Live data from Hacker News

Apple – Privacy – Government Information Requests

apple.com

111–120 of 217 posts

Re: Apple – Privacy – Government Information Requests

#111

Earlier quoted context omitted.

The quote is extremely misleading. Sure, it's encrypted by your passcode, and that's great. It's important to note however that the passcode is just 4 digits long by default, and could be bruteforced by Apple in milliseconds if they wanted to. So to say that "Apple cannot bypass your passcode" is misleading, as guessing it is absurdly easy. http://www.slideshare.net/alexeytroshichev/icloud-keychain-3...

You're not limited to 4 digits. In fact, when you set up Touch ID, the phone prompts you to enter a longer text-based passcode on the basis that you shouldn't have to enter it often.

The government has your fingerprint.

Re: Apple – Privacy – Government Information Requests

#112

"On devices running iOS 8, your personal data such as photos, messages (including attachments), email, contacts, call history, iTunes content, notes, and reminders is placed under the protection of your passcode. Unlike our competitors, Apple cannot bypass your passcode and therefore cannot access this data" This is key. The way we engineer software and services can have a major impact on the war against overly invas…

I am a bit surprised that there is no explicit declaration that they don't have user's passcode.

It should be obvious, but I think it should also be stated in a way that makes it a lie if it's later discovered that left some way to access or keep the passcodes.

Re: Apple – Privacy – Government Information Requests

#113
Here's an observation, and an idea for testing Apple's claims on iMessage privacy:

China seems quite determined to block IM systems which do not cooperate with the authorities and permit monitoring of communications. Most recently, both Line and the Korean KakaoTalk were blocked [1].

Skype remains useable in China, presumably because Skype permits efficient monitoring [2].

It seems unlikely that China would tolerate such a prominent opaque communications channel as iMessage in the hands of a significant proportion of their citizens.

Thus, if China refrains from blocking iMessage for a prolonged period of time, wouldn't it be reasonable to assume that China is in fact able to snoop on iMessage?

[1] http://www.ibtimes.com/china-restricts-messaging-apps-confir...

[2] http://www.reuters.com/article/2012/01/31/us-china-dissident...

Re: Apple – Privacy – Government Information Requests

#114

"On devices running iOS 8, your personal data such as photos, messages (including attachments), email, contacts, call history, iTunes content, notes, and reminders is placed under the protection of your passcode. Unlike our competitors, Apple cannot bypass your passcode and therefore cannot access this data" This is key. The way we engineer software and services can have a major impact on the war against overly invas…

What's keeping government agencies from putting keylogging code on the SIM card or baseband processor (whichever has the best access to host cpu/memory) via the carriers to obtain the passcode? Not much I guess.

Has Apple publicly claimed that they will also refuse to push individualized compromising code updates to devices on demand by gov't authorities?

Re: Apple – Privacy – Government Information Requests

#115
post #96

"On devices running iOS 8, your personal data such as photos, messages (including attachments), email, contacts, call history, iTunes content, notes, and reminders is placed under the protection of your passcode. Unlike our competitors, Apple cannot bypass your passcode and therefore cannot access this data" This is key. The way we engineer software and services can have a major impact on the war against overly invas…

Yet there's no way to be sure of that...

No way to be sure - but, the profit motive is pretty good. Apple is going all in on Privacy as the basis for their $500B+ business model.

Re: Apple – Privacy – Government Information Requests

#116

Earlier quoted context omitted.

The quote is extremely misleading. Sure, it's encrypted by your passcode, and that's great. It's important to note however that the passcode is just 4 digits long by default, and could be bruteforced by Apple in milliseconds if they wanted to. So to say that "Apple cannot bypass your passcode" is misleading, as guessing it is absurdly easy. http://www.slideshare.net/alexeytroshichev/icloud-keychain-3...

Not the point. The point is that they've done enough to legally respond to government requests by saying "we don't have a way to access the data". Hacking customers' phones, regardless of how easy it might be, is far beyond the scope of anything that a US court can order a private party to do.

> is far beyond the scope of anything that a US court can order a private party to do.

They could order Apple to disclose signing keys so that the government can install spyware themselves. See http://en.wikipedia.org/wiki/Lavabit#Suspension_and_gag_orde... for a case where they have done something similar before.

Re: Apple – Privacy – Government Information Requests

#117
post #101

Earlier quoted context omitted.

Is this directed at me? I'm not outraged at Apple at all, I think they're trying to play the long game here. I'm just sick of the word games, deception, and legalese from anyone regarding privacy. It's hard enough fully understanding exactly how all the pieces fit together (technology, laws, politics, etc.) for people that are genuinely interested in this, let alone the average consumer. Pointing out loopholes in wor…

Well, I think whatever Apple says, you will find a "loophole" in the wording that supposedly allows them to do evil things. Try it: pretend you are Apple and just try writing a statement that you would consider acceptable and that you wouldn't call "word games, deception and legalese". Myself, I think they did fairly well, certainly the best of any tech company out there today.

> Try it: pretend you are Apple and just try writing a statement that you would consider acceptable and that you wouldn't call "word games, deception and legalese".

Ok. "We're enabling custom encryption key management. You may now generate and use your own encryption keys. In addition to ensuring the device data is encrypted, nothing in your iCloud account can be recovered if you lose your key because it is all pre-encrypted before being sent to iCloud. Again, if you lose your key, there is no recovery possible. We'll also be opening up a new bug-bounty program specifically for identifying weaknesses and exploits in our baseband, firmware, and OS that could result in the leaking of your encryption keys and personal data. Here at Apple, we take your privacy serious."

Re: Apple – Privacy – Government Information Requests

#118

Earlier quoted context omitted.

Of course they can. All you have to do is leak passwords/private keys. An OS is actually much more powerful, it controls everything, it has direct access to memory. If a user can see his photo, the OS can.

> Not if they designed it properly. You can (and always should) design encryption code without having a single root key. Entirely open sourcing that code should not make any difference to the security of the encrypted data.

And then NSA forces Apple I to issue the OS update that breaks all your efforts.

Re: Apple – Privacy – Government Information Requests

#119

Earlier quoted context omitted.

I think people are outraged at both. With the companies in question, it's not hard to vote with your feet and complain. With the government, it's very difficult.

You get the government you vote for.

No, that's not how it works. You get the most heavily marketed party that pissed the least number of people off in the last couple of years.

Re: Apple – Privacy – Government Information Requests

#120

"On devices running iOS 8, your personal data such as photos, messages (including attachments), email, contacts, call history, iTunes content, notes, and reminders is placed under the protection of your passcode. Unlike our competitors, Apple cannot bypass your passcode and therefore cannot access this data" This is key. The way we engineer software and services can have a major impact on the war against overly invas…

Aren't all these data backed up to iCloud? Is it also protected with a passcode?
Post reply on HN