Live data from Hacker News

Apple dropped plan for encrypting backups after FBI complained

reuters.com

291–300 of 734 posts

Re: Apple dropped plan for encrypting backups after FBI complained

#292
post #206

> aboyt how much Apple cares about users No company cares about anything. A company is not a person. Apple, because of its privacy-marketing, is incentivized to be the privacy player in the market. But only so far as consumers keep them honest about it. They got away with this loophole because it stayed under the radar; if it gets enough attention and enough customers show that it matters to them, it could change. On…

Isn't Android at this point a more secure OS? The price for zero days at least is signaling that.

As far as I know the consensus is still that iOS is more secure. Of course there are different definitions of that. Certainly Android is more ripe for abuse by apps downloaded from the store, for example; they can run freely in the background and do things like draw UX over other apps.

Also, privacy != security. iOS is absolutely in a better position on privacy, even after this new development.

Re: Apple dropped plan for encrypting backups after FBI complained

#293

Earlier quoted context omitted.

Not a solution for Linux users. There are ways to sync to Linux but I’ve had plenty of issues with it.

Linux offers the ability to run virtual machines, does it not?

Apple EULA used to (still does?) prohibit virtualization of macOS on non-Apple hardware, so this setup could get flaky (need to patch around new hardware detection mechanisms when upgrading the OS).

Re: Apple dropped plan for encrypting backups after FBI complained

#294

Earlier quoted context omitted.

Why do people care about phone backups anymore? I don't think I have any apps that don't store everything in the cloud. There's nothing of value that's only on my phone. I could toss it in the bin and set up a new one now and not lose anything.

Because syncing isn't a backup? What happens when you sync corrupted files?

I didn't say syncing was a backup. That's the opposite of what I'm saying.

I'm saying that my phone becomes the synced copy. The cloud is the canonical version (backed up separately elsewhere) and my phone becomes a device I can lose or break and not worry about anything so I don't need to back it up. As soon as I create any content on my phone I upload it to the cloud.

Take my phone from my hand at any moment and as long as I've had signal in the last few minutes I've lost nothing.

Re: Apple dropped plan for encrypting backups after FBI complained

#295
post #57

Apple has a list for that: https://support.apple.com/en-us/HT202303 These are end to end: Home data Health data (requires iOS 12 or later) iCloud Keychain (includes all of your saved accounts and passwords) Payment information QuickType Keyboard learned vocabulary (requires iOS 11 or later) Screen Time Siri information Wi-Fi passwords The messages also end to end but the backup contains the private key. The moral of…

Two things: 1) There is no way Apple would be allowed to sell iPhones in China, without China government having access to anything. So, I assume that Apple users in China have e2e encrypted exactly nothing. 2) I have a strong suspicion that those 'enter your Apple ID password because your account needs it' message really means 'a government has requested your data and even though it's encrypted, we will nag you about…

Regarding #1: iCloud in China is operated by a mainland Chinese company and subject to that company's terms and conditions. So you can pretty much assume iCloud data is completely accessible by the government.

Source: https://support.apple.com/en-us/HT208351

Re: Apple dropped plan for encrypting backups after FBI complained

#296
post #271

Earlier quoted context omitted.

> if you want real protection, do local backups Yes, this is unfortunately true and unfortunately complicated compared to iCloud backups. I backup locally to my mac (encrypted), then I have my mac do time machine backups to my Synology NAS (encrypted) and then I have my NAS backup to BackBlaze (encrypted). I do that to satisfy the two pronged backup strategy: local (fast) and remote (slow, but useful in catastrophic…

I might be mistaken but I thought Backblaze doesn't backup external drives?

There are a few possible approaches. I figured they're using b2. I'm pretty sure Synology has builtin tools to mirror to it. Backblaze will backup external drives that are attached to the computer, but if they are disconnected for 30+ days the data is deleted. While network drives aren't backed up there are ways to have them appear as local drives (which I hear are a pain to deal with).

Re: Apple dropped plan for encrypting backups after FBI complained

#297
post #206

> aboyt how much Apple cares about users No company cares about anything. A company is not a person. Apple, because of its privacy-marketing, is incentivized to be the privacy player in the market. But only so far as consumers keep them honest about it. They got away with this loophole because it stayed under the radar; if it gets enough attention and enough customers show that it matters to them, it could change. On…

Isn't Android at this point a more secure OS? The price for zero days at least is signaling that.

It could be signalling one is a far more attractive target to exploit, because e.g. harden shell, soft interior (M&M architecture). Or maybe Apple patches quicker and gets them out quicker, so exploit lifetime is shorter. Just to be clear, I don't know if that's true, but it's equally plausible explanation for the exploit price

Re: Apple dropped plan for encrypting backups after FBI complained

#298
post #237

Earlier quoted context omitted.

> On the other hand, it's possible that because we have a smartphones duopoly, Apple only needs to maintain a position where people will say "well at least it's not as bad as Google". I'm upset about this personally, but I'm not ditching my iPhone. Of course, this does cement my decision to never pay for iCloud, for what that's worth (much less, but not nothing). Agreed, and I am likely going away from Android and in…

They botched the original Windows Phone through a failure of management. They botched subsequent pushes on it because the bootstrapping problem around apps had grown too deep. At this point, if they tried to give it another go, there would be trust issues: "Am I investing in a phone ecosystem that's going to be dead in a few years?" Not to mention how much they've gone all-in on Android development. A Surface-branded…

They botched the original Windows Phone through a failure of management

This. I had some Windows Phones besides my iPhones, because I liked very much what they were doing. Windows Phone 7, despite being technically weak (it was based on Windows CE), had an awesome UI. Nokia had some really affordable phones that were really well-built for the price and Windows Phone was getting traction. Quite a few friends/colleagues bought a Windows Phone, because it was the hip thing after the iPhone. The development story was also great, they used .NET and XAML (IIRC), which also made it possible to demo applications on web pages through Silverlight.

Then they screwed over all the early adopters by completely deprecating Windows Phone 7, doing one final release (7.8). None of the Windows Phone 7 devices were upgraded to Windows Phone 8. Most of the traction they had up till that point was lost and they were basically starting over with Windows Phone 8. Windows Phone 7 was already late to the market, the hard WP8 cut set them back even more years. And then it was simply too late.

There were technical reasons for WP7 -> WP8 (such as moving to the NT kernel, adding multi-processing support). But the hard cut was a catastrophical mistake. Either they should have started with the NT kernel in the first release or they should have had a gradual migration route from WP7 to WP8.

Re: Apple dropped plan for encrypting backups after FBI complained

#299
post #203

Earlier quoted context omitted.

Have you read the SpiderOak disclaimer though? NOTE: Logging in via the SpiderOak website does temporarily allow SpiderOak employees access to your password. https://spideroak.support/hc/en-us/articles/115001854583-ONE...

That works for any service where you don't fully control the other endpoint. They are just being transparent. Although the wording re: website is peculiar. Could it be their form of a canary like warning?

As a developer, I expect that smaller shops' infrastructure isn't as thoroughly locked down and things like passwords getting logged to splunk/ELK is tech debt, and par for the course. However that's a very specific exception though, to the point that instead of putting work into adding that into their disclaimer, they could have made sure the password wasn't being logged instead.

Re: Apple dropped plan for encrypting backups after FBI complained

#300
post #230

Wonder if this will help to kill a meme, about how much Apple cares about users and what great values they have, how they're going to stand for the user, fight with governments, etc. While iPhone itself is pretty secure as a device phone (and Apple makes sure to remind you about that in each ad, public speaking, attacks on competitors, etc), as an ecosystem it's not secure. And it's like that on purpose - there's no…

As someone who has bought into that meme I will admit this feels like a pretty huge betrayal by Apple. So, yes, I think if Apple sticks with this, their whole privacy stance is going in the toilet now. And a very dirty toilet it is. Beyond just the facts of not protecting data, there is also the deception. This is some really very, very, nasty stuff for Apple's brand and the reputation of every person who works at Ap…

Yeah, but what are the reasonable alternatives? Android, with its freewheeling stance on privacy and app permissions? Do they even let you disable location tracking any more?
Post reply on HN