Live data from Hacker News

Apple pulls data protection tool after UK government security row

bbc.com

851–860 of 1001 posts

Re: Apple pulls data protection tool after UK government security row

#851

Earlier quoted context omitted.

> My assumption is that Google has keys to everything in its kingdom If that were true, then their claims to support E2E encrypted backups are simply false, and they would have been subject to warrants to unlock backups, just like Apple had been until they implemented their "Advanced Data Protection" in 2022. Wouldn't there have been be some evidence of that in the past 7 years, either through security research, or t…

It is possible to set up end to end encryption where two different keys unlock your data. Your key, and a government key. I assume google does this. 1. encrypt data with special key 2. encrypt special key with users key, and 3. encrypt special key with government key Anyone with the special key can read the data.the user key or the government key can be used to get special key. This two step process can be done for g…

I expect this is what they are all doing tbh, although isnt google open source? should be checkable, if the binaries the distribute match the source... oh...

"a special key" afaik is where instead of using 2 large primes for a public key, it uses 1 large prime and the other is a factor of 2 biggish primes, where 1 of the biggish is known, knowing one of the factors lets you factor any public key with a not insignificant but still more compute than most people have access to.

UK has also invested in some serious compute that would appear dedicated to exactly this task.

basically if you dont have full control over the key generation mechansim and enc/dec mechansim it is relatively trivial for states to backdoor anything they want.

Re: Apple pulls data protection tool after UK government security row

#852
post #814
post #428

Earlier quoted context omitted.

ive been through all this with the law. no one ever got jailed for not handing over encryption keys unless they were a definitive criminal and theres strong evidence there is criminal data on the device. they tried this with me (NCA) but the judge wouldnt sign off as they had nothning on me or my device. this did however REALLY want to access it! fuck them. pricks

https://www.telegraph.co.uk/news/2024/10/25/tommy-robinson-c...

you just gave an example of a man who was highly likely to have something of interest on his phone. (as signed by a judge)

Re: Apple pulls data protection tool after UK government security row

#853
post #106

Too right, it was far more problematic than they ever made out. > The UK government's demand came through a "technical capability notice" under the Investigatory Powers Act (IPA), requiring Apple to create a backdoor that would allow British security officials to access encrypted user data globally. The order would have compromised Apple's Advanced Data Protection feature, which provides end-to-end encryption for iCl…

> One scenario would be somebody in an airport and security officials are searching your device under the Counter Terrorism Act

No, it's much broader than that. The UK is asking for a backdoor to your data and backups in the cloud, not on your device. Why bother with searching physical devices when they can just issue a secret subpoena to any account they want?

It's actually pretty amazing that Apple made ADP possible for the general public. This is the culmination of a major breakthrough in privacy architecture about ten years ago.

Traditionally you had to make a choice between end-to-end encryption and data recoverability. If you went with E2EE, it's only useful if you use a strong password, but if you forget it then Apple can't help you recover your account (no password reset possible). So that was totally unsuitable for precious memories like photos for the average user.

Apple's first attempt to make this feasible was a recovery key that you print out and stuff in a drawer somewhere. But you might lose this. The trusted contact feature is also not totally reliable either, because chances are it's your spouse and they might also lose their device at that same time as you (for example in a house fire).

So while recovery keys and trusted contacts help, the solution that really made the breakthrough for ADP was iCloud Keychain Backup. This thing is low-key so cool and kind of rips up the previous assumptions about E2EE.

iCloud Keychain Backup makes it possible to recover your data with a simple, weak 6 digit passcode that you are virtually guaranteed never to forget, yet you are also protected from brute force attacks on the server. It is specifically designed to work on "adversarial clouds" that are being actively attacked. This is... sort of not supposed to be possible in the traditional thinking. But they added something called hardware security modules to limit the number of guesses an attacker can make before it wipes your key.

And crucially it ensures you don't forget this passcode because it's your device passcode which the OS keeps in sync with the backup key. This is part of the reason your iPhone asks you to enter your passcode now and then even though your biometrics work just fine.

It is a true secret that only you know and can keep in your brain even when your house burns down and nobody (hopefully) can derive from something they can research about you. This didn't really exist for the general populace until smartphones came along. And that ultimately was the breakthrough that allowed for changing the conventional wisdom on E2EE.

iCloud Keychain Backup came out about a decade ago and it has taken this long to gradually test the feasibility of going 100% E2EE without significantly risking customer data loss. The UK is kind of panicking but when people see how well ADP protects their most personal data from breaches, I think they will demand it. It just wasn't practical before.

Re: Apple pulls data protection tool after UK government security row

#854
post #395

Earlier quoted context omitted.

Except no one has ever been jailed for simply refusing to unlock a phone unless there was heavy evidence there was something on the phone. Stop spreading incorrect FUD

You're an ignorant fool: https://www.theregister.com/Print/2009/11/24/ripa_jfl/

LOL literally a suspected terrorsit.

Re: Apple pulls data protection tool after UK government security row

#855

Earlier quoted context omitted.

> My assumption is that Google has keys to everything in its kingdom If that were true, then their claims to support E2E encrypted backups are simply false, and they would have been subject to warrants to unlock backups, just like Apple had been until they implemented their "Advanced Data Protection" in 2022. Wouldn't there have been be some evidence of that in the past 7 years, either through security research, or t…

It is possible to set up end to end encryption where two different keys unlock your data. Your key, and a government key. I assume google does this. 1. encrypt data with special key 2. encrypt special key with users key, and 3. encrypt special key with government key Anyone with the special key can read the data.the user key or the government key can be used to get special key. This two step process can be done for g…

"…two different keys…. Your key, and a government key. I assume google does this."

With the present state of politics—lack of both government and corporate ethics, deception, availability of much fake news, etc.—there's no guarantee that you could be certain of the accuracy of any information about this no matter what its source or apparent authenticity.

I'd thus suggest it'd be foolhardy to assume that total privacy is assured on any of these services.

BTW, I don't have need of these E2E services and don't use them, nor would I ever use them intentionally to send encrypted information. That said, occasionally, I'll send a PDF or such to say a relative containing some personal info and to minimize it being skimmed off by all-and-sundry—data brokers, etc. I'll encrypt it, but I always do so on the assumption that government can read it (that's if it's bothered to do so).

Only fools ought to think otherwise. Clearly, those in the know who actually require unbreakable encryption use other systems that are able to be better audited. If I were ever in their position, then I'd still be suspicious and only out of sheer necessity/desperation would I send an absolute minimum of information.

Re: Apple pulls data protection tool after UK government security row

#856

If you're in the UK, please consider signing the below petition. Thanks. https://you.38degrees.org.uk/petitions/keep-our-apple-data-e...

I never understand why people create petitions (targeted at the gov) on a non-official site.

Re: Apple pulls data protection tool after UK government security row

#857
post #805

Earlier quoted context omitted.

> Perhaps Apple has a greater leverage in China due to its outsized manufacturing presence. Perhaps china has greater leverage over apple in this case... China had been an important area of growth for many companies during the 2010s. Apple bent over backwards to cater to that market. It was discussed in every financial release, and they obviously made tons of concessions for iCloud. The UK just comparatively isn't th…

> China had been an important area of growth for many companies during the 2010s. Apple bent over backwards to cater to that market and it is the same with european car companies (like volkswagon). Look at where they are now. I don't believe for a second, that china will not oust apple the moment there's a good reason to.

> Look at where they are now.

Apples revenue from china has been super dependent on new iPhone looking different, and has been steadily declining or flat for years, except for a few quarters when Huawei was sanctioned.

Chinese money was absolutely the forbidden temptress that continues to screw businesses. Luxury goods, cars, electronics, etc were all banking on china’s economic rise to grow their revenue, and post covid recovery saw all that money stay domestic.

China won’t oust Apple because twisting Tim Cook’s arm is way more useful. Same with Tesla and any other company that makes a big bet there. But they absolutely won’t be giving American companies an equal chance at success.

Re: Apple pulls data protection tool after UK government security row

#858
post #589

Earlier quoted context omitted.

> hopefully the US turning from leader of the free world to Russia's tool So much humour in one short phrase. Do you really believe your propaganda or is it just absentmindedly parroting pro permanent war talking points?

He demands $500bn of rare earth minerals, insists that Ukraine started the war by getting invaded and wants Zelensky to be replaced by a Russian puppet. It's amazing how the US went from the defender of the free world to just another thug.

"defender of the free world" is just so funny to me. I'm sorry to burst your bubble of jingoism and US imperialism excepcionalism.

Re: Apple pulls data protection tool after UK government security row

#859

Earlier quoted context omitted.

It is possible to set up end to end encryption where two different keys unlock your data. Your key, and a government key. I assume google does this. 1. encrypt data with special key 2. encrypt special key with users key, and 3. encrypt special key with government key Anyone with the special key can read the data.the user key or the government key can be used to get special key. This two step process can be done for g…

"…two different keys…. Your key, and a government key. I assume google does this." With the present state of politics—lack of both government and corporate ethics, deception, availability of much fake news, etc.—there's no guarantee that you could be certain of the accuracy of any information about this no matter what its source or apparent authenticity. I'd thus suggest it'd be foolhardy to assume that total privacy…

Yes. There is no ability to know one way or the other if Google, and similar services retain a secondary way to access decryption key. In light of this the only option is to _assume_ they have the capability.

Given the carefully crafted way companies describe their encryption services, it seems more likely than not they have master keys of some sort.

Re: Apple pulls data protection tool after UK government security row

#860

Earlier quoted context omitted.

It is possible to set up end to end encryption where two different keys unlock your data. Your key, and a government key. I assume google does this. 1. encrypt data with special key 2. encrypt special key with users key, and 3. encrypt special key with government key Anyone with the special key can read the data.the user key or the government key can be used to get special key. This two step process can be done for g…

"…two different keys…. Your key, and a government key. I assume google does this." With the present state of politics—lack of both government and corporate ethics, deception, availability of much fake news, etc.—there's no guarantee that you could be certain of the accuracy of any information about this no matter what its source or apparent authenticity. I'd thus suggest it'd be foolhardy to assume that total privacy…

> I don’t care for encryption or need it

> encrypts a pdf sent to tech illiterate family members

Post reply on HN