Wonder if this will help to kill a meme, about how much Apple cares about users and what great values they have, how they're going to stand for the user, fight with governments, etc. While iPhone itself is pretty secure as a device phone (and Apple makes sure to remind you about that in each ad, public speaking, attacks on competitors, etc), as an ecosystem it's not secure. And it's like that on purpose - there's no…
> Wonder if this will help to kill a meme, aboyt how much Apple cares about users and what great values they have, how they're going to stand for the user, fight with governments, etc. In this instance, Apple decided to continue to not encrypt iCloud backups because, according to one source, > […] the company did not want to risk being attacked by public officials for protecting criminals, sued for moving previously…
Apple dropped plan for encrypting backups after FBI complained
541–550 of 734 posts
Re: Apple dropped plan for encrypting backups after FBI complained
#542We users are better off if Apple is "compromising" on something like this at the stage we're in now - especially since nobody forces you to use iCloud Backups - than we'll be when/if the US gov makes Apple an offer it can't refuse and forces a real backdoor master-key on the whole system top to bottom.
Assumption: That not going full encrypted backups will prevent the government from having the political capital to enact a "crackdown" forcing a backdoor on the devices, iMessage, etc.
Re: Apple dropped plan for encrypting backups after FBI complained
#543Earlier quoted context omitted.
That link says: Backup Encryption In Transit: Yes Backup Encryption On Server: Yes
So it seems like the data are encrypted both in transit and on the server and it means that nobody is able to get unencrypted data even if they can intercept the traffic or access the server.
That's no different from me offering a remote backup service on a LUKS encrypted box, using sftp or whatever, and then making those claims.
Re: Apple dropped plan for encrypting backups after FBI complained
#544Earlier quoted context omitted.
Sadly, I think you are absolutely correct. Lindsay said outright that either tech companies figure it out, or senate will do the figuring for them. I am not sure Apple made the right move, but.. average person does not seem to care and/or understand the ikplications. Now.. Apple could make them care. They are big enough to make waves and I am not certain goverment could deal with bad PR come election time. edit: corr…
Sure, but if iOS was open enough, users who cared could use some third party online backup that was actually secure. And it could rely on an app that users could obtain, regardless of whether it was legal or not.
Re: Apple dropped plan for encrypting backups after FBI complained
#545Earlier quoted context omitted.
That link says: Backup Encryption In Transit: Yes Backup Encryption On Server: Yes
So it seems like the data are encrypted both in transit and on the server and it means that nobody is able to get unencrypted data even if they can intercept the traffic or access the server.
Re: Apple dropped plan for encrypting backups after FBI complained
#546Earlier quoted context omitted.
> On the other hand, it's possible that because we have a smartphones duopoly, Apple only needs to maintain a position where people will say "well at least it's not as bad as Google". I'm upset about this personally, but I'm not ditching my iPhone. Of course, this does cement my decision to never pay for iCloud, for what that's worth (much less, but not nothing). Agreed, and I am likely going away from Android and in…
I'd argue that Android, without the Google stuff, is still the best option if you care about privacy and security. This is not accessible for average Joe, but I'm pretty certain the majority of readers here can use the tools to load an alternative ROM. That you can enable and use F-droid just fine. And are knowledgeable enough to know what apps to avoid.
eg GrapheneOS currently only supports Pixel 2, 3 and 3a:
Re: Apple dropped plan for encrypting backups after FBI complained
#547Earlier quoted context omitted.
The iCloud keys exist on the iCloud servers (which are under CCP control in China). That's how you can search your mail and documents from any device. If you want to change the subject and talk about iMessage instead of iCloud, the architecture of that system allows for the government to intercept all messages as well. https://www.wired.com/2015/09/apple-fighting-privacy-imessag...
I have not changed the subject. Apple clearly delineates which data is e2e encrypted and which data is not. Those same standards apply in the US and China - unless you have evidence otherwise. I no more trust my privacy to the US government than a Chinese citizen should trust China.
You started this thread by responding to somebody discussing the Chinese government's access to all iCloud data, but you changed the subject to talk about systems where the private key is on device, which does not apply to iCloud. You absolutely did change the subject.
> Those same standards apply in the US and China - unless you have evidence otherwise.
Those same standards don't actually protect your data from whoever controls the iCloud server or whoever controls the iMessage key server. In the US, that is Apple, so Apple has access to that data. In China, that is the Chinese government. Therefore, the Chinese government has access to all Chinese iCloud and iMessage data.
> I no more trust my privacy to the US government than a Chinese citizen should trust China.
Then you are unfamiliar with the laws of both countries.
Re: Apple dropped plan for encrypting backups after FBI complained
#548Earlier quoted context omitted.
It would be trivial for the Chinese gov't to sniff RAM or the bus and get everything they need anyways.
What exactly are they going to “sniff”? Private keys never leave your device.
Re: Apple dropped plan for encrypting backups after FBI complained
#549Earlier quoted context omitted.
If only iTunes worked reliably on Windows and didn't have a long track record of bugs, subtle usability issues causing catastrophic data loss, connection problems where it doesn't detect the device properly... Let me know when iPhones and iPads support standard plug and play protocols that work universally without relying on either Apple's proprietary and frequently broken software or someone else's commercial altern…
So there is a standard plug and play protocol that supports everything that iTunes does? iTunes hasn’t worked well on any platform in over a decade.
Re: Apple dropped plan for encrypting backups after FBI complained
#550Earlier quoted context omitted.
What exactly are they going to “sniff”? Private keys never leave your device.
The keys that encrypt the iCloud data are never on your device. They don't even need to sniff the keys. They control them.