Live data from Hacker News

Apple dropped plan for encrypting backups after FBI complained (2020)

reuters.com

141–150 of 228 posts

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#141
post #140

> However, a former Apple employee said it was possible the encryption project was dropped for other reasons, such as concern that more customers would find themselves locked out of their data more often. Sounds more plausible to me. Most of Apples customers are normal end-users, I can see how loosing access is worse for them as compared to data being available for a search warrant. I suspect "risk of loosing the key…

Almost all of the “iCloud Leaks” aka “The Fappening” occurred because hackers could infiltrate an iCloud account, then use software to exfiltrate the contents of backed up iPhones/iPads, in addition to the user’s photo streams. The backups often contained unsync’d photos, some that were even deleted.

This was a massive PR hit for Apple that continues to this day.

My guess is that they saw encrypted backups as a solution to the leak problem, but the FBI has long used iOS backups as a back door into increasingly difficult and expensive to crack iPhones. Phone analysis is the #1 most common investigative tool for federal (and now, all) law enforcement, so turning off a major tool likely required intervention at the highest levels of government.

Big brother does not like losing their spying abilities.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#142
post #78

Earlier quoted context omitted.

> It seems really unlikely to me that Apple will enable E2EE backups. And even if they did, how would we verify that the code they instruct our hardware to run does e2ee correctly, without bugs or backdoors? Apple doesn't seem to be in the habit of opening much of their code or (on mobile) allowing users to install unapproved builds. Unless that changed, I would be skeptical, just as I am of all "e2ee" software that…

Out of curiousity how are you auditing the pre compiled binaries of otherwise open source software? I spent 2 months going through the signal code base checking it and now I need to audit the production code on their servers as well as the binaries they have compiled. Any tips?

You have to assume that everything you do not control and monitor is compromised.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#143
post #10

Some have speculated that with the introduction of the PSI/CSAM system Apple will enable E2EE backups. Given the lack of an explicit statement on Apple's part and their history regarding E2EE backups (this article, and other statements). It seems really unlikely to me that Apple will enable E2EE backups. Under E2EE, assuming the device key is randomly generated, if you have one device (as many users do) and you lose…

Some also the introduction of the PSI/CSAM system to Apple means anything they do can no longer be considered E2EE as there is a built in backdoor to the encryption that allows a 3rd party to scan communications, as such it should not be considered a End-to-End Encryption system

I agree with this analysis

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#144

I was patiently waiting for the M1 16in MacBook Pro to come out. After reading all these revelations, I am now considering not buying the new MacBook Pro and instead, just stick with Linux.

I am an app developer who was thinking of upgrading to the next M1 Mac mini coming out later this year. For my work, I pretty much need an Apple hardware. However after this whole privacy debacle, I have started looking into Hackintosh and whether I can build one to for building my apps. If anyone has experience with developing for iOS/MacOS on hackintosh, please let me know your experience.

Note that by doing app development you keep feeding the monster.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#145
post #136

Earlier quoted context omitted.

Apple is doing the right thing. About 1 in 4 girls and 1 in 13 boys experience child sexual abuse in the US at some point in childhood (underreported) [1]. What's more important? Your right to "privacy" (which you can still invoke by simply not using iCloud) or their right to a normal life? And yes, their CSAM detection has lots of false-positives, but it will evolve. It will be doubleplusgood. [1] https://www.cdc.go…

>What's more important? Your right to "privacy" (which you can still invoke by simply not using iCloud) or their right to a normal life? My right to privacy of course because the other option is a strawman. What you are doing is the typical slippery slope of selling out something for everyone because of a small minority of criminals. "Should criminal Mr. X be allowed to do Bad-Thing-At-Level-10 to Small-Amount or sho…

25% of all girls (officially). That's not a small minority of criminals, that's a national tragedy.

Americans must use every legal and constitutional tool in their arsenal to fight abuse and protect their children. The numbers make clear that the old rules no longer work.

And it's "clearly illegal" because of... what? Because his (unnamed) attorney claims it's a felony? What if a different attorney claims it's perfectly legal?

It's just a CSAM detector for content you upload to iCloud. We're willing to shut down schools and shops to save lives but if there's a theoretical .000001% chance that some rando might look at my beach photos, it's suddenly mass-surveillance backdoor China stuff? Come on. We live in a society.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#146
post #70

Earlier quoted context omitted.

What data are they responding with? Account name and creation date? IP addresses used to log in to the account? iCloud backups?

I love how outraged people get when a company responds to a court order like in the fantasy world they live in Apples lawyers are running into court, screaming 'Objection Your Honor' while Tim Cook is furioulsy shredding your papers for you. Court orders are part of basic auditing of a service. Seeing what they have to hand over on request (they will hand over everything) tells you exactly what information they have.

NSLs aren't court orders and the FISC is not exactly the pinnacle of due process.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#147
post #10

Some have speculated that with the introduction of the PSI/CSAM system Apple will enable E2EE backups. Given the lack of an explicit statement on Apple's part and their history regarding E2EE backups (this article, and other statements). It seems really unlikely to me that Apple will enable E2EE backups. Under E2EE, assuming the device key is randomly generated, if you have one device (as many users do) and you lose…

I don't know why anyone would assume this changes anything with regards to E2E at all.

Like you've said, Apple haven't announced anything, and I don't see what the business case is from their perspective when most people don't know or care what that means (but surely will care if they lock themselves out of their data forever).

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#148

This really is something Tim needs to address before he again stands on stage and give lip service to Privacy with a capital P. We also need hardball journalists to start asking Tim these tough questions instead of fawning over AirPods And we need employees to start demanding this internally

Marketing. Apple does not care about your privacy but your perception. The EFF cares about your privacy.

It's not just marketing. As I understand it, purporting to provide a public good can help in antitrust negotiations.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#149
post #136

Earlier quoted context omitted.

>What's more important? Your right to "privacy" (which you can still invoke by simply not using iCloud) or their right to a normal life? My right to privacy of course because the other option is a strawman. What you are doing is the typical slippery slope of selling out something for everyone because of a small minority of criminals. "Should criminal Mr. X be allowed to do Bad-Thing-At-Level-10 to Small-Amount or sho…

25% of all girls (officially). That's not a small minority of criminals, that's a national tragedy. Americans must use every legal and constitutional tool in their arsenal to fight abuse and protect their children. The numbers make clear that the old rules no longer work. And it's "clearly illegal" because of... what? Because his (unnamed) attorney claims it's a felony? What if a different attorney claims it's perfec…

25% of all girls what?

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#150

Earlier quoted context omitted.

25% of all girls (officially). That's not a small minority of criminals, that's a national tragedy. Americans must use every legal and constitutional tool in their arsenal to fight abuse and protect their children. The numbers make clear that the old rules no longer work. And it's "clearly illegal" because of... what? Because his (unnamed) attorney claims it's a felony? What if a different attorney claims it's perfec…

25% of all girls what?

[deleted]
Post reply on HN