Live data from Hacker News

Apple dropped plan for encrypting backups after FBI complained

reuters.com

481–490 of 734 posts

Re: Apple dropped plan for encrypting backups after FBI complained

#481

Earlier quoted context omitted.

>t's a common misconception that corporations are amoral incentive-driven machines impervious to ethics, morals or mission. Not really, those leaders are pretty quick to hide behind the corporate veil when it's convenient for dodging questions of moral (or even legal) responsibility. The whole point of corporate legal structure is to create an entity that is _separate_ from the humans that occupy offices. That entity…

> "That entity is not a person." the (current) supreme court doesn't agree, and their opinion carries a tad more weight. corporations are basically super-persons in the eyes of the court, since corporations intrinsically funnel the resources of its many consituents, unlike individuals. instead, any entity exerting outsized power, like corporations, should be held to higher standards of duty and transparency. that's a…

From a distance, to me it's interesting to read about fears of the FBI snooping in our phones and email, and see how quickly the discussion jolts to how immoral (or amoral) corporations are because one of them is not completely defying government.

Re: Apple dropped plan for encrypting backups after FBI complained

#482

Earlier quoted context omitted.

How can Apple share private keys it doesn’t have access to? Apple doesn’t control “private keys” you use to encrypt data. The keys wouldn’t be very private if that were the case. The entire idea behind public/private keys is that you keep access to your private key.

You need to take a step back, take off your engineering hat, and realize that the issue is not about private keys. This is about a company (Apple) needing to follow the laws of the country that it operates in or else it is banned. It doesn't matter if Apple was selling bread or handbags, they MUST provide the government with data about their customers when compelled. This is the case with all companies operating in C…

The only way it could follow the laws of the country would be to rearchitect its entire system and somehow send the private keys to its servers and save them.

While technically they could do that, do you realize how much legal trouble they would be in in the US if they did so without disclosing it?

Alternatively, they would have to have a special build of iOS for China.

Also, none of the “citations” make mention that the Chinese law forces Apple to give private keys to China.

Re: Apple dropped plan for encrypting backups after FBI complained

#483

Earlier quoted context omitted.

Technology is irrelevant here. Laws (or in China, the Chinese Communist Party) govern these things.

So technology is irrelevant when it comes to the entire architecture of how public/private key encryption works?

No. How the technology works is irrelevant when the end result is that the government wants the data.

If your boss asks you to build a machine that produces a widget, does he really care what your code looks like? Probably not. In the same vein, Apple can figure out whatever solution they want, whether it involves conventional use of encryption keys or not, to provide a system where the Chinese government can get access to their users' data.

It's really not that hard.

Re: Apple dropped plan for encrypting backups after FBI complained

#484

When will a startup enter into this space with a privacy focused smartphone? Does this already exist, and is it good? If not, why all the complaints and why hasn't someone entered the market? Obviously startup costs will be high, but there will certainly be funding available for this market, right?

Pine64 and Purism make devices that might fit that bill, but keep in mind that the devices may not be as user-friendly in their current state as you might hope for. There's still a lot of rough edges, I hear.

Re: Apple dropped plan for encrypting backups after FBI complained

#485

Earlier quoted context omitted.

True, but you do get wrung out for personal data in order to sell you ads. There is always that.

And do you believe that running Windows in a virtual machine prevents Microsoft from getting the telemetry data and who knows what else? While you're right that running Android does expose (some of) your data to advertisers, with Windows, we're not even sure what exactly is leaving your machine the last time I checked. Or are you suggesting that an average Linux user who wants to back up their iPhone needs to buy and…

I was just reacting to the iPhone vs Android element of your comment. Obviously you'd have to buy a $1000+ macbook to backup your iPhone.

Re: Apple dropped plan for encrypting backups after FBI complained

#486
post #206

> aboyt how much Apple cares about users No company cares about anything. A company is not a person. Apple, because of its privacy-marketing, is incentivized to be the privacy player in the market. But only so far as consumers keep them honest about it. They got away with this loophole because it stayed under the radar; if it gets enough attention and enough customers show that it matters to them, it could change. On…

Isn't Android at this point a more secure OS? The price for zero days at least is signaling that.

Theoretically, maybe, I have no idea. Realistically, not at all, considering that even flagship Android phones tend to receive updates with an insane delay (except Pixel ones), not even talking about non-flagships or any android phones that have been released 2+ years ago.

Last Android phone I have bought was Galaxy S8+, just a few months after the release. Had to wait about half a year (if not more) for the next major Android update after it had already dropped for Pixel devices.

Re: Apple dropped plan for encrypting backups after FBI complained

#487

Earlier quoted context omitted.

>Wonder if this will help to kill a meme, aboyt how much Apple cares about users and what great values they have, Probably not. The keyboards on their laptops are barely functional but it doesn't stop people from saying how great they are.

> The keyboards on their laptops are barely functional This must be some definition of "barely functional" I'm unfamiliar with. I've had a mid-2017 MBP since they were released. Yeah, I had to get the keyboard replaced when some keys failed after a year, but at least they did it for free. Actually, overall I prefer this keyboard to the 2013 I had previously. I think their failure rate is unacceptable, but they are ce…

It's heavily dependent on personal taste, but for example I make easily twice as many mistakes typing with the new keyboard than I did with the old keyboard, or any other keyboard I own, on other laptops or standalone.

I wouldn't call it "barely functional" either since I can clearly still type on that keyboard, but the combination of mechanical failure rate and personal accuracy issues means that I buy the MBP despite the keyboard.

Re: Apple dropped plan for encrypting backups after FBI complained

#488

Earlier quoted context omitted.

If you lose your device and buy a new one and restore your device with a back up, all your messages will be returned. There’s no way to accomplish this without having the private key in the backup. EDIT: When I say there is no way to accomplish this, I’m talking specifically about the process that exists today where the user doesn’t have to remember a password other than their iCloud password (which today, can also b…

Maybe we're talking about different private keys? To clarify, here's how I think it works: 1) To send you a new iMessage, someone else's iPhone Z encrypts it with your public key and sends it through the iMessage network. Apple can't read this message since they don't have your iMessage private key, which is only on your device. 2) Your iPhone A receives the encrypted iMessages and decrypts them with your iMessage pr…

You are right; Apple isn't storing your private key, they simply have access to an unencrypted dump of your iPhone at the time of iCloud backup creation. My comment implies that once you take a backup, Apple would have the ability to read all your future messages as well.

Re: Apple dropped plan for encrypting backups after FBI complained

#489

>there's no good and easy option to backup your phone other than iCloud. Turn off iCloud and do local encrypted backups to your PC or Mac. This works over your wifi network (if you prefer wireless charging at home) or via a cable connection.

This used to work great and is still my preferred method of back up, however for at least the past year it has been extremely unreliable. I have to manually load iTunes on my computer and initiate a back up from there because it never happens automatically anymore. And there’s no way to manually start the Wi-Fi backup from my iPhone anymore (that was removed in iOS 13). Maybe it’s more reliable if you use a Mac inste…

Worth mentioning iMazing by DigiDNA fixes a LOT of the issues around Apple's poor implementation of iOS PC/Mac support. You can use it to schedule automatic wireless local backups, among other things.

Re: Apple dropped plan for encrypting backups after FBI complained

#490

Earlier quoted context omitted.

> In fact I seem to be one of the few people on the planet who seems to have actually dug into this exact issue while others only offer the typical FUD we've seen about how Apple's encryption works in China. I think instead of researching how Apple works in China, you need to start doing some research on how the Chinese government works and their track record on legal matters and rule of law. Also, the segment in the…

The question and his answer were both completely clear. And most importantly, it's perfectly consistent with what Apple has said multiple times. You can believe they lied to a federal court and Congress if you want, but I certainly don't.

There is no lying here. Only poorly worded questions that are conveniently misguided to the benefit of Apple.
Post reply on HN