Live data from Hacker News

Apple pulls data protection tool after UK government security row

bbc.com

251–260 of 1001 posts

Re: Apple pulls data protection tool after UK government security row

#251

Earlier quoted context omitted.

>> In the UK, there's no right to bear arms, so people are pretty helpless against their oppressing government. There's a right to bear arms in the US and it doesn't seem to be helping them with their oppressive government.

Look into the Black Panthers. It actually does work quite effectively.

Ahh yes the murders of Alex Rackley and Betty Van Patter, truly brave and revolutionary acts!

Re: Apple pulls data protection tool after UK government security row

#252
post #211
post #192

Earlier quoted context omitted.

And yet if I steal your money and refuse to give it back, or let you steal it back, you'll call that hypocritical. What does the size of an entity have to do with whether this is idiotic or not?

You're not an entity, you're a person. Scale really does make a difference.

You're making the argument that the UK government will stop using encryption itself once the information about this becoming illegal makes it through the government.

It won't. The courts will refuse to force them to stop, and even if the courts attempt to force it, some government departments just won't listen, and be protected from the consequences.

This is another case of "the law applies to you, but not to me".

Re: Apple pulls data protection tool after UK government security row

#253

Think about it.. You don't even have to be an Apple user to be affected by this issue. If someone backs up their conversations with you to apple cloud, your exchange is now fair game. You get no say in it either. We all lose.

That's why it's important to use apps like Signal where you can set the retention of your messages. I've got everybody I know using it now!

In a world where they cancel encryption they can't access... doesn't Signal and its CIA funded origins concern you?

Re: Apple pulls data protection tool after UK government security row

#254

Earlier quoted context omitted.

> abide by the laws and regulations of the countries that they operate in. In this case, the UK is seeking to use local law to change what is allowable on an international basis. That's a bit different than a nation controlling the law on their own soil.

That was Apple's interpretation : That to comply with what the UK requested they would have to have the same thing everywhere. But of course that is nonsense, and Apple could theoretically have a nation-specific backdoor (e.g. for accounts in a given country a separate sequestered decryption key is created and kept in escrow for court order). I mean, Apple "complied" by disabling ADP just in the UK. They undermined t…

The keys are stored only in the Secure Enclave. Encryption and decryption are handled outside the standard CPU and OS. This is hardware-level protection, not just some flag on a cloud account to be flipped. The only way for Apple to break this system is to break it for everyone, since anything else would risk bleed over or insufficient compliance.

Re: Apple pulls data protection tool after UK government security row

#256

It's the right choice: don't bow to government pressure, let the people pressure the government.

How? In the UK, there's no right to bear arms, so people are pretty helpless against their oppressing government.

I just dont interact with the government or British society at all. I have turned my back on it.

If they ever come to my door I'll either go postal or leave the country.

Its so bad here now.

Re: Apple pulls data protection tool after UK government security row

#257

Earlier quoted context omitted.

How? In the UK, there's no right to bear arms, so people are pretty helpless against their oppressing government.

Small arms are no match for drones and a fully armed military, a successful rebellion by any populace against a first world military is impossible unless the military lays their arms down voluntarily, full stop.

Every time this argument comes up, I just feel like rolling eyes, it is so overplayed.

Yes, in a direct confrontation and an all out war, the populace stands no chance against the US military (assuming the military will unwaveringly side against the populace), no argument there.

But an all out war is not an option, the government wouldn’t be trying to pulverize an entire nation and leave a rubble in place. If you completely destroy your populace and your cities in an all-out direct war, you got no country and people left to govern. It is all about subjugation and populace control. You can’t achieve this with air strikes that level whole towns.

Similarly, if the US wanted to “win” in Afganistan by just glassing the whole region and capturing it, that would be rather quick and easy (from a technical perspective, not from the perspective of political consequences that would follow). Turns out, populace control and compliance are way more tricky to achieve than just capturing land. And while having overwhelming firepower and technological advantage helps with that, it isn’t enough.

Re: Apple pulls data protection tool after UK government security row

#258
Can someone explain what's changed in the UK that they would consider requesting unfettered access to all Apple customer data (including outside their own borders)? I get that the NSA is infamous for warrant-less surveillance, but this seems a step further.

Re: Apple pulls data protection tool after UK government security row

#259
post #225

Note that this doesn’t satisfy the government’s original request, which was for worldwide backdoor access into E2E-encrypted cloud accounts. But I have a more pertinent question: how can you “pull” E2E encryption without data loss? What happens to those that had this enabled? Edit: Part of my concern is that you have to keep in mind Apple's defense against backdooring E2E is the (US) doctrine that work cannot be comp…

We are told the encryption keys reside only on your device. But Apple control “your” device so they can just issue an update that causes your device to decrypt data and upload it.

Would just upload the keys

Re: Apple pulls data protection tool after UK government security row

#260

The smartphone is a terrible platform. Something like this could never happen on the PC, where you can install any encryption and backup software that you want. While Apple did the right thing by refusing to give the UK government a backdoor, they are responsible for getting users in this situation in the first place. I'm not familiar with the iPhone and maybe there is already an alternative to iCloud ADP, although t…

I haven’t checked lately but since it launched the iPhone has allowed the owner to choose whether to back up to Apple’s servers (which would be affected by the UK order) or back up to their local computer.
Post reply on HN