Live data from Hacker News

Apple dropped plan for encrypting backups after FBI complained

reuters.com

551–560 of 734 posts

Re: Apple dropped plan for encrypting backups after FBI complained

#551

Earlier quoted context omitted.

There's no disinformation in my comments. I seem to be one of the few people on the planet who seems to have actually dug into this exact issue while others only offer the typical FUD we've seen about how Apple's encryption works in China. The fact is that Apple has said multiple times (and even under oath) that end-to-end encryption applies to iPhones and iMessage in China, the same as it does everywhere else. And o…

> In fact I seem to be one of the few people on the planet who seems to have actually dug into this exact issue while others only offer the typical FUD we've seen about how Apple's encryption works in China. I think instead of researching how Apple works in China, you need to start doing some research on how the Chinese government works and their track record on legal matters and rule of law. Also, the segment in the…

I think there might be misunderstanding about what exactly is "encrypted" and how. The comment 3 or 4 levels above says:

> The same "vulnerability" of being able to respond to legal requests for iCloud data that exists in China exists everywhere else in the world.

And an article on Apple's site [1] confirms that most data in the cloud are "encrypted", but without E2E encryption, possibly in a reversible way. That article also notes that while messages are E2E encrypted, a cloud backup might contain a key to decrypt them:

> Messages in iCloud also uses end-to-end encryption. If you have iCloud Backup turned on, your backup includes a copy of the key protecting your Messages. This ensures you can recover your Messages if you lose access to iCloud Keychain and your trusted devices.

So it is possible that the data on the phone are encrypted, the data in transit are encrypted, the data in the cloud are encrypted for every user in the world, but the cloud operator has the encryption keys for some of the encrypted data: Chinese operator for data of Chinese users and Apple for everyone else. This doesn't contradict neither with Apple's statement nor with the article nor with that comment above.

[1] https://support.apple.com/en-us/HT202303

Re: Apple dropped plan for encrypting backups after FBI complained

#552

Earlier quoted context omitted.

I have not changed the subject. Apple clearly delineates which data is e2e encrypted and which data is not. Those same standards apply in the US and China - unless you have evidence otherwise. I no more trust my privacy to the US government than a Chinese citizen should trust China.

> I have not changed the subject. You started this thread by responding to somebody discussing the Chinese government's access to all iCloud data, but you changed the subject to talk about systems where the private key is on device, which does not apply to iCloud. You absolutely did change the subject. > Those same standards apply in the US and China - unless you have evidence otherwise. Those same standards don't ac…

You started this thread by responding to somebody discussing the Chinese government's access to all iCloud data

If some of the data is e2e encrypted using private keys,China doesn’t have access to “all data”

Those same standards don't actually protect your data from whoever controls the iCloud server or whoever controls the iMessage key server.

If the private key is generated by the same entity or “key server” that generates the public key, and then transmitted to the client. That kind of defeats the entire purpose of public/private key encryption.

I’ve never seen an implementation of public/private key encryption where the client device doesn’t create the key pair and send only the public key to encrypt data.

Re: Apple dropped plan for encrypting backups after FBI complained

#553

Earlier quoted context omitted.

I thought iMessage private keys are somehow based on data in the "secure enclave" chip, and thus not able to be stored in the cloud. It's my understanding that Apple could add new "devices" to listen in on future conversations, but it can't read iMessage conversations in transit between existing devices. It can also read iCloud backups of conversation content, which are created by the client device after decrypting t…

Unsubscribing procedure seems however pretty acceptable > Messages in iCloud also uses end-to-end encryption. If you have iCloud Backup turned on, your backup includes a copy of the key protecting your Messages. This ensures you can recover your Messages if you lose access to iCloud Keychain and your trusted devices. When you turn off iCloud Backup, a new key is generated on your device to protect future messages and…

> But wait does it mean that if you haven't iCloud backup activated but use local backup you can actually sync message without storing private key

iMessage doesn’t use the backup for syncing. If you want to sync then both devices need to be logged into your account.

You can turn off iCloud backup for messages (with or without a local backup).

Re: Apple dropped plan for encrypting backups after FBI complained

#554

Earlier quoted context omitted.

So there is a standard plug and play protocol that supports everything that iTunes does? iTunes hasn’t worked well on any platform in over a decade.

Is there a specialised protocol for all types of data stored on iOS devices? Probably not. But plenty of other models of phone, tablet, camera and other data-processing devices manage to communicate just fine with Windows (or Linux or macOS) using generic protocols as USB mass storage devices, there is little excuse for iOS devices not to. In fact, you actually can download your photos and videos from an iPhone to a…

So while it is “communicating” with iPhones. What exactly is it suppose to communicate over standard protocols that would alleviate the need for an application and still perform all of the functions of iTunes?

What other devices perform all of the backup, restore, and os upgrade, functionality of iTunes.

The iPhone doesn’t use the standard “usb mass storage” protocol to allow you to download pictures. It uses the picture transfer protocol.

Re: Apple dropped plan for encrypting backups after FBI complained

#555
post #230

Earlier quoted context omitted.

As someone who has bought into that meme I will admit this feels like a pretty huge betrayal by Apple. So, yes, I think if Apple sticks with this, their whole privacy stance is going in the toilet now. And a very dirty toilet it is. Beyond just the facts of not protecting data, there is also the deception. This is some really very, very, nasty stuff for Apple's brand and the reputation of every person who works at Ap…

Yeah, but what are the reasonable alternatives? Android, with its freewheeling stance on privacy and app permissions? Do they even let you disable location tracking any more?

My favorite apple deceptive practice: allowing you to think you have disabled Bluetooth, when all you have disabled is Your Own ability to use it. Merchant partners of apple can use it to finely track you.

Re: Apple dropped plan for encrypting backups after FBI complained

#557
post #544

Earlier quoted context omitted.

Sure, but if iOS was open enough, users who cared could use some third party online backup that was actually secure. And it could rely on an app that users could obtain, regardless of whether it was legal or not.

The iPhone is plenty open for this. You just need a computer. The rest is fully open source. https://www.libimobiledevice.org/

Does this work with current iOS?

And it's not remote, and you must connect via USB-C, right?

Re: Apple dropped plan for encrypting backups after FBI complained

#558

Earlier quoted context omitted.

Taking this argument to its logical conclusion, you can't trust eating food someone grew for profit, riding in a car someone built for profit, wearing clothes someone made for profit… Under capitalism, encouraging repeat business from a customer is a successful long-term strategy, and maintaining customer satisfaction by not selling them food that will make them sick, cars that have faulty brakes, clothes that deteri…

> Taking this argument to its logical conclusion, you can't trust eating food someone grew for profit, riding in a car someone built for profit, wearing clothes someone made for profit… Indeed, that's why customer protection laws exist. > So if I purchase a product from a company that's been around for a while, I can have a reasonable expectation - a trust - that that product will be of some quality. That's pretty na…

It's really a matter of market efficiency, where efficiency is dictated by how much information is available. In a market where information is accurate and timely, companies cannot abuse customer trust because doing so for anything the customer cares about will result in them valuing that company and its products less. Different industries have different levels of information available, making it easier or harder to depend on what they say or show.

Apple is specifically hard to reason about because some aspect of their value is based on their products being a status symbol, and some value is based on their functionality (this is true to a degree for most products, but is skewed quite high in the status symbol ratio for a tech product for Apple).

On the one hand, Apple has been fairly straightforward in their communication and not lied often, and also has a business model that has less conflicting interests when it comes to consumer privacy, but at the same time they could conceivably get away with more because of their position as a status symbol.

What this means for me is that I take Apple's claims about consumer protection fairly seriously in most cases, but for anything important I would not rely on them. They've banked a lot of good will, and at some point they might see it as worthwhile to make a withdrawal on it (if they hopefully haven't already), and I would rather not be in a poor position if/when that happens.

Re: Apple dropped plan for encrypting backups after FBI complained

#559

Earlier quoted context omitted.

If you scroll down another line you'll see another section titled: End-to-end encrypted data

When the very first line of that table tells people that iCloud Backups are encrypted on the server... to then have the last few lines add effectively "Oh, but not end to end!" is just taking the piss.

You're absolutely right. They could have definitely misled anyone that didn't read the entire support article, including the first paragraph under Data Security:

>iCloud secures your information by encrypting it when it's in transit, storing it in iCloud in an encrypted format, and using secure tokens for authentication. For certain sensitive information, Apple uses end-to-end encryption. This means that only you can access your information, and only on devices where you’re signed into iCloud. No one else, not even Apple, can access end-to-end encrypted information.

Re: Apple dropped plan for encrypting backups after FBI complained

#560

Earlier quoted context omitted.

I know you're being cheeky and pedantic, but that's exactly the spin the title was trying to go for in order to get clicks. While not "technically" wrong, it's still pretty dishonest imo.

"Apple dropped plan for encrypting backups after release of 'National Treasure 2', starring Nicholas Cage"

I would read the hell out of that article.
Post reply on HN