Live data from Hacker News

Apple – Privacy – Government Information Requests

apple.com

31–40 of 217 posts

Re: Apple – Privacy – Government Information Requests

#31
post #27

I'm very skeptical that traditional screen-lock passcodes offer useful protection for the average person. Most people still choose to use 4-digit passcodes for convenience, leaving exhaustive key search [1] well within the reach of even very small attackers. Are these four-digit passcodes being used to derive encryption keys? If so, I'd like to hear where the additional entropy comes from. There's no use encrypting t…

IIRC, there are three crypto keys involved:

1. PIN

2. Random key in effaceable NAND storage (generated on device reset)

3. Burned in permanent CPU-unique key.

I think OP's linked statement from Apple means that Apple is now also encrypting data stored on the iCloud servers.

http://www.apple.com/ipad/business/docs/iOS_Security_Feb14.p...

Re: Apple – Privacy – Government Information Requests

#32
post #4

Edit: Can someone confirm or deny the following? I think this is the current state of affairs. A) Apple will unlock PIN-locked devices by government request, but the best they can do is brute-force. This is very slow, as it can only be done using the phone's on-board crypto hardware (which has a unique burned-in crypto key), and the PIN is stretched with PBKDF2. It has been this way for a while. Apple has no "backdoo…

No, not all iCloud data is encrypted in storage. Email and Notes are not.

Re: Apple – Privacy – Government Information Requests

#33
post #24

So the US is now a country where mainstream companies market it as a competitive advantage that they will try to minimize what they will release to the government. I'm glad companies are doing this, but I'm sad that they even have to.

The desire for privacy, and a healthy dose of suspicion for ones government, have both existed for as long as the notion of government itself. Personally, I'm waiting for the other shoe to drop. Now that the police can't go to Apple for your data, we'll start seeing more judges ordering users to unlock their phones to allow them to be searched. I don't think it will be long before such a case reaches SCOTUS, and then…

The US government forced Lavabit to install a back door that didn't exist before (or go out of business, which isn't really an option for Apple). I wonder what is to legally stop the government from forcing Apple to do the same? I guess one answer is that Apple has more resources to fight or lobby.

Re: Apple – Privacy – Government Information Requests

#34
post #31
post #27

I'm very skeptical that traditional screen-lock passcodes offer useful protection for the average person. Most people still choose to use 4-digit passcodes for convenience, leaving exhaustive key search [1] well within the reach of even very small attackers. Are these four-digit passcodes being used to derive encryption keys? If so, I'd like to hear where the additional entropy comes from. There's no use encrypting t…

IIRC, there are three crypto keys involved: 1. PIN 2. Random key in effaceable NAND storage (generated on device reset) 3. Burned in permanent CPU-unique key. I think OP's linked statement from Apple means that Apple is now also encrypting data stored on the iCloud servers. http://www.apple.com/ipad/business/docs/iOS_Security_Feb14.p...

>I think OP's linked statement from Apple means that Apple is now also encrypting data stored on the iCloud servers.

From today's announcement (scroll to "iCloud"): Mail and Notes are not stored in encrypted form on iCloud servers. http://www.apple.com/privacy/privacy-built-in/

From December 2013: Mail and Notes are not stored in encrypted form on iCloud servers. http://support.apple.com/kb/HT4865

Re: Apple – Privacy – Government Information Requests

#35
post #24

Earlier quoted context omitted.

The desire for privacy, and a healthy dose of suspicion for ones government, have both existed for as long as the notion of government itself. Personally, I'm waiting for the other shoe to drop. Now that the police can't go to Apple for your data, we'll start seeing more judges ordering users to unlock their phones to allow them to be searched. I don't think it will be long before such a case reaches SCOTUS, and then…

The US government forced Lavabit to install a back door that didn't exist before (or go out of business, which isn't really an option for Apple). I wonder what is to legally stop the government from forcing Apple to do the same? I guess one answer is that Apple has more resources to fight or lobby.

Lavabit wasn't forced to install a backdoor, the guy running it just kept refusing to comply with previous legal requests which were much narrower in scope. Since he didn't comply they took the nuclear option (which he could have easily prevented).

Re: Apple – Privacy – Government Information Requests

#37
post #30

Yet no comment from them about what being a "provider" under PRISM entails. * "In addition, Apple has never worked with any government agency from any country to create a “back door” in any of our products or services." If Apple provides an interface to request user-data to law enforcement / NSA, that's not a back door in the product or the service . * "We have also never allowed any government access to our servers.…

>If they provide user-data after being served with a warrant their servers were never accessed, yet the data was provided. Yes, that's true. But if you run an email service that's based in Cupertino, what do you do when served with a lawful search warrant or wiretap order? Say "no," and be found in contempt of court and have all your servers carted away by some men in black so they can find the file they're looking f…

> What do you do when the Feds show up with a lawful order?

I don't expect them to say no. That's why I don't expect them to imply that they would or suggest that they never have.

Re: Apple – Privacy – Government Information Requests

#38
post #30

Yet no comment from them about what being a "provider" under PRISM entails. * "In addition, Apple has never worked with any government agency from any country to create a “back door” in any of our products or services." If Apple provides an interface to request user-data to law enforcement / NSA, that's not a back door in the product or the service . * "We have also never allowed any government access to our servers.…

>If they provide user-data after being served with a warrant their servers were never accessed, yet the data was provided. Yes, that's true. But if you run an email service that's based in Cupertino, what do you do when served with a lawful search warrant or wiretap order? Say "no," and be found in contempt of court and have all your servers carted away by some men in black so they can find the file they're looking f…

I go under the assumption that if I'm not the one generating and providing the encryption keys (and really, pre-encrypting the data), absolutely nothing is secure/encrypted. And in all honesty, if it touched the internet, it's already insecure to some extent.

It's been "fun" to read Jewel vs. NSA proceedings, press statements, and officials' statements about these issues because of the extent to which they play word games to technically not lie according to specific (re)definition of words.

Re: Apple – Privacy – Government Information Requests

#39
post #24

So the US is now a country where mainstream companies market it as a competitive advantage that they will try to minimize what they will release to the government. I'm glad companies are doing this, but I'm sad that they even have to.

The desire for privacy, and a healthy dose of suspicion for ones government, have both existed for as long as the notion of government itself. Personally, I'm waiting for the other shoe to drop. Now that the police can't go to Apple for your data, we'll start seeing more judges ordering users to unlock their phones to allow them to be searched. I don't think it will be long before such a case reaches SCOTUS, and then…

> Now that the police can't go to Apple for your data, we'll start seeing more judges ordering users to unlock their phones to allow them to be searched

Is not that against 5th amendment?

Re: Apple – Privacy – Government Information Requests

#40
post #34
post #31

Earlier quoted context omitted.

IIRC, there are three crypto keys involved: 1. PIN 2. Random key in effaceable NAND storage (generated on device reset) 3. Burned in permanent CPU-unique key. I think OP's linked statement from Apple means that Apple is now also encrypting data stored on the iCloud servers. http://www.apple.com/ipad/business/docs/iOS_Security_Feb14.p...

>I think OP's linked statement from Apple means that Apple is now also encrypting data stored on the iCloud servers. From today's announcement (scroll to "iCloud"): Mail and Notes are not stored in encrypted form on iCloud servers. http://www.apple.com/privacy/privacy-built-in/ From December 2013: Mail and Notes are not stored in encrypted form on iCloud servers. http://support.apple.com/kb/HT4865

Then what has changed?
Post reply on HN