Live data from Hacker News

Apple dropped plan for encrypting backups after FBI complained

reuters.com

111–120 of 734 posts

Re: Apple dropped plan for encrypting backups after FBI complained

#111

Beyond HN and tech circles, is there any detectable groundswell of demand for privacy? When you talk with friends & family about privacy, does anyone care? When average people care about privacy, the large players will respond. Until then, pressure from the state can be accommodated without irking customers, so Big Tech will play along.

There's this popular conception that the average person doesn't care about privacy, but I think that's wrong. I just think that to really get a handle on what it means to be private in the modern digital age is too complicated for the average person. People are concerned but feel overwhelmed by the technical details and don't know where to start. You need to know the fundamentals of encryption, what a key is, backdoors, the difference between E2E and non-E2E, and so on. We, as the tech community, need to do a better job communicating and explaining.

Re: Apple dropped plan for encrypting backups after FBI complained

#112

Beyond HN and tech circles, is there any detectable groundswell of demand for privacy? When you talk with friends & family about privacy, does anyone care? When average people care about privacy, the large players will respond. Until then, pressure from the state can be accommodated without irking customers, so Big Tech will play along.

Obviously there is. Otherwise it wouldn't be advertised on billboards and television.

Privacy is just like your personal health everyone wants a convenient solution but no company can honestly offer it. (Doesn't stop then from pretending they do)

Re: Apple dropped plan for encrypting backups after FBI complained

#114
post #74

Earlier quoted context omitted.

"Apple is intentionally leaving iCloud data insecure" ... if you'd done some research you would know that iCloud backups are not end-to-end encrypted. That means you have a choice: backup to iCloud for the convenience and give up some privacy, or turn off the iCloud backup. It would be nice if Apple was more forthcoming with that fact but there is some onus on the customer these days to understand what's private and…

Please see "iCloud security overview", it clearly states which iCloud data is encrypted in transit, on server, and end-to-end: https://support.apple.com/en-us/HT202303

This is from your own link:

“For certain sensitive information, Apple uses end-to-end encryption.”

“These features and their data are transmitted and stored in iCloud using end-to-end encryption:”

* Home data

* Health data (requires iOS 12 or later)

* iCloud Keychain (includes all of your saved accounts and passwords)

* Payment information

* QuickType Keyboard learned vocabulary (requires iOS 11 or later)

* Screen Time

* Siri information

* Wi-Fi passwords

Re: Apple dropped plan for encrypting backups after FBI complained

#115
post #107

Beyond HN and tech circles, is there any detectable groundswell of demand for privacy? When you talk with friends & family about privacy, does anyone care? When average people care about privacy, the large players will respond. Until then, pressure from the state can be accommodated without irking customers, so Big Tech will play along.

General public are generally ignorant about risks in the tech they use. That doesn't mean they don't care about their privacy. There's an assumption that laws and safeguards are in place so technology in general can be trusted and transacted on. In other words they trust in us "the tech circle" to police ourselves and assert security and privacy. It's not circle jerk about privacy. It's a duty we have by being in the…

Exactly. The general public is never going to say “I demand end to end encryption and complete privacy” because they don’t know how all the tech works. But they’re surely going to expect that their private text messages are private and their private pictures are private. People expect privacy as a default and sharing as an option, and they rely on the “experts” (tech companies, lawmakers, etc) to help them.

Re: Apple dropped plan for encrypting backups after FBI complained

#116
post #71

Earlier quoted context omitted.

"Apple is intentionally leaving iCloud data insecure" ... if you'd done some research you would know that iCloud backups are not end-to-end encrypted. That means you have a choice: backup to iCloud for the convenience and give up some privacy, or turn off the iCloud backup. It would be nice if Apple was more forthcoming with that fact but there is some onus on the customer these days to understand what's private and…

Doesn’t that page show everything as end-to-end encrypted, except email messages on the server? If “backup”, photos, messages, contacts, calendars, iCloud Drive, notes, and safari data (and a few more) are end-to-end encrypted what else is there?

I don't think you are reading the list right. That is all the stuff that is encrypted both at-rest and in-transit (with keys known to Apple).

The list of E2E is further down, separate from the table, and includes: Home data, Health data (requires iOS 12 or later), iCloud Keychain (includes all of your saved accounts and passwords), payment information, QuickType Keyboard learned vocabulary (requires iOS 11 or later), Screen Time, Siri information, and Wi-Fi passwords. So virtually nothing, by comparison.

Messages, probably the most personal and relevant for legal cases, are end-to-end-encrypted as well, but if you have iCloud Backup enabled, the key is stored in the backup, making this useless.

Re: Apple dropped plan for encrypting backups after FBI complained

#117
post #52

Earlier quoted context omitted.

Second step: Delete old backups https://support.apple.com/en-us/HT204247#backups

Eh, maybe, maybe not. What guarantees are there that the backups actually get deleted? Storage is cheap these days...

In the EU, big tech companies actually delete your data within a short period of you clicking the delete button because they're scared of the GDPR requirements.

Outside the EU, small companies, or non-tech companies might we'll keep it forever.

Re: Apple dropped plan for encrypting backups after FBI complained

#118
Between things like this, and the shenanigans Google pulls (with Android, the store, developers, and other things), I'm quickly going in a different direction.

My ultimate plan is to build my own phone; yes, I'll still be stuck with a carrier (I use t-mobile, and I haven't had a problem with them over 10+ years I've used them), and the hardware won't be completely "open source", but the software and OS will at least be what I make of it myself.

In the meantime, I'll be playing with one of the Pine64 phones; hopefully it will give me most if not all of everything I want and need, and maybe I can help with bug testing or perhaps software development? At any rate, it won't be Apple or Google.

There are times that I have when I sometimes think to myself that going back to simple email on a text screen, and not much else, would be a better thing than what the web has become. Maybe go back to BBS's over ssh or something? "Dial In" using my TRS-80 Model 100 "laptop" and move out to the boonies...

Re: Apple dropped plan for encrypting backups after FBI complained

#119

What the... I was under the impression that iCloud backups are end-to-end encrypted. This is a HUGE problem.

You ever read the reviews for the MEGA app? Everyone complains that there's no password reset feature. MEGA is fully encrypted so you literally can't reset your password. It says this when you first crate an account and get a recovery key. I don't think the general public would understand end-to-end encrypted backups. It would probably hurt their company if all backups were totally unrecoverable.

> I don't think the general public would understand end-to-end encrypted backups.

I imagine you're right; it would still be nice for individuals and organizations to have the _option_ though.

Re: Apple dropped plan for encrypting backups after FBI complained

#120

Earlier quoted context omitted.

iPhone/iPad backups stored locally on iTunes (or Finder, in Catalina) are end-to-end encrypted. iCloud backups always were encrypted based on a key derived from your iCloud account credentials, since the beginning...

Do they happen re-encrypt if I change my credentials a bunch of times or do they use my first ever password which was 123456?

The local backups are encrypted with a key separate from your iPhone passcode. You can change it in iTunes, not sure if it re-encrypts or not.

But of course, we are talking about local backups so if you have full-disk encryption or back them up to an encrypted virtual drive, you don't even need whatever encryption comes with them.

Post reply on HN