Live data from Hacker News

U.K. orders Apple to let it spy on users’ encrypted accounts

washingtonpost.com

161–170 of 1001 posts

Re: U.K. orders Apple to let it spy on users’ encrypted accounts

#161
post #155
post #113

UK tech laws seem to consistently be the worst of both worlds. Not rights centric like the EU and not business supportive like the US. Just old people making bad laws about stuff they don't understand - or are straight up citizen hostile, sometimes hard to tell which it is.

> Not rights centric like the EU Sadly, the EU is trying very hard and very persistently to pass the Chat Control bill. So far the EU hasn't succeeded, but I would be surprised if EU politicians didn't keep trying until it is finally codified into law.

There's always competing interests, but I like to look at it as a glass half full. It's the focus on rights that has ensured it's still not passed.

Re: U.K. orders Apple to let it spy on users’ encrypted accounts

#162

Earlier quoted context omitted.

One side wants to purge large parts of the population and the other one doesn't. Yes, all parties can abuse data, but their policies do actually matter.

I think if you value privacy this isn't the right place to be making distinctions between parties. This only serves to alienate people and isn't the core argument. I think it's more likely to get broad support when framed as us vs. them where "us" is normal working people regardless of political affiliation and "them" is our government elites trying to spy on us.

No, sorry, I've read too much history to buy into this line of reasoning. Authoritarians are a concrete threat to people's safety and they have a long history of abusing sensitive information about people to do so.

Re: U.K. orders Apple to let it spy on users’ encrypted accounts

#163
post #115
post #89

> When asked by The Post whether any government had requested a backdoor, Google spokesman Ed Fernandez did not provide a direct answer but suggested none exist: "Google cannot access Android end-to-end encrypted backup data, even with a legal order," he stated. No, that does not suggest none exists, it only says they don’t have access to it. They could have chosen or have been ordered to give the keys to the governm…

Before people immediately think the worst of Google or other corporate representatives, be aware that people working in these companies need to weight their words carefully. From The Verge's article on the issue: The UK has reportedly served Apple a document called a technical capability notice. It’s a criminal offense to even reveal that the government has made a demand. Similarly, if Apple did cede to the UK’s dema…

[dead]

Re: U.K. orders Apple to let it spy on users’ encrypted accounts

#164
It will be interesting to see if Apple will follow up on comments they made when this change was first floated, and remove effected services from the UK.

> Apple says it will remove services such as FaceTime and iMessage from the UK rather than weaken security if new proposals are made law and acted upon.

https://www.bbc.com/news/technology-66256081

Re: U.K. orders Apple to let it spy on users’ encrypted accounts

#165

Earlier quoted context omitted.

I think if you value privacy this isn't the right place to be making distinctions between parties. This only serves to alienate people and isn't the core argument. I think it's more likely to get broad support when framed as us vs. them where "us" is normal working people regardless of political affiliation and "them" is our government elites trying to spy on us.

No, sorry, I've read too much history to buy into this line of reasoning. Authoritarians are a concrete threat to people's safety and they have a long history of abusing sensitive information about people to do so.

I think maybe we're talking past each other. I'm saying that when advocating for privacy, an effective framing (if winning privacy rights battles is the goal) is to make it "us" vs. "them" instead of some kind of party based push.

If it's associated too strongly with a specific party it alienates too many people to ever get mass support and become a fundamental value that "everyone" agrees on

Re: U.K. orders Apple to let it spy on users’ encrypted accounts

#166
post #142

Earlier quoted context omitted.

It depends on whether other countries make or enforce conflicting laws. The UK order says they can't tell people after implementing the backdoor that Advanced Data Protection no longer provides the claimed level of security, which is a form of dishonesty that probably violates consumer protection laws in many countries. And Apple argued to the UK Parliament when the relevant law was being enacted that it violates the…

> The UK doesn't have the geopolitical clout it once did, especially not after Brexit. Aye. But (1) I don't think the UK government really understands that, and (2) for intelligence operations, they might still have enough . Everyone else has the exact same dichotomy of simultaneously wanting all the computers safe from other hackers while also hacking everything themselves, and many also want the added extra of guar…

Sure. But if one country (or one group of countries) legally requires Apple to do this worldwide and another country (or group of countries) legally forbids Apple to do this even within their own national borders, then Apple has to decide which country (or group of countries) it cares more about. It's not obvious to me how that would shake out, but the UK certainly can't assume it would like Apple's decision there, especially since seeming to care about privacy is an important part of Apple's marketing brand.

Re: U.K. orders Apple to let it spy on users’ encrypted accounts

#167
post #89

> When asked by The Post whether any government had requested a backdoor, Google spokesman Ed Fernandez did not provide a direct answer but suggested none exist: "Google cannot access Android end-to-end encrypted backup data, even with a legal order," he stated. No, that does not suggest none exists, it only says they don’t have access to it. They could have chosen or have been ordered to give the keys to the governm…

[deleted]

Re: U.K. orders Apple to let it spy on users’ encrypted accounts

#168

Question: Would it be technically feasible to make an Apple app which encrypts/decrypts the files used in iCloud and is able to use iCloud itself? As a solution to never have unencrypted files in iCloud.

My gf doesn't have iCloud. She makes a backup from time to time by connecting her iphone to her macbook, encrypts the backup folder with 7z, and then I store the resulting file in my dropbox.

I follow the same procedure with my Android phone, no google cloud.

BTW anything I upload to Dropbox is encrypted first.

Re: U.K. orders Apple to let it spy on users’ encrypted accounts

#169
post #89

> When asked by The Post whether any government had requested a backdoor, Google spokesman Ed Fernandez did not provide a direct answer but suggested none exist: "Google cannot access Android end-to-end encrypted backup data, even with a legal order," he stated. No, that does not suggest none exists, it only says they don’t have access to it. They could have chosen or have been ordered to give the keys to the governm…

But if they could give a key to the government agency, it wouldn't be end-to-end encrypted, right? Or are you thinking they would have a copy of users' keys that they gave out? (Which I guess is technically possible.)

If the other end is the government, then it's kinda valid? =)

Re: U.K. orders Apple to let it spy on users’ encrypted accounts

#170
post #90

Earlier quoted context omitted.

Apple still has legal entities in the UK. Pulling out cloud services would be insufficient to prevent the UK authorities from interfering with their activities.

> prevent the UK authorities from interfering with their activities I'm still missing how this could be enforced ? To my layman understanding, this reads the same as if China said : "Meta, Tesla, Valve etc has entities in China therefore we get to see all data they store in the EU and the US. The UK has Zero jurisdiction in Ireland for example where a lot of EU data may be stored.

> I'm still missing how this could be enforced ?

Basically by saying that if they don't comply, they can't do business in the UK.

Post reply on HN