Live data from Hacker News

Apple pulls data protection tool after UK government security row

bbc.com

281–290 of 1001 posts

Re: Apple pulls data protection tool after UK government security row

#282
post #225

Note that this doesn’t satisfy the government’s original request, which was for worldwide backdoor access into E2E-encrypted cloud accounts. But I have a more pertinent question: how can you “pull” E2E encryption without data loss? What happens to those that had this enabled? Edit: Part of my concern is that you have to keep in mind Apple's defense against backdooring E2E is the (US) doctrine that work cannot be comp…

We are told the encryption keys reside only on your device. But Apple control “your” device so they can just issue an update that causes your device to decrypt data and upload it.

Apple has already fought US government demands that they push an update that would allow the US governmrnt to break encryption on a user's device.

> In 2015 and 2016, Apple Inc. received and objected to or challenged at least 11 orders issued by United States district courts under the All Writs Act of 1789. Most of these seek to compel Apple "to use its existing capabilities to extract data like contacts, photos and calls from locked iPhones running on operating systems iOS 7 and older" in order to assist in criminal investigations and prosecutions. A few requests, however, involve phones with more extensive security protections, which Apple has no current ability to break. These orders would compel Apple to write new software that would let the government bypass these devices' security and unlock the phones.

https://www.wikipedia.org/wiki/Apple%E2%80%93FBI_encryption_...

Re: Apple pulls data protection tool after UK government security row

#284

I have a naive question, and it's genuine curiosity, not a defence of what's happening here. This ADP feature has only existed for a couple of years, right? I understand people are mad that it's now gone, but why weren't people mad _before_ it existed? For like, a decade? Why do people treat iCloud as immediately dangerous now, if they didn't before? Did they think it was fully encrypted when it wasn't? Did people no…

A few factors

- e2e encryption is not ubiquitous yet, but awareness is ascending.

- distrust for government also is on the uptrend.

- more organized dissent to preserve privacy.

No people didn't assume data was encrypted.

Yes E2E has been possible for many decades, but businesses don't have privacy as a priority, sometimes even counter incentives to protect it. Personal data sells well.

Things have changed because more people are getting to understand why it matters, forcing the hand of companies having to choice but at least feign to secure privacy.

Re: Apple pulls data protection tool after UK government security row

#285
post #52

Why is there only one "iCloud" to backup your iPhone and store photos? Lots of ADP users would use a corporate or self-hosted solution instead.

As far as I know you can still opt to backup your entire iPhone to a local computer instead of iCloud.

You can also manually transfer photos to the computer. Or you can enable a different app (Google Photos or Dropbox for example) to store copies of every picture you take, and then turn off iCloud Photos.

Note that neither Google nor Dropbox are E2E encrypted either though.

Re: Apple pulls data protection tool after UK government security row

#286
post #15

As a citizen, I don’t understand what the UK government thinks they are getting here - other than the possibility of leaks of the nation’s most sensitive data. Also is it not possible to set up my Apple account outside of the UK while living here?

It's for Labour "data analysts" to go through people photos and search for nudes.

Re: Apple pulls data protection tool after UK government security row

#287

The nightmare continues. For now I am using 3rd party backup services that are (currently) promising me that my backups are encrypted by a key they do not have access to, or control over. But can this even be believed in an age where these secret notices are being served to any number of companies? I suppose the next step would be to ensure that files don't ever arrive in the cloud unencrypted, but I have yet to see…

Convenience usually comes at a cost. You shouldn't have to trust anyone. Just use a generic storage service and only upload encrypted files to it. Syncthing + Rclone will probably get you a similar setup that you control.

Re: Apple pulls data protection tool after UK government security row

#288

Can someone explain what's changed in the UK that they would consider requesting unfettered access to all Apple customer data (including outside their own borders)? I get that the NSA is infamous for warrant-less surveillance, but this seems a step further.

Uncontrolled immigration and terrorist threat, but also probably they want to look at people's nudes. Jolly lot.

Re: Apple pulls data protection tool after UK government security row

#289

Note that this doesn’t satisfy the government’s original request, which was for worldwide backdoor access into E2E-encrypted cloud accounts. But I have a more pertinent question: how can you “pull” E2E encryption without data loss? What happens to those that had this enabled? Edit: Part of my concern is that you have to keep in mind Apple's defense against backdooring E2E is the (US) doctrine that work cannot be comp…

> how can you “pull” E2E encryption without data loss

You can’t. The article says if you don’t disable it (which you have to do yourself, they can’t do it for you, because it’s E2E), your iCloud account will be canceled.

Re: Apple pulls data protection tool after UK government security row

#290

I’m at the point where I’m ready to get a pixel and install graphene

Right but then you are jailed at Heathrow for not unlocking your phone.

The UK has made it clear that Counter Terrorism legislation has no limits in UK law even if that means compromising all systems and leaving them vulnerable to state actor attacks.

MPs will continue to use encrypted messaging systems that disappear messages during any inquiries of course.

Post reply on HN