Live data from Hacker News

UK backing down on Apple encryption backdoor after pressure from US

arstechnica.com

291–300 of 438 posts

Re: UK backing down on Apple encryption backdoor after pressure from US

#292
post #108
post #102

> Apple did not respond to a request for comment. “We have never built a back door or master key to any of our products, and we never will,” Apple said in February. This must be some "technically correct" weasel words bullcrap, as without at least equivalent access there is no chance Apple would be operating in China.

> This must be some "technically correct" weasel words bullcrap Is that even necessary? A gag order means they can't reveal backdoors, and their entire stack is so locked down that discovering them is hard and unlikely.

Gag order cannot force them to lie. A lie like that can be illegal even.

If there's a gag order, then companies say "we have a gag order". Like Google and Twitter did back in the day when asked. And then immediately started releasing Transparency Report to show how many of the gag orders they receive, so gov't couldn't say "we don't request anything".

https://transparencyreport.google.com/user-data/overview

Re: UK backing down on Apple encryption backdoor after pressure from US

#293

Earlier quoted context omitted.

There is nothing extraordinary about a claim that multiple commercial organisations routinely and reliably defeat the security of modern devices on behalf of law enforcement - something that would clearly undermine numerous public claims about the security and privacy of those devices made by their manufacturer? You and I have very different ideas of what is extraordinary!

Multiple vendors advertise and sell devices and software to crack iPhones, they have for years. In the US, any decent size city or county sheriff has access to one. State level forensics labs probably have several types. The manufacturer provides the means to bypass many of the cheaper tools, but few people use them. There are more exotic tools that can bypass security controls. These are more niche and not generally…

Multiple vendors advertise and sell devices and software to crack iPhones, they have for years.

Yes they do. Now name one that works consistently against a fully patched modern iPhone.

Re: UK backing down on Apple encryption backdoor after pressure from US

#294

Earlier quoted context omitted.

> I'm not sure the Trump administration actually has a coherent position That seems to be the most salient property of his presidency. His position on any issue is whatever he just said, with no regard to what it might have been yesterday.

For anyone that wants a good (and fair) example of this, check out his positions on the debt ceiling going back to 2012 (and then on every time it's come up since). When he isn't in power raising the debt ceiling is Unamerican, a political ploy and bad. When he is in power, it should be scrapped entirely and should be above politics. He was remarkably frank about it in an interview a year or two ago when he was runni…

> When he isn't in power raising the debt ceiling is Unamerican, a political ploy and bad. When he is in power, it should be scrapped entirely and should be above politics.

It's too bad that when he is in power he does not actually make the latter happen, because it should be scrapped entirely.

The only other country with a debt limit set in an absolute amount rather than as a percentage of GDP is Denmark, and they sensibly have set theirs far above their actual debt so it becomes just a legal formality rather than a policy tool.

The problem with it in the US is that the debt ceiling limits government borrowing to pay for debts that have already been incurred. It doesn't control the amount of spending or the deficit--that is controlled by the budget that Congress and the President approve.

If we can't just scrap it completely, then at least the budget process should be changed so every budget bill must be accompanied by a raise of the debt ceiling by enough to cover whatever extra debt that budget will be adding.

Re: UK backing down on Apple encryption backdoor after pressure from US

#295
post #272

Earlier quoted context omitted.

For me it's not so much a conspiracy as the natural flow as a society becomes more fascist (as most Western government are leaning) and more "police state". It's inevitable, they want to be able to spy on every aspect of our lives and keep it recorded indefinitely as technology and public sentiment will allow. Cops want to make their jobs as easy as possible, politicians want to be able to get as much dirt on everyon…

That’s just run of the mill authoritarianism, calling it fascism glosses over how it has proponents in every political persuasion. Authoritarianism has become very popular online these days for some reason. Giving in to fear and wanting total control are always going to be traits that pop up again and then humans have to relearn from history about why freedoms are important.

Yes, although fascism is probably a proper word to use here -- it comes from Roman "fasces", symbolizes power to punish king's subjects (i.e. it's not about other states and kings, but about internal affairs).

Re: UK backing down on Apple encryption backdoor after pressure from US

#297
post #108

Earlier quoted context omitted.

> This must be some "technically correct" weasel words bullcrap Is that even necessary? A gag order means they can't reveal backdoors, and their entire stack is so locked down that discovering them is hard and unlikely.

Gag order cannot force them to lie. A lie like that can be illegal even. If there's a gag order, then companies say "we have a gag order". Like Google and Twitter did back in the day when asked. And then immediately started releasing Transparency Report to show how many of the gag orders they receive, so gov't couldn't say "we don't request anything". https://transparencyreport.google.com/user-data/overview

I don't think this is true. There was the whole fiasco around the EULA canary that a company had that, if it was removed, was supposed to indicate that the company had received a gag order. I don't believe it had been actually tested in court. I believe it had to do with the FISA court system. I can't find a link but there are definitely cases of gray area where courts have required entities to lie. https://en.m.wikipedia.org/wiki/Warrant_canary

Re: UK backing down on Apple encryption backdoor after pressure from US

#298

Earlier quoted context omitted.

Just about every confidentiality clause or NDA I've ever signed had a provision specifically excluding information independently in the public domain from its scope. I find it strange to the point of lacking credibility that someone working in a security-related field would have an NDA that required them to pretend to ignore even public domain information yet permitted them to post the kind of innuendo seen in this d…

Why should I disclose public domain knowledge when it’s public? The whole point was to point out there’s ways that aren’t public being used. Believe it or not, I actually care about privacy. Innuendo is not my intent, no maliciousness here, only stating there are programs that have access to your data. Telegram/Signal/Encrypted or not. They don’t need access to your device. Only access to the Internet.

The whole point was to point out there’s ways that aren’t public being used.

For which you have provided not a shred of evidence here beyond the same type of innuendo you've been posting all along - even while implying that some of this is public knowledge that you could therefore cite to establish at least some credibility.

Your claims in combination appear to require that the technical foundation on which almost all serious security on Apple devices is built must be fundamentally flawed and yet somehow this hasn't leaked. That's like saying someone found an efficient solution to the discrete logarithm problem and it's in widespread use among the intelligence community but no-one outside has realised. It's theoretically possible but the chance of something so big staying secret for very long is tiny.

As I said before - extraordinary claims require extraordinary evidence. Thank you for the discussion but there seems little reason to continue it unless you're able to provide some.

Re: UK backing down on Apple encryption backdoor after pressure from US

#299
The attack on privacy does kind of make sense when your remember that it is a freaking monarchy with all the inhabitants being subjects.

Probably well deserved to them if it was not contagious in Europe at the moment.

That being said, the crazy thing about this law and the other ones similar is this:

   Under the terms of the legislation, recipients of such a notice are unable to discuss the matter publicly, even with customers affected by the order, unless granted permission by the Home Secretary
They always justify everything saying that real world "procedures" should apply to the digital world. But, in most occidental countries, no one is allowed to search your home without you to be aware of it and present if you are capable to do so. Still, strangely, for digital data, the norm is that your data can be raped in your back, without you being aware about it or even in the capacity to challenge that.

I really find that stunning that it is so widely accepted. The former german Stasi would probably have been proud of all the parlementaries in US, UK and Europe that allowed such things.

Re: UK backing down on Apple encryption backdoor after pressure from US

#300
post #168

I don't get why the UK always does this. it's like GSM encryption all over again. Is it a particularly snoop-ey culture stemming from GCHQ or something?

UK citizens don't have a constitutional right to free speech, which tends to bleed over in unhealthy ways to the government prioritizing its own interests over citizens'.
Post reply on HN