Live data from Hacker News

France threatens GrapheneOS with arrests / server seizure for refusing backdoors

mamot.fr

31–40 of 399 posts

Re: France threatens GrapheneOS with arrests / server seizure for refusing backdoors

#32
post #9

Is it safe to assume, then, that Google and Apple already have backdoors in their operating systems as likely requested by many governments around the world (not least of which the one from their home country)? Or is GrapheneOS the only one built securely enough to need to be leaned upon? Either way, makes Google and Apple look bad and/or incompetent and GrapheneOS look like some kind of beacon of user protection / p…

Every time I travel internationally I immediately get notifications for Android OS updates. I'm pretty sure they are for satisfying local regulations about the phone's behavior, including the topic at hand.

Interesting. I have never seen anything like that in many years of frequent travelling while using Android. Which countries did you see this in? And are you using stock Android or some vendor's version?

Re: France threatens GrapheneOS with arrests / server seizure for refusing backdoors

#33

Earlier quoted context omitted.

Every time I travel internationally I immediately get notifications for Android OS updates. I'm pretty sure they are for satisfying local regulations about the phone's behavior, including the topic at hand.

This has never happened on my iPhone

They are just done in the background?

Re: France threatens GrapheneOS with arrests / server seizure for refusing backdoors

#34
post #9

Is it safe to assume, then, that Google and Apple already have backdoors in their operating systems as likely requested by many governments around the world (not least of which the one from their home country)? Or is GrapheneOS the only one built securely enough to need to be leaned upon? Either way, makes Google and Apple look bad and/or incompetent and GrapheneOS look like some kind of beacon of user protection / p…

Of course the likes of Apple and Google are complying with lawful orders from the governments of countries they do business in.

Businesses that don't generally cease operating in said country. LavaBit was a highly visible instance of a business shuttering itself instead of complying with such lawful orders.

Re: France threatens GrapheneOS with arrests / server seizure for refusing backdoors

#35
post #9

Is it safe to assume, then, that Google and Apple already have backdoors in their operating systems as likely requested by many governments around the world (not least of which the one from their home country)? Or is GrapheneOS the only one built securely enough to need to be leaned upon? Either way, makes Google and Apple look bad and/or incompetent and GrapheneOS look like some kind of beacon of user protection / p…

Yes, it's safe to assume that companies follow the law in countries where they operate.

Re: France threatens GrapheneOS with arrests / server seizure for refusing backdoors

#36

Earlier quoted context omitted.

I seem to remember the FBI attempting to compel Apple to decrypt a criminal's iPhone, only for Apple to refuse and claim that it wasn't possible. I'm not sure exactly what happened after that. I think it was suspected that the NSA was able to do it by exploiting an unpatched zero-day. So they didn't need Apple's help anymore and the issue was dropped from the public's eye.

That was show put on for the sole reason of the public seeing it.

If you follow the things that have been disclosed / leaked/ confirmed when they’re 20+ years out of date, then yes the probability this is true is significant.

Re: France threatens GrapheneOS with arrests / server seizure for refusing backdoors

#37
post #9

Is it safe to assume, then, that Google and Apple already have backdoors in their operating systems as likely requested by many governments around the world (not least of which the one from their home country)? Or is GrapheneOS the only one built securely enough to need to be leaned upon? Either way, makes Google and Apple look bad and/or incompetent and GrapheneOS look like some kind of beacon of user protection / p…

I seem to remember the FBI attempting to compel Apple to decrypt a criminal's iPhone, only for Apple to refuse and claim that it wasn't possible. I'm not sure exactly what happened after that. I think it was suspected that the NSA was able to do it by exploiting an unpatched zero-day. So they didn't need Apple's help anymore and the issue was dropped from the public's eye.

> remember the FBI attempting to compel Apple to decrypt a criminal's iPhone, only for Apple to refuse and claim that it wasn't possible

Apple refused “to write new software that would let the government bypass these devices' security and unlock” suspects’ phones [1].

> not sure exactly what happened after that

Cupertino got a lot of vitriol and limited support for its efforts.

[1] https://en.wikipedia.org/wiki/Apple%E2%80%93FBI_encryption_d...

Re: France threatens GrapheneOS with arrests / server seizure for refusing backdoors

#39

Earlier quoted context omitted.

Every time I travel internationally I immediately get notifications for Android OS updates. I'm pretty sure they are for satisfying local regulations about the phone's behavior, including the topic at hand.

This has never happened on my iPhone

Apple charges a storage tax so why not ship all that data by default

Re: France threatens GrapheneOS with arrests / server seizure for refusing backdoors

#40

Earlier quoted context omitted.

I seem to remember the FBI attempting to compel Apple to decrypt a criminal's iPhone, only for Apple to refuse and claim that it wasn't possible. I'm not sure exactly what happened after that. I think it was suspected that the NSA was able to do it by exploiting an unpatched zero-day. So they didn't need Apple's help anymore and the issue was dropped from the public's eye.

I don't remember Apple ever saying that it was impossible for them to do it, just that they didn't want to. It was always kind of assumed that they could , by eg signing a malicious OS update without PIN code retry limits, so the FBI could brute force it at their leisure, or something similar.

They said it was impossible for them to build a backdoor into iOS that would only be accessible to legal requests from law enforcement, which is true in the strict sense. So law enforcement bought a vulnerability exploit from a third party.
Post reply on HN