Live data from Hacker News

Apple dropped plan for encrypting backups after FBI complained (2020)

reuters.com

81–90 of 228 posts

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#82
post #58

Earlier quoted context omitted.

Do these laws specify that you're not allowed to make features that encrypt data?

No not that, what I meant was that you have to be able to provide when requested. Meaning that you have to be able to decrypt it if requested. Not just 1 way encryption

So is Amazon breaking the law if I upload GPG-encrypted files to S3?

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#83
post #67

Earlier quoted context omitted.

What is the point of end-to-end encryption if the snitch for objectionable content lives on the device?

Reverse engineers can examine the snitch to see what it's looking for. Without semi-E2E, Apple could hand over every photo of every account to China and we would be none the wiser.

How? I can’t imagine security researchers wanting to hold csam and pictures of the police to test this out…

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#84
post #10

Some have speculated that with the introduction of the PSI/CSAM system Apple will enable E2EE backups. Given the lack of an explicit statement on Apple's part and their history regarding E2EE backups (this article, and other statements). It seems really unlikely to me that Apple will enable E2EE backups. Under E2EE, assuming the device key is randomly generated, if you have one device (as many users do) and you lose…

A viable alternative is multiple LUKS-style key slots, one per registered device that can be unlocked with a device keys, and one that is by default encrypted with a key derived from your iCloud password. If you lose all your iDevices _and_ your password at the same time, you lose your data. They could also make this opt in (add another escrow key slot by default, but allow you to promise that you've written down a r…

[deleted]

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#85
post #67

Earlier quoted context omitted.

Reverse engineers can examine the snitch to see what it's looking for. Without semi-E2E, Apple could hand over every photo of every account to China and we would be none the wiser.

How? I can’t imagine security researchers wanting to hold csam and pictures of the police to test this out…

What's wrong with pictures of the police?

Also, a big concern that people have is what the Chinese government will want to be censored. Researchers in the US can investigate that without fear.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#86
post #41
post #11

Earlier quoted context omitted.

I think we are all throwing wrong questions at wrong entities. What we should ask is what the hell is going on and what is forcing everyone to implement backdoors in this organized manners.

China. Specifically, gradual capitulation to China. "Apple's earnings for Greater China in Q2 2021 were up 87.5% from this time last year, to $17.7 billion. During its latest earnings call, Apple has announced dramatically increased revenues from Greater China for the three months ending March, 2021." China has cracked down hard on domestic Internet companies over the past few weeks (deliberately crushing their tech…

> scan for messages critical of Xi and the boys.

I see what you did there. Touché.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#87
post #10

Some have speculated that with the introduction of the PSI/CSAM system Apple will enable E2EE backups. Given the lack of an explicit statement on Apple's part and their history regarding E2EE backups (this article, and other statements). It seems really unlikely to me that Apple will enable E2EE backups. Under E2EE, assuming the device key is randomly generated, if you have one device (as many users do) and you lose…

> There's been no statement that this is going away. Implementing this functionality with E2EE backups seem highly problematic.

No more problematic than WhatsApp offering WhatsApp web (web.whatsapp.com) or Signal offering its desktop client while being fully end-to-end encrypted and routing communications through the phone.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#88

Earlier quoted context omitted.

A viable alternative is multiple LUKS-style key slots, one per registered device that can be unlocked with a device keys, and one that is by default encrypted with a key derived from your iCloud password. If you lose all your iDevices _and_ your password at the same time, you lose your data. They could also make this opt in (add another escrow key slot by default, but allow you to promise that you've written down a r…

> If you lose all your iDevices _and_ your password at the same time ... I don't know how this is with iPhones (I don't own one), but with Android these events are almost 100% correlated for many people. That's because you never get prompted for your Google account password on your phone. If you don't use the same Google account on your phone as on your desktop, or don't really use your Google account on the desktop…

You can reset your password with email and phone number. Did it once.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#89
post #41
post #11

Earlier quoted context omitted.

I think we are all throwing wrong questions at wrong entities. What we should ask is what the hell is going on and what is forcing everyone to implement backdoors in this organized manners.

China. Specifically, gradual capitulation to China. "Apple's earnings for Greater China in Q2 2021 were up 87.5% from this time last year, to $17.7 billion. During its latest earnings call, Apple has announced dramatically increased revenues from Greater China for the three months ending March, 2021." China has cracked down hard on domestic Internet companies over the past few weeks (deliberately crushing their tech…

> Apple literally cannot lose that market

China could also ban manufacturing there. That would suck for AAPL too.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#90
post #10

Some have speculated that with the introduction of the PSI/CSAM system Apple will enable E2EE backups. Given the lack of an explicit statement on Apple's part and their history regarding E2EE backups (this article, and other statements). It seems really unlikely to me that Apple will enable E2EE backups. Under E2EE, assuming the device key is randomly generated, if you have one device (as many users do) and you lose…

4th option. A user provided key, not derived from the password. Chrome uses (used?) this for History encryption, etc.

5th option:

Apple (or whomever) could sell a "backup box": a simple embedded device with RAID 1 (mirroring) storage and the usual data/charging port(s). First time you plug an iphone into it you are asked to verify using the connected device to store backups.

The user then uses the "backup box" as their regular home charger. Backups happen automatically while charging. The user doesn't worry about keys; attack surface is limited to physically local risks (no network!). People already understand how to protect a physical device: lock in in a safe, move it to a safer location, etc. Instead of trying to solve the security problem for the user, give the user tool they can understand that allow them to protect themselves.

Post reply on HN