Live data from Hacker News

Apple says it'll remove iMessage and FaceTime in UK rather than break encryption

9to5mac.com

601–610 of 785 posts

Re: Apple says it'll remove iMessage and FaceTime in UK rather than break encryption

#601

Earlier quoted context omitted.

I like this vein of argument: assume that it is good that the government be able to snoop on your text messages. Why not in-person conversations as well? OK, let's make it so everything you say gets recorded. Eesh.

Yeah... the crux is should electronic conversations be afforded the same rights, and by extension are they assumed rights for all communication? Where to draw the line? It's definitely murky.

By analogy, what if I have multiple pairs of tin cans, where each pair of tin cans is connected by a string, and sell those pairs of cans to people so that they can have private conversations at a distance from one another.

If I provide privately owned physical infrastructure for protecting those strings and facilitating the routing of the strings am I obligated to make that available to the government for eavesdropping?

Re: Apple says it'll remove iMessage and FaceTime in UK rather than break encryption

#602
post #370

Earlier quoted context omitted.

Individually no, but in aggregate... A few games here, iMessage, Facetime, Whatsapp maybe, some other internet products, etc Does it boast something else to make up for the loss of these things? Trading something for nothing always feels kinda bad. And if the trade is "We stood up for the right thing with respect to Cloud Gaming monopolization", you constituents might be kinda pissed after a while. You know the old a…

in reality another large company will enter the void where apple was with the correct regulatory approval and take the entire market

The market is far less lucrative without the network effects of iMessage and WhatsApp

Re: Apple says it'll remove iMessage and FaceTime in UK rather than break encryption

#603
I am proud of Apple for doing this. I give the same praise to Signal for making the same decision.

Breaking encryption via backdoors is like a gift to organized crime.

Privacy is also crucially important if you want to maintain free societies long term. Same comment for free speech for public discourse.

Re: Apple says it'll remove iMessage and FaceTime in UK rather than break encryption

#604

Earlier quoted context omitted.

iCloud Keys are managed by a Chinese company, so in practice, yes. iPhone E2E stuff like iMessage, by definition, does not have keys that anyone else (including the government) possess. Though it hardly matters when ~90% of iPhone users likely have iCloud Backup on. In which case their messages will be backed up to the cloud to where the government could get keys.

Source? IIRC Apple was hosting data from Chinese citizens in China to comply with regulation but still keeping encryption keys outside of China.

They gave it over. Apple does not care about privacy the way it has trained American consumer to think it does.

Re: Apple says it'll remove iMessage and FaceTime in UK rather than break encryption

#605
I dont think they realise the hacking I've seen on computers is at the HW level.

Take this PC, a fairly new dell, all patched with the bios et al, and certain websites (dailymail, youtube and reddit) with adverts deliver something that disables the dell mouse.

Only option is to reboot the pc but I have to take the mouse out of the usb and plug it back otherwise the dell usb mouse still wont work after a reboot.

So I love their hubris, but I dont think they see some of the hacking that goes on because its at the hw level.

Re: Apple says it'll remove iMessage and FaceTime in UK rather than break encryption

#606
I am reminded of a conversation on Security Now where Steve Gibson recommended that each website that has traffic inside the UK to have a red banner at the top of the page to sentiment of something like, "The UK Government is forcibly watching traffic on this website."

Watch how quickly that turns the conversation around.

This argument lawmakers have here is entirely built upon the straw man. I understand the deep yearning to protect children but all this won't make the criminals stop using the tools that are currently legal. They will continue to use them. Making them "illegal" won't make them stop using them because they can still be acquired.

Re: Apple says it'll remove iMessage and FaceTime in UK rather than break encryption

#608
post #600

Earlier quoted context omitted.

> I feel we've been collectively losing the battle to keep our conversations private. The USA is still doing pretty good but the UK and the EU are staunchly anti privacy. They're pretty good on consumer privacy but don't believe that privacy from the government should exist.

This feels pretty opposite to me. I mean sure UK is pretty privacy hostile in practice (CCTVs everywhere), but what does the US have for companies surveillance of people? How much of that data is legal for governments to buy? Maybe the US gov isn't spying on citizens, but how many 5-eyes partners are definitely sending data to them in proxy (by careful surveillance design)? I guess my question boils down to what spec…

Is TFA not a good enough example?

Re: Apple says it'll remove iMessage and FaceTime in UK rather than break encryption

#609
post #370
post #325

Earlier quoted context omitted.

Inversely, is the UK so much worse off for not having a few games in their market? Neither is so big it can go without the other, not only the UK.

Individually no, but in aggregate... A few games here, iMessage, Facetime, Whatsapp maybe, some other internet products, etc Does it boast something else to make up for the loss of these things? Trading something for nothing always feels kinda bad. And if the trade is "We stood up for the right thing with respect to Cloud Gaming monopolization", you constituents might be kinda pissed after a while. You know the old a…

Maybe it does boast something else. I am genuinely unsure whether being able (after a judge orders it) to unlock encryption, similar to a front door, is a bad thing. I don't like it, it stinks, I'd hate to experiment with things like this and so I'd vote against it, but is it going to end up worse for the greater good? Can't we still just use proper/steganographic encryption when an authoritarian regime gains power, and until then is it better? I can't say that beyond reasonable doubt. That safer society can be argued to be a boast that makes up for it (I'm not saying it definitely is. I'm unsure. Very unsure).

And for the other, anti-monopolistic market authorities, the "boast" is a level playing field.

Re: Apple says it'll remove iMessage and FaceTime in UK rather than break encryption

#610
post #520

Earlier quoted context omitted.

Isn't that why we pay gov agents to hang out in the seedy parts of the web? If CP consumers are able to find each other with relative ease, I'm sure agents impersonating them can find them too. Then it's up to them to locate them, likely by exploiting an opsec failure along the way. I see no reason the give the gov eyes on everything when they have a perfectly valid route to investigations.

I'll also play Devil's advocate even though I'm a very vocal advocate for data privacy in real life. These government agents are people as well, and as people they'll suffer to wade through the dark corners of the web to locate a minuscule part of all the CP data available worldwide. These people will inevitably require mental care to deal with the trauma of looking at GiBs and GiBs of small kids being raped, that's…

Stop focusing on CP/Abuse.

Governments use CP/Abuse to pass legislation, which is immediately used for almost anything other than that. If a government did actually care about child welfare there are many things they could do that would actually help children.

But this law to "protect children" is being passed by a government that is simultaneously cutting services that help children, and also trying to reduce/restrict sex ed that so that it is easier to abuse children, I'm going to say that "protecting children" is not their goal with this law.

As I said elsewhere, any argument for "we need the ability to remotely access the content of a phone" (which is what the law is demanding: silent updates to remove encryption and anything else they "need") equally applies to having a government mandated cameras in every house. That would actually prevent child abuse. It would prevent domestic violence. If such was happening the police could intervene immediately. It would remove he said/she said from courts: you can simply play the video from the home.

By the definition of "no encryption because protect-the-children", mandatory cameras in every room of every house is both acceptable, and also objectively superior to BS anti-encryption laws. You can't abuse or beat your family members in the first place if a camera is watching, but anyone moving CSAM around on the internet isn't going to have a problem getting an actual encrypted channel - all the law does is make your personal communication, banking, finances, etc insecure, criminals are safe. Of course even if someone does use a now insecure communication channel to share their child abuse it's moot: the cameras in their house would have already caught them.

So why screw around with "make everyone (including children) unsafe to 'protect the children'" when there's a much more effective solution that would stop the abuse in the first place?

Also, the UK already passed a bunch of "you don't get privacy" laws in order to "prevent terrorism", and they seem to be used primarily to catch people not picking up dog poop, not paying tv licensing fees, etc which sure as shit doesn't sound like it's terrorism related.

In summary: if a law that would otherwise violate fairly basic rights is being pushed with clearly emotive justifications like "child abuse", "terrorism" you should assume you are being played.

The police do not need more power. They do not need to violate everyone's rights. They need to do their jobs and do actual work with what they already have, and demonstrate basic competence before they get any more invasive tools. Recall the Ariana grande bombing in the UK? Multiple friends and family of the bomber had independently and repeatedly reported them to the UK police. 9/11: multiple US government agencies had all the information needed, but were too busy trying to compete with each other. In addition (tens of, if you look at the US) thousands rape kits that aren't even processed, and weirdly they keep finding serial killers and rapists when. they. just. do. their. job.

Throwing away more of our privacy, when police already have huge amounts of information that they just can't be bothered to look at, is beyond stupid.

Similarly, based on the track record of supporting and aiding child abusers, and cutting support for children, any claims a government makes saying something is to "protect children" is clearly false.

Post reply on HN