Live data from Hacker News

Oura says it gets government demands for user data

this.weekinsecurity.com

161–168 of 168 posts

Re: Oura says it gets government demands for user data

#161

Earlier quoted context omitted.

> Apple literally removed encrypted file storage as a feature in the UK rather than comply with demands for access to encrypted customer data from the UK government. Does that mean that instead of UK government accessing the data (through a backdoor), UK government can now access to data (because it's not encrypted at all)?

They removed a specific (non-default) feature which provided end to end encryption rather than build a backdoor. They continue to offer encrypted backups etc. although they hold the keys. So not great but also not a backdoor that breaks encryption for everyone and can potential be accessed without legal oversight.

To be a bit more clear:

They offer standard encryption by default, where they hold a copy of your encryption key and can assist you if you lose access to your key.

They also allow you to opt into advanced data protection, where they do not have a copy of your encryption key, so you need to be sure you protect it yourself.

If a company has a copy of the customer's encryption key on their server, you have no choice but to hand it over in response to a warrant, as we recently saw with Microsoft handing over the bitlocker key for a customer's computer.

Re: Oura says it gets government demands for user data

#162
post #29

What will the government even do with my heart rate and blood oxygen data? "Mr Smith has been running again, we better bring him in for questioning!" Edit: to be clear, the government is requesting the data, so clearly they're doing something with it... But what? I don't see it!

"I see Mr Smith was running in [street/location] when the explosion occurred - we'd better bring him in for questioning". Maybe the Oura doesn't record that, but if they can match other metadata with Smith's ring it could put him firmly in the frame.

Re: Oura says it gets government demands for user data

#163
post #71

Earlier quoted context omitted.

My understanding is that E2E encryption implies encryption in transit. The message is encrypted at the source and only decrypted at the destination, so it is encrypted everywhere in between.

The term has kind of degraded, because people started marketing that "end-to-end encryption" is the "right" answer. Encryption in transit means that network intermediates can't read the data. The two endpoints of the network communication can. E2E encryption is more context-sensitive, and its context mostly comes from messaging. It means that the data is encrypted and that operational intermediates cannot read it. So…

GP is saying E2E encryption implies encryption in transit, because by definition "in transit" is not an "end".

I would agree with your definition that E2E means "operational intermediates cannot read it", but I would define intermediaries as people/organizations, not as devices. If my phone can read my data from my ring, that's not an intermediary because it's my phone. If a cloud server can read the data, then that is an intermediary because it's not my cloud server.

Re: Oura says it gets government demands for user data

#164
post #159
post #136

Earlier quoted context omitted.

They can read all your emails that are over 6 months old? What are you basing this on? First I've heard of it.

It is well known, just no-one talks about it anymore like NSA, DHS violations, etc. Why do you think she had a personal email server in her basement instead of using a 3rd party? Bill Clinton signed 1986 Electronic Communications Act into law https://en.wikipedia.org/wiki/Electronic_Communications_Priv... Any communication, email, sms, etc. on a 3rd party like Gmail that is 180 days old is cleverly considered "abando…

Wow, that's crazy! Thanks for the link. Seems high time to get off US based e-mail services.

Re: Oura says it gets government demands for user data

#166
post #76

Earlier quoted context omitted.

Not very strange but E2EE is thrown around a lot and everyone interprets it differently. And in some cases the expectations are unrealistic. Take a messenger app using a server as middleman. E2EE means only the 2 users get to see the content, not the middleman company server. For Oura there’s only a user and the company server and a lot of people assume Oura can’t read the data, like the Signal or WhatsApp servers ca…

> everyone interprets it differently. No, they don't. You're spreading misinformation. If the service provider can see the data then it is not E2EE. There is no room for negotiation here. Let me be perfectly clear that any service provider that claims E2EE while having access to user data is committing blatant fraud. That said, it does not appear that Oura ever claimed E2EE. The author is merely making it clear to th…

> No, they don't. You're spreading misinformation.

You can confidently say that everyone is qualified enough and understands E2EE the same way you do? Is it magic or an LLM whispered in your ear?

Because by the nature of my job I talk every 2 days with someone who doesn't really understand what E2EE is, what it does and more importantly what it doesn't do. They learn from marketing materials nit from reading technical info, you know, like almost all users out there.

Re: Oura says it gets government demands for user data

#167

Earlier quoted context omitted.

> everyone interprets it differently. No, they don't. You're spreading misinformation. If the service provider can see the data then it is not E2EE. There is no room for negotiation here. Let me be perfectly clear that any service provider that claims E2EE while having access to user data is committing blatant fraud. That said, it does not appear that Oura ever claimed E2EE. The author is merely making it clear to th…

Agreed. Weird to see a bunch of posts trying to argue that E2E doesn't imply that provider can't see the data, at rest or in transit.

> Weird to see a bunch of posts trying to argue that E2E doesn't imply that provider can't see the data, at rest or in transit.

It's only weird for the people in that middle ground where they know "something" about it, but really not much at all. There are ways to get educated and at least acknowledge the misunderstandings but who has time for that [0].

E2E explicitly means from one end to another. Obviously when the provider is one of the ends, as sender or final recipient of the data, they can have access to the data and not violate the principle of E2EE. When the provider is just an intermediary they should not be able to decrypt the data because they are not one of the ends.

Some companies slap the E2EE sticker on their product even when it's meaningless because it makes the product sound more secure. Like when they were slapping "blockchain" on everything. Or "AI" and "agentic" these days. It means nothing, it's misleading, but not factually wrong.

[0] https://www.researchgate.net/publication/342621891_Improving...

Re: Oura says it gets government demands for user data

#168

Earlier quoted context omitted.

Agreed. Weird to see a bunch of posts trying to argue that E2E doesn't imply that provider can't see the data, at rest or in transit.

> Weird to see a bunch of posts trying to argue that E2E doesn't imply that provider can't see the data, at rest or in transit. It's only weird for the people in that middle ground where they know "something" about it, but really not much at all. There are ways to get educated and at least acknowledge the misunderstandings but who has time for that [0]. E2E explicitly means from one end to another. Obviously when the…

No, again, that is misinformation on your part. By your own logic every https connection qualifies as E2EE by virtue of traversing untrusted intermediaries as it crosses the public internet.

That obviously makes no sense as it renders the term entirely pointless. The entire reason for the term to exist is the difference from encryption in transit. It specifically means that one or more of the intended recipients (generally the service provider) do not have default access to the data.

The "meaningless" usage you describe is fraud seeing as it's an intentional attempt to deceive the consumer. It is factually wrong in the exact same way that slapping an open source label on something made available on github under a proprietary license is.

Post reply on HN