Live data from Hacker News

Apple dropped plan for encrypting backups after FBI complained (2020)

reuters.com

11–20 of 228 posts

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#11

This really is something Tim needs to address before he again stands on stage and give lip service to Privacy with a capital P. We also need hardball journalists to start asking Tim these tough questions instead of fawning over AirPods And we need employees to start demanding this internally

I think we are all throwing wrong questions at wrong entities. What we should ask is what the hell is going on and what is forcing everyone to implement backdoors in this organized manners.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#12
post #8

Don't use the cloud if you care about privacy, or encrypt the data yourself before uploading. Has always been the case.

The point is that offline content detection on data that will be uploaded to iCloud feels like a prelude to offline detection of all content on your device.

In fact, given that Apple do not E2E encrypt backups and already implement CSAM functionality by scanning data in iCloud [1] it's not clear what the purpose of the new PSI/CSAM system is. Which leads many to speculate that it's only purpose is as a prelude to scanning all offline content.

[1] https://nakedsecurity.sophos.com/2020/01/09/apples-scanning-...

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#13
post #10

Some have speculated that with the introduction of the PSI/CSAM system Apple will enable E2EE backups. Given the lack of an explicit statement on Apple's part and their history regarding E2EE backups (this article, and other statements). It seems really unlikely to me that Apple will enable E2EE backups. Under E2EE, assuming the device key is randomly generated, if you have one device (as many users do) and you lose…

There is a third option, which is to use secure elements in the datacenter to encrypt the device key with the user's screen lock code. The secure element prevents brute force attacks even with a low entropy passcode. The user can restore their backups on a fresh device only knowing their screen lock code, but backups remain end-to-end encrypted.

Google has done this for Android backups. Apple has actually done it too, but only for Keychain passwords and a couple of other things. So Apple actually already has an implementation of the right solution and intentionally prevents you from using it to secure your backups, reportedly because they failed to stand up to the FBI. Which is strange given their public stance in the San Bernardino case.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#14

This really is something Tim needs to address before he again stands on stage and give lip service to Privacy with a capital P. We also need hardball journalists to start asking Tim these tough questions instead of fawning over AirPods And we need employees to start demanding this internally

> This really is something Tim needs to address before he again stands on stage and give lip service to Privacy with a capital P.

Cui bono?

Why does Tim Cook need to address this? To benefit Apple shareholders? To assuage the doubts of Apple customers who bought the false claims that Apple has made regarding their respect for users privacy?

Truth be told I don't think that Tim Cook as CEO of one of the richest and most powerful organizations in history needs to do anything because Apple has their customers by the balls. What are the few Apple users who even care about this issue going to do? Switch to Microsoft? Linux? Hah!

Face it, Apple users have made their bed and now they have to lie in it. People have been warning them for years about the Faustian bargain that they were making and how it was corrosive to society to entrench an entity like Apple and now here we are.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#15
post #14

This really is something Tim needs to address before he again stands on stage and give lip service to Privacy with a capital P. We also need hardball journalists to start asking Tim these tough questions instead of fawning over AirPods And we need employees to start demanding this internally

> This really is something Tim needs to address before he again stands on stage and give lip service to Privacy with a capital P. Cui bono? Why does Tim Cook need to address this? To benefit Apple shareholders? To assuage the doubts of Apple customers who bought the false claims that Apple has made regarding their respect for users privacy? Truth be told I don't think that Tim Cook as CEO of one of the richest and mo…

> false claims that Apple has made regarding their respect for users privacy

What false claim have they made?

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#17
post #10

Some have speculated that with the introduction of the PSI/CSAM system Apple will enable E2EE backups. Given the lack of an explicit statement on Apple's part and their history regarding E2EE backups (this article, and other statements). It seems really unlikely to me that Apple will enable E2EE backups. Under E2EE, assuming the device key is randomly generated, if you have one device (as many users do) and you lose…

There is a third option, which is to use secure elements in the datacenter to encrypt the device key with the user's screen lock code. The secure element prevents brute force attacks even with a low entropy passcode. The user can restore their backups on a fresh device only knowing their screen lock code, but backups remain end-to-end encrypted. Google has done this for Android backups. Apple has actually done it too…

This still seems like it would require a significant change in functionality, which they would likely announce. I.e. lose your lock code, lose all your data. Also, are you going to enter your lock code online to browse photos in a browser? What about syncing between devices?

In the absence of an explicit announcement regarding these changes in functionality it seems unlikely to me.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#18

This really is something Tim needs to address before he again stands on stage and give lip service to Privacy with a capital P. We also need hardball journalists to start asking Tim these tough questions instead of fawning over AirPods And we need employees to start demanding this internally

> And we need employees to start demanding this internally

If anything, this is the only thing which can actually get Apple to reverse their moves. Similar to what happened to Google.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#19
post #10

Some have speculated that with the introduction of the PSI/CSAM system Apple will enable E2EE backups. Given the lack of an explicit statement on Apple's part and their history regarding E2EE backups (this article, and other statements). It seems really unlikely to me that Apple will enable E2EE backups. Under E2EE, assuming the device key is randomly generated, if you have one device (as many users do) and you lose…

> if you have one device (as many users do) and you lose that device you would lose all your data. The alternative is the key is derived from your iCloud password, in which case, if you forget your password, you lose all your data.

This is all a good point.

Purely coincidentally, the imminent next release of iOS adds new account recovery options: https://9to5mac.com/2021/08/06/how-to-use-icloud-data-recove...

Post reply on HN