Live data from Hacker News

France threatens GrapheneOS with arrests / server seizure for refusing backdoors

mamot.fr

41–50 of 399 posts

Re: France threatens GrapheneOS with arrests / server seizure for refusing backdoors

#42
post #34
post #9

Is it safe to assume, then, that Google and Apple already have backdoors in their operating systems as likely requested by many governments around the world (not least of which the one from their home country)? Or is GrapheneOS the only one built securely enough to need to be leaned upon? Either way, makes Google and Apple look bad and/or incompetent and GrapheneOS look like some kind of beacon of user protection / p…

Of course the likes of Apple and Google are complying with lawful orders from the governments of countries they do business in. Businesses that don't generally cease operating in said country. LavaBit was a highly visible instance of a business shuttering itself instead of complying with such lawful orders.

That's also the ploy of basically every VPN provider out there. They say they don't store or give out data, but they still adhere to lawful requests. That necessarily includes requests from countries where they legally offer their service, even if their HQ is in some country with lax legal frameworks. It also means, if there is a legal way to coerce them into recording your data or handing it over, they will do so.

https://www.pcmag.com/news/nordvpn-actually-we-do-comply-wit...

Re: France threatens GrapheneOS with arrests / server seizure for refusing backdoors

#43
post #9

Is it safe to assume, then, that Google and Apple already have backdoors in their operating systems as likely requested by many governments around the world (not least of which the one from their home country)? Or is GrapheneOS the only one built securely enough to need to be leaned upon? Either way, makes Google and Apple look bad and/or incompetent and GrapheneOS look like some kind of beacon of user protection / p…

I seem to remember the FBI attempting to compel Apple to decrypt a criminal's iPhone, only for Apple to refuse and claim that it wasn't possible. I'm not sure exactly what happened after that. I think it was suspected that the NSA was able to do it by exploiting an unpatched zero-day. So they didn't need Apple's help anymore and the issue was dropped from the public's eye.

There's a couple overlapping things here:

1. Apple can and does comply with subpoenas for user information that it has access to. This includes tons of data from your phone unless you're enrolled in Advanced Data Protection, because Apple stores your data encrypted at rest but retains the ability to decrypt it so that users who lose their device/credentials can still restore their data.

2. Apple has refused on multiple occasions, publicly, to take advantage of their position in the supply chain to insert malicious code that expands the data they have access to. This would be things like shipping an updated iOS that lets them fetch end-to-end encrypted data off of a suspect's device.

Re: France threatens GrapheneOS with arrests / server seizure for refusing backdoors

#44
post #43

Earlier quoted context omitted.

I seem to remember the FBI attempting to compel Apple to decrypt a criminal's iPhone, only for Apple to refuse and claim that it wasn't possible. I'm not sure exactly what happened after that. I think it was suspected that the NSA was able to do it by exploiting an unpatched zero-day. So they didn't need Apple's help anymore and the issue was dropped from the public's eye.

There's a couple overlapping things here: 1. Apple can and does comply with subpoenas for user information that it has access to. This includes tons of data from your phone unless you're enrolled in Advanced Data Protection, because Apple stores your data encrypted at rest but retains the ability to decrypt it so that users who lose their device/credentials can still restore their data. 2. Apple has refused on multip…

Not to mention, while apple will publically deny it, there are government agents working undercover at every major tech firm. They may or may not know. They certainly exist.

Re: France threatens GrapheneOS with arrests / server seizure for refusing backdoors

#45

Earlier quoted context omitted.

I seem to remember the FBI attempting to compel Apple to decrypt a criminal's iPhone, only for Apple to refuse and claim that it wasn't possible. I'm not sure exactly what happened after that. I think it was suspected that the NSA was able to do it by exploiting an unpatched zero-day. So they didn't need Apple's help anymore and the issue was dropped from the public's eye.

I always assume these public performances are merely performances and that no one hears about the actual dirty work.

And of course Apple is quite right not to miss the marketing opportunity, on behalf of the shareholders. While acquiescing to lawful demands of course.

Re: France threatens GrapheneOS with arrests / server seizure for refusing backdoors

#46
post #9

Is it safe to assume, then, that Google and Apple already have backdoors in their operating systems as likely requested by many governments around the world (not least of which the one from their home country)? Or is GrapheneOS the only one built securely enough to need to be leaned upon? Either way, makes Google and Apple look bad and/or incompetent and GrapheneOS look like some kind of beacon of user protection / p…

Every time I travel internationally I immediately get notifications for Android OS updates. I'm pretty sure they are for satisfying local regulations about the phone's behavior, including the topic at hand.

I am not saying there are no backdoors, but this never happened to me.

And I am an Android user since the first G1 phone.

Re: France threatens GrapheneOS with arrests / server seizure for refusing backdoors

#48
post #15

Earlier quoted context omitted.

The EU doesn't seem to shy about forcing Apple or Google to do things, so I don't think it's a size thing.

France isn’t the EU though.

True, but from what I understand France and Germany quite often get their way in the EU.

Re: France threatens GrapheneOS with arrests / server seizure for refusing backdoors

#50

Earlier quoted context omitted.

Every time I travel internationally I immediately get notifications for Android OS updates. I'm pretty sure they are for satisfying local regulations about the phone's behavior, including the topic at hand.

Interesting. I have never seen anything like that in many years of frequent travelling while using Android. Which countries did you see this in? And are you using stock Android or some vendor's version?

Stock android. Traveling between US, Europe, LATAM and China.
Post reply on HN