Some have speculated that with the introduction of the PSI/CSAM system Apple will enable E2EE backups. Given the lack of an explicit statement on Apple's part and their history regarding E2EE backups (this article, and other statements). It seems really unlikely to me that Apple will enable E2EE backups. Under E2EE, assuming the device key is randomly generated, if you have one device (as many users do) and you lose…
Apple dropped plan for encrypting backups after FBI complained (2020)
31–40 of 228 posts
Re: Apple dropped plan for encrypting backups after FBI complained (2020)
#32Some have speculated that with the introduction of the PSI/CSAM system Apple will enable E2EE backups. Given the lack of an explicit statement on Apple's part and their history regarding E2EE backups (this article, and other statements). It seems really unlikely to me that Apple will enable E2EE backups. Under E2EE, assuming the device key is randomly generated, if you have one device (as many users do) and you lose…
They could also make this opt in (add another escrow key slot by default, but allow you to promise that you've written down a recovery key and then destroy the escrow key slot).
Online browsing would use the iCloud password to decrypt the images client side. Thumbnails could be generated client side and stored alongside the images under the same key.
You can make this pretty transparent.
Re: Apple dropped plan for encrypting backups after FBI complained (2020)
#33Re: Apple dropped plan for encrypting backups after FBI complained (2020)
#34Earlier quoted context omitted.
> if you have one device (as many users do) and you lose that device you would lose all your data. The alternative is the key is derived from your iCloud password, in which case, if you forget your password, you lose all your data. This is all a good point. Purely coincidentally, the imminent next release of iOS adds new account recovery options: https://9to5mac.com/2021/08/06/how-to-use-icloud-data-recove...
That's a really interesting link, thanks. I'd not seen that. This statement: > The service requires Apple to maintain access to your data to help you recover it. For your privacy, Apple can’t access or help you recover your end-to-end encrypted information, such as Keychain, Screen Time, and Health data. Seems to suggest that there is no change to end-to-end encryption on iCloud.
Re: Apple dropped plan for encrypting backups after FBI complained (2020)
#35Edit: damn downvotes, is this reddit? I'm literally asking because I don't know. nothing is controversial here
Re: Apple dropped plan for encrypting backups after FBI complained (2020)
#36Earlier quoted context omitted.
This still seems like it would require a significant change in functionality, which they would likely announce. I.e. lose your lock code, lose all your data. Also, are you going to enter your lock code online to browse photos in a browser? What about syncing between devices? In the absence of an explicit announcement regarding these changes in functionality it seems unlikely to me.
You're right, Apple is definitely not going to secretly enable end-to-end encryption without announcing it. If this client side photo scanning thing is part of an ongoing plan to eventually enable end-to-end encryption of iCloud, then Apple made a huge blunder. They should have waited until end to end encryption was ready first so that they could announce it simultaneously.
I don’t know how much I believe that, though.
Re: Apple dropped plan for encrypting backups after FBI complained (2020)
#37This really is something Tim needs to address before he again stands on stage and give lip service to Privacy with a capital P. We also need hardball journalists to start asking Tim these tough questions instead of fawning over AirPods And we need employees to start demanding this internally
It is an extraordinary claim that requires extraordinary commitment and action. To me, at least, that means privacy without compromise - and for everyone. ("Fundamental human rights" apply to all of us, right?)
Privacy with a bunch of disclaimers attached to it indicating all of the conditions under which your privacy will be abridged is not privacy. And it's certainly not the behaviour of a company that treats privacy as a "fundamental human right".
Apple needs to get a grip when it comes to dealing with and living up to this self-stated core value. I think that given the waves created by this CSAM on-device hash checking announcement and the questions many have about how to square this with their privacy talk, Apple's executives should say something and they should be unequivocal in what they say.
Re: Apple dropped plan for encrypting backups after FBI complained (2020)
#38This really is something Tim needs to address before he again stands on stage and give lip service to Privacy with a capital P. We also need hardball journalists to start asking Tim these tough questions instead of fawning over AirPods And we need employees to start demanding this internally
I think we are all throwing wrong questions at wrong entities. What we should ask is what the hell is going on and what is forcing everyone to implement backdoors in this organized manners.
Re: Apple dropped plan for encrypting backups after FBI complained (2020)
#39I'm actually curious, are they allowed to encrypt backups if FBI requested them not to? I thought as American company you have to comply with the law as well. Not sure though Edit: damn downvotes, is this reddit? I'm literally asking because I don't know. nothing is controversial here
Re: Apple dropped plan for encrypting backups after FBI complained (2020)
#40Some have speculated that with the introduction of the PSI/CSAM system Apple will enable E2EE backups. Given the lack of an explicit statement on Apple's part and their history regarding E2EE backups (this article, and other statements). It seems really unlikely to me that Apple will enable E2EE backups. Under E2EE, assuming the device key is randomly generated, if you have one device (as many users do) and you lose…