Live data from Hacker News

U.K. demand for a back door to Apple data threatens Americans, lawmakers say

washingtonpost.com

121–130 of 331 posts

Re: U.K. demand for a back door to Apple data threatens Americans, lawmakers say

#121
post #93
post #81

Earlier quoted context omitted.

Because the US don’t ask for a backdoor in encryption, they build it https://en.wikipedia.org/wiki/Dual_EC_DRBG

Your own article admits it's basically used nowhere. That's important, because OP specifically claims that the US government has"access to all non-American's personal data". Moreover it was widely condemned, contrary to OP's claim of "but when the UK/EU wants something similar, suddenly it's a massive outrage. Is it just "we're stronger than you", so it's ok when we do it?".

At least UK demands it openly.

The US spied on EU’s industry with ECHOLON, 9/11 prevented further investigations.

https://en.wikipedia.org/wiki/ECHELON

And the US and Germany sold backdoored crypto hardware to allies per Crypto AG in Switzerland.

https://en.wikipedia.org/wiki/Crypto_AG

My point is: the UK demands are bad but I‘m sure the US agencies have similar demands and also backdoors, I‘m looking at you Cisco, just not openly.

The UK is playing with open cards, the US don‘t. I trust neither but the US are more devious.

Re: U.K. demand for a back door to Apple data threatens Americans, lawmakers say

#122
post #92

Earlier quoted context omitted.

You only need to worry about GDPR if you are harvesting and saving personal and identifiable information on your users. If you are not doing that then you dont even have to think about it.

This always gets trotted out, usually by people who seem to have never run any web service before. IPs are apparently PII, and all default server configs log them. If you don’t, good luck complying with any security audits that will require you to keep them to make forensics possible. This is just one of the things that makes GDPR, in practice, an “if we don’t like you, we’ll investigate you and will definitely find…

I am a data controller for multiple companies, I have read the GDPR legislation cover to cover multiple times, I have been through multiple audits. You only need to care about it if you are storing personal data, end of. Downvote me if you like but thats the cold hard truth.

> IPs are apparently PII

It always pains me when people spout stuff about GDPR that they think they know but dont. Go talk to an auditor like I have many times, then you wont need to use words like 'apparently' and you will actually know what you are talking about.

Re: U.K. demand for a back door to Apple data threatens Americans, lawmakers say

#123
post #118

Earlier quoted context omitted.

Yes, in this case: successfully used this argument to delay until the FBI gave up. If it had gone to court, the argument was considered strong, but of course no one knows until a verdict is reached and appeals are exhausted.

This is a gross simplification of the many factors that lead to the FBI dropping the demand against Apple, in my opinion.

But it is everything we know.

The expectation was that FBI would lose in court. But that was not guaranteed, certainly.

FBI had multiple reasons to abandon the effort, but one was that if legal precedent was established at that time, for that case, it would be harder to bypass in future cases.

Re: U.K. demand for a back door to Apple data threatens Americans, lawmakers say

#124
post #31

Earlier quoted context omitted.

> This is a dramatic overreach of authority. Well, the rest of the world lives with the USA constantly doing this. Hopefully you dont support that as well.

The US does not require Apple to make a backdoor to its encryption.

Apple has a history of giving the US government whatever user data they want, lying about it, then when it leaks publicly they are able to say 'Well we couldnt tell you because it would have been breaking the law, sorry about that'.

Have an example, of when it leaked that apple was secretly syphoning off all push notifications to the US government:

https://www.macrumors.com/2023/12/06/apple-governments-surve...

Re: U.K. demand for a back door to Apple data threatens Americans, lawmakers say

#125
post #53
post #50

Earlier quoted context omitted.

Here's the BBC report on the matter: https://www.bbc.co.uk/news/articles/c20g288yldko It applies to content stored using ADP, Apple's E2EE tech. A backdoor into that would mean applying a backdoor into iOS on the phone itself, which is a much larger attack surface than anything centralised. All of which highlights the clownish nature of these regulations. They are so easy for bad actors to circumvent (eg using their…

I'm entirely against what the UK government wants, however I would say: Although you're right that tech people would still be able to choose secure encrypted options, the fact is that the majority of criminals by pure numbers are not very sophisticated - so while this sort of backdoor obviously wouldn't be a guarantee that every criminal conversation could be snooped on, it would work on the 90-99% (I'd guess towards…

Most GSW victims are killed by one or two bullets, not hundreds of them.

You don't need a "vast majority" of criminals to break down a system and exfiltrate data when just a single, possibly state-backed, criminal operation can break your system down and do the job.

Re: U.K. demand for a back door to Apple data threatens Americans, lawmakers say

#126

Earlier quoted context omitted.

How do you know that? Similarly to the UK, USA has a process to force companies to add back doors. For all we know it might the USA wanting access and using its five eyes allies to get it done.

Point to the law that requires them to do it and keep quiet about it. The US law. I'll wait.

Heres an example of when Apple got caught giving the US government all users push notifications, and then quite openly said they had been bound by law to keep quiet about it.

https://www.macrumors.com/2023/12/06/apple-governments-surve...

> "In this case, the federal government prohibited us from sharing any information,"

Re: U.K. demand for a back door to Apple data threatens Americans, lawmakers say

#127
post #50

Earlier quoted context omitted.

Here's the BBC report on the matter: https://www.bbc.co.uk/news/articles/c20g288yldko It applies to content stored using ADP, Apple's E2EE tech. A backdoor into that would mean applying a backdoor into iOS on the phone itself, which is a much larger attack surface than anything centralised. All of which highlights the clownish nature of these regulations. They are so easy for bad actors to circumvent (eg using their…

This is a government that believes in thought crimes. They will likely arrest people for having illegal memes on their phones or for texting messages to friends of which the government does not approve. If there was prequal to 1984, it would look something like this.

By "thought crimes", would you mean firing people for holding positions responsible for DEI policies which were assigned to them and which there was a legal obligation to enforce?

Because that would NEVER happen in the US, certainly no government agency would fire its own people for having following legally enacted government policy just because that policy was no longer in fashion (though still legal government policy, because Congress hadn't yet changed the law).

Re: U.K. demand for a back door to Apple data threatens Americans, lawmakers say

#128
I keep saying this, and nobody believes me, but I'm just going to keep trying:

These things happen because so often we focus the privacy conversation on corporations, which is exactly where the governments want it to be.

My controversial but strong opinion is that privacy from corporations matters very little, but privacy from governments matters very much.

We need to stop allowing the conversation to get distracted by talking about cookies and ad-tracking and whatnot, and always bring it right back to privacy from governments.

Yes, corporations and the government are often in cahoots here - but even then we should be talking about how wrong it is for governments to be buying/taking/demanding data from corporations - keeping the focus squarely on the government.

The worst thing a corporation is likely to do (other than giving your data to governments) is to sell you something. That's all they want. They collect data so they can make money off you. That's not so scary to me. Governments want to put you in jail (or freeze your bank account, etc) if you get out of line.

Re: U.K. demand for a back door to Apple data threatens Americans, lawmakers say

#129
post #47

Not to be cynical, but if anyone has looked at anything revealed about security agencies in the last few years it's very clear what's happening here - whenever US wants to do something unpopular/straight up illegal, it just asks the UK(or any other partner country) to do it instead. American government can't ask Apple for data on any American citizen, but if UK obtains that data and then it happens to be shared betwe…

I wouldn't go full-on conspiracy, because I expect the impetus came from the UK, but... I doubt it would have gotten this far without tacit US gov support.

Governments are huge and constantly changing things.

The cops think this is great, more power in their hands.

The feds think it'll help them out, but those local cops will try to abuse it for sure, let's hope the courts keep on top of the warrants.

The spies already have access that's almost as good by illegal means, without the need for any of those pesky warrants. But it'll be useful not to have to keep their access secret.

The judges think this is a Fourth Amendment bust-up waiting to happen, why would you even... ugh.

The defensive cyber-security types think this is very obviously a bad move.

The diplomats think the Brits are OK and will do their warrant stuff properly, but for sure there will immediately be a request from some oil-rich middle eastern dictatorship for the same access. That will make for some awkward conversations.

The elected politicians in power want to get votes, and are safe against this power being used against them. Being tough on crime and Backing The Blue might be a vote-winner. 95% of voters don't know the difference between "encrypted end-to-end" and "encrypted in transit and at rest" so getting this right might not win you many votes. On the other hand, if this takes off in the public consciousness as snooping, or intrusion, or an expansion of state power, could lose you a lot of votes. Maybe wait and see how the public reacts?

The elected politicians who aren't in power think ooooh boy, this is not a power I want used against me, and not an administration I'd trust not to use it against me.

Post reply on HN