Live data from Hacker News

U.K. demand for a back door to Apple data threatens Americans, lawmakers say

washingtonpost.com

91–100 of 331 posts

Re: U.K. demand for a back door to Apple data threatens Americans, lawmakers say

#91

Earlier quoted context omitted.

How do you know that? Similarly to the UK, USA has a process to force companies to add back doors. For all we know it might the USA wanting access and using its five eyes allies to get it done.

Point to the law that requires them to do it and keep quiet about it. The US law. I'll wait.

There does not have to be a law for the US government to do something.

Remember the NSA spying scandal?

Re: U.K. demand for a back door to Apple data threatens Americans, lawmakers say

#92
post #71
post #65

Earlier quoted context omitted.

It'd be kinda like GDPR if the EU has demanded that non EU companies apply GDPR to non EU citizens As described by the parent post it's nothing like EU "overreach" on privacy (whatever that even means)

How am I supposed to put up a website intended for US citizens onto the world -wide-web, without worrying about GDPR?

You only need to worry about GDPR if you are harvesting and saving personal and identifiable information on your users.

If you are not doing that then you dont even have to think about it.

Re: U.K. demand for a back door to Apple data threatens Americans, lawmakers say

#93
post #81
post #57

Earlier quoted context omitted.

Define "backdoor". US authorities being able to demand data service providers have access to (eg. your gmail account) is nowhere comparable to an encryption backdoor, which is what's proposed here.

Because the US don’t ask for a backdoor in encryption, they build it https://en.wikipedia.org/wiki/Dual_EC_DRBG

Your own article admits it's basically used nowhere. That's important, because OP specifically claims that the US government has"access to all non-American's personal data". Moreover it was widely condemned, contrary to OP's claim of "but when the UK/EU wants something similar, suddenly it's a massive outrage. Is it just "we're stronger than you", so it's ok when we do it?".

Re: U.K. demand for a back door to Apple data threatens Americans, lawmakers say

#94
post #5

I think this is an unquestionable overreach on the UK's part. If you live in any country that isn't the UK, you should feel the threat from this: the UK government believes that it is entitled to a backdoor on your hardware, even if you've never stepped a foot on UK soil or intend to. Mass surveillance is a threat to everyone, but this is not an instance of that, which has guards against it, like encryption. This is…

I'm from the UK, and I completely agree.

The general public either don't know about growing mass surveillance and privacy invasions, or don't care. "Terrorism and child abuse = bad, and if this prevents it and I have nothing to hide then why would it be a problem for me?"

Re: U.K. demand for a back door to Apple data threatens Americans, lawmakers say

#95
post #53
post #50

Earlier quoted context omitted.

Here's the BBC report on the matter: https://www.bbc.co.uk/news/articles/c20g288yldko It applies to content stored using ADP, Apple's E2EE tech. A backdoor into that would mean applying a backdoor into iOS on the phone itself, which is a much larger attack surface than anything centralised. All of which highlights the clownish nature of these regulations. They are so easy for bad actors to circumvent (eg using their…

I'm entirely against what the UK government wants, however I would say: Although you're right that tech people would still be able to choose secure encrypted options, the fact is that the majority of criminals by pure numbers are not very sophisticated - so while this sort of backdoor obviously wouldn't be a guarantee that every criminal conversation could be snooped on, it would work on the 90-99% (I'd guess towards…

The majority of criminals have no idea that their their iMessage encryption keys and iMessages are synced into the cloud and available to law enforcement with a warrant. No need to break devices security, no need for back doors.

Re: U.K. demand for a back door to Apple data threatens Americans, lawmakers say

#96
post #92
post #71

Earlier quoted context omitted.

How am I supposed to put up a website intended for US citizens onto the world -wide-web, without worrying about GDPR?

You only need to worry about GDPR if you are harvesting and saving personal and identifiable information on your users. If you are not doing that then you dont even have to think about it.

This always gets trotted out, usually by people who seem to have never run any web service before. IPs are apparently PII, and all default server configs log them. If you don’t, good luck complying with any security audits that will require you to keep them to make forensics possible.

This is just one of the things that makes GDPR, in practice, an “if we don’t like you, we’ll investigate you and will definitely find something” law.

Re: U.K. demand for a back door to Apple data threatens Americans, lawmakers say

#97
post #43

Earlier quoted context omitted.

As with the US, I would not equate "British lawmakers passed" with "British people are happy to". British people are not given direct referendum on this issue specifically, and all of the mainstream British parties currently support the Snooper's Charter.

Mate, the "take all steps necessary to root out paedophiles" referendum would be won with 95% of the vote. It's all in the framing, you know that.

> It's all in the framing

Yeah, that's the root of the problem, I think.

It's easy to sell people that "we just need this one more bit of access to your private data, it helps us stops paedophiles and terrorists", but each step takes us further down a bad path.

I'm sure everybody would agree that having full camera surveillance inside every UK home is too far, but no oversight at all is also bad.

There is a point along that line where society would say "no, that's enough", but successive governments have realised that they can slowly push that point further right and nobody seems to notice, or care.

Re: U.K. demand for a back door to Apple data threatens Americans, lawmakers say

#98
post #50
post #5

I think this is an unquestionable overreach on the UK's part. If you live in any country that isn't the UK, you should feel the threat from this: the UK government believes that it is entitled to a backdoor on your hardware, even if you've never stepped a foot on UK soil or intend to. Mass surveillance is a threat to everyone, but this is not an instance of that, which has guards against it, like encryption. This is…

Here's the BBC report on the matter: https://www.bbc.co.uk/news/articles/c20g288yldko It applies to content stored using ADP, Apple's E2EE tech. A backdoor into that would mean applying a backdoor into iOS on the phone itself, which is a much larger attack surface than anything centralised. All of which highlights the clownish nature of these regulations. They are so easy for bad actors to circumvent (eg using their…

Since it seems to be illegal to even reveal if one of these requests was received, it's also worrying that, by extension, it would be illegal to declare a data breach once the backdoor was inevitably exploited by another bad actor.

So, how would anybody know that a foreign government was spying on them? Nothing would stop them installing Pegasus on your phone and exfiltrating even your 'secure' data.

The stupid thing is that these laws always find a way to say that people in government are exempt from the provisions, and everybody except them is allowed to be spied on, but they are obviously going to be the first people to be targeted. Not some randomer hoarding CSAM.

Re: U.K. demand for a back door to Apple data threatens Americans, lawmakers say

#99

Not to be cynical, but if anyone has looked at anything revealed about security agencies in the last few years it's very clear what's happening here - whenever US wants to do something unpopular/straight up illegal, it just asks the UK(or any other partner country) to do it instead. American government can't ask Apple for data on any American citizen, but if UK obtains that data and then it happens to be shared betwe…

UK governments have been pushing for this for years, usually invoking some recent terrorist event as justification.

I'm not suggesting you're wrong, but I don't think this is _just_ the UK being a US puppet, there is very much an appetite for it in the UK parliament too.

Re: U.K. demand for a back door to Apple data threatens Americans, lawmakers say

#100
post #88
post #82

Earlier quoted context omitted.

market cap is not comparable to GDP. GDP is comparable to value added or profit.

Apple doesn’t need the UK business, but many people will get upset if their iPhone stops working. That’s pretty big leverage.

> Apple doesn’t need the UK business,

I think shareholders would disagree. Several billion in sales and all assets in the UK are not insignificant. On top if that would be the reaction of other governments to seeing a business successfully defy a government. ait could be them next.

>That’s pretty big leverage.

True and it shows how foolish governments are to allow such reliance on foreign suppliers.

Post reply on HN