It would be interesting to know how that data breaks down -- like photos vs videos vs software backups vs saved movies, etc. I assume that most people stream movies, TV shows, and music these days, and that few people save them to disk. And even for those that do, Apple could deduplicate (i.e., store exactly one copy of Men in Black even if 100,000 people saved it). Software installs are easily deduplicated as well.…
Apple Reportedly Storing over 8M Terabytes of iCloud Data on Google Servers
71–80 of 229 posts
Re: Apple Reportedly Storing over 8M Terabytes of iCloud Data on Google Servers
#72Earlier quoted context omitted.
Let's say Eve was working at Google with access to the ciphertext and io traffic, and was a jealous lover to a iPhone user Alice. They could be interested in profiling IM app usage, to know about size profile of content (pictures?) were stored at what times to know about Alice's activity profile when out of sight. They could also be interested in fingerprinting apps used so they could be matched to for example differ…
How are you going to figure out a specific user's content size (of a specific app or content type) from a sea of encrypted exabytes? What about this is practical?
Anyway, there are many scenarios that come to mind for knowing their IO sizes. Apps probably have IO fingerprints. Or you could send the set of suspected users differently sized files to probe them. Etc.
Re: Apple Reportedly Storing over 8M Terabytes of iCloud Data on Google Servers
#73Earlier quoted context omitted.
> Highly doubt Google has access to any iCloud data other than an estimate of the immense size of the service. They do of course have access to the ciphertext and access to traffic patterns, in crypto threat models traffic analysis tells the adversary a wealth of information.
Very true when each user is accessing its own encrypted data directly. But from what I read here in the comments, Apple is managing encryption on their own HW, which almost surely means that data is read and wrote from Apple’s machines. Such aggregation of read and write calls across users makes access traffic patterns analyses risk fairly minimal...
Re: Apple Reportedly Storing over 8M Terabytes of iCloud Data on Google Servers
#74How much would you pay to store such amount data? 8TB hard drive is about 200 dollars nowadays, so this amount of data is about 200m dollars worthy of retail hard drives. Ofc the calculation is super inaccurate, which doesn't take redundancies into consideration, and discounted prices for someone like Google to purchase hardware, plus the discount for Apple as a big customer. But had the scale be comparable, in which…
The article claims that Apple is on track to spend around $300 million on GCP storage services this year. With redundancies, server costs, and DC costs, the upfront price could easily touch 3 to 6 billion, or 10 to 20 years of GCP storage costs.
Surely it didn't cost GOOG $6B upfront worth of infrastructure to get $300M of annual revenue from Apple. Yes, there's economies of scale, but I think you overstate the case.
Re: Apple Reportedly Storing over 8M Terabytes of iCloud Data on Google Servers
#75Re: Apple Reportedly Storing over 8M Terabytes of iCloud Data on Google Servers
#76Earlier quoted context omitted.
You can’t do backup or sync the Photos.app to a random cloud. The “integration” here is just that occasionally you can save to and load from your server. That’s all.
I don't think you can do the full device backup on anything but icloud and I agree that should change but your own storage has the same access as google does on ios. You can have your own photos app which automatically uploads everything in the photo roll and can delete photos to keep them in sync with your cloud.
Re: Apple Reportedly Storing over 8M Terabytes of iCloud Data on Google Servers
#77Earlier quoted context omitted.
Same reason for we say 1000 km instead of 1 Mm, or Sun to Earth 150 M km instead of 150 Gm. Some units are usual in some contexts, some are not. In one word, habits.
> Same reason for we say 1000 km instead of 1 Mm Speak for yourself, I've been trying to popularise "1Mm" for years. Admittedly not with a huge amount of success. > or Sun to Earth 150 M km instead of 150 Gm Surely "1 AU" is the preferred form for this one.
The point would be to put it in a familiar unit, even though '150 million' isn't easy to visualize.
Re: Apple Reportedly Storing over 8M Terabytes of iCloud Data on Google Servers
#78Earlier quoted context omitted.
> Highly doubt Google has access to any iCloud data other than an estimate of the immense size of the service. They do of course have access to the ciphertext and access to traffic patterns, in crypto threat models traffic analysis tells the adversary a wealth of information.
Why would Google even attempt to spy on those patterns? it serves no purpose and how do you justify employee time spent for such useless things? Not to mention apple proxies all requests through their servers rendering such analysis utterly useless to begin with.
Re: Apple Reportedly Storing over 8M Terabytes of iCloud Data on Google Servers
#79Earlier quoted context omitted.
Unless you have encryption that is guaranteed to never be obsolete it ALWAYS matters where you store the data.
It does seem likely that Google will pay to store every bit of encrypted customer data that is currently stored forever because potentially decades from now it could be cracked and they could access all that amazing ancient private information.
Re: Apple Reportedly Storing over 8M Terabytes of iCloud Data on Google Servers
#80Earlier quoted context omitted.
How are you going to figure out a specific user's content size (of a specific app or content type) from a sea of encrypted exabytes? What about this is practical?
I'm just sketching something, I'm not claiming to have developed a vulnerability research result here from my arm chair. But there's a lot of terrain between "it's encrypted so there are no attack" and "you haven't presented a fully developed attack" especially about a system we don't know much about. Anyway, there are many scenarios that come to mind for knowing their IO sizes. Apps probably have IO fingerprints. Or…
I asked for practical examples. I don’t need an in-depth report to see that this doesn’t qualify.
Most of this crypto stuff is completely impractical risk, especially compared to some phishing emails.