Earlier quoted context omitted.
> I have not changed the subject. You started this thread by responding to somebody discussing the Chinese government's access to all iCloud data, but you changed the subject to talk about systems where the private key is on device, which does not apply to iCloud. You absolutely did change the subject. > Those same standards apply in the US and China - unless you have evidence otherwise. Those same standards don't ac…
You started this thread by responding to somebody discussing the Chinese government's access to all iCloud data If some of the data is e2e encrypted using private keys,China doesn’t have access to “all data” Those same standards don't actually protect your data from whoever controls the iCloud server or whoever controls the iMessage key server. If the private key is generated by the same entity or “key server” that g…
You have two mistakes in this sentence.
1. None of the iCloud data (mail, docs, drive, etc.) is E2E encrypted. Some of the data stored in iCloud (like keychain backups) is encrypted prior to being sent to iCloud (using symmetric encryption, not with asymmetric key pairs). China has access to the data that was ultimately sent to iCloud.
2. The way Apple implements E2E encryption for services like iMessage that are E2E encrypted allows China access to that data.
> If the private key is generated by the same entity or “key server” that generates the public key, and then transmitted to the client.
That's the point. Since Apple's implementation relies on a key server to distribute public keys, it is straightforward for the key server to generate its own key pair and serve a fraudulent public key to the recipient, decrypting and re-encrypting messages that the iMessage servers relay. Apple relies on the technical illiteracy of its users to get away with its deceptive and often plain false marketing claims. Now you know better.