by launching data privacy PR campaigns against Google. Meanwhile, Apple and Microsoft quietly censor their products in China, surrender data to Chinese authorities, and now we find Apple is intentionally leaving iCloud data insecure. Presumably Google w…

Just a reminder, Apple ceded control of its iCloud management in China to a state-controlled company, in addition began storing its encryption keys in China in order to "comply with local regulations". So whether or not your backups are encrypted is almost a moot point, given that the government can submit a lawful demand for your data at any time..

Apple will store some iCloud encryption keys in China, raising security concerns https://www.theverge.com/2018/2/26/17052802/apple-icloud-enc...

Re: Apple dropped plan for encrypting backups after FBI complained

#73
Beyond HN and tech circles, is there any detectable groundswell of demand for privacy? When you talk with friends & family about privacy, does anyone care?

When average people care about privacy, the large players will respond. Until then, pressure from the state can be accommodated without irking customers, so Big Tech will play along.

Re: Apple dropped plan for encrypting backups after FBI complained

#74
post #35

Earlier quoted context omitted.

It's mostly marketing bullshit. Apple and Microsoft both tried to build ad businesses, but when they weren't as successful as Google, they turned lemons into lemonade by launching data privacy PR campaigns against Google. Meanwhile, Apple and Microsoft quietly censor their products in China, surrender data to Chinese authorities, and now we find Apple is intentionally leaving iCloud data insecure. Presumably Google w…

"Apple is intentionally leaving iCloud data insecure" ... if you'd done some research you would know that iCloud backups are not end-to-end encrypted. That means you have a choice: backup to iCloud for the convenience and give up some privacy, or turn off the iCloud backup. It would be nice if Apple was more forthcoming with that fact but there is some onus on the customer these days to understand what's private and…

Please see "iCloud security overview", it clearly states which iCloud data is encrypted in transit, on server, and end-to-end:

https://support.apple.com/en-us/HT202303

Re: Apple dropped plan for encrypting backups after FBI complained

#75

End-to-end backup encryption is hard. Apple had faced criticism from cryptographers for failing to implement it. https://blog.cryptographyengineering.com/2012/04/05/icloud-w... The fact that they started working on the problem then abandoned it after the FBI complained is disappointing, especially to Apple consumers. But all it means is the status quo marches on. Headlines like this vindicate my decision to never pur…

>Headlines like this vindicate my decision to never purchase an Apple product.

What else can you buy? Surely not Android...do you live without a smartphone (serious question, not judging)?

Re: Apple dropped plan for encrypting backups after FBI complained

#76
post #59
post #25

Earlier quoted context omitted.

Arguably making it harder for enforcement agency to do their jobs. I believe this is their burden to bear and work with, since privacy for every citizens is also important.

Tell you what. The minute the entire government and FBI start recording their activities openly on an immutable blockchain, or at least every police officer wears a bodycam on-duty, we can talk about handing over keys for all citizen data being open to said government. But still hard to search and index en masse. And same goes for every other government. Why should the government can do whatever they want secretly?

I can't speak for all governments, but in the US the National Archives has responsibility for recording the things the federal government undertakes on behalf of the people. This includes even the tapes Nixon made of his own conversations as President.

The guiding principle the US government operates on in this context is "When a man assumes a public trust he should consider himself a public property" (Thomas Jefferson). There are plenty of ways the fed falls short of the goal, but the goal is set.

... and I don't think anyone's talking about "handing over the keys for all citizen data being open to said government." But we are talking about avoiding having common practice for private citizen information stored in servers owned by a third-party private corporation becoming "It's stored in such a way that nobody, not even the third-party private corporation, can ever access the data without a key the private citizen can throw away." There are some good cost-benefit discussions to be had about whether that should be a thing commonly offered (even if an individual can build it themselves).

To give a concrete example, imagine if Epstein's data on the human trafficking he conducted were impossibly ciphered now in an iCloud backup he made. Does that benefit society? And more practically (regardless of larger ideal morality questions), is it a good PR look for Apple if their tech made it easy for him to do and when the fed comes knocking on Apple's door to retrieve from Apple's servers a dead man's documents that could bring justice for sex-trafficked children, Apple's response was "Sorry; we don't have enough computing power to help you?"

Re: Apple dropped plan for encrypting backups after FBI complained

#77

Earlier quoted context omitted.

The point of key derivation is that it can use a key to encrypt that is in turn protected by another key/password. So the amount necessary to re-encrypt when your password changes is just the encryption applied to the key. A similar technique is used in local disk encryption, where you don’t need to spend hours re-encrypting your hard drive just because you’ve changed your local account password...

Then it must need my password to decrypt the key which was used to encrypt the raw data? What if I do not tell them my password, (assuming my password is one way hashed and stored) would that brick the key and in turn brick the data? Clearly I am missing something here.. Edit: or since it is "derived" and not really password which is used for encryption -- the derived thing could well be the hashed password. We are d…

You’re overthinking it. Create a private key. Protect that key with a pass phrase. If you change your password, you’re really changing the pass phrase.

Does that clear it up at all?

FYI these concepts are originated from military crypto. The foundations are solid. Implementation... well you know how that always is.... one CVE away from perfect!!

Re: Apple dropped plan for encrypting backups after FBI complained

#78
post #57

Apple has a list for that: https://support.apple.com/en-us/HT202303 These are end to end: Home data Health data (requires iOS 12 or later) iCloud Keychain (includes all of your saved accounts and passwords) Payment information QuickType Keyboard learned vocabulary (requires iOS 11 or later) Screen Time Siri information Wi-Fi passwords The messages also end to end but the backup contains the private key. The moral of…

> The messages also end to end but the backup contains the private key.

Should this even be called E2E? I suppose it is, technically, but clearly not in spirit.

Re: Apple dropped plan for encrypting backups after FBI complained

#79
post #3

Earlier quoted context omitted.

Apple has a key for iCloud backups. [1] 1. https://fixitalready.eff.org/apple

That's generally what "on the server" means, it's only encrypted so their storage provider (shown to be GCP https://www.theverge.com/2018/2/26/17053496/apple-google-clo... ) can't see their user data.

Maybe this is me being out of touch with modern deployment, but that is absolutely not what my impression of "on the server" means. My mental model is that of a client, whatever software is under my control, and a server, which is whatever my client connects to. "Encrypted on the server" then means that at no point is the plaintext data visible to any part of the server.

If Apple splits up the server into a web server and a storage server, then uses "encrypted on the server" to refer only to the storage server, that is entirely disingenuous.

Re: Apple dropped plan for encrypting backups after FBI complained

#80

End-to-end backup encryption is hard. Apple had faced criticism from cryptographers for failing to implement it. https://blog.cryptographyengineering.com/2012/04/05/icloud-w... The fact that they started working on the problem then abandoned it after the FBI complained is disappointing, especially to Apple consumers. But all it means is the status quo marches on. Headlines like this vindicate my decision to never pur…

And which phone do you use in its place to participate in basic aspects of modern life?
Post reply on HN