Live data from Hacker News

Apple will notify users about state-sponsored cybersecurity threats

support.apple.com

141–150 of 166 posts

Re: Apple will notify users about state-sponsored cybersecurity threats

#141
post #75
post #73

Earlier quoted context omitted.

iMessage is extremely secure and utilizes end-to-end encryption, why is this concerning to you?

And it has spam problems: https://www.wired.com/2014/08/apples-imessage-is-being-taken... The problem is authenticity and authority, not encryption. How can the user know this message really came from Apple and not a spammer?

Yes thank you. this was the concern i was trying - seems like failed - to express.

There was even an article on HN a couple days ago about a money transfer service phishing scam whose initial message looks very similar to this message from Apple.

I think a LOT of people will fall for phishing with cold messages that look like this

Re: Apple will notify users about state-sponsored cybersecurity threats

#142

Earlier quoted context omitted.

Not anymore[*]. [*] If you enable "Messages" sync in iCloud, encrypted message history is synced across your iCloud devices in an E2E manner.

An important caveat. If the messages are backed up to iCloud then they are not en encrypted. Apple may encrypt iCloud backups, but they hold the key and can turn the data over to the law enforcement. Syncing messages across your devices is very much different than backing up your iPhone to iCloud. The above should be pretty well known by now, but unfortunately isn’t the case. If someone wants to dispute my comment, p…

You are correct. I was confused because since the “Messages for iCloud” was introduced, the backup itself won’t include plaintext message data if that feature is enabled (unlike before). However, this is where I stand corrected: it seems they store a copy of the Messages for iCloud encryption key in your iCloud Backup, if you have enabled iCloud Backup, which effectively defeats that encryption. The solution seems to be keep message sync on and backups off.

“For Messages in iCloud, if you have iCloud Backup turned on, your backup includes a copy of the key protecting your messages. This ensures you can recover your messages if you lose access to your Keychain and your trusted devices. When you turn off iCloud Backup, a new key is generated on your device to protect future messages and isn't stored by Apple.”[1]

[1]: https://support.apple.com/en-us/HT202303

Re: Apple will notify users about state-sponsored cybersecurity threats

#143

Earlier quoted context omitted.

Can you provide citation for this? Also how they are different from any other tech company? My MacBooks security keys are not trivial to acquire because they aren’t in icloud. In some of the countries in five eyes nations, you don’t have a choice about cooperating or not. But what do 5 eyes have to do with Chinese users?

You shouldn't argue with @smoldesu, he has a history of trying to troll and spread FUD about Apple at every possible opportunity, even on completely unrelated topics. It's so ridiculous, a complaint about it is the #1 result on Google if you type "smoldesu" in. They also are not typically the most factual of complaints but they aren't interested in corrections. Beats me why the mods haven't sent warnings.

I mean with a "lolicon"-sounding name like "smoldesu" let's all hope hating on Apple as a substitute for his father is the worst thing about him...

Re: Apple will notify users about state-sponsored cybersecurity threats

#144

Earlier quoted context omitted.

I shouldn't be arguing with the trolls - but in case anyone was curious about these (nonsense) allegations: Your links do not document cooperation with PRISM other than that the NSA believed they got information from them, which is very different. For all we know, it could have been the NSA abusing an API endpoint. Also, it said that it got lots of stuff like email, address, and so on when all of these services were…

We have known what PRISM is for almost a decade now (since we saw Snowden's slides for it), and it is neither what you nor smoldesu claim it to be. The FBI issues a court order to tap a particular account, and the company complies by forwarding that account's email and messages. Then PRISM ingests that data into NSA databases.

> Then PRISM ingests that data into NSA databases.

And if I'm not mistaken it's illegal for an US business entity to directly say that they are co-operating with the NSA or other such US institutions, so Apple actually sending messages to their users warning them about such co-operation might be also illegal (I also feel that the canary tests have failed their intended mission, nobody has time to decipher those messages in the minutest of details).

Re: Apple will notify users about state-sponsored cybersecurity threats

#145

Earlier quoted context omitted.

> Can you provide citation for this? Apple's cooperation with PRISM[0] is well documented[1], but if you want to find the particularly damning details you'll need to do your own research. The dust has settled since the Snowden revelations, and many mentions of the program have been sterilized. > Also how they are different from any other tech company? It's not. But the claim that Apple puts extra effort into protecti…

I'd like to discuss with you in Good faith. But your points seem to be made in bad faith. PRISM wasn't really a cooperative program, it was a highjacking of the internet backbone wasn't it? Your citation doesn't confirm any kind of cooperation. I didn't really make any claim about Apple doing extra, I was challenging the idea that they some how do worse. They seem to play as fair as you can in the given political env…

> PRISM wasn't really a cooperative program,

Not the OP, but afaik directly saying you're co-operating with the NSA as a US business entity might be illegal, so Apple not saying it doesn't mean they didn't, quite the contrary (especially taking into consideration Snowden's revelations).

Re: Apple will notify users about state-sponsored cybersecurity threats

#146
post #75
post #73

Earlier quoted context omitted.

iMessage is extremely secure and utilizes end-to-end encryption, why is this concerning to you?

And it has spam problems: https://www.wired.com/2014/08/apples-imessage-is-being-taken... The problem is authenticity and authority, not encryption. How can the user know this message really came from Apple and not a spammer?

The use goes to the Apple ID website to confirm. Then they know if the message was genuine.

Re: Apple will notify users about state-sponsored cybersecurity threats

#147
post #43

Earlier quoted context omitted.

I think you need to add a translation of the tweet. Because it sounds as if he didn't obey Apple's warning. Yet I think he approves of Apple's s notification. It is the government who he wasn't obeying? So the government installed the spyware?

It is like polish Watergate: the prosecutor has been criticizing minister Ziobro and already lost her job (not only her, this problem is now on EU table and European trials say polish gov is breaking the law doing this) and now she learned minister Ziobro was spying her (and probably is still doing this)

The problem is that Ziobro was already doing this (illegally wiretapping opposition) together with Kamiński and Kaczyński when they were in power in 00s. They lost power, almost got to jail but avoided it thanks to political calculation of the next party (that used them as "look at least we aren't like them" threat), then they got elected again anyway in 2015.

They have majority support right now because of social spending and their supporters don't care about rule of law, corruption, any of that. There were already dozens of similar-scale scandals since 2015. Nobody cares. It's frustrating, really.

Re: Apple will notify users about state-sponsored cybersecurity threats

#148
post #73

Earlier quoted context omitted.

Is it concerning to any security people with more knowledge than me that this is sent via iMessage?!

iMessage is extremely secure and utilizes end-to-end encryption, why is this concerning to you?

Can we reasonably say any piece of software is extremely secure against state sponsored attacks?

Re: Apple will notify users about state-sponsored cybersecurity threats

#150

Earlier quoted context omitted.

NSA surveillance is illegal. Will we be notified?

Which surveillance? By what ruling? The phone metadata collection was ruled illegal, but that does not affect Apple.

> By what ruling?

https://news.ycombinator.com/item?id=24356741

https://news.ycombinator.com/item?id=24362047

Post reply on HN