Live data from Hacker News

Time to start de-Appling

heatherburns.tech

131–140 of 471 posts

Re: Time to start de-Appling

#131

Earlier quoted context omitted.

# Encrypt a file openssl enc -aes-256-cbc -salt -in secret.txt -out secret.enc # Decrypt openssl enc -d -aes-256-cbc -in secret.enc -out secret.txt Wow that was hard.

I'm reminded of the infamous HN Dropbox comment.

Reference: https://news.ycombinator.com/item?id=9224

Re: Time to start de-Appling

#132

From the article: > Otherwise, please make sure you de-Apple, de-Google, and de-American Stack yourself when you have time, clarity, and focus to do it. Start today. I don't understand the core of this advice. So if you're in the UK and do all the above, can you suddenly get similar E2EE cloud storage from a different provider without a UK government-mandated backdoor?

Because no US corp can promise you true E2EE. Even an app like Signal - are you sure the version you're getting from the App Store is always the one with "unbreakable E2EE"?

Re: Time to start de-Appling

#133
post #36

Earlier quoted context omitted.

It's more likely to be a problem with Apple (and Google) because they have put themselves in a position where they are a gateway to everybody . There are multitudes of online storage providers outside of the UK's reach and jurisdiction but 0% of iPhone users back up to them because of technical limitations that inhibit iCloud competitors or any compatible storage solution.

> they are a gateway to everybody They are, and most time this allows them to abuse you. But what do you think happens once you that gateway is blown open, isn't your front door next? > There are multitudes of online storage providers outside of the UK's reach and jurisdiction What I said above means that once you normalize the situation that providers have to open the gate to your yard whenever the state comes knock…

> But what do you think happens once you that gateway is blown open, isn't your front door next?

Yes this is the way policing should work, if they think you have done something they knock on your door rather than go to Apple and Google and compromise the entire population all at once through the convenience of their monopolies. Bonus points if a judge needs to grant them the privilege of knocking on your door too.

Re: Time to start de-Appling

#134

From the article: > Otherwise, please make sure you de-Apple, de-Google, and de-American Stack yourself when you have time, clarity, and focus to do it. Start today. I don't understand the core of this advice. So if you're in the UK and do all the above, can you suddenly get similar E2EE cloud storage from a different provider without a UK government-mandated backdoor?

The first two are reasonable positions. The third, on the merits of the argument in the article, is absolutely bonkers. It's the UK government that is unleashing this stupidity on the world. There is no European alternative that is any safer, and it's the UK's own hands that are at fault in the first place.

Not that there aren't other reasons to be skeptical of American companies' right, but it's just so easy to fall into nationalistic prattle instead of fixing the real problem.

Re: Time to start de-Appling

#135

From the article: > Otherwise, please make sure you de-Apple, de-Google, and de-American Stack yourself when you have time, clarity, and focus to do it. Start today. I don't understand the core of this advice. So if you're in the UK and do all the above, can you suddenly get similar E2EE cloud storage from a different provider without a UK government-mandated backdoor?

I'm sort of out of the loop as a US citizen....Does the UK really have the ability to enforce every E2EE storage solution on GitHub to comply?

Even if you monitor downloads, every VPN, every ISP..... can't I copy paste the source code?

Isn't SFTP already E2EE? They're not going to come down on SFTP....right? I really hope not...

Re: Time to start de-Appling

#136

From the article: > Otherwise, please make sure you de-Apple, de-Google, and de-American Stack yourself when you have time, clarity, and focus to do it. Start today. I don't understand the core of this advice. So if you're in the UK and do all the above, can you suddenly get similar E2EE cloud storage from a different provider without a UK government-mandated backdoor?

My new high-privacy, high-control data management solution revolves around pen & paper. As far as I am aware, these implements have not yet been banned in the UK.

I don't know why everything must be digital. If you don't put it on a computer, it's almost as if it doesn't exist. If you do this often enough, it is almost as if you don't exist.

Re: Time to start de-Appling

#137
post #56

Earlier quoted context omitted.

I can encrypt anything and store it in anything that provides storage. Why are people acting like "end to end encryption" is a feature you need a cloud service to provide to you. Rather the opposite - it's really something you can only do yourself.

Sure, but almost no one is managing their own keys and knows enough about the various e2ee algorithms to make these decisions on their own. Do you know of a good piece of software or tool that lets a layperson interface with any cloud storage provider?

The closest I've found is VeraCrypt, which is near the edge of what I'd call layperson-friendly. But if you store a VeraCrypt drive on the cloud, you'll need to re-upload the entire encrypted file--usually quite large--every time you change anything at all. That's a _lot_ of bandwidth, and likely to be quite slow to sync.

Re: Time to start de-Appling

#138

From the article: > Otherwise, please make sure you de-Apple, de-Google, and de-American Stack yourself when you have time, clarity, and focus to do it. Start today. I don't understand the core of this advice. So if you're in the UK and do all the above, can you suddenly get similar E2EE cloud storage from a different provider without a UK government-mandated backdoor?

The first two are reasonable positions. The third, on the merits of the argument in the article, is absolutely bonkers. It's the UK government that is unleashing this stupidity on the world. There is no European alternative that is any safer, and it's the UK's own hands that are at fault in the first place. Not that there aren't other reasons to be skeptical of American companies' right, but it's just so easy to fall…

> but it's just so easy to fall into nationalistic prattle instead of fixing the real problem.

Right. This, right now, is 100% a UK problem. De-Americanising your tech stack isn't going to fix the political issues domestically. Hence Apple pulling ADP out, they made the choice of not complying with the UK and not offering the service instead of compromising the service for everyone else in the world.

UK citizens need to direct their attention inwards against their own government.

Re: Time to start de-Appling

#139

From the article: > Otherwise, please make sure you de-Apple, de-Google, and de-American Stack yourself when you have time, clarity, and focus to do it. Start today. I don't understand the core of this advice. So if you're in the UK and do all the above, can you suddenly get similar E2EE cloud storage from a different provider without a UK government-mandated backdoor?

It's not a backdoor per se. UK just banned using E2EE (at least for Apple users' data). I don't think though they can ban E2EE in general - like, if I upload a binary blob to a data store, how would they know whether it's encrypted or not? Short of banning all strong encryption completely (which even UK yet is not stupid enough to do) it's not possible to prevent. But they did not build a "backdoor" into encryption - they demanded that, and Apple refused, so there's now no encryption at all for UK users. There's no door.

They are just going for service providers that make E2EE easy for users - clearly betting on the fact that people they want to surveil would be too lazy/incompetent to use a custom solution providing strong E2EE encryption. And they may be right - most iphone users would keep using the same services even with the knowledge that the data is now widely open - and eventually of course will be breached and available to every kind of criminal, as it happened many times already with other massive data warehouses.

But I believe even is the UK you still can encrypt your own backup and upload it, e.g., to rsync.net and nobody would be able to stop you. Just most people won't.

Post reply on HN