Live data from Hacker News

Apple – Privacy – Government Information Requests

apple.com

51–60 of 217 posts

Re: Apple – Privacy – Government Information Requests

#51

Yet no comment from them about what being a "provider" under PRISM entails. * "In addition, Apple has never worked with any government agency from any country to create a “back door” in any of our products or services." If Apple provides an interface to request user-data to law enforcement / NSA, that's not a back door in the product or the service . * "We have also never allowed any government access to our servers.…

There are interviews were Tim Cook states the range of warrant requests (he isn't allowed to tell the exact numbers): http://www.youtube.com/watch?v=Bmm5faI_mLo

Seemingly, they also have some sort of canary in place in case they get secret requests under the patriot act: http://boingboing.net/2013/11/05/apple-hides-a-patriot-act-b...

Re: Apple – Privacy – Government Information Requests

#52
The honest truth about all of this is, even if Apple were handing over information because of back doors, custom database interface applications for the NSA, they wouldn't tell us and would probably be gagged from doing so anyway, have we all forgotten about Lavabit? I hope not.

I think we are all intelligent enough to know that even if Apple were handing over information, it wouldn't exactly be good for business to admit you've been complicit in handing over personal details to the Government, would it? "Yes, we have been giving away your information, but we promise not to do it any more. Hey, we just released a couple of new iPhones, want to buy one"

Anyone else notice the page is cleverly worded and any mention of security seems to be limited to iOS 8 context? "In iOS 8 your data is secure", "In iOS 8 we can't give law enforcement access to your phone" - maybe I am just overanalysing things here, but I have learned not to be so trusting of companies as big as Apple considering the amount of information that they hold.

You know we're living in a new kind of world when privacy is being used for marketing purposes...

Re: Apple – Privacy – Government Information Requests

#53

Yet no comment from them about what being a "provider" under PRISM entails. * "In addition, Apple has never worked with any government agency from any country to create a “back door” in any of our products or services." If Apple provides an interface to request user-data to law enforcement / NSA, that's not a back door in the product or the service . * "We have also never allowed any government access to our servers.…

> If Apple provides an interface to request user-data to law enforcement / NSA, that's not a back door in the product or the service.

I consider that a back door.

>We have also never allowed any government access to our servers. And we never will

Makes it clear what he means in the first statement.

I've known Apple to engage in hyperbole to a significant degree, but never -- in nearly 40 years-- to lie publicly.

They haven't denied providing information under warrant. Basically, every US company is going to do that.

But that's on a case by case basis, not wholesale.

Re: Apple – Privacy – Government Information Requests

#54
post #53

Yet no comment from them about what being a "provider" under PRISM entails. * "In addition, Apple has never worked with any government agency from any country to create a “back door” in any of our products or services." If Apple provides an interface to request user-data to law enforcement / NSA, that's not a back door in the product or the service . * "We have also never allowed any government access to our servers.…

> If Apple provides an interface to request user-data to law enforcement / NSA, that's not a back door in the product or the service. I consider that a back door. >We have also never allowed any government access to our servers. And we never will Makes it clear what he means in the first statement. I've known Apple to engage in hyperbole to a significant degree, but never -- in nearly 40 years-- to lie publicly. They…

An interface to request data wouldn't be a back door, as that falls under the "request/response" model. "Here is our warrant for Person X by judge Y in district Z" != "sudo apple-get * /mount/nsa" The important distinction there is that each request is an individual request and can't be automated / done in bulk / wholesale.

I'm very interested to see how the device vs. account data-request ratio maintains/changes with the release and adoption of iOS 8.

Re: Apple – Privacy – Government Information Requests

#57

Yet no comment from them about what being a "provider" under PRISM entails. * "In addition, Apple has never worked with any government agency from any country to create a “back door” in any of our products or services." If Apple provides an interface to request user-data to law enforcement / NSA, that's not a back door in the product or the service . * "We have also never allowed any government access to our servers.…

Apple has directly addressed the PRISM diclosures, last year: https://www.apple.com/apples-commitment-to-customer-privacy/ In addition the new section launched today includes a page on government information requests, including "National Security Orders from the U.S. government." One sentence summary: they provide data to the government when required to by law. PRISM itself is a program that is structured as a reques…

> The initial report of PRISM implied that the NSA and FBI had direct, unfettered access to providers' "central servers", but that has been since walked back a bit.

Really? I haven't been able to follow every report, as the Snowden leaks generated a lot of content over the past year. Can you give a source to where PRISM's central server access has been "walked back a bit"?

Re: Apple – Privacy – Government Information Requests

#58
post #34
post #31

Earlier quoted context omitted.

IIRC, there are three crypto keys involved: 1. PIN 2. Random key in effaceable NAND storage (generated on device reset) 3. Burned in permanent CPU-unique key. I think OP's linked statement from Apple means that Apple is now also encrypting data stored on the iCloud servers. http://www.apple.com/ipad/business/docs/iOS_Security_Feb14.p...

>I think OP's linked statement from Apple means that Apple is now also encrypting data stored on the iCloud servers. From today's announcement (scroll to "iCloud"): Mail and Notes are not stored in encrypted form on iCloud servers. http://www.apple.com/privacy/privacy-built-in/ From December 2013: Mail and Notes are not stored in encrypted form on iCloud servers. http://support.apple.com/kb/HT4865

Just to be clear, we're talking about mail sent with an @icloud.com or @me.com address, right?

Surely all IMAP traffic doesn't flow through their servers.

Re: Apple – Privacy – Government Information Requests

#59
post #51

Yet no comment from them about what being a "provider" under PRISM entails. * "In addition, Apple has never worked with any government agency from any country to create a “back door” in any of our products or services." If Apple provides an interface to request user-data to law enforcement / NSA, that's not a back door in the product or the service . * "We have also never allowed any government access to our servers.…

There are interviews were Tim Cook states the range of warrant requests (he isn't allowed to tell the exact numbers): http://www.youtube.com/watch?v=Bmm5faI_mLo Seemingly, they also have some sort of canary in place in case they get secret requests under the patriot act: http://boingboing.net/2013/11/05/apple-hides-a-patriot-act-b...

I highly doubt the canary would be a valid defence.

By omitting the line you are, for most intents and purposes, saying that you received a request. Now, saying you received a request and saying specifically what request you received are different, but I imagine the gag order doesn't make that differentiation.

Gag order is not that you can't say a specific thing, it's that you can't communicate a specific piece of information. The canary is communicating something.

A court order can ask you to lie, so the "I can't lie to my customers" defence probably won't work.

Re: Apple – Privacy – Government Information Requests

#60
post #48

Earlier quoted context omitted.

I'd like to see a breakdown of exactly what they can provide with a device request and an account request. I think that would be reasonable information to share, because it'd educate both law enforcement and the general public about what data is available from their devices. Plus it'd settle the issue of word games- or at least bring it closer to being settled in my eyes. We can't get a good idea of what is going on…

http://images.apple.com/privacy/docs/legal-process-guideline... Page 4 onwards provides a list of information they provide to law enforcement agencies. Probably prudent if you're an apple customer to simply assume all of this information is as good as public.

I. Extracting Data from Passcode Locked iOS Devices

...

For all devices running iOS 8.0 and later versions, Apple will no longer be performing iOS data extractions as the data sought will be encrypted and Apple will not possess the encryption key.

Interesting. What changed in iOS 8, I wonder?

Post reply on HN