Live data from Hacker News

Apple pulls data protection tool after UK government security row

bbc.com

261–270 of 1001 posts

Re: Apple pulls data protection tool after UK government security row

#261

Earlier quoted context omitted.

Because that’s working so well for the US

it's working really well, we don't get arrested for social media posts as far as I can tell

https://www.justice.gov/usao-edny/pr/social-media-influencer...

https://www.bbc.co.uk/news/articles/c86l4p583y6o

https://www.aljazeera.com/news/2021/1/19/holdindigenous-man-...

Yes you do

Re: Apple pulls data protection tool after UK government security row

#262

Earlier quoted context omitted.

That's why it's important to use apps like Signal where you can set the retention of your messages. I've got everybody I know using it now!

Setting a retention time out is playing with fire. If the police get ahold of the other party's device, and present an exhibit which they say contains the true conversation, you could be worse off than if you retained the conversation. The fact that you have since deleted it could be incriminating. In some jurisdiction, yes, legally, such evidence might not be probative, but you might still convicted because of it.

message retention has literally NEVER been used as incrimination in a court of law. So you are wrong.

Re: Apple pulls data protection tool after UK government security row

#263

I have a naive question, and it's genuine curiosity, not a defence of what's happening here. This ADP feature has only existed for a couple of years, right? I understand people are mad that it's now gone, but why weren't people mad _before_ it existed? For like, a decade? Why do people treat iCloud as immediately dangerous now, if they didn't before? Did they think it was fully encrypted when it wasn't? Did people no…

I think it is more about going backwards. It is often difficult to remove laws than to add them. This is a similar situation.

In this situation, I agree that it is bad day for personal privacy/security

Re: Apple pulls data protection tool after UK government security row

#264

Earlier quoted context omitted.

Small arms are no match for drones and a fully armed military, a successful rebellion by any populace against a first world military is impossible unless the military lays their arms down voluntarily, full stop.

Rebels are able to use techniques that a government never could or would. I think you underestimate the usefulness of small arms in guerilla warfare.

You underestimate the nasty things goverments have done.

Re: Apple pulls data protection tool after UK government security row

#265

I have a naive question, and it's genuine curiosity, not a defence of what's happening here. This ADP feature has only existed for a couple of years, right? I understand people are mad that it's now gone, but why weren't people mad _before_ it existed? For like, a decade? Why do people treat iCloud as immediately dangerous now, if they didn't before? Did they think it was fully encrypted when it wasn't? Did people no…

Think most people had no idea how it worked, it was magic to them.

iCloud hacks (like in 2014) have raised awareness for the need for E2EE.

Re: Apple pulls data protection tool after UK government security row

#266

I have a naive question, and it's genuine curiosity, not a defence of what's happening here. This ADP feature has only existed for a couple of years, right? I understand people are mad that it's now gone, but why weren't people mad _before_ it existed? For like, a decade? Why do people treat iCloud as immediately dangerous now, if they didn't before? Did they think it was fully encrypted when it wasn't? Did people no…

I guess I'm one of the people who was upset that it didn't exist before, and I didn't enable iCloud Backup as a result. I didn't use iCloud Photos. I had everything stored on a NAS (which was in-fact encrypted properly) and used a rube goldberg-esque setup to move data to it periodically. I used iMazing and local encrypted backups on a schedule.

Lots of people called for E2EE on this stuff, but let's be real about one thing: encryption as a feature being more accessible means more people can be exposed to it. Not everyone can afford a rube goldberg machine to backup their data to a NAS and not make it easily lost if that NAS dies or loses power. It takes immense time, skill, and energy to do that.

And my fear isn't the government, either, mind you. I simply don't trust any cloud service provider to not be hacked or compromised (e.g., due to software vulnerability, like log4j) on a relatively long timescale. It's a pain to think about software security in that context.

For me, ADP solves this and enables a lot of people who wouldn't otherwise be protected from cloud-based attacks to be protected. Sure, protection against crazy stuff like government requests is a bonus, but we've seen with Salt Typhoon that any backdoor can be found and exploited. We've seen major exploits in embedded software (log4j) that turn out to break massive providers.

So, there were people upset, their concerns were definitely voiced on independent blogs and random publications, and now, we're back in the limelight because of the removal of the feature for people in the UK.

But, speaking as a user of ADP outside of the UK, I am happy that ADP is standing up for it, and thankful that it exists.

(To be clear: government backdoors, and government requests also scare me, but they aren't a direct threat to myself as much as a vulnerability that enables all user data to be viewed or downloaded by a random third-party).

Re: Apple pulls data protection tool after UK government security row

#269

Earlier quoted context omitted.

I'm guessing this is because they haven't figured out a way to do it yet. I'm not very well versed in how these systems work but surely this type of encryption can't be disabled by Apple remotely (or they would have that backdoor they don't want)?

The Bloomberg article has a little more detail about this: > Customers already using Advanced Data Protection, or ADP, will need to manually disable it during an unspecified grace period to keep their iCloud accounts. The company said it will issue additional guidance in the future to affected users and that it does not have the ability to automatically disable it on their behalf.

The “grace period” will also function nicely as a period of time for UK citizens to shout at their government representatives about this.

Re: Apple pulls data protection tool after UK government security row

#270

Earlier quoted context omitted.

This was Brexits doing. As we are no longer EU, we have our own cool rules such as the upcoming PM allowed to watch me take a piss law.

The EU is currently planning exactly the same thing with Chat Control.

What EU is planning with chat control is much worse. The UK still requires a warrant to access your iCloud data. EU wants to force companies to install spyware on your devices that will monitor whatever you send or receive in real time without any probable cause or suspicion.
Post reply on HN