Live data from Hacker News

Apple pulls data protection tool after UK government security row

bbc.com

311–320 of 1001 posts

Re: Apple pulls data protection tool after UK government security row

#311
Apple could have disabled iCloud completely for UK users. This would protect both UK users and other users who’s data would also been captured in an iCloud backup.

They would lose some money on services, but would have been the better choice to stand up to the UK government and protect the UK users.

Re: Apple pulls data protection tool after UK government security row

#312

I have a naive question, and it's genuine curiosity, not a defence of what's happening here. This ADP feature has only existed for a couple of years, right? I understand people are mad that it's now gone, but why weren't people mad _before_ it existed? For like, a decade? Why do people treat iCloud as immediately dangerous now, if they didn't before? Did they think it was fully encrypted when it wasn't? Did people no…

The problem here is not with iCloud but with the U.K. government. People like to tell themselves the government isn’t actually trampling their rights but events like this make it impossible to ignore.

Re: Apple pulls data protection tool after UK government security row

#313

Think about it.. You don't even have to be an Apple user to be affected by this issue. If someone backs up their conversations with you to apple cloud, your exchange is now fair game. You get no say in it either. We all lose.

Security hinges on trust. The only real privacy tool is PGP which uses a web of trust model. But it only works if people own their own computers and storage devices. What they've done is got everyone to rent their computers and storage instead. There's no security model that works for the users here.

Re: Apple pulls data protection tool after UK government security row

#315

Not gonna lie, I expected Apple to just kind of roll over and take the blow on this one. Interesting.

They did. They've giving the UK Government a backdoor to all UK users. Apple lost here.

Technically, they are leaving the front door open to all interested parties

Re: Apple pulls data protection tool after UK government security row

#316
post #106

Too right, it was far more problematic than they ever made out. > The UK government's demand came through a "technical capability notice" under the Investigatory Powers Act (IPA), requiring Apple to create a backdoor that would allow British security officials to access encrypted user data globally. The order would have compromised Apple's Advanced Data Protection feature, which provides end-to-end encryption for iCl…

how much distance between

1) tech monopoly strong enough to stand up to G7 nation state demands

2) tech monopoly strong enough to remove itself from G7 nation state jurisdiction?

edit: s/monopoly/empire, apologies

Re: Apple pulls data protection tool after UK government security row

#317

I have a naive question, and it's genuine curiosity, not a defence of what's happening here. This ADP feature has only existed for a couple of years, right? I understand people are mad that it's now gone, but why weren't people mad _before_ it existed? For like, a decade? Why do people treat iCloud as immediately dangerous now, if they didn't before? Did they think it was fully encrypted when it wasn't? Did people no…

Many of us were very upset about Apple's slow-rolling this feature. There were many claims that they delayed the rollout due to government pressure [1] (note: that story is by the same reporter who broke today's news a couple of weeks ago.)

Rolling out encryption takes time, so the best I can say is "finally it arrived," and then it was immediately attacked by the U.K. government and has now been disabled over there. I imagine that Apple is also now intimidated to further advertise the feature even here in the U.S. To me this indicates we (technical folks) should be making a much bigger deal about this feature to our non-technical friends.

[1] https://www.reuters.com/article/world/exclusive-apple-droppe...

Re: Apple pulls data protection tool after UK government security row

#318
post #225

Earlier quoted context omitted.

We are told the encryption keys reside only on your device. But Apple control “your” device so they can just issue an update that causes your device to decrypt data and upload it.

Would just upload the keys

Presumably these keys live in a hardware security module on your phone called “secure enclave” and cannot be extracted

Re: Apple pulls data protection tool after UK government security row

#319

Earlier quoted context omitted.

> abide by the laws and regulations of the countries that they operate in. In this case, the UK is seeking to use local law to change what is allowable on an international basis. That's a bit different than a nation controlling the law on their own soil.

That was Apple's interpretation : That to comply with what the UK requested they would have to have the same thing everywhere. But of course that is nonsense, and Apple could theoretically have a nation-specific backdoor (e.g. for accounts in a given country a separate sequestered decryption key is created and kept in escrow for court order). I mean, Apple "complied" by disabling ADP just in the UK. They undermined t…

> They undermined their own "worldwide" claim, as ADP still works everywhere else, and the UK has no access.

Disagree. There is a difference between ADP being unavailable in one country and it working differently in that country. Implementing a backdoor would mean changing the way ADP works.

Re: Apple pulls data protection tool after UK government security row

#320

The nightmare continues. For now I am using 3rd party backup services that are (currently) promising me that my backups are encrypted by a key they do not have access to, or control over. But can this even be believed in an age where these secret notices are being served to any number of companies? I suppose the next step would be to ensure that files don't ever arrive in the cloud unencrypted, but I have yet to see…

IMO the only thing you can have a high level of trust in is your own *nix server. Backup those devices to it then encrypt there before being sent to the cloud.

Handling the encryption yourself is the way to go, but for maximum security, don't send that encrypted data to the cloud. Keep it all on your own server(s).

That doesn't help people who aren't technically capable, of course. But at least those who are can protect themselves.

Post reply on HN