Live data from Hacker News

Apple – Privacy – Government Information Requests

apple.com

1–10 of 217 posts

Re: Apple – Privacy – Government Information Requests

#2
If you're an iOS user who becomes the target of an investigation by a law enforcement or intelligence agency, remember your data is likely unencrypted in the cloud. So if your device is inaccessible, your email, your location history, your text messages, your phone call history will probably remain accessible. Apple acknowledges, for example, that "iCloud does not encrypt data stored on IMAP mail servers": http://support.apple.com/kb/HT4865

[Edited because it now seems unclear which Apple policies have changed.]

Re: Apple – Privacy – Government Information Requests

#4
Edit:

Can someone confirm or deny the following? I think this is the current state of affairs.

A) Apple will unlock PIN-locked devices by government request, but the best they can do is brute-force. This is very slow, as it can only be done using the phone's on-board crypto hardware (which has a unique burned-in crypto key), and the PIN is stretched with PBKDF2. It has been this way for a while. Apple has no "backdoor" on the PIN or any form of cryptographic advantage here that we know of.

B) The new thing mentioned in the OP's link is that things stored on Apple's servers are now encrypted as well, with your iCloud password.

Is this correct?

Re: Apple – Privacy – Government Information Requests

#5
post #4

Edit: Can someone confirm or deny the following? I think this is the current state of affairs. A) Apple will unlock PIN-locked devices by government request, but the best they can do is brute-force. This is very slow, as it can only be done using the phone's on-board crypto hardware (which has a unique burned-in crypto key), and the PIN is stretched with PBKDF2. It has been this way for a while. Apple has no "backdoo…

Not surprisingly, that instruction was for the general population. Not the police.

Re: Apple – Privacy – Government Information Requests

#6
post #4

Edit: Can someone confirm or deny the following? I think this is the current state of affairs. A) Apple will unlock PIN-locked devices by government request, but the best they can do is brute-force. This is very slow, as it can only be done using the phone's on-board crypto hardware (which has a unique burned-in crypto key), and the PIN is stretched with PBKDF2. It has been this way for a while. Apple has no "backdoo…

It's actually really easy to recover the passcode from iTunes backups (so probably from iCloud backups too). I've had to do it before to rescue photos off a friend's iPhone. Don't know about >iOS6 though.

Re: Apple – Privacy – Government Information Requests

#7
post #2

If you're an iOS user who becomes the target of an investigation by a law enforcement or intelligence agency, remember your data is likely unencrypted in the cloud. So if your device is inaccessible, your email, your location history, your text messages, your phone call history will probably remain accessible. Apple acknowledges, for example, that "iCloud does not encrypt data stored on IMAP mail servers": http://sup…

> though the celeb hacking shows the limits of that approach

Apple has clearly stated that its system was not compromised.

The user reset questions were socially engineered meaning it is irrelevant whether or not the data is encrypted. From Apple's perspective the owner of the data is downloading it.

Re: Apple – Privacy – Government Information Requests

#8
post #4

Edit: Can someone confirm or deny the following? I think this is the current state of affairs. A) Apple will unlock PIN-locked devices by government request, but the best they can do is brute-force. This is very slow, as it can only be done using the phone's on-board crypto hardware (which has a unique burned-in crypto key), and the PIN is stretched with PBKDF2. It has been this way for a while. Apple has no "backdoo…

It's actually really easy to recover the passcode from iTunes backups (so probably from iCloud backups too). I've had to do it before to rescue photos off a friend's iPhone. Don't know about >iOS6 though.

>It's actually really easy to recover the passcode from iTunes backups

What do you mean by this? I doubt the passcode is stored in plaintext anywhere, and if I recall correctly, the passcode is convolved with the CPU's burned-in crypto key before storage, so you couldn't recover it from a backup without the corresponding phone.

Re: Apple – Privacy – Government Information Requests

#9
post #2

If you're an iOS user who becomes the target of an investigation by a law enforcement or intelligence agency, remember your data is likely unencrypted in the cloud. So if your device is inaccessible, your email, your location history, your text messages, your phone call history will probably remain accessible. Apple acknowledges, for example, that "iCloud does not encrypt data stored on IMAP mail servers": http://sup…

You don't have to guess -- they specify exactly what is encrypted in iCloud;

  "On devices running iOS 8, your personal data such as photos,
  messages (including attachments), email, contacts, call history,
  iTunes content, notes, and reminders is placed under the
  protection of your passcode."

Re: Apple – Privacy – Government Information Requests

#10
> less than 0.00385% of customers had data disclosed due to government information requests.

According to [1], there are about 600 million apple users, so this translates to 23,000 customers exposed due to government information requests.

Seems like a large number. Is 600M correct?

[1] http://www.cnet.com/news/apple-to-reach-600-million-users-by...

Post reply on HN