Live data from Hacker News

Apple dropped plan for encrypting backups after FBI complained

reuters.com

231–240 of 734 posts

Re: Apple dropped plan for encrypting backups after FBI complained

#231

>there's no good and easy option to backup your phone other than iCloud. Turn off iCloud and do local encrypted backups to your PC or Mac. This works over your wifi network (if you prefer wireless charging at home) or via a cable connection.

Not a solution for Linux users. There are ways to sync to Linux but I’ve had plenty of issues with it.

Re: Apple dropped plan for encrypting backups after FBI complained

#232
post #223

Earlier quoted context omitted.

Two things: 1) There is no way Apple would be allowed to sell iPhones in China, without China government having access to anything. So, I assume that Apple users in China have e2e encrypted exactly nothing. 2) I have a strong suspicion that those 'enter your Apple ID password because your account needs it' message really means 'a government has requested your data and even though it's encrypted, we will nag you about…

My impression is that iMessage is indeed encrypted end-to-end in China, same as everywhere else.

iMessage is. iMessage backups are not.

Re: Apple dropped plan for encrypting backups after FBI complained

#235
post #228

Wonder if this will help to kill a meme, about how much Apple cares about users and what great values they have, how they're going to stand for the user, fight with governments, etc. While iPhone itself is pretty secure as a device phone (and Apple makes sure to remind you about that in each ad, public speaking, attacks on competitors, etc), as an ecosystem it's not secure. And it's like that on purpose - there's no…

>While iPhone itself is pretty secure as a device phone I simply don't understand why people would blindly believe marketing material from a for-profit corporation. It's a device running closed source software. There is no way to prove this claim. If anything, Apple has been caught in the past sending very very personal sensitive information [1]. [1] https://www.theguardian.com/technology/2019/jul/26/apple-con...

Not blindly. Outside of marketing material there have been more meaningful signs and signals indicating that they did care. Including principled people working there, threatening to quit if the FBI got its way on San Bernardino, etc. This is new.

Re: Apple dropped plan for encrypting backups after FBI complained

#236
post #223

Earlier quoted context omitted.

Two things: 1) There is no way Apple would be allowed to sell iPhones in China, without China government having access to anything. So, I assume that Apple users in China have e2e encrypted exactly nothing. 2) I have a strong suspicion that those 'enter your Apple ID password because your account needs it' message really means 'a government has requested your data and even though it's encrypted, we will nag you about…

My impression is that iMessage is indeed encrypted end-to-end in China, same as everywhere else.

The key is included in the iCloud backup stored by Guizhou on the “Cloud Big Data Industrial Development Co., Ltd.“

https://support.apple.com/en-us/HT208351

Re: Apple dropped plan for encrypting backups after FBI complained

#237
post #206

> aboyt how much Apple cares about users No company cares about anything. A company is not a person. Apple, because of its privacy-marketing, is incentivized to be the privacy player in the market. But only so far as consumers keep them honest about it. They got away with this loophole because it stayed under the radar; if it gets enough attention and enough customers show that it matters to them, it could change. On…

> On the other hand, it's possible that because we have a smartphones duopoly, Apple only needs to maintain a position where people will say "well at least it's not as bad as Google". I'm upset about this personally, but I'm not ditching my iPhone. Of course, this does cement my decision to never pay for iCloud, for what that's worth (much less, but not nothing). Agreed, and I am likely going away from Android and in…

They botched the original Windows Phone through a failure of management. They botched subsequent pushes on it because the bootstrapping problem around apps had grown too deep. At this point, if they tried to give it another go, there would be trust issues: "Am I investing in a phone ecosystem that's going to be dead in a few years?" Not to mention how much they've gone all-in on Android development.

A Surface-branded Android phone wouldn't be out of the question, but my gut tells me it would die a quiet death from thin margins and differentiators that aren't big enough for people to get excited.

Re: Apple dropped plan for encrypting backups after FBI complained

#238
post #57

Apple has a list for that: https://support.apple.com/en-us/HT202303 These are end to end: Home data Health data (requires iOS 12 or later) iCloud Keychain (includes all of your saved accounts and passwords) Payment information QuickType Keyboard learned vocabulary (requires iOS 11 or later) Screen Time Siri information Wi-Fi passwords The messages also end to end but the backup contains the private key. The moral of…

> if you want real protection, do local backups

Yes, this is unfortunately true and unfortunately complicated compared to iCloud backups.

I backup locally to my mac (encrypted), then I have my mac do time machine backups to my Synology NAS (encrypted) and then I have my NAS backup to BackBlaze (encrypted). I do that to satisfy the two pronged backup strategy: local (fast) and remote (slow, but useful in catastrophic local situations such as fire, flood, theft, etc).

Re: Apple dropped plan for encrypting backups after FBI complained

#239
post #57

Apple has a list for that: https://support.apple.com/en-us/HT202303 These are end to end: Home data Health data (requires iOS 12 or later) iCloud Keychain (includes all of your saved accounts and passwords) Payment information QuickType Keyboard learned vocabulary (requires iOS 11 or later) Screen Time Siri information Wi-Fi passwords The messages also end to end but the backup contains the private key. The moral of…

I thought iMessage private keys are somehow based on data in the "secure enclave" chip, and thus not able to be stored in the cloud. It's my understanding that Apple could add new "devices" to listen in on future conversations, but it can't read iMessage conversations in transit between existing devices. It can also read iCloud backups of conversation content, which are created by the client device after decrypting t…

The secure enclave is a feature to secure the device and the data on it from casual threats. Apple gets a bit evasive any time the subject of security shifts to their cloud services. (i.e. they will talk about how a particular feature is e2e encrypted but their security talking points seem to mostly end at the device)

I think a better way to look at what they're selling you is a device that provides you pretty-to-very good protection from casual hacking and theft. But in the event of a government knocking on their door for more information, they'll quietly hand over what they can which probably is quite a bit more than the average consumer thinks it is. All bets are off as to what the full story is when the government/jurisdiction involved is not the United States.

Re: Apple dropped plan for encrypting backups after FBI complained

#240
post #187

Earlier quoted context omitted.

You do have the option. Local device backup with a password. You can’t even turn off the backup password on an existing device for a new backup without knowing the old password (protecting against Evil Maid problem). I’ve had to reset a device when I forgot my local iPhone backup password to get it back to unencrypted backups.

You're right, of course. I had in mind an e2e encrypted backup on Apple's servers, which would be far more convenient than doing it locally. That's all.

Well yeah, hence TFA;

> More than two years ago, Apple told the FBI that it planned to offer users end-to-end encryption when storing their phone data on iCloud, according to one current and three former FBI officials and one current and one former Apple employee.

> Under that plan, primarily designed to thwart hackers, Apple would no longer have a key to unlock the encrypted data, meaning it would not be able to turn material over to authorities in a readable form even under court order.

Post reply on HN