Live data from Hacker News

Apple dropped plan for encrypting backups after FBI complained

reuters.com

651–660 of 734 posts

Re: Apple dropped plan for encrypting backups after FBI complained

#651

Earlier quoted context omitted.

But isn’t morality universal?

Morality is defined by culture, so there is no "universal" morality as such. However, there are certain specific things that are included in almost all moral frameworks.

‘There is no absolute’ (except for this statement) always amuses me.

Re: Apple dropped plan for encrypting backups after FBI complained

#652
post #528
post #56

Earlier quoted context omitted.

You should look into the 'borg' backup tool - it has become the de facto standard for remote backups because it does everything that rsync does (efficient, changes only backups) but also produces strongly encrypted remote backup sets that only you have a key to ... your cloud provider has no access to the data. The borg website is here: https://borgbackup.readthedocs.io/en/stable/ and a good description of how it wor…

How does this help with the context we're dealing with here: the iPhone (and other iDevices) being heavily encrypted/secure and iCloud not being secure? Quickly looking at Borg's website (thanks for the heads up - great tool/option) I see it doesn't support iOS or backing up an iOS device. I assume you're just suggesting it as a general purpose option for general backups on the desktop?

Maybe backup to desktop and then Borg.

I wonder how efficient Borg would be with this setup.

Re: Apple dropped plan for encrypting backups after FBI complained

#653

Earlier quoted context omitted.

echelon did not claim to be someone who takes a principled stand on global poverty, health, or factory farming. https://en.wikipedia.org/wiki/Straw_man Meanwhile, Apple says: > Privacy is a fundamental human right. At Apple, it’s also one of our core values. Your devices are important to so many parts of your life. What you share from those experiences, and who you share it with, should be up to you. We design Apple…

Somehow it seems like you have mistaken my comment for sarcasm. I wasn’t straw manning anyone, I was simply lauding a principled stand and articulating my desire to see that in more places. I certainly wasn’t defending Apple in this case.

My apologies. Smileys are sometimes used to show sarcasm, and it wasn't clear here.

Re: Apple dropped plan for encrypting backups after FBI complained

#654

Earlier quoted context omitted.

Apple says the joint venture does not mean that China has any kind of “backdoor” into user data and that Apple alone – not its Chinese partner – will control the encryption keys. But Chinese customers will notice some differences from the start: their iCloud accounts will now be co-branded with the name of the local partner, a first for Apple.

From the same article: > That means Chinese authorities will no longer have to use the U.S. courts to seek information on iCloud users and can instead use their own legal system to ask Apple to hand over iCloud data for Chinese users, legal experts said. U.S. courts are highly unlikely to order Apple to release iCloud data to Chinese officials. Any cases would be public and attract international media attention. For…

How many countries have laws that state user data must not be in foreign data centers?

Every company in the US has to comply when it’s ordered by the court to give up user data. The US justice system is not exactly a shining light on the hill when it comes to needing a high bar to give investigators search warrants. All someone has to do is say “terrorism”, “drugs” or “protect the children” and courts will fall over backwards.

Also from the same article:

Until now, Apple appears to have handed over very little data about Chinese users. From mid-2013 to mid-2017, Apple said it did not give customer account content to Chinese authorities, despite having received 176 requests, according to transparency reports published by the company. By contrast, Apple has given the United States customer account content in response to 2,366 out of 8,475 government requests.

You have much more faith in the US justice system than I do.

Re: Apple dropped plan for encrypting backups after FBI complained

#655
post #165
post #56

Earlier quoted context omitted.

You should look into the 'borg' backup tool - it has become the de facto standard for remote backups because it does everything that rsync does (efficient, changes only backups) but also produces strongly encrypted remote backup sets that only you have a key to ... your cloud provider has no access to the data. The borg website is here: https://borgbackup.readthedocs.io/en/stable/ and a good description of how it wor…

Are there any advantages of using borg over rclone?

Yes.

Rclone simply copies data. If you `sync` `~/Documents` to your remote it will keep an exact copy.

This is a simple backup since you only have one version. Anything deleted, the next time it syncs, gets deleted.

Borg is a backup tool. Versioning is at its core. It does that efficiently by deduplicating file (chunks really) even if they’re not in the same location.

So with Borg, if you create a backup 1 of `~/Documents` today and a backup 2 tomorrow of `~/Documents` you can see both backups and work with each snapshot. The size it takes should be close to the amount of data changed in the whole source.

If you move directories or files inside, rclone has to reupload them. Borg detects but doesn’t have to store it again.

With rclone some remotes have versioning (Google Drive, Dropbox). This could help in this case, but it depends on the remote. With Borg this is built in and you can change the underlying storage and migrate without loosing any data. Using versioning with crypt would probably be a pain too due to the file names. Not sure if rclone has commands/flags to help with this that I simply don’t know about.

Re: Apple dropped plan for encrypting backups after FBI complained

#656

Earlier quoted context omitted.

I have not changed the subject. Apple clearly delineates which data is e2e encrypted and which data is not. Those same standards apply in the US and China - unless you have evidence otherwise. I no more trust my privacy to the US government than a Chinese citizen should trust China.

> I have not changed the subject. You started this thread by responding to somebody discussing the Chinese government's access to all iCloud data, but you changed the subject to talk about systems where the private key is on device, which does not apply to iCloud. You absolutely did change the subject. > Those same standards apply in the US and China - unless you have evidence otherwise. Those same standards don't ac…

The laws of the US say a lot of things. But the facts are that all the government has to do is scream “terrorism”, “drugs”, “or think about the children” and they can easily get a warrant. The law states that one branch of government has to ask another branch of government for a warrant. You have to believe that the judicial branch actually would safe guard privacy and keep law enforcement from overreaching.

Re: Apple dropped plan for encrypting backups after FBI complained

#657

Earlier quoted context omitted.

Can you explain how this works? I'm assuming my IPhone itself is encrypted with my own password (or thumbprint) and that Apple could absolutely not get into it without that thumbprint. But when you send a backup, it's decrypted, sent to Apple, and then re-encrypted with a key that Apple controls, and has nothing to do with any of the "things I personally know"? IOW, I couldn't myself decrypt my Apple backup stored on…

Apple can't comply with a law enforcement request to get into your iPhone. They can comply with anything in your iCloud Backup except for the things under End-to-end encrypted data on this page [1]. Backups are encrypted "in transit" and "at rest", but Apple retains a key. That's how they can comply with legal requests and how you can restore your data if you forget your password. [1] https://support.apple.com/en-us/…

My computer, or theirs.

My phone, my data.

Back up my data to their computer, their control.

This is perfect plausible deniability for them.

"Hey, we gave them a secure device. But they chose to upload their data to us, and we made it clear how we handle it in our terms of service."

Which it is.

Re: Apple dropped plan for encrypting backups after FBI complained

#658

Earlier quoted context omitted.

> Wonder if this will help to kill a meme, aboyt how much Apple cares about users and what great values they have, how they're going to stand for the user, fight with governments, etc. In this instance, Apple decided to continue to not encrypt iCloud backups because, according to one source, > […] the company did not want to risk being attacked by public officials for protecting criminals, sued for moving previously…

It's one thing for them to not encrypt the backups, its another thing to go out of their way to include the iMessage private key in the backup, which completely undermines iMessage E2E for 99% of users.

I’m not defending it, but they kindof have to if you want to recover your messages if you forget your password.

Re: Apple dropped plan for encrypting backups after FBI complained

#659

Earlier quoted context omitted.

If backups aren't encrypted, then neither is your device

But backups to iCloud are optional. Apple has to strike a balance. This is cliche as can be, but the trade off is security for convenience. Fact is, iOS is consumed largely by people who want convenience. They don’t want to lose all of their data if they forget their passwords. But for those people who are ok with that type of unforgiving paradigm, then don’t use iCloud backups, and you’re all set.

> Apple has to strike a balance.

I see this in the thread. What does that mean? Do they have to? Are they being forced? What is the balance between?

Why aren't iCloud backups e2e encrypted?

Re: Apple dropped plan for encrypting backups after FBI complained

#660

What the... I was under the impression that iCloud backups are end-to-end encrypted. This is a HUGE problem.

I don’t understand. Am I just tired or misreading? The table on this page clearly shows backups are encrypted in transit and at rest... https://support.apple.com/en-us/HT202303
Post reply on HN