Live data from Hacker News

Apple pulls data protection tool after UK government security row

bbc.com

651–660 of 1001 posts

Re: Apple pulls data protection tool after UK government security row

#651
post #106

Too right, it was far more problematic than they ever made out. > The UK government's demand came through a "technical capability notice" under the Investigatory Powers Act (IPA), requiring Apple to create a backdoor that would allow British security officials to access encrypted user data globally. The order would have compromised Apple's Advanced Data Protection feature, which provides end-to-end encryption for iCl…

"technical capability notice" under the Investigatory Powers Act (IPA)

Sounds a lot like the godawful "assistance and access" laws that were rushed through in Australia a couple of years ago, right down to the name of the secret instrument sent to the entity who gets forced into to building the intercept capability.

Now that Apple has caved once, I expect to see other providers strongarmed in the same way, as well as the same move tried in other countries.

Re: Apple pulls data protection tool after UK government security row

#652
post #619

Earlier quoted context omitted.

My assumption is that Google has keys to everything in its kingdom [1]. [1] https://qz.com/1145669/googles-true-origin-partly-lies-in-ci...

> My assumption is that Google has keys to everything in its kingdom If that were true, then their claims to support E2E encrypted backups are simply false, and they would have been subject to warrants to unlock backups, just like Apple had been until they implemented their "Advanced Data Protection" in 2022. Wouldn't there have been be some evidence of that in the past 7 years, either through security research, or t…

It is possible to set up end to end encryption where two different keys unlock your data. Your key, and a government key. I assume google does this.

1. encrypt data with special key 2. encrypt special key with users key, and 3. encrypt special key with government key

Anyone with the special key can read the data.the user key or the government key can be used to get special key.

This two step process can be done for good or bad purposes. A user can have their key on their device, and a second backup key could be in a usb stick locked in a safe, so if you loose your phone you can get your data back using the second key.

Re: Apple pulls data protection tool after UK government security row

#654
This provides an incentive for Apple computer users to do the right thing: Stop storing sensitive data on Apple servers. Unfortunately, due to Apple's pre-installed proprietary operating systems that phone home incessantly, that may be more challenging than it should be.

Re: Apple pulls data protection tool after UK government security row

#655
post #135

Free speech already under threat and now y'all are giving up the right of private communication too? For anyone cheering this on, do you honestly think this will only affect the "bad people", and you'll never have your own neck under the government's boot? Even if you trust the government today, what happens when your neighbors elect a government you disagree with ideologically?

I don’t think anyone is cheering this on.

Many people do, unfortunately, so long as it's framed as "only terrorists and pedophiles need encryption that cops can't break".

Re: Apple pulls data protection tool after UK government security row

#656
post #15

As a citizen, I don’t understand what the UK government thinks they are getting here - other than the possibility of leaks of the nation’s most sensitive data. Also is it not possible to set up my Apple account outside of the UK while living here?

The UK is arresting people for posting memes. They want full control and that's it.

Re: Apple pulls data protection tool after UK government security row

#657
post #395

Earlier quoted context omitted.

Right but then you are jailed at Heathrow for not unlocking your phone. The UK has made it clear that Counter Terrorism legislation has no limits in UK law even if that means compromising all systems and leaving them vulnerable to state actor attacks. MPs will continue to use encrypted messaging systems that disappear messages during any inquiries of course.

Except no one has ever been jailed for simply refusing to unlock a phone unless there was heavy evidence there was something on the phone. Stop spreading incorrect FUD

You're an ignorant fool: https://www.theregister.com/Print/2009/11/24/ripa_jfl/

Re: Apple pulls data protection tool after UK government security row

#659
post #358

Fundamentally, I think the issue is more about technical literacy amongst the political establishment who consistently rely on the fallacy that having nothing to hide means you have nothing to fear. Especially in the UK which operates as a paternalistic state and enjoys authoritarian support across all parties. On the authoritarianism: these laws are always worded in such a way that they can be applied or targeted va…

"it's hardly likely that pedo rings or rape gangs will be top of the list of priorities".... is this not one of the most disturbing, disgusting, psychologically troubling and damning ideas ever to be put to words/brought to awareness? . Right up there "let's meticulously plan out this horrific, atrocious, dehumanizing act and meditate upon the consequences, and then choose the most brutal and villainous option". Dear…

People are extremely opposed to pedos, so they're a primary rationalization for oppressive technology. But then you have two problems.

First, pedos know everybody hates them, so they take measures normal people wouldn't in order to avoid detection, and then backdooring the tech used by everybody else doesn't work against them because they'll use something else. But it does impair the security of normal people.

Second, there aren't actually that many pedos and the easy to catch ones get caught regardless and the hard to catch ones get away with it regardless, which leaves the intersection of "easy enough to catch but wouldn't have been caught without this" as a set plausibly containing zero suspects. Not that they won't use it against the ones who would have been caught anyway and then declare victory, but it's the sort of thing that's pretty useless against the ones it's claimed to exist in order to catch, and therefore not something it can be used effectively in order to do.

Whereas industrial espionage or LOVEINT or draining grandma's retirement account or manipulating ordinary people who don't realize they should be taking countermeasures -- the abuses of the system -- those are the things it's effective at bringing about, because ordinary people don't expect themselves to be targets.

Re: Apple pulls data protection tool after UK government security row

#660
post #619

Earlier quoted context omitted.

My assumption is that Google has keys to everything in its kingdom [1]. [1] https://qz.com/1145669/googles-true-origin-partly-lies-in-ci...

> My assumption is that Google has keys to everything in its kingdom If that were true, then their claims to support E2E encrypted backups are simply false, and they would have been subject to warrants to unlock backups, just like Apple had been until they implemented their "Advanced Data Protection" in 2022. Wouldn't there have been be some evidence of that in the past 7 years, either through security research, or t…

I don't know the particulars, but in general, silence around a massive tech company on warrants does not mean "they said no and the feds decided to leave them alone"
Post reply on HN