Live data from Hacker News

Apple dropped plan for encrypting backups after FBI complained

reuters.com

451–460 of 734 posts

Re: Apple dropped plan for encrypting backups after FBI complained

#453
post #431

Earlier quoted context omitted.

Thinking about long-term profits instead of short ones, and sacrificing profits for some greater moral purpose, are not at all the same thing. It's entirely possible to do immoral things for the sake of profit while still being prudent about your company's future. As for sacrificing profits to a moral end: private companies may do this occasionally. Not often, but sometimes. But the CEO of a publicly-traded company e…

>> But the CEO of a publicly-traded company expressly does not have the option of sacrificing profits for any higher purpose, unless that directive comes from his shareholders. This is not true AFAICT. In practice it might be.

to go a little deeper, corporate charters set out the values and goals of the company, as amended by the board from time to time, so it's whatever the (amended) charter says (it doesn't have to be solely profit-seeking). executives are judged by their ability to deliver on the goals of the charter.

baords are largely controlled by the various (professional) shareholders, and most, if not all, of them explicity seek profits above all else. that's one way markets get dominated by profit-seeking companies.

the other common argument is that in capital-oriented markets, not-primarily-profit-seeking corporations are at a competitive disadvantage over time, as the extra profits of greedy corporations can push them faster/further along the technology adoption/innovation curve (or economies of scale/scope).

so it's hard for such companies to survive. i don't think in practice that this is a dominant factor in competitive markets, but it's an argument often made (in business schools, for example).

Re: Apple dropped plan for encrypting backups after FBI complained

#454

Earlier quoted context omitted.

Incorrect. Please see the official Apple Support page [1] that debunks this. It specifically states: "iCloud services and all the data you store with iCloud, including photos, videos, documents, and backups, will be subject to the new terms and conditions of iCloud operated by GCBD." And since all Chinese companies are bound by local laws, you can be assured that your data is readily available for access by the gover…

That still doesn’t make the original statement that “encryption keys are given to China” correct. The data that is available in China is not encrypted and would also be available to US authorities. Can you quote the part of the article that states that Apple must give China private keys? Can you find a citation where a third party has found proof that Apple changed the iMessage architecture?

Apple may still be controlling the encryption keys but this says nothing about sharing the keys if compelled to do so.

> Can you quote the part of the article that states that Apple must give China private keys? Can you find a citation where a third party has found proof that Apple changed the iMessage architecture?

Apple is smarter than to put some text on their official website saying that the Chinese government has access to all your data. The key here is that their Terms and Conditions state that they operate "...in accordance to local laws". This is a cop-out legalese way of saying "We abide by whatever the Chinese government tells us to do".

Re: Apple dropped plan for encrypting backups after FBI complained

#455

Earlier quoted context omitted.

>t's a common misconception that corporations are amoral incentive-driven machines impervious to ethics, morals or mission. Not really, those leaders are pretty quick to hide behind the corporate veil when it's convenient for dodging questions of moral (or even legal) responsibility. The whole point of corporate legal structure is to create an entity that is _separate_ from the humans that occupy offices. That entity…

OK, but isn't this largely semantics? Saying Apple doesn't care about customers may technically be true, but that is taking it quite literally. The statement can also be meant to imply the people in Apple care, of course no one would speculate that a non human corporate entity would care. I also largely agree that the Apple meme of privacy being trotted out lately doesn't quite jive with this news, but at the same ti…

The people at Apple who write the code usually do care about privacy. Their bosses and execs? It is harder to tell.

From the information I have, the majority of Apple employees do care about values such as privacy and ethical business practices, as well as product quality and usability, but those values can sometimes be undermined by executive decisions based on business and monetary motives.

Re: Apple dropped plan for encrypting backups after FBI complained

#456

Earlier quoted context omitted.

I would urge you to read up on the Chinese cryptography law [1] which took effect on the 1st of this year. Essentially all companies foreign or not must provide unencrypted access to data to the Chinese government and must do so in secrecy. Prior to this, companies were being compelled to give up their data anyways but this just makes things easier. By the way, the source below is an official Chinese government media…

Do you have any evidence that Apple rearchitected their system to have access to private keys that it doesn’t have access to anywhere, to have access to give it to China?

Technology is irrelevant here. Laws (or in China, the Chinese Communist Party) govern these things.

Re: Apple dropped plan for encrypting backups after FBI complained

#457
post #206

> aboyt how much Apple cares about users No company cares about anything. A company is not a person. Apple, because of its privacy-marketing, is incentivized to be the privacy player in the market. But only so far as consumers keep them honest about it. They got away with this loophole because it stayed under the radar; if it gets enough attention and enough customers show that it matters to them, it could change. On…

"because of its privacy-marketing"

No, it's because they can't effectively leverage your data to sell you stuff, they don't need it.

Thus follows the privacy marketing.

If Apple did find your data useful, they wouldn't be able to leverage that marketing angle.

Companies are made up of people, who care about people, and also, corporate objectives are not evil, generally. Working with the FBI might raise your eyebrow, but it may not for others, and it's an ambiguous question to most.

In the end, the balance of power has not fundamentally shifted. Most people have little to worry about, some criminals may have more to worry about. Of course the problem arises when innocents are needlessly entangled - hopefully this can be minimised. It's not like the FBI has instant and easy access to your phone, thankfully.

Re: Apple dropped plan for encrypting backups after FBI complained

#458

Earlier quoted context omitted.

That still doesn’t make the original statement that “encryption keys are given to China” correct. The data that is available in China is not encrypted and would also be available to US authorities. Can you quote the part of the article that states that Apple must give China private keys? Can you find a citation where a third party has found proof that Apple changed the iMessage architecture?

Apple may still be controlling the encryption keys but this says nothing about sharing the keys if compelled to do so. > Can you quote the part of the article that states that Apple must give China private keys? Can you find a citation where a third party has found proof that Apple changed the iMessage architecture? Apple is smarter than to put some text on their official website saying that the Chinese government ha…

How can Apple share private keys it doesn’t have access to?

Apple doesn’t control “private keys” you use to encrypt data. The keys wouldn’t be very private if that were the case.

The entire idea behind public/private keys is that you keep access to your private key.

Re: Apple dropped plan for encrypting backups after FBI complained

#459

Earlier quoted context omitted.

>1) There is no way Apple would be allowed to sell iPhones in China, without China government having access to anything. So, I assume that Apple users in China have e2e encrypted exactly nothing. E2E works exactly the same in China. You can read more in my comments here: https://news.ycombinator.com/item?id=20904857 The same "vulnerability" of being able to respond to legal requests for iCloud data that exists in Chi…

Please stop spreading disinformation. Your sources are outdated and the quotes that you are referencing are not legally binding. The fact is that Apple has clearly stated that iCloud data for Mainland Chinese users is stored on servers operated by a Chinese company, which must abide by the local laws and regulations. It is also a well known fact that all companies operating in China can be compelled by the Chinese go…

There's no disinformation in my comments. I seem to be one of the few people on the planet who seems to have actually dug into this exact issue while others only offer the typical FUD we've seen about how Apple's encryption works in China.

The fact is that Apple has said multiple times (and even under oath) that end-to-end encryption applies to iPhones and iMessage in China, the same as it does everywhere else.

And once again Erik Neuenschwander, an Apple privacy exec, told Congress in a hearing in December that this was still the case.

At 02:10:46

https://www.judiciary.senate.gov/meetings/encryption-and-law...

Re: Apple dropped plan for encrypting backups after FBI complained

#460

Earlier quoted context omitted.

Apple uses third party data centers, if it can't host encrypted data on a Chinese server without China having access to the data, there is something wrong with the encryption.

It would be trivial for the Chinese gov't to sniff RAM or the bus and get everything they need anyways.

What exactly are they going to “sniff”? Private keys never leave your device.
Post reply on HN