Live data from Hacker News

Apple – Privacy – Government Information Requests

apple.com

41–50 of 217 posts

Re: Apple – Privacy – Government Information Requests

#41
post #24

So the US is now a country where mainstream companies market it as a competitive advantage that they will try to minimize what they will release to the government. I'm glad companies are doing this, but I'm sad that they even have to.

The desire for privacy, and a healthy dose of suspicion for ones government, have both existed for as long as the notion of government itself. Personally, I'm waiting for the other shoe to drop. Now that the police can't go to Apple for your data, we'll start seeing more judges ordering users to unlock their phones to allow them to be searched. I don't think it will be long before such a case reaches SCOTUS, and then…

I am no lawyer.

While lower court decisions have gone both ways, according to wikipedia,

    in United States v. Doe, the United States Court of Appeals for the 
   Eleventh Circuit ruled on 24 February 2012 that forcing the decryption of 
   one's laptop violates the Fifth Amendment [1]
So there is hope.

Perhaps a more practical problem is even with a 5 digit pin, it's entirely possible to simply try all combinations. You probably need more than 8 digits before that becomes impossible.

[1] http://en.wikipedia.org/wiki/Key_disclosure_law#United_State...

Re: Apple – Privacy – Government Information Requests

#42
My fundamental issue with Apple's privacy claims is they are pretending that they have a technological solution to what is, ultimately, a political problem. As the laws in the US (and I imagine some other countries stand), Apple can be compelled provide your data to appropriate governmental authorities, install back doors, not tell you and even lie to you and the world about it. As long as that's true, no assurance from any third-party service provider is worth a damn.

I can understand the marketing benefits Apple sees in making these disingenuous privacy claims. I'd be willing to call that "just business" except for one thing: Trying to persuade people they have a technological solution will necessarily get in the way of the absolutely vital political project of destroying the political and legal foundations of the surveillance state.

Re: Apple – Privacy – Government Information Requests

#43
post #42

My fundamental issue with Apple's privacy claims is they are pretending that they have a technological solution to what is, ultimately, a political problem. As the laws in the US (and I imagine some other countries stand), Apple can be compelled provide your data to appropriate governmental authorities, install back doors, not tell you and even lie to you and the world about it. As long as that's true, no assurance f…

Apple is doing what should be done. If everyone is informed enough to understand your point, there is no need of privacy policy, and NSA wont be an issue, and on and on...

Re: Apple – Privacy – Government Information Requests

#44
post #30

Yet no comment from them about what being a "provider" under PRISM entails. * "In addition, Apple has never worked with any government agency from any country to create a “back door” in any of our products or services." If Apple provides an interface to request user-data to law enforcement / NSA, that's not a back door in the product or the service . * "We have also never allowed any government access to our servers.…

>If they provide user-data after being served with a warrant their servers were never accessed, yet the data was provided. Yes, that's true. But if you run an email service that's based in Cupertino, what do you do when served with a lawful search warrant or wiretap order? Say "no," and be found in contempt of court and have all your servers carted away by some men in black so they can find the file they're looking f…

> A third is to move your servers to Switzerland, though then you get served with process from the Swiss authorities instead of FBIDHSDEAetc.

And, if you keep your headquarters in Cupertino, quite possibly from US authorities as well (see the currently in-progress Microsoft case about access to servers in Ireland).

Re: Apple – Privacy – Government Information Requests

#45

Yet no comment from them about what being a "provider" under PRISM entails. * "In addition, Apple has never worked with any government agency from any country to create a “back door” in any of our products or services." If Apple provides an interface to request user-data to law enforcement / NSA, that's not a back door in the product or the service . * "We have also never allowed any government access to our servers.…

Apple has directly addressed the PRISM diclosures, last year:

https://www.apple.com/apples-commitment-to-customer-privacy/

In addition the new section launched today includes a page on government information requests, including "National Security Orders from the U.S. government." One sentence summary: they provide data to the government when required to by law.

PRISM itself is a program that is structured as a request/response, and the requests are approved by the FISA court, so it would fit into Apple's language in that section.

The initial report of PRISM implied that the NSA and FBI had direct, unfettered access to providers' "central servers", but that has been since walked back a bit. The points of concern with PRISM are 1) poor oversight from the FISA court, 2) overly broad request criteria resulting in huge datasets collected, and 3) the lack of public oversight due to gag orders.

Re: Apple – Privacy – Government Information Requests

#46
post #23
post #16

Earlier quoted context omitted.

"Last Modified: Dec 12, 2013".

That December 2013 page is linked to from today's announcement, under "Learn more about iCloud security." See: http://www.apple.com/privacy/privacy-built-in/ Also note that today's announcement says Mail and Notes are "encrypted in transit" only. In other words the December 2013 page remains current.

OK. You win 2 internets. And fuck that highly misleading ad copy, Apple. :-(

[Edit] - Clearly something is off here. iPhone keeps a copy of the last several hundred emails downloaded from my IMAP server, I would expect an iCloud backup of those emails would be "under the protection of the passcode" (a.k.a encrypted).

That doesn't mean Apple is somehow encrypting the messages stored on my IMAP server. Likewise, it doesn't mean Apple is encrypting customer emails stored on their @iCloud.com (or whatever) email servers....

I'm going to assume there are just some wires crossed here, but I do hope they clean up the document and clarify this.

Re: Apple – Privacy – Government Information Requests

#47
post #31
post #27

I'm very skeptical that traditional screen-lock passcodes offer useful protection for the average person. Most people still choose to use 4-digit passcodes for convenience, leaving exhaustive key search [1] well within the reach of even very small attackers. Are these four-digit passcodes being used to derive encryption keys? If so, I'd like to hear where the additional entropy comes from. There's no use encrypting t…

IIRC, there are three crypto keys involved: 1. PIN 2. Random key in effaceable NAND storage (generated on device reset) 3. Burned in permanent CPU-unique key. I think OP's linked statement from Apple means that Apple is now also encrypting data stored on the iCloud servers. http://www.apple.com/ipad/business/docs/iOS_Security_Feb14.p...

And this means the passcode has to be broken on the device. The key is generated from the passcode and the other keys you mention via PBKDF2, which slows down the cracking process. You also have to have a non-destructive jailbreak or Apple's update-signing key to do the cracking.

I'd recommend using a longer passcode. If you don't want to use the keyboard, choose a long number for a passcode and you will still get a number-pad when entering it.

Another loophole to be aware of is the "escrow keybag". If you're paired with a laptop, there is a file in /var/db/lockdown that can work in place of the PIN (the device can decrypt the escrow keybag with #2 and #3 above and use the keys therein to decrypt the files it needs). Apple did this to allow backups without unlocking the device.

Re: Apple – Privacy – Government Information Requests

#48

Yet no comment from them about what being a "provider" under PRISM entails. * "In addition, Apple has never worked with any government agency from any country to create a “back door” in any of our products or services." If Apple provides an interface to request user-data to law enforcement / NSA, that's not a back door in the product or the service . * "We have also never allowed any government access to our servers.…

I'd like to see a breakdown of exactly what they can provide with a device request and an account request. I think that would be reasonable information to share, because it'd educate both law enforcement and the general public about what data is available from their devices. Plus it'd settle the issue of word games- or at least bring it closer to being settled in my eyes. We can't get a good idea of what is going on…

http://images.apple.com/privacy/docs/legal-process-guideline...

Page 4 onwards provides a list of information they provide to law enforcement agencies. Probably prudent if you're an apple customer to simply assume all of this information is as good as public.

Re: Apple – Privacy – Government Information Requests

#49
post #2

If you're an iOS user who becomes the target of an investigation by a law enforcement or intelligence agency, remember your data is likely unencrypted in the cloud. So if your device is inaccessible, your email, your location history, your text messages, your phone call history will probably remain accessible. Apple acknowledges, for example, that "iCloud does not encrypt data stored on IMAP mail servers": http://sup…

[deleted]

Re: Apple – Privacy – Government Information Requests

#50
post #40
post #34

Earlier quoted context omitted.

>I think OP's linked statement from Apple means that Apple is now also encrypting data stored on the iCloud servers. From today's announcement (scroll to "iCloud"): Mail and Notes are not stored in encrypted form on iCloud servers. http://www.apple.com/privacy/privacy-built-in/ From December 2013: Mail and Notes are not stored in encrypted form on iCloud servers. http://support.apple.com/kb/HT4865

Then what has changed?

This is a very good question. I'm now no longer sure.
Post reply on HN