Live data from Hacker News

Apple dropped plan for encrypting backups after FBI complained

reuters.com

521–530 of 734 posts

Re: Apple dropped plan for encrypting backups after FBI complained

#521

Earlier quoted context omitted.

If only iTunes existed for Windows....

If only iTunes worked reliably on Windows and didn't have a long track record of bugs, subtle usability issues causing catastrophic data loss, connection problems where it doesn't detect the device properly... Let me know when iPhones and iPads support standard plug and play protocols that work universally without relying on either Apple's proprietary and frequently broken software or someone else's commercial altern…

So there is a standard plug and play protocol that supports everything that iTunes does?

iTunes hasn’t worked well on any platform in over a decade.

Re: Apple dropped plan for encrypting backups after FBI complained

#522

Earlier quoted context omitted.

I perfectly understand how public/private key encryption works. Can you find any citations to support your specific claims that Apple is sending user’s private keys from their devices and giving those keys to China?

Tell me how you think public/private keys helps Apple from skirting Chinese law that stipulates that they must provide access to user data.

It doesn’t by itself - but you have neither shown that Apple has surreptitiously uploaded user’s private keys in China or that it was required to do so.

Re: Apple dropped plan for encrypting backups after FBI complained

#523

Earlier quoted context omitted.

I've just read the article you linked[1], as well as several others [2][3][4] and cannot find any information about this: >all companies foreign or not must provide unencrypted access to data to the Chinese government and must do so in secrecy either plainly stated or implied. Can you provide a source for this claim? I don't doubt that this may occur, but I'd like to speak with _my own_ managers about my china & encr…

This is the most in-depth article I've seen on the topic: https://www.chinalawblog.com/2019/11/chinas-new-cryptography... .

Care to post which part of the article says that companies must give Chins user’s private keys?

Re: Apple dropped plan for encrypting backups after FBI complained

#524
Apple should allow third-party backup solutions. Backblaze is the option I would use if I had the choice, because they already support end-to-end encryption (end-to-end does have a downside: losing the encryption password means losing the data. Most people would make this tradeoff, but many HN readers would).

Re: Apple dropped plan for encrypting backups after FBI complained

#525

Earlier quoted context omitted.

Do you have any proof? Any citations from security experts?

It doesn't take Bruce Schneier to understand how laws work.

And you still haven’t provided proof that it is required or that Apple has uploaded users private keys or given up private keys.

Re: Apple dropped plan for encrypting backups after FBI complained

#526
post #230

Earlier quoted context omitted.

As someone who has bought into that meme I will admit this feels like a pretty huge betrayal by Apple. So, yes, I think if Apple sticks with this, their whole privacy stance is going in the toilet now. And a very dirty toilet it is. Beyond just the facts of not protecting data, there is also the deception. This is some really very, very, nasty stuff for Apple's brand and the reputation of every person who works at Ap…

There is a plausible argument that Apple needed to give a little in order to avoid the creation of laws against any encryption. And/Or also avoid laws that required a backdoor to everything. I know I'm going to be called a fanboy or too generous to Apple, but given that the government has used every opportunity to call out Apple for not helping (when they have helped where they could) there is a line here that Apple…

There's no way to legislate backdoors now. They tried and failed with Clipper.

The current status quo is good enough for the spooks. Zero regulation of data privacy allows third-party aggregators to do the desired collection activities without explicit government involvement. When they want something they know who to ask, warrant optional. Enacting laws that expose what the government is doing would risk a public backlash like the mass mobilization to deploy HTTPS.

Re: Apple dropped plan for encrypting backups after FBI complained

#527
post #296
post #271

Earlier quoted context omitted.

I might be mistaken but I thought Backblaze doesn't backup external drives?

There are a few possible approaches. I figured they're using b2. I'm pretty sure Synology has builtin tools to mirror to it. Backblaze will backup external drives that are attached to the computer, but if they are disconnected for 30+ days the data is deleted. While network drives aren't backed up there are ways to have them appear as local drives (which I hear are a pain to deal with).

> Synology has built in tools to mirror to it

Yes exactly, this is what I'm using. There is a time machine folder on the NAS, the Synology tool mirrors that encrypted folder to backblaze. I have the backblaze sync set to run at 1am so it's not uploading and affecting my bandwidth while I'm (typically) awake. Yes, my remote backup is up to 24 hours behind my local time machine backup, but this is acceptable to me since it's only for catastrophic recovery.

Re: Apple dropped plan for encrypting backups after FBI complained

#528
post #56

What the... I was under the impression that iCloud backups are end-to-end encrypted. This is a HUGE problem.

You should look into the 'borg' backup tool - it has become the de facto standard for remote backups because it does everything that rsync does (efficient, changes only backups) but also produces strongly encrypted remote backup sets that only you have a key to ... your cloud provider has no access to the data. The borg website is here: https://borgbackup.readthedocs.io/en/stable/ and a good description of how it wor…

How does this help with the context we're dealing with here: the iPhone (and other iDevices) being heavily encrypted/secure and iCloud not being secure?

Quickly looking at Borg's website (thanks for the heads up - great tool/option) I see it doesn't support iOS or backing up an iOS device.

I assume you're just suggesting it as a general purpose option for general backups on the desktop?

Re: Apple dropped plan for encrypting backups after FBI complained

#529

What the... I was under the impression that iCloud backups are end-to-end encrypted. This is a HUGE problem.

So here's the thing... Apple is able to recover your backups even if you forget your password. Therefore they can decrypt it without your password.

Re: Apple dropped plan for encrypting backups after FBI complained

#530

Earlier quoted context omitted.

Apple has never marketed the idea that iCloud backups are encrypted.

You need to be extremely technical to understand the difference between "Encryption: Yes" and not end-to-end encrypted. To the lay user, Apple is explicitly telling you that they're encrypted. See https://support.apple.com/en-us/HT202303 .

[deleted]
Post reply on HN