Live data from Hacker News

Apple pulls data protection tool after UK government security row

bbc.com

871–880 of 1001 posts

Re: Apple pulls data protection tool after UK government security row

#871
post #852
post #814

Earlier quoted context omitted.

https://www.telegraph.co.uk/news/2024/10/25/tommy-robinson-c...

you just gave an example of a man who was highly likely to have something of interest on his phone. (as signed by a judge)

It is likely there is something of interest on your phone (as signed by my friend Joe). Now unlock your phone or you will be jailed.

Re: Apple pulls data protection tool after UK government security row

#872
post #619

Earlier quoted context omitted.

> you think Google didn't already sign up to this? My understanding is that Android's Google Drive backup has had an E2E encryption option for many years (they blogged about it at https://security.googleblog.com/2018/10/google-and-android-h... ), and that the key is only stored locally in the Titan Security Module. If they are complying with the IPA, wouldn't that mean that they must build a mechanism into Android to…

My assumption is that Google has keys to everything in its kingdom [1]. [1] https://qz.com/1145669/googles-true-origin-partly-lies-in-ci...

The linked article makes a lot of assumptions about the "Massive Digital Data Systems Program". It seems this program existed. For example, here is a 1996 paper [1] about research funded by the "Massive Digital Data Systems (MDDS) Program, through the Department of Defense."

But it's not clear that funding for early research into data warehousing (back when a terabyte was a lot of data) has anything to do with whether or not Google uses end-to-end encryption? Lots of research got funded through the Department of Defense.

Without having relevant evidence, this is just "let's assume X is true, therefore X is true."

[1] https://papers.rgrossman.com/proc-047.htm

Re: Apple pulls data protection tool after UK government security row

#873

Earlier quoted context omitted.

In the case of Linux Mint, I can check the commit history, build the software myself and even validate it against public checksums. It is expressly defended against these types of attacks, making it an odd choice to single out.

Isn't it already a law violation using it in certain scenarios? Or will be soon?

No? Instead of speaking in question marks, why not link or reference the law or scenarios you're talking about?

Re: Apple pulls data protection tool after UK government security row

#874

Earlier quoted context omitted.

It is possible to set up end to end encryption where two different keys unlock your data. Your key, and a government key. I assume google does this. 1. encrypt data with special key 2. encrypt special key with users key, and 3. encrypt special key with government key Anyone with the special key can read the data.the user key or the government key can be used to get special key. This two step process can be done for g…

"…two different keys…. Your key, and a government key. I assume google does this." With the present state of politics—lack of both government and corporate ethics, deception, availability of much fake news, etc.—there's no guarantee that you could be certain of the accuracy of any information about this no matter what its source or apparent authenticity. I'd thus suggest it'd be foolhardy to assume that total privacy…

> …there's no guarantee that you could be certain of the accuracy of any information about this no matter what its source or apparent authenticity.

In any case like this, the only thing you could truly trust would be the source code and even then you’d have to be on the lookout for backdoors, which would definitely be beyond my own capability to spot.

In other words, the best bet is to probably only use open source solutions that have been audited and have a good track record, wherever available. Not that there are that many options when it comes to mobile OSes, although at least there are some for file storage and encryption.

Re: Apple pulls data protection tool after UK government security row

#875
post #619

Earlier quoted context omitted.

My assumption is that Google has keys to everything in its kingdom [1]. [1] https://qz.com/1145669/googles-true-origin-partly-lies-in-ci...

> My assumption is that Google has keys to everything in its kingdom If that were true, then their claims to support E2E encrypted backups are simply false, and they would have been subject to warrants to unlock backups, just like Apple had been until they implemented their "Advanced Data Protection" in 2022. Wouldn't there have been be some evidence of that in the past 7 years, either through security research, or t…

[dead]

Re: Apple pulls data protection tool after UK government security row

#876
post #716

Earlier quoted context omitted.

A trivial method for circumventing code review is to simply push a targeted update of the firmware to devices subject to a government search order. There are no practical end-user protections against this vector. PS: I strongly suspect that at least a few public package distribution services are run by security agencies to enable this kind of attack. They can distribute clean packages 99.999% of the time, except for…

> Chocolatey, which popped up out of nowhere Chocolatey assuredly did not "pop up out of nowhere" - it was a labour of love from Rob Reynolds to make Windows even barely usable. It likely existed for years before you ever heard of it. > had no visible source of funding Rob was employed by Puppet Labs to develop it until he started the commercial entity which now backs it. > a small building in the middle of nowhere.…

There was no evidence of any of this on the website until recently (maybe 2 or 3 years ago?), and I did look at every page on there. Similarly, I searched on Google for a while and raised the question in more than a few forums. I dug through the business registration records, etc... and found none of the above.

Sure, now, they have staff photos and the actual names of people on their about page, but just a few years ago it was almost completely devoid of information: https://web.archive.org/web/20190906125729/https://chocolate...

Look at it from the perspective of a paranoid sysadmin half way around the world raising a quizzical eyebrow when random Reddit posts mention how convenient it is, but it's distributing binaries to servers with absolutely no obvious links back to any organisations, people, or even a legitimate looking business building.

Re: Apple pulls data protection tool after UK government security row

#877

Earlier quoted context omitted.

And that certainly wouldn't raise their suspicion. Surely, they'd immediately let you go after that stunt.

Of course they could throw a tantrum, but it wouldn't be nothing but that, and they will have to release you once they cool down. What are they going to say? That they won't release you until you magically unerase the phone? There's nothing to wait for.

I agree there is nothing to coerce out of you anymore and so you'd not be held on this forced decryption law... but not complying with such a court order probably results in another offence for which you can then get punished (not sure if a fine, community service, or jail time would be most likely for this), on top of that it doesn't look good to the judge who presides over the original case in which they de demanded the decryption in the first place

Re: Apple pulls data protection tool after UK government security row

#878
post #106

Too right, it was far more problematic than they ever made out. > The UK government's demand came through a "technical capability notice" under the Investigatory Powers Act (IPA), requiring Apple to create a backdoor that would allow British security officials to access encrypted user data globally. The order would have compromised Apple's Advanced Data Protection feature, which provides end-to-end encryption for iCl…

> you think Google didn't already sign up to this? My understanding is that Android's Google Drive backup has had an E2E encryption option for many years (they blogged about it at https://security.googleblog.com/2018/10/google-and-android-h... ), and that the key is only stored locally in the Titan Security Module. If they are complying with the IPA, wouldn't that mean that they must build a mechanism into Android to…

Apple's ADP is not E2E for only its backups, it's E2E for _everything_ in iCloud Drive and a few other iCloud services.

Re: Apple pulls data protection tool after UK government security row

#879

If you're in the UK, please consider signing the below petition. Thanks. https://you.38degrees.org.uk/petitions/keep-our-apple-data-e...

I never understand why people create petitions (targeted at the gov) on a non-official site.

I'm not familiar with UK law, but what's the matter? They're equally valid in jurisdictions that I know of, a signature is a signature no matter where it was put

I'd personally just trust the government variant more with my government ID data than a third party but that's up to the petitioners to weigh and decide

Re: Apple pulls data protection tool after UK government security row

#880
post #106

Too right, it was far more problematic than they ever made out. > The UK government's demand came through a "technical capability notice" under the Investigatory Powers Act (IPA), requiring Apple to create a backdoor that would allow British security officials to access encrypted user data globally. The order would have compromised Apple's Advanced Data Protection feature, which provides end-to-end encryption for iCl…

What I fund 'amusing' is the swap between Left vs Right. 'Back in the day' it was the "Right" that wanted have total access/total control over everything. So people turned a bit "left". Now the "Left" government is seeking totalitarian-style control ('because paedophiles/drugs/etc.). As a reminder, both Right and Left extremes went from 'liberal/conservatives' to "we don't need elections ever again - trust me!". I sa…

>> 'Back in the day' it was the "Right" that wanted have total access/total control over everything.

It was the Clinton administration that pushed for the Clipper chip.

Are you talking about a 'day' before that time?

Post reply on HN