Live data from Hacker News

Apple dropped plan for encrypting backups after FBI complained (2020)

reuters.com

21–30 of 228 posts

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#21
post #15
post #14

Earlier quoted context omitted.

> This really is something Tim needs to address before he again stands on stage and give lip service to Privacy with a capital P. Cui bono? Why does Tim Cook need to address this? To benefit Apple shareholders? To assuage the doubts of Apple customers who bought the false claims that Apple has made regarding their respect for users privacy? Truth be told I don't think that Tim Cook as CEO of one of the richest and mo…

> false claims that Apple has made regarding their respect for users privacy What false claim have they made?

Every claim that Apple makes about respecting user privacy is false because Apple does not allow users the means to independently verify the claims made by Apple regarding security. Additionally Apple does not allow users the means t control the hardware that they purchase by for instance, installing whatever software that they want on their devices.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#22

I was patiently waiting for the M1 16in MacBook Pro to come out. After reading all these revelations, I am now considering not buying the new MacBook Pro and instead, just stick with Linux.

I am an app developer who was thinking of upgrading to the next M1 Mac mini coming out later this year. For my work, I pretty much need an Apple hardware. However after this whole privacy debacle, I have started looking into Hackintosh and whether I can build one to for building my apps.

If anyone has experience with developing for iOS/MacOS on hackintosh, please let me know your experience.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#23
post #17

Earlier quoted context omitted.

There is a third option, which is to use secure elements in the datacenter to encrypt the device key with the user's screen lock code. The secure element prevents brute force attacks even with a low entropy passcode. The user can restore their backups on a fresh device only knowing their screen lock code, but backups remain end-to-end encrypted. Google has done this for Android backups. Apple has actually done it too…

This still seems like it would require a significant change in functionality, which they would likely announce. I.e. lose your lock code, lose all your data. Also, are you going to enter your lock code online to browse photos in a browser? What about syncing between devices? In the absence of an explicit announcement regarding these changes in functionality it seems unlikely to me.

You're right, Apple is definitely not going to secretly enable end-to-end encryption without announcing it.

If this client side photo scanning thing is part of an ongoing plan to eventually enable end-to-end encryption of iCloud, then Apple made a huge blunder. They should have waited until end to end encryption was ready first so that they could announce it simultaneously.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#24

I was patiently waiting for the M1 16in MacBook Pro to come out. After reading all these revelations, I am now considering not buying the new MacBook Pro and instead, just stick with Linux.

I had already decided to switch back to Linux. I was planning on continuing to use an iPhone but after the news stories of the past week I might even ditch the iPhone too.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#25
post #10

Some have speculated that with the introduction of the PSI/CSAM system Apple will enable E2EE backups. Given the lack of an explicit statement on Apple's part and their history regarding E2EE backups (this article, and other statements). It seems really unlikely to me that Apple will enable E2EE backups. Under E2EE, assuming the device key is randomly generated, if you have one device (as many users do) and you lose…

There is a third option, which is to use secure elements in the datacenter to encrypt the device key with the user's screen lock code. The secure element prevents brute force attacks even with a low entropy passcode. The user can restore their backups on a fresh device only knowing their screen lock code, but backups remain end-to-end encrypted. Google has done this for Android backups. Apple has actually done it too…

This is the pattern that signal took with secure value recovery as well.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#26
post #8

Don't use the cloud if you care about privacy, or encrypt the data yourself before uploading. Has always been the case.

That’s not enough, Apple is “open” to adding these APIs to 3rd party apps as of today’s news.

It was never going to stop at iCloud uploads.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#27

I was patiently waiting for the M1 16in MacBook Pro to come out. After reading all these revelations, I am now considering not buying the new MacBook Pro and instead, just stick with Linux.

I am an app developer who was thinking of upgrading to the next M1 Mac mini coming out later this year. For my work, I pretty much need an Apple hardware. However after this whole privacy debacle, I have started looking into Hackintosh and whether I can build one to for building my apps. If anyone has experience with developing for iOS/MacOS on hackintosh, please let me know your experience.

You can build one. Lots of guides out there and compatibility lists for components. It’s going to be a science project though with only community support for an adversarial operating system.

If you plan to use it for work then buy a Mac. It’s a tool for a job.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#28
post #10

Some have speculated that with the introduction of the PSI/CSAM system Apple will enable E2EE backups. Given the lack of an explicit statement on Apple's part and their history regarding E2EE backups (this article, and other statements). It seems really unlikely to me that Apple will enable E2EE backups. Under E2EE, assuming the device key is randomly generated, if you have one device (as many users do) and you lose…

> if you have one device (as many users do) and you lose that device you would lose all your data. The alternative is the key is derived from your iCloud password, in which case, if you forget your password, you lose all your data. This is all a good point. Purely coincidentally, the imminent next release of iOS adds new account recovery options: https://9to5mac.com/2021/08/06/how-to-use-icloud-data-recove...

That's a really interesting link, thanks. I'd not seen that. This statement:

> The service requires Apple to maintain access to your data to help you recover it. For your privacy, Apple can’t access or help you recover your end-to-end encrypted information, such as Keychain, Screen Time, and Health data.

Seems to suggest that there is no change to end-to-end encryption on iCloud.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#29

Earlier quoted context omitted.

I am an app developer who was thinking of upgrading to the next M1 Mac mini coming out later this year. For my work, I pretty much need an Apple hardware. However after this whole privacy debacle, I have started looking into Hackintosh and whether I can build one to for building my apps. If anyone has experience with developing for iOS/MacOS on hackintosh, please let me know your experience.

You can build one. Lots of guides out there and compatibility lists for components. It’s going to be a science project though with only community support for an adversarial operating system. If you plan to use it for work then buy a Mac. It’s a tool for a job.

running it virtually is also an option. I run macos in virtualbox for the times I need it (for me that's not daily) and have no issues with it

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#30
What to make of this whole thing? Hard to say. But here’s an amusing thought.

Before I start: I’ll invoke dang’s rage for a moment and say this is yet another burner account due to my previous ones being flagged/banned - not for anything actually illegal or low brow or whatever, but for going against the orthodoxy. Trite and cliche statement, yes.

This whole thing is yet another nail in the coffin. Maybe Apple will back out, maybe not, but really it doesn’t matter. Could be any other company, I don’t particularly care.

What does matter is how HN treats its members and how moderator(s) handle things when we bring these possibilities up. This is where I think the ball has been dropped. You can also substitute HN for other technophile forums, again, doesn’t matter.

You need to learn that shunning us when we are telling you what’s going to happen isn’t the way to go about this. You deplatform us on these topics because you think you know better and we are the trolls and conspiracy theorists with our unsubstantiated claims, lack of evidence, data, and so on. To us, you can’t see the forest for the trees nor the train wreck approaching. I think most of us just stopped caring.

You can say every so often that a broken clock is right twice a day. But I am pretty sure both Assange and Snowden shake their heads at such a statement here and wonder if it’s true naïveté or if you’re trying to guile others.

But, for the time being you can believe what the news and Snopes say and continue to shitpost HN. Eventually it’ll be you on the chopping block.

Post reply on HN