Live data from Hacker News

Apple pulls data protection tool after UK government security row

bbc.com

241–250 of 1001 posts

Re: Apple pulls data protection tool after UK government security row

#241
post #154

Earlier quoted context omitted.

How? In the UK, there's no right to bear arms, so people are pretty helpless against their oppressing government.

Weird. In the US there is a right to bear arms, yet people are also pretty helpless against their oppressing government.

Who do you know that's been arrested for posting on social media? I don't know of anyone.

Re: Apple pulls data protection tool after UK government security row

#242

The nightmare continues. For now I am using 3rd party backup services that are (currently) promising me that my backups are encrypted by a key they do not have access to, or control over. But can this even be believed in an age where these secret notices are being served to any number of companies? I suppose the next step would be to ensure that files don't ever arrive in the cloud unencrypted, but I have yet to see…

security and convenience are ever at war.

Re: Apple pulls data protection tool after UK government security row

#244
post #106

Too right, it was far more problematic than they ever made out. > The UK government's demand came through a "technical capability notice" under the Investigatory Powers Act (IPA), requiring Apple to create a backdoor that would allow British security officials to access encrypted user data globally. The order would have compromised Apple's Advanced Data Protection feature, which provides end-to-end encryption for iCl…

Feels like marvel was onto something with captain america and winter soldier.

The real prescient threat in that movie was the predictive AI algorithm that tracked individual behaviors and identified potential threats to the regime. In the movie they had a big airship with guns that would kill them on sight, but a more realistic threat is the AI deciding to feed them individualized propaganda to curtail their behavior. This is the villain's plot in Metal Gear Solid 2, which is another great story.

This got me thinking about MGS2 again and rewatching the colonel's dialogue at the end of the game: https://www.youtube.com/watch?v=eKl6WjfDqYA

> Your persona, experiences, triumphs, and defeats are nothing but byproducts. The real objective was ensuring that we could generate and manipulate them.

It's really brilliant to use a video game to deliver the message of the effectiveness of propaganda. 'Game design' as a concept is just about manipulation and hijacking dopamine responses. I don't think another medium can as effectively demonstrate how systems can manipulate people's behavior.

Re: Apple pulls data protection tool after UK government security row

#245

Earlier quoted context omitted.

That's why it's important to use apps like Signal where you can set the retention of your messages. I've got everybody I know using it now!

Given historical backups are the norm here, retention only does so much. Really, apps should encrypt their own storage with keys that aren't stored in the backups. That's how you get security/privacy back.

Many people want control over whether they back up conversations with others, and think it would be crazy for sender to control the retention policy instead of receiver.

I think sender should just be able to send a recommended preference hint on retention and you could have an option to respect it or not.

Re: Apple pulls data protection tool after UK government security row

#246

Think about it.. You don't even have to be an Apple user to be affected by this issue. If someone backs up their conversations with you to apple cloud, your exchange is now fair game. You get no say in it either. We all lose.

That's why it's important to use apps like Signal where you can set the retention of your messages. I've got everybody I know using it now!

Setting a retention time out is playing with fire. If the police get ahold of the other party's device, and present an exhibit which they say contains the true conversation, you could be worse off than if you retained the conversation. The fact that you have since deleted it could be incriminating.

In some jurisdiction, yes, legally, such evidence might not be probative, but you might still convicted because of it.

Re: Apple pulls data protection tool after UK government security row

#248

Earlier quoted context omitted.

That's why it's important to use apps like Signal where you can set the retention of your messages. I've got everybody I know using it now!

Given historical backups are the norm here, retention only does so much. Really, apps should encrypt their own storage with keys that aren't stored in the backups. That's how you get security/privacy back.

> That's how you get security/privacy back.

Nothing an app does on a device guarantees you security or privacy if you don't trust or fully control the device.

Re: Apple pulls data protection tool after UK government security row

#249
post #106

Too right, it was far more problematic than they ever made out. > The UK government's demand came through a "technical capability notice" under the Investigatory Powers Act (IPA), requiring Apple to create a backdoor that would allow British security officials to access encrypted user data globally. The order would have compromised Apple's Advanced Data Protection feature, which provides end-to-end encryption for iCl…

This is why, while I applaud what Apple is doing here, they need to allow us to supply our own E2E encryption keys.

Re: Apple pulls data protection tool after UK government security row

#250

Earlier quoted context omitted.

> Doesn't the US have access to all the data of non US citizens whose data is stored in the US without any oversight? Er, no...? I'm not sure where you get that idea. Access requires a warrant, and companies are not compelled to build systems which enable them to decrypt all data covered by the warrant. See, for example, the Las Vegas shooter case, where Apple refused to create an iOS build that would bypass iCloud s…

I asked if your Android backup is encrypted. Implies I'm talking about unencrypted data. > See, for example, the Las Vegas shooter case I am not in Las Vegas or anywhere else in the US. So as far as i know all the data about me that is stored in the US is easily accessible without a warrant unless it's encrypted with a key that's not available with the storage. > companies are not compelled to build systems which ena…

This is why Apple, and more recently Google, create systems where they don't have access to your unencrypted data on their servers.

> Google Maps is changing the way it handles your location data. Instead of backing up your data to the cloud, Google will soon store it locally on your device.

https://www.theverge.com/2024/6/5/24172204/google-maps-delet...

You can't be forced to hand over data on your servers that you don't have access to, warrant or no.

The UK wants to make this workaround illegal on an international basis.

Post reply on HN