Live data from Hacker News

Apple dropped plan for encrypting backups after FBI complained (2020)

reuters.com

31–40 of 228 posts

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#31
post #10

Some have speculated that with the introduction of the PSI/CSAM system Apple will enable E2EE backups. Given the lack of an explicit statement on Apple's part and their history regarding E2EE backups (this article, and other statements). It seems really unlikely to me that Apple will enable E2EE backups. Under E2EE, assuming the device key is randomly generated, if you have one device (as many users do) and you lose…

Also if Apple did enable E2EE backups then law enforcement would put tremendous pressure on them to expand what they're scanning for in this new client side CSAM layer.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#32
post #10

Some have speculated that with the introduction of the PSI/CSAM system Apple will enable E2EE backups. Given the lack of an explicit statement on Apple's part and their history regarding E2EE backups (this article, and other statements). It seems really unlikely to me that Apple will enable E2EE backups. Under E2EE, assuming the device key is randomly generated, if you have one device (as many users do) and you lose…

A viable alternative is multiple LUKS-style key slots, one per registered device that can be unlocked with a device keys, and one that is by default encrypted with a key derived from your iCloud password. If you lose all your iDevices _and_ your password at the same time, you lose your data.

They could also make this opt in (add another escrow key slot by default, but allow you to promise that you've written down a recovery key and then destroy the escrow key slot).

Online browsing would use the iCloud password to decrypt the images client side. Thumbnails could be generated client side and stored alongside the images under the same key.

You can make this pretty transparent.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#34
post #28

Earlier quoted context omitted.

> if you have one device (as many users do) and you lose that device you would lose all your data. The alternative is the key is derived from your iCloud password, in which case, if you forget your password, you lose all your data. This is all a good point. Purely coincidentally, the imminent next release of iOS adds new account recovery options: https://9to5mac.com/2021/08/06/how-to-use-icloud-data-recove...

That's a really interesting link, thanks. I'd not seen that. This statement: > The service requires Apple to maintain access to your data to help you recover it. For your privacy, Apple can’t access or help you recover your end-to-end encrypted information, such as Keychain, Screen Time, and Health data. Seems to suggest that there is no change to end-to-end encryption on iCloud.

If there is some upcoming change that has not been announced, Apple would try to be careful not to make any mention of it in the public betas.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#35
I'm actually curious, are they allowed to encrypt backups if FBI requested them not to? I thought as American company you have to comply with the law as well. Not sure though

Edit: damn downvotes, is this reddit? I'm literally asking because I don't know. nothing is controversial here

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#36
post #17

Earlier quoted context omitted.

This still seems like it would require a significant change in functionality, which they would likely announce. I.e. lose your lock code, lose all your data. Also, are you going to enter your lock code online to browse photos in a browser? What about syncing between devices? In the absence of an explicit announcement regarding these changes in functionality it seems unlikely to me.

You're right, Apple is definitely not going to secretly enable end-to-end encryption without announcing it. If this client side photo scanning thing is part of an ongoing plan to eventually enable end-to-end encryption of iCloud, then Apple made a huge blunder. They should have waited until end to end encryption was ready first so that they could announce it simultaneously.

Or, get the contentious part out of the way so that your E2EE announcement isn’t overshadowed.

I don’t know how much I believe that, though.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#37

This really is something Tim needs to address before he again stands on stage and give lip service to Privacy with a capital P. We also need hardball journalists to start asking Tim these tough questions instead of fawning over AirPods And we need employees to start demanding this internally

As I've mentioned in another thread, Apple has been marketing itself so strongly as the leader in privacy that it now speaks about how it now treats privacy as a "fundamental human right". Their executives started using this phrasing when discussing privacy.

It is an extraordinary claim that requires extraordinary commitment and action. To me, at least, that means privacy without compromise - and for everyone. ("Fundamental human rights" apply to all of us, right?)

Privacy with a bunch of disclaimers attached to it indicating all of the conditions under which your privacy will be abridged is not privacy. And it's certainly not the behaviour of a company that treats privacy as a "fundamental human right".

Apple needs to get a grip when it comes to dealing with and living up to this self-stated core value. I think that given the waves created by this CSAM on-device hash checking announcement and the questions many have about how to square this with their privacy talk, Apple's executives should say something and they should be unequivocal in what they say.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#38
post #11

This really is something Tim needs to address before he again stands on stage and give lip service to Privacy with a capital P. We also need hardball journalists to start asking Tim these tough questions instead of fawning over AirPods And we need employees to start demanding this internally

I think we are all throwing wrong questions at wrong entities. What we should ask is what the hell is going on and what is forcing everyone to implement backdoors in this organized manners.

You already know the answers, though. It's either "OMG terrorists!" or "OMG child porn!".

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#39

I'm actually curious, are they allowed to encrypt backups if FBI requested them not to? I thought as American company you have to comply with the law as well. Not sure though Edit: damn downvotes, is this reddit? I'm literally asking because I don't know. nothing is controversial here

The FBI can request until they’re blue in the face. They don’t make laws. And so far, there aren’t any laws preventing Apple from encrypting backups.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#40
post #10

Some have speculated that with the introduction of the PSI/CSAM system Apple will enable E2EE backups. Given the lack of an explicit statement on Apple's part and their history regarding E2EE backups (this article, and other statements). It seems really unlikely to me that Apple will enable E2EE backups. Under E2EE, assuming the device key is randomly generated, if you have one device (as many users do) and you lose…

At this point, with Apple introducing a feature for law enforcement the general public had no opinion on or interest in, I'd argue Apple is more likely to expand what the new system does than improve E2EE.
Post reply on HN