Live data from Hacker News

UK backing down on Apple encryption backdoor after pressure from US

arstechnica.com

151–160 of 438 posts

Re: UK backing down on Apple encryption backdoor after pressure from US

#151

Earlier quoted context omitted.

The UK AI bill included a proposal to create an AI authority, forcing third party to align with their approaches to AI. They've been looking to use AI for consumer surveillance; AI user monitoring essentially. "We can't have a backdoor so we can't use AI to monitor the user"

AI and encryption are technically orthogonal. But they’ll use any guise to further their agenda.

They’re closely related for some use cases, like client-side content screening. If they can’t have a backdoor then maybe they’ll push for a local LLM to spy on the user’s activity and phone home when it sees something bad.

Re: UK backing down on Apple encryption backdoor after pressure from US

#152
post #25

Earlier quoted context omitted.

They are forcefully pushing for whatever the position of US companies is in conflicts between US companies and EU regulators. The position of the US executive on encryption is well summarized by the Lavabit case.

The U.S. also attempted to force Apple to add a back door just a decade ago. > Tim Cook, the C.E.O. of Apple, which has been ordered to help the F.B.I. get into the cell phone of the San Bernardino shooters, wrote in an angry open letter this week that "the U.S. government has asked us for something we simply do not have, and something we consider too dangerous to create." The second part of that formulation has righ…

The US succeeded, according to American lawmakers: https://arstechnica.com/tech-policy/2023/12/apple-admits-to-...

  Apple has since confirmed in a statement provided to Ars that the US federal government "prohibited" the company "from sharing any information," but now that Wyden has outed the feds, Apple has updated its transparency reporting and will "detail these kinds of requests" in a separate section on push notifications in its next report.
Apple's hidden at least one warrantless backdoor in their systems for the purpose of federal surveillance. I have no reason to believe the exploitation stops there.

Re: UK backing down on Apple encryption backdoor after pressure from US

#153

Earlier quoted context omitted.

The EU is not going to build its own Google, Facebook, Apple, Microsoft, AWS etc. Anytime the lack of “influential European tech companies” come up, the best anyone can do is money losing/barely profitable Spotify. And the data doesn’t back your idea up that Europe is moving away from any of those companies. The EU is moving its dependence away from the US military industrial complex admittedly.

I guess not no, but we don't need those, really. We definitely don't want carbon copies of those companies because they are causing a lot of what's wrong with this world. What we need is more ethical companies that understand the EU market. No paying with our data, no manipulative algorithms. We've been pushing for that for years but Trump has been the turning point, now people are really on board with the idea that…

I agree that no one needs Facebook and if it disappeared off of the face of the earth, nothing of value would be lost.

And even a simplified version of AWS shouldn’t be impossible to build that’s “good enough” [1] or another search engine that’s good enough (Google) and Google search sucks these days anyway.

But Europe is not going to be able to replicate the ecosystem of Android like China did and definitely not Apple on the high end or MS for operating systems.

[1] before anyone replies that I don’t understand the complexity of AWS, I have been working with AWS technologies exclusively for over 7 years including a former 3+ year stint at AWS.

Re: UK backing down on Apple encryption backdoor after pressure from US

#154
post #102

> Apple did not respond to a request for comment. “We have never built a back door or master key to any of our products, and we never will,” Apple said in February. This must be some "technically correct" weasel words bullcrap, as without at least equivalent access there is no chance Apple would be operating in China.

I mean they just disabled advanced data protection which allowed normal law enforcement requests to access the data since they are not e2e encrypted if you don't use advanced data protection. I really don't think they needed to implement a new backdoor. They would just need implement a procedure that would fast track UK requests.

Re: UK backing down on Apple encryption backdoor after pressure from US

#155

Earlier quoted context omitted.

To point out that your data isn't safe from law enforcement. Quite the contrary. I think everyone should be aware of the state we are in. And while I can't go into detail about how I know, I want others to be aware that anything on their devices is fair game. Now a day's with or without a warrant. Three letter agencies are operating with impunity. Using this very tech.

Again - extraordinary claims require extraordinary evidence. It's no secret that there are groups actively looking for new exploits and that sometimes vulnerabilities are discovered that become zero days. It's a good bet that police and security services take an active interest in those vulnerabilities when they are found. But that's very different to claiming the police can easily unlock any device any time they wan…

It's not extraordinary at all. Ron Wyden, a US Senator subject to special briefings, basically repeated the same thing when asked about federal backdoors:

  "As with all of the other information these companies store for or about their users, because Apple and Google deliver push notification data, they can be secretly compelled by governments to hand over this information," Wyden wrote.
https://arstechnica.com/tech-policy/2023/12/apple-admits-to-...

Re: UK backing down on Apple encryption backdoor after pressure from US

#156
post #4

I really sort of expected that by the time I reached my age that we'd have more policy makers that understood tech a little better. I feel like in the last say 25 or more years ... the needle hasn't moved.

I mean, yes many policymakers still struggle with the nuances of modern tech, but claiming that "the needle hasn't moved" in 25 years is an exaggeration. In the late 90s/early 2000s, encryption debates featured lawmakers who barely understood email. Since then, there are committees focused specifically on tech policy, even some lawmakers with backgrounds in CS or cybersecurity... and far more nuanced public debates about encryption, surveillance, and privacy.

I recently listened to some clips from a hearing with questions about zero-knowledge proofs, algorithmic transparency, etc...this was pretty unthinkable two decades ago. Some agencies and legislative bodies also now have technical staffers and some advisory boards with technologists. So, yeah it it slow and sometimes frustrating, but it's not static.

Re: UK backing down on Apple encryption backdoor after pressure from US

#157

Earlier quoted context omitted.

It's a lot easier now because there's a huge demand all of a sudden for local services. Previously it was hard to compete with the US because the lack of regulation there and investors in the EU having more expectations rather than just throwing money at the wall and hoping it sticks. But with the exploitative business models like Google's consumer tracking and now with Trump and his trade wars the US is no longer vi…

After the local EU services/products all have Brussels Mandated encryption back-doors and permit free decrypting of your private data, I will bet there will be a surge back to non-EU services. https://www.bankinfosecurity.com/eu-pushes-for-backdoors-in-...

I mean a lot of EU would prefer EU backed backdoor to US backed backdoor. EU backed backdoor still sucks but I don't get this argument

Re: UK backing down on Apple encryption backdoor after pressure from US

#158

Earlier quoted context omitted.

The UK AI bill included a proposal to create an AI authority, forcing third party to align with their approaches to AI. They've been looking to use AI for consumer surveillance; AI user monitoring essentially. "We can't have a backdoor so we can't use AI to monitor the user"

AI and encryption are technically orthogonal. But they’ll use any guise to further their agenda.

[deleted]

Re: UK backing down on Apple encryption backdoor after pressure from US

#159

Earlier quoted context omitted.

I guess not no, but we don't need those, really. We definitely don't want carbon copies of those companies because they are causing a lot of what's wrong with this world. What we need is more ethical companies that understand the EU market. No paying with our data, no manipulative algorithms. We've been pushing for that for years but Trump has been the turning point, now people are really on board with the idea that…

I agree that no one needs Facebook and if it disappeared off of the face of the earth, nothing of value would be lost. And even a simplified version of AWS shouldn’t be impossible to build that’s “good enough” [1] or another search engine that’s good enough (Google) and Google search sucks these days anyway. But Europe is not going to be able to replicate the ecosystem of Android like China did and definitely not App…

What I am wondering is if the complexity of AWS is required for 99 percentile. There are a lot of niche services and duplicated ones on AWS and a targeted replacement for the most popular ones would be enough for most.

Re: UK backing down on Apple encryption backdoor after pressure from US

#160
I’m struggling to square Vance and the administration’s position here with the fact that the US IC uses GCHQ to collect on US persons since they’re not allowed to do so directly. Why wouldn’t they want it to be easier for NSA to spy on Americans?
Post reply on HN