Live data from Hacker News

Apple pulls data protection tool after UK government security row

bbc.com

351–360 of 1001 posts

Re: Apple pulls data protection tool after UK government security row

#351

I have a naive question, and it's genuine curiosity, not a defence of what's happening here. This ADP feature has only existed for a couple of years, right? I understand people are mad that it's now gone, but why weren't people mad _before_ it existed? For like, a decade? Why do people treat iCloud as immediately dangerous now, if they didn't before? Did they think it was fully encrypted when it wasn't? Did people no…

At one point in time, the entirety of web communication was completely unencrypted. Why were people not mad then? Do you think people would be angrier now, if HTTPS were suddenly outlawed? Among other valid answers, removing rights and privileges generally makes people angrier than not having those rights or privileges in the first place.

Counterpoint: when web communication was unencrypted it was before we did our banking, tax filing, sent medical records, and sent all other kinds of sensitive information over the internet. The risks today are not remotely the same as they once were.

Re: Apple pulls data protection tool after UK government security row

#352

It's the right choice: don't bow to government pressure, let the people pressure the government.

This is Apple condeeding. Apple lost. UK Government got (almost) what they wanted - a backdoor into iCloud accounts. Apple's only consolation prize is that its limited to UK users for now. But it seems inevitable that ADP will gradually be made illegal all around the world.

Given that they’ve only prevented new signups it looks to me more like Apple is trying to apply pressure to the U.K. government to get them to back down. The law that permits this was passed in 2016 so the situation was default lost already.

Re: Apple pulls data protection tool after UK government security row

#353

Earlier quoted context omitted.

Feels like marvel was onto something with captain america and winter soldier.

Life is imitating too many dystopian books, movies, etc these days. I think we need to put an end to all creative works before the timeline becomes irrecoverably destroyed.

I suspect you’re being flippant, but destruction of and restrictions on creative works as an _antidote_ to dystopia is a take I haven’t seen before.

Re: Apple pulls data protection tool after UK government security row

#354
post #341

Wow - how sad. To think the 2nd highest scoring post ever on hacker news is Apple's 2016 A Message to Our Customers . A display of intelligence, morality and courage under great pressure: https://hn.algolia.com How things have changed. > In a statement Apple said it was "gravely disappointed" So are we, Apple. So are we.

Apple did the right thing.

I would much rather they were transparent, so that people can move services, rather than build a backdoor in secret, to appease the far-left Labour government.

Re: Apple pulls data protection tool after UK government security row

#355

Note that this doesn’t satisfy the government’s original request, which was for worldwide backdoor access into E2E-encrypted cloud accounts. But I have a more pertinent question: how can you “pull” E2E encryption without data loss? What happens to those that had this enabled? Edit: Part of my concern is that you have to keep in mind Apple's defense against backdooring E2E is the (US) doctrine that work cannot be comp…

I think Prof Woodward's quote in the article will likely hold true for Apple's response to the original UK government request:

"It was naïve of the UK government to think they could tell a US technology company what to do globally"

Re: Apple pulls data protection tool after UK government security row

#356
post #106

Too right, it was far more problematic than they ever made out. > The UK government's demand came through a "technical capability notice" under the Investigatory Powers Act (IPA), requiring Apple to create a backdoor that would allow British security officials to access encrypted user data globally. The order would have compromised Apple's Advanced Data Protection feature, which provides end-to-end encryption for iCl…

[deleted]

Re: Apple pulls data protection tool after UK government security row

#357

Does this mean I should treat travel to the UK the same way as China and only bring a burner device with no information on it or on cloud backup accounts?

Border control agents in all countries -- including the US -- have fairly extensive powers to search your devices or deny you entry. I'm not sure this decision should change your calculus on that point.

See also https://medium.com/@thegrugq/stop-fabricating-travel-securit...

Re: Apple pulls data protection tool after UK government security row

#358
Fundamentally, I think the issue is more about technical literacy amongst the political establishment who consistently rely on the fallacy that having nothing to hide means you have nothing to fear. Especially in the UK which operates as a paternalistic state and enjoys authoritarian support across all parties.

On the authoritarianism: these laws are always worded in such a way that they can be applied or targeted vaguely, basically to work around other legislation. They will stop thinking of the children as soon as the law is put into play, and it's hardly likely that pedo rings or rape gangs will be top of the list of priorities.

On the technical literacy: the government has the mistaken belief that their back door will know the difference between the good guys (presumably them) and the bad guys, and the bad guys will be locked out. However, the only real protection is security by obscurity: it's illegal to reveal that this backdoor exists or was even requested. Any bad guy can make a reasonable assumption that a multinational tech company offering cloud services has been compromised, so this just paints another target on their backs.

I've said it before, but I guarantee that the monkey's paw has been infinitely curling with this, and it's a dream come true for any black or grey hat hacker who wants to try and compromise the government through a backdoor like this.

Re: Apple pulls data protection tool after UK government security row

#359

Earlier quoted context omitted.

I asked if your Android backup is encrypted. Implies I'm talking about unencrypted data. > See, for example, the Las Vegas shooter case I am not in Las Vegas or anywhere else in the US. So as far as i know all the data about me that is stored in the US is easily accessible without a warrant unless it's encrypted with a key that's not available with the storage. > companies are not compelled to build systems which ena…

> all the data about me that is stored in the US is easily accessible without a warrant No, law enforcement needs a warrant to legally access any data. This is why Prism was illegal, and why companies like Google are pushing back against overly broad geofence search warrants.

> This is why Prism was illegal

Yet it still existed, and was used for surveillance by 3 letter agencies. Why do you think this is any different?

Re: Apple pulls data protection tool after UK government security row

#360

Earlier quoted context omitted.

>> In the UK, there's no right to bear arms, so people are pretty helpless against their oppressing government. There's a right to bear arms in the US and it doesn't seem to be helping them with their oppressive government.

Look into the Black Panthers. It actually does work quite effectively.

The fact that I can’t tell if this is a joke speaks volumes.
Post reply on HN