Live data from Hacker News

Apple – Privacy – Government Information Requests

apple.com

21–30 of 217 posts

Re: Apple – Privacy – Government Information Requests

#21
Yet no comment from them about what being a "provider" under PRISM entails.

* "In addition, Apple has never worked with any government agency from any country to create a “back door” in any of our products or services."

If Apple provides an interface to request user-data to law enforcement / NSA, that's not a back door in the product or the service.

* "We have also never allowed any government access to our servers. And we never will."

If they provide user-data after being served with a warrant (possibly through email or to their legal department), their servers were never accessed, yet the data was provided.

It's always interesting to read what is and isn't said. Word games, I swear.

Re: Apple – Privacy – Government Information Requests

#22

> less than 0.00385% of customers had data disclosed due to government information requests. According to [1], there are about 600 million apple users, so this translates to 23,000 customers exposed due to government information requests. Seems like a large number. Is 600M correct? [1] http://www.cnet.com/news/apple-to-reach-600-million-users-by...

The "less than" seems pretty superfluous when they're giving that many digits...

Re: Apple – Privacy – Government Information Requests

#23
post #16
post #12

Earlier quoted context omitted.

But "iCloud does not encrypt data stored on IMAP mail servers" or Notes http://support.apple.com/kb/HT4865

"Last Modified: Dec 12, 2013".

That December 2013 page is linked to from today's announcement, under "Learn more about iCloud security." See: http://www.apple.com/privacy/privacy-built-in/

Also note that today's announcement says Mail and Notes are "encrypted in transit" only. In other words the December 2013 page remains current.

Re: Apple – Privacy – Government Information Requests

#24

So the US is now a country where mainstream companies market it as a competitive advantage that they will try to minimize what they will release to the government. I'm glad companies are doing this, but I'm sad that they even have to.

The desire for privacy, and a healthy dose of suspicion for ones government, have both existed for as long as the notion of government itself.

Personally, I'm waiting for the other shoe to drop. Now that the police can't go to Apple for your data, we'll start seeing more judges ordering users to unlock their phones to allow them to be searched. I don't think it will be long before such a case reaches SCOTUS, and then we'll see how that works out...

Re: Apple – Privacy – Government Information Requests

#26

Yet no comment from them about what being a "provider" under PRISM entails. * "In addition, Apple has never worked with any government agency from any country to create a “back door” in any of our products or services." If Apple provides an interface to request user-data to law enforcement / NSA, that's not a back door in the product or the service . * "We have also never allowed any government access to our servers.…

I'd like to see a breakdown of exactly what they can provide with a device request and an account request.

I think that would be reasonable information to share, because it'd educate both law enforcement and the general public about what data is available from their devices.

Plus it'd settle the issue of word games- or at least bring it closer to being settled in my eyes. We can't get a good idea of what is going on with these 10k foot marketing pronouncements.

Re: Apple – Privacy – Government Information Requests

#27
I'm very skeptical that traditional screen-lock passcodes offer useful protection for the average person. Most people still choose to use 4-digit passcodes for convenience, leaving exhaustive key search [1] well within the reach of even very small attackers.

Are these four-digit passcodes being used to derive encryption keys? If so, I'd like to hear where the additional entropy comes from. There's no use encrypting things with a 128-bit key when the effective entropy of the key is really only ~12.3 bits.

I'm sure the engineers at Apple would not have overlooked this; it would be great to hear more about the specifics.

[1] especially if the attacker can download encrypted data and try an infinite number of times (instead of e.g. typing the passcode on the phone or hitting the iCloud servers)

Re: Apple – Privacy – Government Information Requests

#28
post #4

Edit: Can someone confirm or deny the following? I think this is the current state of affairs. A) Apple will unlock PIN-locked devices by government request, but the best they can do is brute-force. This is very slow, as it can only be done using the phone's on-board crypto hardware (which has a unique burned-in crypto key), and the PIN is stretched with PBKDF2. It has been this way for a while. Apple has no "backdoo…

> According to Apple, the only way to crack the passcode was via brute force.

I imagine every vendor selling encryption would make this claim. Otherwise, they would have to say there is a flaw in their implementation or publicly reveal their backdoor.

Re: Apple – Privacy – Government Information Requests

#30

Yet no comment from them about what being a "provider" under PRISM entails. * "In addition, Apple has never worked with any government agency from any country to create a “back door” in any of our products or services." If Apple provides an interface to request user-data to law enforcement / NSA, that's not a back door in the product or the service . * "We have also never allowed any government access to our servers.…

>If they provide user-data after being served with a warrant their servers were never accessed, yet the data was provided.

Yes, that's true. But if you run an email service that's based in Cupertino, what do you do when served with a lawful search warrant or wiretap order? Say "no," and be found in contempt of court and have all your servers carted away by some men in black so they can find the file they're looking for?

There are a few ways around this. One is not to permanently store warrant-worthy user data (Snapchat, Wickr, etc.). Another is end-to-end encryption (original version of Hushmail), though key distribution and UX become problems. A third is to move your servers to Switzerland, though then you get served with process from the Swiss authorities instead of FBIDHSDEAetc.

Apple has taken none of these steps. Assume our hypothetical Cupertino-based email service has not either. What do you do when the Feds show up with a lawful order?

Post reply on HN