Live data from Hacker News

Apple dropped plan for encrypting backups after FBI complained

reuters.com

151–160 of 734 posts

Re: Apple dropped plan for encrypting backups after FBI complained

#153

Another case of a headline not being supported by the story: “ Reuters could not determine why exactly Apple dropped the plan. “Legal killed it, for reasons you can imagine,” another former Apple employee said he was told, without any specific mention of why the plan was dropped or if the FBI was a factor in the decision.” And further on: “ However, a former Apple employee said it was possible the encryption project…

In fairness, the title does not say that Apple dropped plan for encrypting backups because FBI complained :P

Re: Apple dropped plan for encrypting backups after FBI complained

#155
post #137
post #57

Apple has a list for that: https://support.apple.com/en-us/HT202303 These are end to end: Home data Health data (requires iOS 12 or later) iCloud Keychain (includes all of your saved accounts and passwords) Payment information QuickType Keyboard learned vocabulary (requires iOS 11 or later) Screen Time Siri information Wi-Fi passwords The messages also end to end but the backup contains the private key. The moral of…

E2e means next to nothing when using closed source software. Apple could (have) issue(d) an update with code to steal yr anything, without you knowing, so FBI-or-whatever does not "complain". I currently use one e2e service, BitWarden as keychain, that ticks the boxes (e2e AND open source client).

This hard line is too facile. If you are paranoid about malicious code updates, then making part of your stack open-source doesn’t matter. I could push an update to your OS that reads the keys out of your BitWarden.

Re: Apple dropped plan for encrypting backups after FBI complained

#156
post #35

Reminds me of WhatsApp claiming it had encryption everywhere and then this [0] dropped. Except, in this case, I'm actually surprised. Didn't Apple publicly claim that it wouldn't bow down to any demands from the agencies? [0]: https://www.theinquirer.net/inquirer/news/3061660/whatsapp-i...

It's mostly marketing bullshit. Apple and Microsoft both tried to build ad businesses, but when they weren't as successful as Google, they turned lemons into lemonade by launching data privacy PR campaigns against Google. Meanwhile, Apple and Microsoft quietly censor their products in China, surrender data to Chinese authorities, and now we find Apple is intentionally leaving iCloud data insecure. Presumably Google w…

I totally disagree. I work for Apple, and I can tell you that for everything you do privacy is involved. It’s not just marketing.

Re: Apple dropped plan for encrypting backups after FBI complained

#157

Earlier quoted context omitted.

https://www.sync.com provides end-to-end encrypted cloud storage options. Disclaimer I work there.

So does https://spideroak.com/ (I have no affiliation)

Have you read the SpiderOak disclaimer though?

NOTE: Logging in via the SpiderOak website does temporarily allow SpiderOak employees access to your password.

https://spideroak.support/hc/en-us/articles/115001854583-ONE...

Re: Apple dropped plan for encrypting backups after FBI complained

#158
post #143

Reminds me of WhatsApp claiming it had encryption everywhere and then this [0] dropped. Except, in this case, I'm actually surprised. Didn't Apple publicly claim that it wouldn't bow down to any demands from the agencies? [0]: https://www.theinquirer.net/inquirer/news/3061660/whatsapp-i...

What Apple claims and do are two different things... just like politicians tend to do.

Not true.

Disclaimer: I work for Apple.

Re: Apple dropped plan for encrypting backups after FBI complained

#159
post #74

Earlier quoted context omitted.

Please see "iCloud security overview", it clearly states which iCloud data is encrypted in transit, on server, and end-to-end: https://support.apple.com/en-us/HT202303

This is from your own link: “For certain sensitive information, Apple uses end-to-end encryption.” “These features and their data are transmitted and stored in iCloud using end-to-end encryption:” * Home data * Health data (requires iOS 12 or later) * iCloud Keychain (includes all of your saved accounts and passwords) * Payment information * QuickType Keyboard learned vocabulary (requires iOS 11 or later) * Screen Ti…

Yes, I wasn't debating a point, just providing a list of exactly how Apple encrypts user data.

Re: Apple dropped plan for encrypting backups after FBI complained

#160
post #137

Earlier quoted context omitted.

E2e means next to nothing when using closed source software. Apple could (have) issue(d) an update with code to steal yr anything, without you knowing, so FBI-or-whatever does not "complain". I currently use one e2e service, BitWarden as keychain, that ticks the boxes (e2e AND open source client).

This hard line is too facile. If you are paranoid about malicious code updates, then making part of your stack open-source doesn’t matter. I could push an update to your OS that reads the keys out of your BitWarden.

Of course, there are open source operating systems out there...
Post reply on HN