Live data from Hacker News

Apple dropped plan for encrypting backups after FBI complained

reuters.com

181–190 of 734 posts

Re: Apple dropped plan for encrypting backups after FBI complained

#181
post #169

Apple has an opportunity to stand separate as a leader in user privacy first. But to do so means constantly standing up to government(s).

It literally doesn't matter. You are talking about their latest ad campaign.

Apple internal is complete detached from the commercials you see. It's about sales, not teaching users.

Re: Apple dropped plan for encrypting backups after FBI complained

#182

So now that iTunes is gone, how does one do a local iPhone backup?

It's part of the Finder now. Same UI (and probably code) just doesn't come as part of a monolithic application (but now part of a even more monolithic OS).

Re: Apple dropped plan for encrypting backups after FBI complained

#183

As a big fan of the Mac and iPhone this is incredibly disappointing. I always assumed the privacy situation with Apple was candy-coated but I didn't think they were this spineless.

How can you be a big fan of a product knowing that it's full of lies?

Serious question.

Re: Apple dropped plan for encrypting backups after FBI complained

#184
post #25

Earlier quoted context omitted.

Arguably making it harder for enforcement agency to do their jobs. I believe this is their burden to bear and work with, since privacy for every citizens is also important.

I agree that the resopnsibility is on the FBI to do investigation, but transitioning from a world where private documents are irretrievable without a warrant to one where they're structurally irretrievable because of mathematics and computational limitation would fundamentally alter the balance of power between society and individuals within that society in ways that society hasn't had to explore. It's something that…

Consider this then. What happens if freedom of speech is taken away (something that is already being talked about in some radical circles). If some group of people don't think you have the right to free speech comes into power and now have access to your private communications you could be "ghosted" away to the gulag for "hate speech" for something a benign as telling as an offensive joke if you upset the powers that be. To quote George Carlin. "F$ck the Children"

Re: Apple dropped plan for encrypting backups after FBI complained

#185
post #160

Earlier quoted context omitted.

This hard line is too facile. If you are paranoid about malicious code updates, then making part of your stack open-source doesn’t matter. I could push an update to your OS that reads the keys out of your BitWarden.

Of course, there are open source operating systems out there...

But is there fully open source hardware with no possibility of a backdoor?

Re: Apple dropped plan for encrypting backups after FBI complained

#186
post #160

Earlier quoted context omitted.

Of course, there are open source operating systems out there...

Yeah, I always verify the hashes of updated binaries match what I compile myself in parallel. Also that takes too much time so I just never update anything and have a homebrew version of 'Damn Vulnerable Linux'. /s

Long-term, there may eventually come a solution to this problem in the form of [binary transparency](https://wiki.mozilla.org/Security/Binary_Transparency). However, we're obviously a long way away from that being the norm, and there's still the problem of supply-chain attacks on hardware to consider.

Re: Apple dropped plan for encrypting backups after FBI complained

#187

Earlier quoted context omitted.

You ever read the reviews for the MEGA app? Everyone complains that there's no password reset feature. MEGA is fully encrypted so you literally can't reset your password. It says this when you first crate an account and get a recovery key. I don't think the general public would understand end-to-end encrypted backups. It would probably hurt their company if all backups were totally unrecoverable.

> I don't think the general public would understand end-to-end encrypted backups. I imagine you're right; it would still be nice for individuals and organizations to have the _option_ though.

You do have the option. Local device backup with a password.

You can’t even turn off the backup password on an existing device for a new backup without knowing the old password (protecting against Evil Maid problem).

I’ve had to reset a device when I forgot my local iPhone backup password to get it back to unencrypted backups.

Re: Apple dropped plan for encrypting backups after FBI complained

#188
post #39

Earlier quoted context omitted.

Well, you just have to “trust” the server to not serve a website that will phone home your password. Apple pinky swears they won’t do that, and all your browser extensions running all the time do, too. As Mark Zuckerberg once opined: “They ‘trust’ me. Those dumbfucks.” https://www.businessinsider.com/embarrassing-and-damaging-zu... And it’s not just mere words, here is he actually set up a honeypot site to get people…

None of what you said has anything to do with E2E encryption.

Yes it does. The password and other secret data can be sent in ways that are not end-to-end encrypted.

Re: Apple dropped plan for encrypting backups after FBI complained

#189
post #80

Earlier quoted context omitted.

And which phone do you use in its place to participate in basic aspects of modern life?

Please define your terms. Why do I have to use a phone in its place ? Apple products aren't a basic human necessity. I like to think I can just use a phone for the sake of wanting a phone, not to replace the void that not being an Apple consumer leaves in my soul, or something. What exactly do you mean by "basic aspects of modern life"? I have a desktop PC, a laptop, a work laptop, a LineageOS (Android-based) phone,…

I tried to get by with Lineage without gapps for a year and a half (if you don't forego gapps then there's no point from a privacy perspective).

I couldn't get push notifications on Slack because they went through gapps.

I couldn't use several online dating services because they were only on mobile, and their mobile apps broke without gapps.

I couldn't check my bank account from my phone because I couldn't get a hold of its app outside of the Play store, and because its mobile site locked my account for suspicious activity because I roamed between cell towers while using it.

I couldn't find places because there was no reasonable mapping option (OSMAnd, at least at the time, was abysmal to the point of being almost useless).

I once bought a pair of headphones that I couldn't use at all because you had to use Bose's app to set them up, and - you guessed it - the app was broken without gapps.

Even Signal - the OSS encrypted messenger - was partially hampered without gapps.

We can talk all day about how we got to this status quo and what can or can't be done about it, but the reality is that if you want to live a real, modern, urban life in 2020, so many people and organizations just assume you to have a fully-functional smartphone that you will be actively hampered without one.

Re: Apple dropped plan for encrypting backups after FBI complained

#190
post #180
post #49

Earlier quoted context omitted.

Except that this is a backdoor that circumvents device protections for the vast majority of users.

It is not a backdoor, nor does it circumvent anything. It is a front door convenience feature which has distinct privacy/security trade-offs. There exists no magical way to provide a means of lost password/device recovery which doesn’t grant Apple access to decrypt your data. It turns out that a lot of users want to have a way to recover from a lost device/password and are willing to let Apple decrypt their data. You…

> There exists no magical way to provide a means of lost password/device recovery which doesn’t grant Apple access to decrypt your data.

In modern times your face and your fingerprints could be that magic.

Post reply on HN