Live data from Hacker News

Apple dropped plan for encrypting backups after FBI complained (2020)

reuters.com

51–60 of 228 posts

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#51
post #10

Some have speculated that with the introduction of the PSI/CSAM system Apple will enable E2EE backups. Given the lack of an explicit statement on Apple's part and their history regarding E2EE backups (this article, and other statements). It seems really unlikely to me that Apple will enable E2EE backups. Under E2EE, assuming the device key is randomly generated, if you have one device (as many users do) and you lose…

>Some have speculated that with the introduction of the PSI/CSAM system Apple will enable E2EE backups. For me it seems that latest changes do not change anything, FBI will still object with the same reasons as in the past, because they will have a legal obtained warrant and they need the user backups/phone content. I do not see Apple fighting this in courts especially now when they also have a big fight vs Epic and…

> I do not see Apple fighting this in courts especially now when they also have a big fight vs Epic and a fight vs right to repair.

Apple already gives up data on tens of thousands of users and accounts each year in response on requests from governments. Apple keeps statistics about those data requests here[1].

For reference, Apple gave data on over 31,000 users/accounts based on FISA requests and National Security Letter requests in the first half of 2020 alone[1].

During that same period, Apple provided data to the government's requests (non-FISA or NSL) about 9,000 times, and responded to requests for data with the data about ~85% of the time, and 92% in cases of "emergencies"[1].

[1] https://www.apple.com/legal/transparency/us.html

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#53

I was patiently waiting for the M1 16in MacBook Pro to come out. After reading all these revelations, I am now considering not buying the new MacBook Pro and instead, just stick with Linux.

I am an app developer who was thinking of upgrading to the next M1 Mac mini coming out later this year. For my work, I pretty much need an Apple hardware. However after this whole privacy debacle, I have started looking into Hackintosh and whether I can build one to for building my apps. If anyone has experience with developing for iOS/MacOS on hackintosh, please let me know your experience.

> For my work, I pretty much need an Apple hardware.

How would going to a hackintosh and loading on the Apple software you are skeptical of help you?

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#54

I'm actually curious, are they allowed to encrypt backups if FBI requested them not to? I thought as American company you have to comply with the law as well. Not sure though Edit: damn downvotes, is this reddit? I'm literally asking because I don't know. nothing is controversial here

The FBI can request until they’re blue in the face. They don’t make laws. And so far, there aren’t any laws preventing Apple from encrypting backups.

Right.. yeah because some laws like anti terrorism or money laundering etc stated that tech companies has to save the data and share with the gov if the gov requested.

Source: I work in fintech

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#55
There's a way to make fully encrypted backups of your iPhone locally, check out my blog post from my self-hosting series:

https://www.naut.ca/blog/2020/03/20/self-hosting-series-part...

This works well on Linux, and iOS 14. You can skip to the section `Compiling idevicebackup2`.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#56
In the first half of 2020, Apple gave data on over 31,000 users/accounts based on FISA requests National Security Letter requests[1]. Apple provided data to the government's requests roughly 9,000 times.

About 85% - 92% of the time, according to Apple, they responded to data requests from the government with the data that was requested.

I don't see why Apple would turn about face and make it impossible to respond to the requests that they choose to respond with data about 85% of the time.

[1] https://www.apple.com/legal/transparency/us.html

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#57
post #50

Earlier quoted context omitted.

It’s really sad how right you are. Never admitted it to myself yet.

Why sad? It seems to me this is the only thing to expect from a for-profit corporation under these circumstances. I don't really see how anybody could expect something different, specially here.

The coffee shop hacker culture belives there is such thing as good and bad companies, hence why Google has been able to fool them with "do no evil" crap.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#58

Earlier quoted context omitted.

The FBI can request until they’re blue in the face. They don’t make laws. And so far, there aren’t any laws preventing Apple from encrypting backups.

Right.. yeah because some laws like anti terrorism or money laundering etc stated that tech companies has to save the data and share with the gov if the gov requested. Source: I work in fintech

Do these laws specify that you're not allowed to make features that encrypt data?

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#59
These people really hate you and think low enough of you that they feel they have a right to rummage through your personal belongings anytime they wish. America feels like its over. The dream is dead. The supreme court full of weak people that will rubber stamp the rot. People feared AI, and they got laughed at. But its literally AI bots manufacturing consent on twitter and social media to this authoritarian slide.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#60
post #46
post #10

Some have speculated that with the introduction of the PSI/CSAM system Apple will enable E2EE backups. Given the lack of an explicit statement on Apple's part and their history regarding E2EE backups (this article, and other statements). It seems really unlikely to me that Apple will enable E2EE backups. Under E2EE, assuming the device key is randomly generated, if you have one device (as many users do) and you lose…

An obvious solution would be to allow third-party storage services where you can dump your device data pre-encrypted and restore from those services. Only you would have the key. It isn't hard to implement. The hard part would be getting the US security apparatus to allow it. ALL major storage providers DON'T support end-to-end encryption for this reason. Not Google. Not Microsoft. Not Apple. Not Dropbox. Isn't this…

Google's Android backups claim end to end encryption.

> By design, this means that no one (including Google) can access a user's backed-up application data without specifically knowing their passcode.

https://security.googleblog.com/2018/10/google-and-android-h...

Post reply on HN