Live data from Hacker News

Apple dropped plan for encrypting backups after FBI complained

reuters.com

471–480 of 734 posts

Re: Apple dropped plan for encrypting backups after FBI complained

#471

Earlier quoted context omitted.

Please stop spreading disinformation. Your sources are outdated and the quotes that you are referencing are not legally binding. The fact is that Apple has clearly stated that iCloud data for Mainland Chinese users is stored on servers operated by a Chinese company, which must abide by the local laws and regulations. It is also a well known fact that all companies operating in China can be compelled by the Chinese go…

There's no disinformation in my comments. I seem to be one of the few people on the planet who seems to have actually dug into this exact issue while others only offer the typical FUD we've seen about how Apple's encryption works in China. The fact is that Apple has said multiple times (and even under oath) that end-to-end encryption applies to iPhones and iMessage in China, the same as it does everywhere else. And o…

> In fact I seem to be one of the few people on the planet who seems to have actually dug into this exact issue while others only offer the typical FUD we've seen about how Apple's encryption works in China.

I think instead of researching how Apple works in China, you need to start doing some research on how the Chinese government works and their track record on legal matters and rule of law.

Also, the segment in the Senate hearing you referenced shows a senator who obviously does not have a good grasp on encryption technology asking bumbling questions about encryption. I have paraphrased the section here:

> Senator: Do you sell phones in China? Are they encrypted? > Apple: The phones are the same and all of our phones are encrypted across the world

Yes, obviously all phones have encryption but the Senator did not clarify what was being encrypted here and Apple took advantage of this in the response.

> Senator: You're telling me that they [China] allows you to sell devices without you allowing them to breach the encryption and gain information about the users? > Apple: You're 100% correct

Once again, the question posed was incoherent. Of course there is no "breaching of encryption" here - the Chinese government just asks for the keys or the data. It's all about language here.

If this Senate hearing is your case for why data is safe in China, I honestly fear for all the political and religious dissidents that are trusting Apple for their safety.

Re: Apple dropped plan for encrypting backups after FBI complained

#472
post #391

Earlier quoted context omitted.

What you say makes sense. Still, if that’s the case, then when they decided not to go down the user-is-in-full-and-absolute-control path for encryption of iCloud backups, they should have publicized it loudly and with extreme clarity on what exactly was happening and where the lines were. So that users could make informed choices.

They have never hidden how iCloud backups or anything else related to iOS security works. This support document spells out clearly what data is end-to-end encrypted [1]. No one was actually misled into thinking all iCloud data was E2E. For one, most of Apple's customers don't know or care about the technical architecture of their products and services. The people who do would have known better when you can go to iclo…

Typical users who may care about privacy were definitely misled by Apple's public pro-security and pro-privacy stances. I have family who fall into that category.

The difference between E2E and 'yup we're encrypted!' isn't understood by laypeople. Let's not do ourselves or the average folks out there a disservice by letting Apple off the hook for bad communication and the intentional misleading of users.

Re: Apple dropped plan for encrypting backups after FBI complained

#473
post #391

Earlier quoted context omitted.

What you say makes sense. Still, if that’s the case, then when they decided not to go down the user-is-in-full-and-absolute-control path for encryption of iCloud backups, they should have publicized it loudly and with extreme clarity on what exactly was happening and where the lines were. So that users could make informed choices.

It has been known and talked about on HN for a long time that only certain things are E2E encrypted on iCloud. And, if full privacy was the goal, then either the user can only do local backups or no backups at all.

HN is among the most technologically-literate demographics in the world. Using HN as a control group to say that it's been 'known and talked about' is a bit disingenuous when we're the proverbial 1% who are in the know. Meanwhile, the other 99% are left trusting Apple's advertising.

Re: Apple dropped plan for encrypting backups after FBI complained

#474

What the... I was under the impression that iCloud backups are end-to-end encrypted. This is a HUGE problem.

End to End encryption doesn't work very well when the government nationalizes the servers with the end data and the keys to decrypt it.

https://techcrunch.com/2018/07/17/apples-icloud-user-data-in...

Re: Apple dropped plan for encrypting backups after FBI complained

#475
Is anyone surprised by this?

It could be for many reasons too, including average people forgetting iCloud passwords and wanting their data back. Does Apple unlock an iCloud backup in that situation?

Perhaps a pro-privacy compromise would be for Apple to offer the feature but have it turned off by default, which means 99.99% of users won't ever change that.

Re: Apple dropped plan for encrypting backups after FBI complained

#476

Wonder if this will help to kill a meme, about how much Apple cares about users and what great values they have, how they're going to stand for the user, fight with governments, etc. While iPhone itself is pretty secure as a device phone (and Apple makes sure to remind you about that in each ad, public speaking, attacks on competitors, etc), as an ecosystem it's not secure. And it's like that on purpose - there's no…

Do you have any personal recommendations on DIY iCloud alternatives?

Re: Apple dropped plan for encrypting backups after FBI complained

#477
post #26

What the... I was under the impression that iCloud backups are end-to-end encrypted. This is a HUGE problem.

Why would you think it was end-to-end encrypted? Did you never use icloud.com where you can simply access all your icloud data with a usernam+password?

In that case, isn't the web server storing the E2E key to decrypt for serving it up via the icloud web front-end?

Re: Apple dropped plan for encrypting backups after FBI complained

#478
It turns over data more often in response to secret U.S. intelligence court directives, which sought content from more than 18,000 accounts in the first half of 2019, the most recently reported six-month period.

When you think about it, that volume is staggering. 36,000 iDevice-using intelligence targets every year? Imagine the amount of analyst time required just to go through 36,000 iCloud backups every year!

Re: Apple dropped plan for encrypting backups after FBI complained

#479

Earlier quoted context omitted.

There's no disinformation in my comments. I seem to be one of the few people on the planet who seems to have actually dug into this exact issue while others only offer the typical FUD we've seen about how Apple's encryption works in China. The fact is that Apple has said multiple times (and even under oath) that end-to-end encryption applies to iPhones and iMessage in China, the same as it does everywhere else. And o…

> In fact I seem to be one of the few people on the planet who seems to have actually dug into this exact issue while others only offer the typical FUD we've seen about how Apple's encryption works in China. I think instead of researching how Apple works in China, you need to start doing some research on how the Chinese government works and their track record on legal matters and rule of law. Also, the segment in the…

The question and his answer were both completely clear. And most importantly, it's perfectly consistent with what Apple has said multiple times. You can believe they lied to a federal court and Congress if you want, but I certainly don't.

Re: Apple dropped plan for encrypting backups after FBI complained

#480

Earlier quoted context omitted.

Apple may still be controlling the encryption keys but this says nothing about sharing the keys if compelled to do so. > Can you quote the part of the article that states that Apple must give China private keys? Can you find a citation where a third party has found proof that Apple changed the iMessage architecture? Apple is smarter than to put some text on their official website saying that the Chinese government ha…

How can Apple share private keys it doesn’t have access to? Apple doesn’t control “private keys” you use to encrypt data. The keys wouldn’t be very private if that were the case. The entire idea behind public/private keys is that you keep access to your private key.

You need to take a step back, take off your engineering hat, and realize that the issue is not about private keys. This is about a company (Apple) needing to follow the laws of the country that it operates in or else it is banned. It doesn't matter if Apple was selling bread or handbags, they MUST provide the government with data about their customers when compelled. This is the case with all companies operating in China, foreign or domestic.
Post reply on HN