Live data from Hacker News

Apple dropped plan for encrypting backups after FBI complained (2020)

reuters.com

151–160 of 228 posts

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#151

Earlier quoted context omitted.

25% of all girls (officially). That's not a small minority of criminals, that's a national tragedy. Americans must use every legal and constitutional tool in their arsenal to fight abuse and protect their children. The numbers make clear that the old rules no longer work. And it's "clearly illegal" because of... what? Because his (unnamed) attorney claims it's a felony? What if a different attorney claims it's perfec…

25% of all girls what?

"About 1 in 4 girls [...] experience child sexual abuse at some point in childhood."

https://www.cdc.gov/violenceprevention/childsexualabuse/fast...

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#152
post #136

Earlier quoted context omitted.

>What's more important? Your right to "privacy" (which you can still invoke by simply not using iCloud) or their right to a normal life? My right to privacy of course because the other option is a strawman. What you are doing is the typical slippery slope of selling out something for everyone because of a small minority of criminals. "Should criminal Mr. X be allowed to do Bad-Thing-At-Level-10 to Small-Amount or sho…

25% of all girls (officially). That's not a small minority of criminals, that's a national tragedy. Americans must use every legal and constitutional tool in their arsenal to fight abuse and protect their children. The numbers make clear that the old rules no longer work. And it's "clearly illegal" because of... what? Because his (unnamed) attorney claims it's a felony? What if a different attorney claims it's perfec…

> Americans must use every legal and constitutional tool in their arsenal to fight abuse and protect their children.

They could start by regulating guns. That would prevent the death, injury, and traumatisation of many children[1]. As a bonus, it would do the same for adults[2].

Or they could deal with the “urgent and preventable crisis” of having 1 in 6 children living in poverty[3].

People in these discussions aren’t against protecting children. Rather, they’re questioning the ulterior motives behind specific policies. If governments and companies could be trusted to keep their promises and not overreach, no one would be batting an eye at the recent Apple announcement. But historically, the inverse has been true: they’re pretty much guaranteed to try to abuse the system.

[1]: https://en.wikipedia.org/wiki/List_of_school_shootings_in_th...

[2]: https://en.wikipedia.org/wiki/List_of_mass_shootings_in_the_...

[3]: https://www.childrensdefense.org/policy/resources/soac-2020-...

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#153

In the first half of 2020, Apple gave data on over 31,000 users/accounts based on FISA requests National Security Letter requests[1]. Apple provided data to the government's requests roughly 9,000 times. About 85% - 92% of the time, according to Apple, they responded to data requests from the government with the data that was requested. I don't see why Apple would turn about face and make it impossible to respond to…

FISA orders (PRISM) are not NSLs.

Neither FISA/702 orders or NSLs are warrants though, and they do not require probable cause.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#154
post #111

Earlier quoted context omitted.

At this point, with Apple introducing a feature for law enforcement the general public had no opinion on or interest in, I'd argue Apple is more likely to expand what the new system does than improve E2EE.

The theory was that they are adding the client-side backdoor to please the US institutions and to be allowed to E2EE iCloud.

Pretty insane that one needs to kowtow to illegal spies to be able to publish software.

Seems like a 1A battle they don't want to fight, because the actual retaliation for the 1A exercise would come in the form of regulation or antitrust that is unrelated to the publication of the objectionable software.

Sad state of affairs in the USA.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#155
post #10

Some have speculated that with the introduction of the PSI/CSAM system Apple will enable E2EE backups. Given the lack of an explicit statement on Apple's part and their history regarding E2EE backups (this article, and other statements). It seems really unlikely to me that Apple will enable E2EE backups. Under E2EE, assuming the device key is randomly generated, if you have one device (as many users do) and you lose…

Correct me if I am wrong. But I think E2EE also makes storage cost much more expensive since no piece of Data are the same again.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#156

I'm actually curious, are they allowed to encrypt backups if FBI requested them not to? I thought as American company you have to comply with the law as well. Not sure though Edit: damn downvotes, is this reddit? I'm literally asking because I don't know. nothing is controversial here

It's legal to do e2e backups; Google does for android.

Apple knows which way the wind blows. If they piss off the USG spies, there are lots of "unrelated" ways to make them hurt, including but not limited to additional regulation or antitrust enforcement against their anticompetitive moneymaker App Store.

What this means is that if you are big enough, the 1A doesn't actually apply to you and you can't publish any legal software you like, because the FBI/IC/military will cause you to suffer even though you haven't broken the law.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#157
post #152

Earlier quoted context omitted.

25% of all girls (officially). That's not a small minority of criminals, that's a national tragedy. Americans must use every legal and constitutional tool in their arsenal to fight abuse and protect their children. The numbers make clear that the old rules no longer work. And it's "clearly illegal" because of... what? Because his (unnamed) attorney claims it's a felony? What if a different attorney claims it's perfec…

> Americans must use every legal and constitutional tool in their arsenal to fight abuse and protect their children. They could start by regulating guns. That would prevent the death, injury, and traumatisation of many children[1]. As a bonus, it would do the same for adults[2]. Or they could deal with the “urgent and preventable crisis” of having 1 in 6 children living in poverty[3]. People in these discussions aren…

Please don't use Whataboutism to derail this thread. This discussion is about handling Child Sexual Abuse Material (CSAM) on iPhones.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#158

There's a way to make fully encrypted backups of your iPhone locally, check out my blog post from my self-hosting series: https://www.naut.ca/blog/2020/03/20/self-hosting-series-part... This works well on Linux, and iOS 14. You can skip to the section `Compiling idevicebackup2`.

Doesn't matter; everyone you iMessage with is sending the plaintext of all of your conversations and attachments to Apple in their device's non-e2e iCloud backup. SMS too!

Local backups won't get you privacy when the other end of the chat is still doing cloud backups.

It's sort of like moving email providers and continuing to send and receive email from people with gmail addresses. Google is still reading all of your mail and attachments, just out of your friends' gmail boxes.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#159

Earlier quoted context omitted.

A viable alternative is multiple LUKS-style key slots, one per registered device that can be unlocked with a device keys, and one that is by default encrypted with a key derived from your iCloud password. If you lose all your iDevices _and_ your password at the same time, you lose your data. They could also make this opt in (add another escrow key slot by default, but allow you to promise that you've written down a r…

> If you lose all your iDevices _and_ your password at the same time ... I don't know how this is with iPhones (I don't own one), but with Android these events are almost 100% correlated for many people. That's because you never get prompted for your Google account password on your phone. If you don't use the same Google account on your phone as on your desktop, or don't really use your Google account on the desktop…

> “That's because you never get prompted for your Google account password on your phone. […] then you might never need to know your password.”

This is so true. 1Password silently changed their UX on iPhone app 4 years (?) ago and the primary password was not required between app-quit. I had tweaked my password after using it every minute one weekend installing a new system. When I finally needed the master password, the new password was not accepted. Evidently I misremembered the tweak. That experience still burns me. Not forgotten, not forgiven.

iPhone requires iCloud for purchases, but I use touch password and bypass this. I never need to use iCloud password.

Re: Apple dropped plan for encrypting backups after FBI complained (2020)

#160

The answer is simple. Disable iCloud/iMessage, backup/restore your files the old fashioned way, and use Telegram or something for messaging. Don’t even opt into any of the ways they can spy on you. iCloud and iMessage suck anyways, you aren’t really losing anything of value

Apple can reach in and turn those on and trigger a backup whenever they want. I'm actually curious how telegram and signal deal with this, I haven't researched that yet. End to end doesn't work if the endpoint is compromised, and apple has that baked in as a "feature".

Answering myself;

https://medium.com/@elcomsoft/forensic-guide-to-imessage-wha...

Signal; -Legal requests: Signal does not keep communication histories its servers. Since there is nothing to request, Signal conversations cannot be obtained with legal requests. -Vendor cloud: Signal does not keep conversations on its servers. Cloud acquisition is not possible. -Local backups: Signal does not store conversations in local (iTunes) backups. -iCloud backups: Same as above. Signal does not store conversation histories in iCloud backups. -iCloud Drive: No stand-alone backups in iCloud Drive. -File system: Signal database is encrypted. The encryption key is stored in the keychain with the highest protection class. Extracting and decrypting the keychain (e.g. with Elcomsoft iOS Forensic Toolkit) is required in order to decrypt the Signal database.

Telegram; -Legal requests: Telegram keeps a comprehensive history of the user’s regular (non-secret) chats on its servers. Regular and group chats can be obtained with a legal request depending on jurisdiction. Secret chats are never stored and cannot be obtained with a legal request. Telegram is notable for ignoring legal requests in some jurisdictions, which had led the service banned in several countries. -Vendor cloud: As mentioned above, Telegram keeps the history on its own servers. By authenticating as a user, one can retrieve those communications (except secret chats) from Telegram servers. -Local backups: Telegram does not store conversations in local backups. Instead, conversation histories are synchronized using Telegram’s own cloud service. -iCloud backups: Same as above. Telegram does not store conversation histories in iCloud backups. -iCloud Drive: There are no stand-alone backups in iCloud Drive. -File system: Telegram does not feature any additional protection to the working database. Once a file system image is captured from the iPhone, extracting and analyzing Telegram conversations including secret chats and attachments is trivial.

Post reply on HN