This really is something Tim needs to address before he again stands on stage and give lip service to Privacy with a capital P. We also need hardball journalists to start asking Tim these tough questions instead of fawning over AirPods And we need employees to start demanding this internally
Apple dropped plan for encrypting backups after FBI complained (2020)
11–20 of 228 posts
Re: Apple dropped plan for encrypting backups after FBI complained (2020)
#12Don't use the cloud if you care about privacy, or encrypt the data yourself before uploading. Has always been the case.
In fact, given that Apple do not E2E encrypt backups and already implement CSAM functionality by scanning data in iCloud [1] it's not clear what the purpose of the new PSI/CSAM system is. Which leads many to speculate that it's only purpose is as a prelude to scanning all offline content.
[1] https://nakedsecurity.sophos.com/2020/01/09/apples-scanning-...
Re: Apple dropped plan for encrypting backups after FBI complained (2020)
#13Some have speculated that with the introduction of the PSI/CSAM system Apple will enable E2EE backups. Given the lack of an explicit statement on Apple's part and their history regarding E2EE backups (this article, and other statements). It seems really unlikely to me that Apple will enable E2EE backups. Under E2EE, assuming the device key is randomly generated, if you have one device (as many users do) and you lose…
Google has done this for Android backups. Apple has actually done it too, but only for Keychain passwords and a couple of other things. So Apple actually already has an implementation of the right solution and intentionally prevents you from using it to secure your backups, reportedly because they failed to stand up to the FBI. Which is strange given their public stance in the San Bernardino case.
Re: Apple dropped plan for encrypting backups after FBI complained (2020)
#14This really is something Tim needs to address before he again stands on stage and give lip service to Privacy with a capital P. We also need hardball journalists to start asking Tim these tough questions instead of fawning over AirPods And we need employees to start demanding this internally
Cui bono?
Why does Tim Cook need to address this? To benefit Apple shareholders? To assuage the doubts of Apple customers who bought the false claims that Apple has made regarding their respect for users privacy?
Truth be told I don't think that Tim Cook as CEO of one of the richest and most powerful organizations in history needs to do anything because Apple has their customers by the balls. What are the few Apple users who even care about this issue going to do? Switch to Microsoft? Linux? Hah!
Face it, Apple users have made their bed and now they have to lie in it. People have been warning them for years about the Faustian bargain that they were making and how it was corrosive to society to entrench an entity like Apple and now here we are.
Re: Apple dropped plan for encrypting backups after FBI complained (2020)
#15This really is something Tim needs to address before he again stands on stage and give lip service to Privacy with a capital P. We also need hardball journalists to start asking Tim these tough questions instead of fawning over AirPods And we need employees to start demanding this internally
> This really is something Tim needs to address before he again stands on stage and give lip service to Privacy with a capital P. Cui bono? Why does Tim Cook need to address this? To benefit Apple shareholders? To assuage the doubts of Apple customers who bought the false claims that Apple has made regarding their respect for users privacy? Truth be told I don't think that Tim Cook as CEO of one of the richest and mo…
What false claim have they made?
Re: Apple dropped plan for encrypting backups after FBI complained (2020)
#16Re: Apple dropped plan for encrypting backups after FBI complained (2020)
#17Some have speculated that with the introduction of the PSI/CSAM system Apple will enable E2EE backups. Given the lack of an explicit statement on Apple's part and their history regarding E2EE backups (this article, and other statements). It seems really unlikely to me that Apple will enable E2EE backups. Under E2EE, assuming the device key is randomly generated, if you have one device (as many users do) and you lose…
There is a third option, which is to use secure elements in the datacenter to encrypt the device key with the user's screen lock code. The secure element prevents brute force attacks even with a low entropy passcode. The user can restore their backups on a fresh device only knowing their screen lock code, but backups remain end-to-end encrypted. Google has done this for Android backups. Apple has actually done it too…
In the absence of an explicit announcement regarding these changes in functionality it seems unlikely to me.
Re: Apple dropped plan for encrypting backups after FBI complained (2020)
#18This really is something Tim needs to address before he again stands on stage and give lip service to Privacy with a capital P. We also need hardball journalists to start asking Tim these tough questions instead of fawning over AirPods And we need employees to start demanding this internally
If anything, this is the only thing which can actually get Apple to reverse their moves. Similar to what happened to Google.
Re: Apple dropped plan for encrypting backups after FBI complained (2020)
#19Some have speculated that with the introduction of the PSI/CSAM system Apple will enable E2EE backups. Given the lack of an explicit statement on Apple's part and their history regarding E2EE backups (this article, and other statements). It seems really unlikely to me that Apple will enable E2EE backups. Under E2EE, assuming the device key is randomly generated, if you have one device (as many users do) and you lose…
This is all a good point.
Purely coincidentally, the imminent next release of iOS adds new account recovery options: https://9to5mac.com/2021/08/06/how-to-use-icloud-data-recove...
Re: Apple dropped plan for encrypting backups after FBI complained (2020)
#20Not sure, what's the point of sharing a two years old news.