Live data from Hacker News

Apple dropped plan for encrypting backups after FBI complained

reuters.com

701–710 of 734 posts

Re: Apple dropped plan for encrypting backups after FBI complained

#701

Earlier quoted context omitted.

The laws of the US say a lot of things. But the facts are that all the government has to do is scream “terrorism”, “drugs”, “or think about the children” and they can easily get a warrant. The law states that one branch of government has to ask another branch of government for a warrant. You have to believe that the judicial branch actually would safe guard privacy and keep law enforcement from overreaching.

> You have to believe that the judicial branch actually would safe guard privacy and keep law enforcement from overreaching. These warrants become public record. I don't have to blindly believe it. I can look at the records and see that the US is not even close to China as far as government access to user data.

These records become public record?

Unless the government screams “terrorism”. Ever heard of a FISA warrant?

https://www.ajc.com/news/national/what-fisa-warrant/WqP428Eg...

Re: Apple dropped plan for encrypting backups after FBI complained

#702

Earlier quoted context omitted.

The “key server” does not in fact “generate public keys”. It distributes public keys. But you can’t decrypt a message with public keys - that’s kind of the point... But after reading research from security experts you have found a citation where Apple is generating a key pair from its servers and sending the private key to the client?

> The “key server” does not in fact “generate public keys”. That's the point. It should not, but the security model of iMessage allows the key server to get away with it, which is almost certainly happening in China right now. Try reading the article and following the example. > But after reading research from security experts you have found a citation where Apple is generating a key pair from its servers and sending…

Again, if it Apple were in fact creating their own key pairs on their server and sending users the key pair, don’t you think someone would have discovered.

But since it’s in a Wikipedia article, I guess that kind of closes the case.

Re: Apple dropped plan for encrypting backups after FBI complained

#703

Earlier quoted context omitted.

How many countries have laws that state user data must not be in foreign data centers? Every company in the US has to comply when it’s ordered by the court to give up user data. The US justice system is not exactly a shining light on the hill when it comes to needing a high bar to give investigators search warrants. All someone has to do is say “terrorism”, “drugs” or “protect the children” and courts will fall over…

You're missing the point. From your quote: > Until now, Apple appears to have handed over very little data about Chinese users. From mid-2013 to mid-2017, Apple said it did not give customer account content to Chinese authorities, despite having received 176 requests, according to transparency reports published by the company. By moving iCloud data and keys to China, the amount of data Apple handed to Chinese authori…

The linked Rueters article quoted a statement where Apple said “they are still in control of the keys.”

Re: Apple dropped plan for encrypting backups after FBI complained

#704

What the... I was under the impression that iCloud backups are end-to-end encrypted. This is a HUGE problem.

I don’t understand. Am I just tired or misreading? The table on this page clearly shows backups are encrypted in transit and at rest... https://support.apple.com/en-us/HT202303

If it rains it gets wet outside. But if it's wet outside does not mean it's rained. This is an example of a recurring case where snakeoil and dishonest companies use this seemingly obvious logic puzzle, because people in general are bad at logic.

To answer your question directly. TLS encryption from your phone to apple's servers means they terminate encryption at the other end when they receive your data. This means "they decrypt the information that was in transit". Then they explicitly apply another encryption to the received and decrypted data before storing it on disk. Since these are two separate steps, you have no protection what-so-ever since apple will have a registry of all decryption keys for the disk backups that they'll happily use for whatever reason when they want to get hold of your data.

The only thing their disk encryption protects against is if someone were to walk away with the physical disks. It protects squat against the threats customers actually care about (unauthorized access to the data by someone other than the customer owning that data).

And seeing as they run on AWS, physical security means that the only way metal leaves the data center is if it's in millimeter sized shredded metal grain. So the threat model of concern here is exactly what apple has decided not to provide customers any protection against.

Re: Apple dropped plan for encrypting backups after FBI complained

#705
post #360

Earlier quoted context omitted.

Since when? I didn't see any such option in iTunes when I was trying last week (maybe it's because I'm using Windows?)

It's iPhone side; actually it's part of a settings reset: https://support.apple.com/en-us/HT205220#help

But can it be done without resetting all settings on the phone?

Re: Apple dropped plan for encrypting backups after FBI complained

#706
post #188

Earlier quoted context omitted.

None of what you said has anything to do with E2E encryption.

Yes it does. The password and other secret data can be sent in ways that are not end-to-end encrypted.

If the password is sent to the server and the data can be decrypted with the password then it's not end-to-end encrypted.

Re: Apple dropped plan for encrypting backups after FBI complained

#707

Earlier quoted context omitted.

If everything is being transferred off your device locally, why can't you use whatever backup arrangements you normally make for your other data? We already have a good, properly secured backup system that we use for all our workstations and servers. We just want to be able to export data from any mobile devices we use and manage that data using the same policies and tools. In most cases, that is straightforward. The…

“We already have a good, properly secured backup system that we use for all our workstations and servers” And this is the same myopic geek viewpoint that came out with the iPod “Less space than the Nomad. No wireless lame.” Do you actually believe that most people have a good backup solution at all? Is that really what you are suggesting for a general backup solution? That’s just like when DropBox was introduced and…

I'm not making any claim at all about "most people".

I'm saying that iCloud isn't properly encrypted, which for some people and organisations will be a problem, and that it is then a greater problem for those people and organisations that it is unusually difficult to transfer data between iOS devices and other systems through other means because of the inhibiting choices that Apple has made.

It's much like the argument that the default behaviour for consumer software should normally be to install security updates automatically, but installation of updates should still be configurable for those who do know what they're doing and need more control over their systems.

Re: Apple dropped plan for encrypting backups after FBI complained

#708
post #140

Earlier quoted context omitted.

You vote if you actually have a choice. What choice is there beyond Apple or Google in terms of smartphones? And I mean actual, ergonomic, everyday convenient choice -- my mother will firmly refuse me if I said "I'll buy you a phone but will have to tinker a full weekend to make it half-privacy-aware". And even if she was on board, she'll just yell at me if she can't do a basic task (this is a controversial topic aro…

> How can we really vote in a way that will make a difference? We (that is, tech users) have a choice, if we choose it. The ones who don't are the people who can't take that option (ie, your mother). You've stated as much. What is your choice today, as someone technically inclined? Well - you mentioned modded Android; but there are several other options, if you don't mind fiddling with things. More than a few phone o…

[deleted]

Re: Apple dropped plan for encrypting backups after FBI complained

#709

Earlier quoted context omitted.

“We already have a good, properly secured backup system that we use for all our workstations and servers” And this is the same myopic geek viewpoint that came out with the iPod “Less space than the Nomad. No wireless lame.” Do you actually believe that most people have a good backup solution at all? Is that really what you are suggesting for a general backup solution? That’s just like when DropBox was introduced and…

I'm not making any claim at all about "most people". I'm saying that iCloud isn't properly encrypted, which for some people and organisations will be a problem, and that it is then a greater problem for those people and organisations that it is unusually difficult to transfer data between iOS devices and other systems through other means because of the inhibiting choices that Apple has made. It's much like the argume…

If you’re part of an organization where security is important, you would force all of your employees to register with your MDM solution and prohibit any iCloud backups, you would probably have them using Office for iOS and tell them to save their files to OneDrive for Business and enable encryption.

I doubt many businesses are using iWorks with iCloud.

Re: Apple dropped plan for encrypting backups after FBI complained

#710
The small bit of iCloud E2EE which Apple allows (for health data, passwords and Mac-to-Mac clipboard sharing) is using your iPhone's 6-digit passcode and your Mac's admin password.

That means that Apple can also now perform an offline brute-force attack against your file vault password.

This makes even your offline devices less secure.

Post reply on HN