Live data from Hacker News

U.K. demand for a back door to Apple data threatens Americans, lawmakers say

washingtonpost.com

231–240 of 331 posts

Re: U.K. demand for a back door to Apple data threatens Americans, lawmakers say

#231
post #90

Earlier quoted context omitted.

I really don’t like the UK governments stance on cyber security / counter-terrorism / et al either. In fact, as a UK citizen I’ve actively campaigned against a great many of their policies. However this “thought police” and “arrested for posting memes” comment that often gets pointed on here is itself a nonsense meme. What actually happened was people were arrested for instigating riots. This is no different to what…

>However this “thought police” and “arrested for posting memes” comment that often gets pointed on here is itself a nonsense meme. Are you for real? These accusations are not merely memes. While I don't endorse terrible people, it is note worth sometimes awful people are the target of even more awful laws. For example, you can do research into a person named "Adam Smith-Connor" who was literally convicted for standin…

So, loitering with intent, like this guy was arrested for 120 years ago.

https://en.wikipedia.org/wiki/Loitering#/media/File:Gilbert_...

Or in fact a specific crime of hanging around abortion clinics.

Re: U.K. demand for a back door to Apple data threatens Americans, lawmakers say

#232
post #77

Earlier quoted context omitted.

The idea that criminals are not sophisticated is a weak excuse for this system. Once the government starts mining data from iPhones, criminals will quickly adapt while every law-abiding citizen gets caught in the crossfire. It opens the door for abuse: officials could easily spy on their partners, dig up dirt on rivals, or target those they dislike without breaking any laws. Meanwhile, cybercriminals will have an eas…

Very weak considering we have a criminal in the White House

He is not sophisticated and did not needed to be sophisticated to be in the White House. And untouchable by the law.

Re: U.K. demand for a back door to Apple data threatens Americans, lawmakers say

#233

Not to be cynical, but if anyone has looked at anything revealed about security agencies in the last few years it's very clear what's happening here - whenever US wants to do something unpopular/straight up illegal, it just asks the UK(or any other partner country) to do it instead. American government can't ask Apple for data on any American citizen, but if UK obtains that data and then it happens to be shared betwe…

I highly doubt that considering this article is about US complaints towards the UK demand.

Why? Obviously in public they have to say they are outraged by it. The collaboration and intelligence sharing between UK and US is not really up to debate, it's been going on for decades.

Re: U.K. demand for a back door to Apple data threatens Americans, lawmakers say

#234

I keep saying this, and nobody believes me, but I'm just going to keep trying: These things happen because so often we focus the privacy conversation on corporations, which is exactly where the governments want it to be. My controversial but strong opinion is that privacy from corporations matters very little, but privacy from governments matters very much. We need to stop allowing the conversation to get distracted…

[deleted]

Re: U.K. demand for a back door to Apple data threatens Americans, lawmakers say

#235

Earlier quoted context omitted.

> very likely they also have a backdoor in Apple phone with a gag order, given Apple was part of PRISM People keep repeating this as if PRISM was a voluntary, or even secretly cooperative, program. PRISM was no such thing. PRISM was the US govt snarfing up whatever data they could (under questionable legal authority), but no one has ever alleged that the data they were snarfing was provided willingly or knowingly by…

Wikipedia clearly states: PRISM collects stored internet communications based on demands made to internet companies such as Google LLC and Apple under Section 702 of the FISA Amendments Act of 2008 to turn over any data that match court-approved search terms. https://en.m.wikipedia.org/wiki/PRISM They were actively providing the data on request.

Sorry, I should have been more explicit. Of course all US companies comply with US court orders.

The controversial new revelation re: PRISM, via Snowden, was that NSA was also snarfing everything they could including unencrypted comms over frame relay/etc networks comprising, e.g., Google's internal inter-site networks.

To which all mentioned companies said "we were not aware of this, we never authorized a backdoor for LE at any level, this is a breach of trust and probably not legal, and now we'll encrypt everything between our internal systems too".

Re: U.K. demand for a back door to Apple data threatens Americans, lawmakers say

#236

I keep saying this, and nobody believes me, but I'm just going to keep trying: These things happen because so often we focus the privacy conversation on corporations, which is exactly where the governments want it to be. My controversial but strong opinion is that privacy from corporations matters very little, but privacy from governments matters very much. We need to stop allowing the conversation to get distracted…

[deleted]

Re: U.K. demand for a back door to Apple data threatens Americans, lawmakers say

#237
post #158

Earlier quoted context omitted.

Are you suggesting that the UK government isn't snoopy or creative enough to initiate this idea on their own??

No. Maybe it was their idea, maybe it was the US's. One thing's for sure though we wouldn't be pushing ahead with this without the tacit support of the US, particularly in the current environment.

Tenuous. The UK did not need US approval to make all of its existing privacy-violating laws. Nor did Australia, or parts of the EU.

Don't get me wrong. The only thing holding the US government back from growing all the more monstrous is a patchwork of sketchy laws that might have teeth.

But I don't see any reason to assume that the stupidity of Brits is the fault of Americans. This time.

Re: U.K. demand for a back door to Apple data threatens Americans, lawmakers say

#238
post #152

I keep saying this, and nobody believes me, but I'm just going to keep trying: These things happen because so often we focus the privacy conversation on corporations, which is exactly where the governments want it to be. My controversial but strong opinion is that privacy from corporations matters very little, but privacy from governments matters very much. We need to stop allowing the conversation to get distracted…

I can hold my government accountable via the polling booth I have no control over Apple or Amazon or Alphabet. I can petition the government through the court system if it tries to put me in jail, the government functions with a massive series of checks and balances. I can't petition google, they are an unelected uncontrollable unaccountable entity that not even the government has power over

[deleted]

Re: U.K. demand for a back door to Apple data threatens Americans, lawmakers say

#239
post #122

Earlier quoted context omitted.

This always gets trotted out, usually by people who seem to have never run any web service before. IPs are apparently PII, and all default server configs log them. If you don’t, good luck complying with any security audits that will require you to keep them to make forensics possible. This is just one of the things that makes GDPR, in practice, an “if we don’t like you, we’ll investigate you and will definitely find…

I am a data controller for multiple companies, I have read the GDPR legislation cover to cover multiple times, I have been through multiple audits. You only need to care about it if you are storing personal data, end of. Downvote me if you like but thats the cold hard truth. > IPs are apparently PII It always pains me when people spout stuff about GDPR that they think they know but dont. Go talk to an auditor like I…

> > IPs are apparently PII

> It always pains me when people spout stuff about GDPR that they think they know but dont.

Are you trying to suggest end user IPs are not PII? There is judgement from CJEU (Patrick Breyer v Bundesrepublik Deutschland, ECLI:EU:C:2016:779) regarding the older Data Protection Directive that IP address is personal data if the service provider can give the IP address to competent authority and that authority has a way to connect it to user. As most (all?) EU countries mandate that ISPs keep logs that match IP address to subscriber and competent authority can get this information, the IP address is almost always PII.

Or is your auditor suggesting that GDPR is less strict than the older directive regarding this case? From my reading the only real difference was that GDPR added a bit more precision on what reasonable actions are ("such as the costs of and the amount of time required for identification, taking into consideration the available technology at the time of the processing and technological developments"). At least to me the example given in the court case would be reasonable when taking those in account.

You can, of course, have legitimate interest to collect it (like many other forms of PII as well), even for cases where the data subject cannot object to it. It doesn't change the fact that it's almost certainly PII.

Re: U.K. demand for a back door to Apple data threatens Americans, lawmakers say

#240
post #181

Earlier quoted context omitted.

Apple’s own transparency report. Look at the FISA (FAA702, aka Prism) section. Per the Snowden slides, this (FAA702 collection) is the #1 most used collection method by US spies. They can basically read approximately every camera roll and iMessage in the country with a few clicks.

So, seems that E2E is a total bullshit then?

Only if it's backdoored (or otherwise breakable).
Post reply on HN