Earlier quoted context omitted.
If backups aren't encrypted, then neither is your device
You can back them up locally.
Apple dropped plan for encrypting backups after FBI complained
621–630 of 734 posts
Re: Apple dropped plan for encrypting backups after FBI complained
#622Earlier quoted context omitted.
Because if you turn on iCloud backup, Apple might give it to the FBI. (Which is the whole topic of this article...)
Right, so don't backup your phone, on iCloud or anywhere else. Use another cloud service to store your files and only sync to your phone, don't back it up.
Re: Apple dropped plan for encrypting backups after FBI complained
#623Earlier quoted context omitted.
There are two things that make this problem “hard” if not “intractable”. Encryption keys are precise integer values (or can be represented as such) and they gain a large part of their security from two facts; a key that is wrong by even one bit will appear totally wrong / disclose zero information, and two, the key space is unfathomably large. To turn a fingerprint directly into an encryption key would require first;…
I found some research on fingerprints [1]. At 512 dpi fingerprint sensors have 0.01 bits per pixel of information mutual between samples but still individual, meaning that 160x160 sensors can give 256 bits of information usable for keys. And there are multiple fingers, so it seems enough to derive an encryption key from and even some room for redundancy. Refreshing it every few years isn't a big deal (as obviously no…
It doesn’t seem like you read my reply at all.
It’s not a question of raw entropy from the sensor, which is what the paper is discussing. It’s an issue of repeatability.
Re: Apple dropped plan for encrypting backups after FBI complained
#624Earlier quoted context omitted.
> Wonder if this will help to kill a meme, aboyt how much Apple cares about users and what great values they have, how they're going to stand for the user, fight with governments, etc. In this instance, Apple decided to continue to not encrypt iCloud backups because, according to one source, > […] the company did not want to risk being attacked by public officials for protecting criminals, sued for moving previously…
>Most people, including technically knowledgable users here on HN, were unaware iCloud backups have always been unencrypted. iCloud backups are definitely encrypted. They just aren't end-to-end encrypted. That should have been plainly obvious to any technically knowledgeable user because you don't lose your data forever when you forget your Apple ID password. Or the fact that you can see your photos through a web bro…
You could build a system where there's a key stored on each of your devices, and your password also acts like a key. In that case, you could
- Lose all your devices, but unlock with password
- Forget your password, but unlock with any device
- Lose one device, but unlock with your password or any other device
Of course, most people's passwords would probably be way to weak, no matter how much time Apple spends stretching it into a key, but for people who use a decent password this would be fairly secure.
Re: Apple dropped plan for encrypting backups after FBI complained
#625Earlier quoted context omitted.
Yeah, but what are the reasonable alternatives? Android, with its freewheeling stance on privacy and app permissions? Do they even let you disable location tracking any more?
No, but Android/Google doesn't go out and advertise themselves as a privacy first company.
I mean if they started tracking your behavour and location, and mining it to better sell ads, maybe that would.
Re: Apple dropped plan for encrypting backups after FBI complained
#626Earlier quoted context omitted.
Apple has never marketed the idea that iCloud backups are encrypted.
Apple did market to users that it was technically incapable of helping unlock iPhones. After the FBI showed that Apple technically can do so, that marketing disappeared very quickly. https://www.nbcnews.com/tech/security/ios-8-even-apple-cant-...
I believe Apple changed how operating system updates were installed after this point so that they did not have the capability to upgrade the phone's operating system without access to the device passcode.
Re: Apple dropped plan for encrypting backups after FBI complained
#627Earlier quoted context omitted.
> there's no good and easy option to backup your phone other than iCloud. Just plug your phone, click "Backup up". You don't even have to open iTunes anymore, just open "Finder" window. Can't be easier than that.
Tell that to us Windows and Linux people
Re: Apple dropped plan for encrypting backups after FBI complained
#628The iCloud security overview [1] says iCloud backups are encrypted "in transit" and "on server", but indeed doesn't say much about the encryption keys. There is "end-to-end encryption" on just a few items (iCloud keychain, WiFi passwords, etc.) 1. https://support.apple.com/en-us/HT202303
Re: Apple dropped plan for encrypting backups after FBI complained
#629Earlier quoted context omitted.
You should look into the 'borg' backup tool - it has become the de facto standard for remote backups because it does everything that rsync does (efficient, changes only backups) but also produces strongly encrypted remote backup sets that only you have a key to ... your cloud provider has no access to the data. The borg website is here: https://borgbackup.readthedocs.io/en/stable/ and a good description of how it wor…
After looking at a few alternatives (Borg, Duplicacy etc.), I setup Arq on my Mac yesterday. One thing that irks me about these solutions is that they seem to scan my folders each time they want to backup. Are there tools that are smarter about this? For e.g., while running, they could keep a log of what's changing and only scan those while backing up.
I've used it on my macs for years without any issues at all. I switched after Time Machine broke down for the n'th time in a month saying it needed to recreate the backup, and not once in the 3-5 years i've been using it has it every given me any problems with broken repositories, and every integrity check/restore has succeeded.
Arq on Windows is a different beast though. I'm sure it's technically solid, but the UI leaves a lot to be desired. On windows boxes i default to Duplicaty.
Re: Apple dropped plan for encrypting backups after FBI complained
#630Earlier quoted context omitted.
That’s only for devices where the region is set as China. Why would it be a moot point elsewhere for that reason?
"It's not happening in my country" is a naive argument. You might not care if human rights activists and HK protesters are affected. But Apple's actions in China set a precedent for other countries to follow. If a country demands that Apple "comply with local laws" by providing encryption keys or else risk losing access to that marketplace, Apple will comply, regardless of its effect on user privacy.
I didn't say that Apple is right to do it in China or elsewhere. I merely pointed out that it's happening in one place and asked why that would make it moot elsewhere. I agree with everything you said except for the phrasing of your first sentence.