Live data from Hacker News

Apple dropped plan for encrypting backups after FBI complained (2020)

reuters.com

121–130 of 228 posts

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#121
post #47

Earlier quoted context omitted.

The privacy issues with apple pretty much lie within their software. Going hackintosh isn't going to move you further away from the issues you have.

I don't particularly need macOS for anything else except the app development work. Other stuff, I can get done on Ubuntu. I am looking into whether I can run MacOS in a VM on Ubuntu.

You can run macOS in VM on any Windows laptop/PC. Are you really a developer?

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#122
post #10

Some have speculated that with the introduction of the PSI/CSAM system Apple will enable E2EE backups. Given the lack of an explicit statement on Apple's part and their history regarding E2EE backups (this article, and other statements). It seems really unlikely to me that Apple will enable E2EE backups. Under E2EE, assuming the device key is randomly generated, if you have one device (as many users do) and you lose…

> if you have one device (as many users do) and you lose that device you would lose all your data.

Apple has given that excuse before, but they could just provide the option with a serious warning, or make you jump through a couple of hoops first.

Apple is known for not bifurcating user experiences by giving users many options to choose from, but they are also known for their stance on privacy. I don't see why they wouldn't allow for this, maybe at first to trial it on the few that want it before deciding to roll it iCloud-wide.

If I were Apple, from a legal standpoint, I'd prefer not to have the ability to decrypt my users' data. Only in that light does it make sense to introduce the PSI/CSAM system on Apple devices, so you can claim you don't host such content, even if you allow users E2EE backups.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#124
post #10

Some have speculated that with the introduction of the PSI/CSAM system Apple will enable E2EE backups. Given the lack of an explicit statement on Apple's part and their history regarding E2EE backups (this article, and other statements). It seems really unlikely to me that Apple will enable E2EE backups. Under E2EE, assuming the device key is randomly generated, if you have one device (as many users do) and you lose…

A viable alternative is multiple LUKS-style key slots, one per registered device that can be unlocked with a device keys, and one that is by default encrypted with a key derived from your iCloud password. If you lose all your iDevices _and_ your password at the same time, you lose your data. They could also make this opt in (add another escrow key slot by default, but allow you to promise that you've written down a r…

>If you lose all your iDevices _and_ your password at the same time, you lose your data.

This is the risk most non-tech Apple users aren't willing or even expecting to take. No way Apple would enable this, even as opt-in, because many would misconfigure it, lose their data and blame Apple that failed them.

And good luck explaining they need to buy another iPhone and guard the two instead of one to be truly secure.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#125
post #47

Earlier quoted context omitted.

The privacy issues with apple pretty much lie within their software. Going hackintosh isn't going to move you further away from the issues you have.

I don't particularly need macOS for anything else except the app development work. Other stuff, I can get done on Ubuntu. I am looking into whether I can run MacOS in a VM on Ubuntu.

Hackintosh is pretty easy to do if you have compatible hardware.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#126

Earlier quoted context omitted.

> As pointed out this feature isn't even being launched in China. Source?

That’s right let’s ask for the source of the extremely believable claim of only launched in US[0]. But no one sourcing the “China is pressuring Apple to do this”. As stated in the article Apple have said it is US only and will be switched on country by country… so surely if this was “BeCAusE ChIna!!!” It’d be switched on there first right? [0] https://9to5mac.com/2021/08/09/apple-csam-faq/?_gl=1*l17q2t*... .

Well, its actually extremely believable that its launching everywhere that gets iOS 15. And your confidence indicated you had a source ;)

> so surely if this was “BeCAusE ChIna!!!” It’d be switched on there first right?

Is all of your comments on here arguments?

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#127
post #78

Earlier quoted context omitted.

> It seems really unlikely to me that Apple will enable E2EE backups. And even if they did, how would we verify that the code they instruct our hardware to run does e2ee correctly, without bugs or backdoors? Apple doesn't seem to be in the habit of opening much of their code or (on mobile) allowing users to install unapproved builds. Unless that changed, I would be skeptical, just as I am of all "e2ee" software that…

Out of curiousity how are you auditing the pre compiled binaries of otherwise open source software? I spent 2 months going through the signal code base checking it and now I need to audit the production code on their servers as well as the binaries they have compiled. Any tips?

I find it's much easier to audit the source code, and build the binaries yourself from that code.

Also, it's a collaborative effort. If you build your binaries from the same sources that other people use, then you can split up the work, and you all benefit from anyone's discoveries.

Obviously, we don't have perfect verification of the code we run. People can overlook things. Compilers can be subverted. Operating systems can be pwned. Malicious hardware can undermine all of our efforts. But let's not let perfect be the enemy of good, and let's not fool ourselves into thinking that faith in a corporation is a substitute for transparency.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#128
post #49
post #41

Earlier quoted context omitted.

China. Specifically, gradual capitulation to China. "Apple's earnings for Greater China in Q2 2021 were up 87.5% from this time last year, to $17.7 billion. During its latest earnings call, Apple has announced dramatically increased revenues from Greater China for the three months ending March, 2021." China has cracked down hard on domestic Internet companies over the past few weeks (deliberately crushing their tech…

These new features both launch US-only, however.

So far.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#129
post #107

Earlier quoted context omitted.

So you think if Apple announced a new algorithm that would be used for mass surveillance of the Chinese, there'd be some kind of mass outrage. And to avoid that mass outrage, they're starting with mass surveillance against Americans instead. None of that makes sense. Why would using the system only to target child abuse in the US make people change their mind about using it against political dissidents?

Well, speaking broadly: that’s not how politics works. If you go for a thing directly you show your hand and get a lot of backlash. Case in point: the British NHS (because we can see it happening in real time). Add the capability to do something for a good reason (NHS spending should be more efficient; we need approved suppliers // do it for the children) in order to make the further move of what you really want with…

>If you go for a thing directly you show your hand and get a lot of backlash.

In this context, it is exactly how politics work, and you have described shifting the Overton window or even floating the Trial balloon.

re: NHS. The case you are making doesn't fit your reasoning. As for privatisation in general, the current government is following a very basic rulebook:

1. Sabotage/kneecap an institution/ 2. Offer a solution involving cronies/ 3. Achievement Unlocked

1. For example, some Tory MP's (the elite that make the decisions for the plebs) don't need to rely on NHS for healthcare exclusively, hence they have a callous attitude towards it. They deploy all manner of subterfuge, replete with claps, lies and smiles, to starve out a public service funded by taxpayers.

2. The ultimate goal; offer a solution to the problem you manufactured (1) and share the spoils amongst yourselves, by awarding/rewarding and looking after each other's interests.

3. Self-explanatory.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#130

I was patiently waiting for the M1 16in MacBook Pro to come out. After reading all these revelations, I am now considering not buying the new MacBook Pro and instead, just stick with Linux.

I am an app developer who was thinking of upgrading to the next M1 Mac mini coming out later this year. For my work, I pretty much need an Apple hardware. However after this whole privacy debacle, I have started looking into Hackintosh and whether I can build one to for building my apps. If anyone has experience with developing for iOS/MacOS on hackintosh, please let me know your experience.

> please let me know your experience

You can run Linux as a host, macOS as a guest[1] under QEMU, buy a second GPU that is supported by Apple (e.g., Sapphire Radeon RX 580 Pulse 4GB) and pass that GPU in its entirety to the guest macOS. The same for one of the USB controllers on your motherboard. Effectively, you get native macOS performance under Linux. A bonus: you can use the iptables firewall with the FORWARD ruleset to control guest macOS network access. The overall setup process is involving, but nothing that an intermediate Linux user would not be able to handle. Please note that it might be actually illegal (?) in some (?) countries to run macOS software on non-Apple hardware.

[1] https://github.com/kholia/OSX-KVM

Post reply on HN