Live data from Hacker News

Apple – Privacy – Government Information Requests

apple.com

11–20 of 217 posts

Re: Apple – Privacy – Government Information Requests

#11
post #4

Edit: Can someone confirm or deny the following? I think this is the current state of affairs. A) Apple will unlock PIN-locked devices by government request, but the best they can do is brute-force. This is very slow, as it can only be done using the phone's on-board crypto hardware (which has a unique burned-in crypto key), and the PIN is stretched with PBKDF2. It has been this way for a while. Apple has no "backdoo…

It's actually really easy to recover the passcode from iTunes backups (so probably from iCloud backups too). I've had to do it before to rescue photos off a friend's iPhone. Don't know about >iOS6 though.

iTunes backups are encrypted by default. And I can't imagine a typical person deliberately disabling it.

Your example is a little unique though because you have physical access to both their computer and their phone. In theory you could just brute force their iTunes backup password.

Re: Apple – Privacy – Government Information Requests

#12
post #9
post #2

If you're an iOS user who becomes the target of an investigation by a law enforcement or intelligence agency, remember your data is likely unencrypted in the cloud. So if your device is inaccessible, your email, your location history, your text messages, your phone call history will probably remain accessible. Apple acknowledges, for example, that "iCloud does not encrypt data stored on IMAP mail servers": http://sup…

You don't have to guess -- they specify exactly what is encrypted in iCloud; "On devices running iOS 8, your personal data such as photos, messages (including attachments), email, contacts, call history, iTunes content, notes, and reminders is placed under the protection of your passcode."

But "iCloud does not encrypt data stored on IMAP mail servers" or Notes

http://support.apple.com/kb/HT4865

Re: Apple – Privacy – Government Information Requests

#13

Earlier quoted context omitted.

It's actually really easy to recover the passcode from iTunes backups (so probably from iCloud backups too). I've had to do it before to rescue photos off a friend's iPhone. Don't know about >iOS6 though.

iTunes backups are encrypted by default. And I can't imagine a typical person deliberately disabling it. Your example is a little unique though because you have physical access to both their computer and their phone. In theory you could just brute force their iTunes backup password.

No they aren't. You have to check a box in iTunes to have them encrypted.

Re: Apple – Privacy – Government Information Requests

#14
post #12
post #9

Earlier quoted context omitted.

You don't have to guess -- they specify exactly what is encrypted in iCloud; "On devices running iOS 8, your personal data such as photos, messages (including attachments), email, contacts, call history, iTunes content, notes, and reminders is placed under the protection of your passcode."

But "iCloud does not encrypt data stored on IMAP mail servers" or Notes http://support.apple.com/kb/HT4865

How is Apple supposed to encrypt data stored on servers they do not own?

Re: Apple – Privacy – Government Information Requests

#16
post #12
post #9

Earlier quoted context omitted.

You don't have to guess -- they specify exactly what is encrypted in iCloud; "On devices running iOS 8, your personal data such as photos, messages (including attachments), email, contacts, call history, iTunes content, notes, and reminders is placed under the protection of your passcode."

But "iCloud does not encrypt data stored on IMAP mail servers" or Notes http://support.apple.com/kb/HT4865

"Last Modified: Dec 12, 2013".

Re: Apple – Privacy – Government Information Requests

#17

> less than 0.00385% of customers had data disclosed due to government information requests. According to [1], there are about 600 million apple users, so this translates to 23,000 customers exposed due to government information requests. Seems like a large number. Is 600M correct? [1] http://www.cnet.com/news/apple-to-reach-600-million-users-by...

There are millions of people arrested in the US alone every year. It doesn't seem unbelievable that 23,000 of them had iPhones/iPads that law enforcement wanted data off of.

Re: Apple – Privacy – Government Information Requests

#18
post #2

If you're an iOS user who becomes the target of an investigation by a law enforcement or intelligence agency, remember your data is likely unencrypted in the cloud. So if your device is inaccessible, your email, your location history, your text messages, your phone call history will probably remain accessible. Apple acknowledges, for example, that "iCloud does not encrypt data stored on IMAP mail servers": http://sup…

> though the celeb hacking shows the limits of that approach Apple has clearly stated that its system was not compromised. The user reset questions were socially engineered meaning it is irrelevant whether or not the data is encrypted. From Apple's perspective the owner of the data is downloading it.

> The user reset questions were socially engineered

Yep, you're right. My point, perhaps poorly stated, is that if Random Hacker X can figure out the answers to the iCloud reset questions, so can a law enforcement agency. Then they can log into that account. Impersonating someone this way is legal -- or at least has not been ruled to be illegal -- as long as it's done under court supervision under the Wiretap Act or similar legal authority authorizing prospective surveillance.

Possibly related: I disclosed last year that the Feds have demanded that major Internet companies divulge targeted users' stored passwords, and in some cases the algorithm used and the salt: http://www.cnet.com/news/feds-tell-web-firms-to-turn-over-us...

Re: Apple – Privacy – Government Information Requests

#19
post #2

If you're an iOS user who becomes the target of an investigation by a law enforcement or intelligence agency, remember your data is likely unencrypted in the cloud. So if your device is inaccessible, your email, your location history, your text messages, your phone call history will probably remain accessible. Apple acknowledges, for example, that "iCloud does not encrypt data stored on IMAP mail servers": http://sup…

In the end this is not about an information security solution (which is measured by the weakest link). This is about engineering consumer expectations. Privacy and security must be measured in terms of the overall digital-economic ecosystem. Systems at the margins of everyday consumer experience will determine how absolutely secure any computation can be. Consider the baseband processor in each iphone.

I think companies like apple and google are undertaking PR exercises like this in the hopes of finding that sweet-spot between the sense of crisis (excitement?) that smart phone ownership brings and the banal integration of technology into everyday life. There _are_ government requests, but they do not affect _you_. maybe. So my question: Is government surveillance now officially part of the iPhone experience?

To the extent that a debate exists, apple is engaging and steering that discussion. This is just pure organizational reflex. And it's cynical in some sense, but apple doesn't really have a choice in the matter either. Ultimately it is what the US officials consider to be an acceptable level of visible surveillance, which is a political consideration.

Re: Apple – Privacy – Government Information Requests

#20

Earlier quoted context omitted.

iTunes backups are encrypted by default. And I can't imagine a typical person deliberately disabling it. Your example is a little unique though because you have physical access to both their computer and their phone. In theory you could just brute force their iTunes backup password.

No they aren't. You have to check a box in iTunes to have them encrypted.

They are if you have a passcode lock
Post reply on HN