Live data from Hacker News

Apple dropped plan for encrypting backups after FBI complained

reuters.com

121–130 of 734 posts

Re: Apple dropped plan for encrypting backups after FBI complained

#121

What the... I was under the impression that iCloud backups are end-to-end encrypted. This is a HUGE problem.

This is a HUGE problem.

Well, you can choose not to use iCloud for that reason (as some of us do).

A bigger problem is that Apple deliberately locks up iDevices so it's hard to get your data off them using only local means, particularly if you don't also want to buy an Apple laptop just to do it.

Re: Apple dropped plan for encrypting backups after FBI complained

#122

Beyond HN and tech circles, is there any detectable groundswell of demand for privacy? When you talk with friends & family about privacy, does anyone care? When average people care about privacy, the large players will respond. Until then, pressure from the state can be accommodated without irking customers, so Big Tech will play along.

> does anyone care?

Actually yes. Some even have bought into VPN services without me recommending it and without any missionary ambitions from my part. Generally these are also not people using services of the largest offenders too much though.

I would even say the majority in my circle cares about it. They just have no real clue how to mimimize data exposure. There certainly is an effect that influences consumption though.

From the techies within my cirlce everybody cares, most to a pretty large degree.

Re: Apple dropped plan for encrypting backups after FBI complained

#123

Earlier quoted context omitted.

That’s only for devices where the region is set as China. Why would it be a moot point elsewhere for that reason?

Injustice anywhere is a threat to justice everywhere.

Different places define (in)justice differently.

Re: Apple dropped plan for encrypting backups after FBI complained

#124
Is Apple’s privacy white paper dealing with fats on iCloud just an eyewash now?

> Instead of protecting all of iCloud with end-to-end encryption, Apple has shifted to focus on protecting some of the most sensitive user information, such as saved passwords and health data.

> But backed-up contact information and texts from iMessage, WhatsApp and other encrypted services remain available to Apple employees and authorities.

Way to confuse laypeople with promises of security and data privacy. If Apple had concerns about users losing the key, why not implement it similar to two factor authentication on Apple IDs where Apple also provides the recovery codes (and additionally disallow any other mechanism of recovery)?

Re: Apple dropped plan for encrypting backups after FBI complained

#125

Beyond HN and tech circles, is there any detectable groundswell of demand for privacy? When you talk with friends & family about privacy, does anyone care? When average people care about privacy, the large players will respond. Until then, pressure from the state can be accommodated without irking customers, so Big Tech will play along.

Here in Germany there is a big TV ads campaign by Apple focusing on privacy.

At least their marketers seem to believe that there is a large enough groundswell to justify a campaign.

Re: Apple dropped plan for encrypting backups after FBI complained

#126
post #57

Apple has a list for that: https://support.apple.com/en-us/HT202303 These are end to end: Home data Health data (requires iOS 12 or later) iCloud Keychain (includes all of your saved accounts and passwords) Payment information QuickType Keyboard learned vocabulary (requires iOS 11 or later) Screen Time Siri information Wi-Fi passwords The messages also end to end but the backup contains the private key. The moral of…

I thought iMessage private keys are somehow based on data in the "secure enclave" chip, and thus not able to be stored in the cloud. It's my understanding that Apple could add new "devices" to listen in on future conversations, but it can't read iMessage conversations in transit between existing devices. It can also read iCloud backups of conversation content, which are created by the client device after decrypting t…

If you lose your device and buy a new one and restore your device with a back up, all your messages will be returned.

There’s no way to accomplish this without having the private key in the backup.

EDIT: When I say there is no way to accomplish this, I’m talking specifically about the process that exists today where the user doesn’t have to remember a password other than their iCloud password (which today, can also be reset).

Re: Apple dropped plan for encrypting backups after FBI complained

#127

Beyond HN and tech circles, is there any detectable groundswell of demand for privacy? When you talk with friends & family about privacy, does anyone care? When average people care about privacy, the large players will respond. Until then, pressure from the state can be accommodated without irking customers, so Big Tech will play along.

Asking the real important questions.

Re: Apple dropped plan for encrypting backups after FBI complained

#128

Are the iMessages in an iCloud backup encrypted or not? As of now. It seems actually unclear.

Yes, but the key is stored in your iCloud backup if you use it. As soon as you disable iCloud backups it will roll the key for iMessage and they will be effectively E2E encrypted.

When Messages in iCloud is enabled, iMessage, Business Chat, text (SMS), and MMS messages are removed from the user’s existing iCloud Backup, and are instead stored in an end-to-end encrypted CloudKit container for Messages. The user’s iCloud Backup retains a key to that container. If the user subsequently disables iCloud Backup, that container’s key is rolled, the new key is stored only in iCloud Keychain (inaccessible to Apple and any third parties), and new data written to the container can’t be decrypted with the old container key.

https://support.apple.com/guide/security/icloud-backup-conte...

Re: Apple dropped plan for encrypting backups after FBI complained

#129
post #100
post #35

Earlier quoted context omitted.

It's mostly marketing bullshit. Apple and Microsoft both tried to build ad businesses, but when they weren't as successful as Google, they turned lemons into lemonade by launching data privacy PR campaigns against Google. Meanwhile, Apple and Microsoft quietly censor their products in China, surrender data to Chinese authorities, and now we find Apple is intentionally leaving iCloud data insecure. Presumably Google w…

A good way to figure out whether this kind of claim is marketing bullshit, is to look for a PR claim that goes the other way: that Apple or whoever helps the FBI find uploaded images of child sexual abuse. If they are matching on your data, they can’t be encrypting it; if they’re encrypting it, they can’t be matching on it. It’s one or the other. And, well, Apple have confirmed that they‘re matching on your data[1].…

This was clarified to be iCloud Mail attachments.

Re: Apple dropped plan for encrypting backups after FBI complained

#130
post #57

Apple has a list for that: https://support.apple.com/en-us/HT202303 These are end to end: Home data Health data (requires iOS 12 or later) iCloud Keychain (includes all of your saved accounts and passwords) Payment information QuickType Keyboard learned vocabulary (requires iOS 11 or later) Screen Time Siri information Wi-Fi passwords The messages also end to end but the backup contains the private key. The moral of…

https://www.sync.com provides end-to-end encrypted cloud storage options. Disclaimer I work there.
Post reply on HN