Live data from Hacker News

U.K. orders Apple to let it spy on users’ encrypted accounts

washingtonpost.com

11–20 of 1001 posts

Re: U.K. orders Apple to let it spy on users’ encrypted accounts

#11
post #2

US tech needs to obey the laws of the country in which it operates. I am sure the demands of UK government are more than reasonable - and, as it is a democracy - as full endorsement of the people / users

It doesn't. Apple could play hardball and threaten to withdraw from the UK market, with a propaganda notification like TikTok did. They could also appeal to Trump/Elon for help.

Also the wider part of this order is that Apple would access to the international users data, including US customers, if I understand the article correctly.

Re: U.K. orders Apple to let it spy on users’ encrypted accounts

#12

The bad guys know where to find solid open source crypto for their cloud backups and whatnot. Therefore you know this is not about chasing the bad guys. It's about keeping the Average Joe under the thumb.

> The bad guys know where to find solid open source crypto for their cloud backups and whatnot.

That's a very bold assumption after EncroChat and SkyECC.

Re: U.K. orders Apple to let it spy on users’ encrypted accounts

#14

The bad guys know where to find solid open source crypto for their cloud backups and whatnot. Therefore you know this is not about chasing the bad guys. It's about keeping the Average Joe under the thumb.

I don't know to what extent this is true. A lot of criminals strike me as good at chopping off fingers etc but not computer stuff.

There absolutely is a balance between Average Joe's right to privacy and privacy restrictions for fighting crime. Without undermining the former, I'm astounded how HN discounts the latter 100%. It is real.

Re: U.K. orders Apple to let it spy on users’ encrypted accounts

#15

Apple should green bubble all UK text messages and explain that it is the law.

Is green bubble iMessage or SMS? iMessage is barely used in the UK, WhatsApp is the default messaging platform here

I'm in the UK pretty much only use iMessage/Snapchat.

I had a look at the stats though and you're probably correct about WhatsApp being default, although we do have a surprisingly diverse and competitive messenger market:

https://www.statista.com/forecasts/997945/most-used-messenge...

Re: U.K. orders Apple to let it spy on users’ encrypted accounts

#16
post #2

US tech needs to obey the laws of the country in which it operates. I am sure the demands of UK government are more than reasonable - and, as it is a democracy - as full endorsement of the people / users

I’m from the U.K. and I consider the government’s actions around digital privacy to be somewhere between incompetent and malicious.

Re: U.K. orders Apple to let it spy on users’ encrypted accounts

#17

The bad guys know where to find solid open source crypto for their cloud backups and whatnot. Therefore you know this is not about chasing the bad guys. It's about keeping the Average Joe under the thumb.

It'll catch the bad guys who don't know what they're doing, which is a pretty big percentage of them.

Re: U.K. orders Apple to let it spy on users’ encrypted accounts

#18

Apple should green bubble all UK text messages and explain that it is the law.

Is green bubble iMessage or SMS? iMessage is barely used in the UK, WhatsApp is the default messaging platform here

Green bubble is messages you sent via SMS (and so may have been charged by your carrier depending on your cellular plan)

Blue bubble is messages you sent via iMessage.

All incoming messages are grey, regardless of whether they were sent to you via SMS or iMessage.

Re: U.K. orders Apple to let it spy on users’ encrypted accounts

#19
Archive link: https://archive.is/3Pp0U

I was wondering whether this is about Advanced Data Protection, which encrypts almost all data end-to-end on iCloud. It’s only later in this report that it gets into this key detail:

> At issue is cloud storage that only the user, not Apple, can unlock. Apple started rolling out the option, which it calls Advanced Data Protection, in 2022.

Before stating this, the article says:

> Rather than break the security promises it made to its users everywhere, Apple is likely to stop offering encrypted storage in the U.K., the people said.

This means Apple would be prevented from providing Advanced Data Protection to users in the U.K.

Not making Advanced Data Protection available is made worse by this requirement:

> One of the people briefed on the situation, a consultant advising the United States on encryption matters, said Apple would be barred from warning its users that its most advanced encryption no longer provided full security.

Apple can appeal, but is forced to comply meanwhile (until the appeal is heard) anyway:

> Apple can appeal the U.K. capability notice to a secret technical panel, which would consider arguments about the expense of the requirement, and to a judge who would weigh whether the request was in proportion to the government’s needs. But the law does not permit Apple to delay complying during an appeal.

Re: U.K. orders Apple to let it spy on users’ encrypted accounts

#20

The bad guys know where to find solid open source crypto for their cloud backups and whatnot. Therefore you know this is not about chasing the bad guys. It's about keeping the Average Joe under the thumb.

That's true at a point in time, but bad guys start out as clueless noobs with poor opsec. The Silk Road guy, for example, was identified by forum posts he made before becoming a drug lord. The sort of people who become radicalized through online videos aren't using strong crypto until after they've committed to becoming terrorists. So a database of texts going back several years is quite useful in catching actual bad guys.

Which is not to say I approve of more surveillance. Just that surveillance of convenient modes of communication (iMessage) is useful to serious crime fighting.

Post reply on HN