Live data from Hacker News

Apple dropped plan for encrypting backups after FBI complained

reuters.com

661–670 of 734 posts

Re: Apple dropped plan for encrypting backups after FBI complained

#661

Earlier quoted context omitted.

Arq for Mac is great for backing up, though the restore util could use a little work. It's not exactly user friendly. I've used it on my macs for years without any issues at all. I switched after Time Machine broke down for the n'th time in a month saying it needed to recreate the backup, and not once in the 3-5 years i've been using it has it every given me any problems with broken repositories, and every integrity…

> Duplicaty Did you mean Duplicacy or Duplicati?

Duplicati (https://www.duplicati.com/).

On my servers i use Borg like any sane person would, but the lack of a good client UI makes scheduling backups on a personal computer a lot more work than i'm willing to put in.

Re: Apple dropped plan for encrypting backups after FBI complained

#662
post #25

Earlier quoted context omitted.

Arguably making it harder for enforcement agency to do their jobs. I believe this is their burden to bear and work with, since privacy for every citizens is also important.

I agree that the resopnsibility is on the FBI to do investigation, but transitioning from a world where private documents are irretrievable without a warrant to one where they're structurally irretrievable because of mathematics and computational limitation would fundamentally alter the balance of power between society and individuals within that society in ways that society hasn't had to explore. It's something that…

Despite the media's breathlessness on the subject, and when aren't they breathless? There has not been a singe "24" style case where the FBI needed to unlock some phone in order to save a stadium full of people. It's always some after the fact circle-jerk on a phone where the perp already wiped all the data. It's them trying to gain the upper hand on us and get everything they want--shitty, back-doored encryption.

Re: Apple dropped plan for encrypting backups after FBI complained

#663

Earlier quoted context omitted.

From the same article: > That means Chinese authorities will no longer have to use the U.S. courts to seek information on iCloud users and can instead use their own legal system to ask Apple to hand over iCloud data for Chinese users, legal experts said. U.S. courts are highly unlikely to order Apple to release iCloud data to Chinese officials. Any cases would be public and attract international media attention. For…

How many countries have laws that state user data must not be in foreign data centers? Every company in the US has to comply when it’s ordered by the court to give up user data. The US justice system is not exactly a shining light on the hill when it comes to needing a high bar to give investigators search warrants. All someone has to do is say “terrorism”, “drugs” or “protect the children” and courts will fall over…

You're missing the point. From your quote:

> Until now, Apple appears to have handed over very little data about Chinese users. From mid-2013 to mid-2017, Apple said it did not give customer account content to Chinese authorities, despite having received 176 requests, according to transparency reports published by the company.

By moving iCloud data and keys to China, the amount of data Apple handed to Chinese authorities on Chinese iCloud users went from zero to a nonzero amount. Therefore, Apple degraded the security and privacy of Chinese iCloud users by making the switch to Chinese servers.

Due process is much more frequently ignored in China than in the United States, but that fact isn't even necessary to establish that Apple's switch to Chinese servers negatively affected Chinese iCloud users. The above is sufficient.

https://web.archive.org/web/20111019034145/http://www.law.ya...

Re: Apple dropped plan for encrypting backups after FBI complained

#664

Wonder if this will help to kill a meme, about how much Apple cares about users and what great values they have, how they're going to stand for the user, fight with governments, etc. While iPhone itself is pretty secure as a device phone (and Apple makes sure to remind you about that in each ad, public speaking, attacks on competitors, etc), as an ecosystem it's not secure. And it's like that on purpose - there's no…

> Wonder if this will help to kill a meme, about how much Apple cares about users and what great values they have, how they're going to stand for the user, fight with governments, etc.

I interpret this opinion as Black/White thinking or all-or-nothing thinking: https://en.wikipedia.org/wiki/Splitting_(psychology)

Re: Apple dropped plan for encrypting backups after FBI complained

#666
post #49

Earlier quoted context omitted.

> Didn't Apple publicly claim IIRC it said it wouldn't bow down on implementing back doors to unlock protected devices and encrypted content on them, which is specific enough not to cover this case. Bowing down on implementing new security features doesn't go against the promise to not bow down on the security of existing ones, as written. It can be argued to go against the spirit of the earlier public statement of c…

Except that this is a backdoor that circumvents device protections for the vast majority of users.

To quote spoc in ST-TWOK: "not a lie, an ommision".

It isn't a deliberately implemented backdoor. It is a deliberate decision to not install doors at all, just empty frames. I know we are arguing semantics here, and it doesn't make it right, but it doesn't go against the letter of how they've claimed they'll behave.

Re: Apple dropped plan for encrypting backups after FBI complained

#667
post #600

Earlier quoted context omitted.

> Apple has a balance to strike between the issues of encryption, privacy, and law enforcement [...] No, they do not. If Apple wants a reputation for privacy and respecting its customers, then it has to put them first. Don't apologize for them making this user-hostile choice. We could be merely a generation away from the hell hole that is social credit. We can't afford to keep ceding ground on privacy. We have to eng…

> We could be merely a generation away from the hell hole that is social credit. I fear we have one foot there already. If you are so inclined, you can dig up a lot of dox on most people, all freely given to social media, or via scrapers like Spokeo. I guess it's all still optional, kinda. And there is no centralized clearinghouse. But it is scary.

Not to worry, you are free to post on Yandex, “down with Trump,” and you are free to post on Facebook, “down with Trump”.

Re: Apple dropped plan for encrypting backups after FBI complained

#668

Earlier quoted context omitted.

Yeah, I always verify the hashes of updated binaries match what I compile myself in parallel. Also that takes too much time so I just never update anything and have a homebrew version of 'Damn Vulnerable Linux'. /s

Long-term, there may eventually come a solution to this problem in the form of [binary transparency]( https://wiki.mozilla.org/Security/Binary_Transparency ). However, we're obviously a long way away from that being the norm, and there's still the problem of supply-chain attacks on hardware to consider.

Not that long way off: Debian is currently already 94% reproducible https://tests.reproducible-builds.org/debian/reproducible.ht...

https://reproducible-builds.org/

Re: Apple dropped plan for encrypting backups after FBI complained

#669
post #575

Earlier quoted context omitted.

I think the overlooked answer in this conversation is that Apple doesn't need to modify their service for China at all. In in all countries, they hold the encryption keys for most user data. Only these things are E2E encrypted[1]: Home data Health data (requires iOS 12 or later) iCloud Keychain (includes all of your saved accounts and passwords) Payment information QuickType Keyboard learned vocabulary (requires iOS…

Or you can specifically turn off iCloud for iMessages in settings....

[deleted]

Re: Apple dropped plan for encrypting backups after FBI complained

#670

Earlier quoted context omitted.

Involved isn’t the same as guaranteed. I think commenters here are arguing that Apple isn’t being honest about what is available to law enforcement. My guess would be silent updates targeted at individual users who they have search warrants against.

The list of E2E above is quite transparent. The notion of building a special version of the OS to target an individual is just not how the infrastructure works, and totally goes against the entire spirit of privacy that pervades everything you do internally.

Sorry to be blunt (and I am a big fan of Apple's pro-privacy shift of late) but nobody outside Apple can know that with any certainty.

Even the 2016 blackhat talk on youtube, which describes an elaborate signing mechanism for updates, doesn't preclude shipping targeted OS updates to individual users. Maybe I missed something though, and in that case I'd appreciate you pointing it out.

Post reply on HN