Live data from Hacker News

iPhones send call history to Apple, security firm says

theintercept.com

11–20 of 85 posts

Re: iPhones send call history to Apple, security firm says

#12
post #9

> Apple's Reply: >> Device data is encrypted with a user’s passcode, and access to iCloud data including backups requires the user’s Apple ID and password. Can't Apple ID password be reset? If so, how can it be a true encryption?

> Device data is encrypted with a user’s passcode

I think it uses the passcode you set on your phone, not the password of your iCloud account.

Re: iPhones send call history to Apple, security firm says

#13
post #12
post #9

> Apple's Reply: >> Device data is encrypted with a user’s passcode, and access to iCloud data including backups requires the user’s Apple ID and password. Can't Apple ID password be reset? If so, how can it be a true encryption?

> Device data is encrypted with a user’s passcode I think it uses the passcode you set on your phone, not the password of your iCloud account.

> I think it uses the passcode you set on your phone, not the password of your iCloud account.

May be true, but

> access to iCloud data including backups requires the user’s Apple ID and password.

probably doesn't requires the passcode that the user have set, because this data is available across several devices, and the only common thing would be the Apple ID and its password.

Re: iPhones send call history to Apple, security firm says

#14
post #13
post #12

Earlier quoted context omitted.

> Device data is encrypted with a user’s passcode I think it uses the passcode you set on your phone, not the password of your iCloud account.

> I think it uses the passcode you set on your phone, not the password of your iCloud account. May be true, but > access to iCloud data including backups requires the user’s Apple ID and password. probably doesn't requires the passcode that the user have set, because this data is available across several devices, and the only common thing would be the Apple ID and its password.

If you've recently set up iOS devices you'll have seen it ask for the passcode for another device before you can access iCloud data on the new one.

Re: iPhones send call history to Apple, security firm says

#15

i'm still using my trusty motorolla razr

If you're not joking, I'm curious how long the battery lasts nowadays. Has it significantly declined since you first got it?

It has one of those old-fashioned replaceable batteries, so he could always just buy a new one if it goes downhill.

Re: iPhones send call history to Apple, security firm says

#16
post #7

Earlier quoted context omitted.

I feel like "sync" is an iCloud feature.

It is, but they are talking specifically about iCloud's backup feature being switched off, not iCloud itself. Syncing is not the same as backup.

Yup, this is exactly it. Even with backup turned off you can answers calls from your Mac/iPad... Why is this surprising?

Re: iPhones send call history to Apple, security firm says

#17
post #9

> Apple's Reply: >> Device data is encrypted with a user’s passcode, and access to iCloud data including backups requires the user’s Apple ID and password. Can't Apple ID password be reset? If so, how can it be a true encryption?

I don't know whether they do, but the data still is on your device, so if you change your password, your phone can overwrite the version in the cloud with a newly encrypted one.

Using Apple ID and password is (for the typical user) fairly weak encryption, though. That could be improved by having your devices exchange encryption keys.

Re: iPhones send call history to Apple, security firm says

#18

i'm still using my trusty motorolla razr

If you're not joking, I'm curious how long the battery lasts nowadays. Has it significantly declined since you first got it?

If he's referring the flip phone, and not the Droid Razr, then we're talking about a phone that had a standby time measured in weeks. At best it lasts probably 10x longer than today's smartphones so even a 75% reduction in battery life is still better than what we deal with today.

Re: iPhones send call history to Apple, security firm says

#19
Note to media companies (and everyone else) talking about security: You have to put security elements in context to say anything reasonable

That means both: 1) Consider your audience, and 2) Do a 'risk analysis' (Meaning figure out where the security issue starts to outweigh the convenience and describe the actual impact of the issue.)

This article (and Forbes') are both severely damaged by a failure to do either. Without stating the contexts where this call logging is a problem, and who it is likely to affect you end up writing alarmist nonsense- especially when the audience is the general public.

Post reply on HN