Live data from Hacker News

Apple dropped plan for encrypting backups after FBI complained (2020)

reuters.com

61–70 of 228 posts

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#61
post #46
post #10

Some have speculated that with the introduction of the PSI/CSAM system Apple will enable E2EE backups. Given the lack of an explicit statement on Apple's part and their history regarding E2EE backups (this article, and other statements). It seems really unlikely to me that Apple will enable E2EE backups. Under E2EE, assuming the device key is randomly generated, if you have one device (as many users do) and you lose…

An obvious solution would be to allow third-party storage services where you can dump your device data pre-encrypted and restore from those services. Only you would have the key. It isn't hard to implement. The hard part would be getting the US security apparatus to allow it. ALL major storage providers DON'T support end-to-end encryption for this reason. Not Google. Not Microsoft. Not Apple. Not Dropbox. Isn't this…

> The hard part would be getting the US security apparatus to allow it. This is why ALL the major storage providers DON'T support end-to-end encryption.

I don't think so. The reason is there's no money to be earned with being simply a storage provider. Additional processing, indexing, workflow tools etc. is what people pay for. That's not possible with E2E encryption.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#62
post #11

This really is something Tim needs to address before he again stands on stage and give lip service to Privacy with a capital P. We also need hardball journalists to start asking Tim these tough questions instead of fawning over AirPods And we need employees to start demanding this internally

I think we are all throwing wrong questions at wrong entities. What we should ask is what the hell is going on and what is forcing everyone to implement backdoors in this organized manners.

What's the backdoor that has been implemented?

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#63
post #41
post #11

Earlier quoted context omitted.

I think we are all throwing wrong questions at wrong entities. What we should ask is what the hell is going on and what is forcing everyone to implement backdoors in this organized manners.

China. Specifically, gradual capitulation to China. "Apple's earnings for Greater China in Q2 2021 were up 87.5% from this time last year, to $17.7 billion. During its latest earnings call, Apple has announced dramatically increased revenues from Greater China for the three months ending March, 2021." China has cracked down hard on domestic Internet companies over the past few weeks (deliberately crushing their tech…

This is all pure speculation. Everyone in china is using WeChat anyway. China have this capability already. No one is sitting around a table thinking: "What do we do about Apple Messages", and if they were their solution would be: Block Apple messages. NOT: Ask an American company to implement spying for us and trust that they'll do it accurately... non sensical.

As pointed out this feature isn't even being launched in China.

But sorry to derail your narrative: China are the bad guys and all bad things are because of china.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#64
post #41

Earlier quoted context omitted.

China. Specifically, gradual capitulation to China. "Apple's earnings for Greater China in Q2 2021 were up 87.5% from this time last year, to $17.7 billion. During its latest earnings call, Apple has announced dramatically increased revenues from Greater China for the three months ending March, 2021." China has cracked down hard on domestic Internet companies over the past few weeks (deliberately crushing their tech…

It’s really sad how right you are. Never admitted it to myself yet.

It's sad that you think they're right. Rather than asking evidence of such a bold claim.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#65
post #57
post #50

Earlier quoted context omitted.

Why sad? It seems to me this is the only thing to expect from a for-profit corporation under these circumstances. I don't really see how anybody could expect something different, specially here.

The coffee shop hacker culture belives there is such thing as good and bad companies, hence why Google has been able to fool them with "do no evil" crap.

Believe != Reality.

I still don't see the why though. It seems obvious to me that nothing is to be expected from corporations, other than a hopefully nice product at a reasonable price. Anything other than that sounds like wishful thinking to my ears, but I might be philosophically wrong.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#66
post #10

Some have speculated that with the introduction of the PSI/CSAM system Apple will enable E2EE backups. Given the lack of an explicit statement on Apple's part and their history regarding E2EE backups (this article, and other statements). It seems really unlikely to me that Apple will enable E2EE backups. Under E2EE, assuming the device key is randomly generated, if you have one device (as many users do) and you lose…

> if you have one device (as many users do) and you lose that device you would lose all your data. The alternative is the key is derived from your iCloud password, in which case, if you forget your password, you lose all your data. This is all a good point. Purely coincidentally, the imminent next release of iOS adds new account recovery options: https://9to5mac.com/2021/08/06/how-to-use-icloud-data-recove...

From the screenshot of turning on "Use Recovery Key":

> If you create a recovery key and can't access your devices, Apple won't be able to help you regain access to your account or your data.

That sounds like E2EE backups, but its impossible to know if that is truly the case until they provide more details.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#67

Earlier quoted context omitted.

Or, get the contentious part out of the way so that your E2EE announcement isn’t overshadowed. I don’t know how much I believe that, though.

What is the point of end-to-end encryption if the snitch for objectionable content lives on the device?

Reverse engineers can examine the snitch to see what it's looking for. Without semi-E2E, Apple could hand over every photo of every account to China and we would be none the wiser.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#68
post #65
post #57

Earlier quoted context omitted.

The coffee shop hacker culture belives there is such thing as good and bad companies, hence why Google has been able to fool them with "do no evil" crap.

Believe != Reality. I still don't see the why though. It seems obvious to me that nothing is to be expected from corporations, other than a hopefully nice product at a reasonable price. Anything other than that sounds like wishful thinking to my ears, but I might be philosophically wrong.

It is wishful thinking, yet you will find plenty of places arguing about company X "good", company Z "bad".

Any good deeds a company happens to do, is for publicity and helping sales.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#69
post #58

Earlier quoted context omitted.

Right.. yeah because some laws like anti terrorism or money laundering etc stated that tech companies has to save the data and share with the gov if the gov requested. Source: I work in fintech

Do these laws specify that you're not allowed to make features that encrypt data?

No not that, what I meant was that you have to be able to provide when requested. Meaning that you have to be able to decrypt it if requested. Not just 1 way encryption

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#70

In the first half of 2020, Apple gave data on over 31,000 users/accounts based on FISA requests National Security Letter requests[1]. Apple provided data to the government's requests roughly 9,000 times. About 85% - 92% of the time, according to Apple, they responded to data requests from the government with the data that was requested. I don't see why Apple would turn about face and make it impossible to respond to…

What data are they responding with? Account name and creation date? IP addresses used to log in to the account? iCloud backups?
Post reply on HN