Live data from Hacker News

iPhones send call history to Apple, security firm says

theintercept.com

31–40 of 85 posts

Re: iPhones send call history to Apple, security firm says

#31
post #21

Earlier quoted context omitted.

What (TF) are you talking about??!!

People have been talking about shutting down "fake news" outlets in recent days, but The Intercept matches many of the criteria that they have been discussing so far. -TI is new -TI is small -TI primarily publishes content that makes politicians look bad -TI relies on word of mouth through social media You're really playing with fire if you think it's a good idea to let other people classify things as "real" and "fak…

Given that one of its founding journalists, Glenn Greenwald, is a pulitzer prize winner, and that the site has published many stories on one of the most significant news topics of the decade (the Snowden revelations), I don't think anyone could reasonably place it in the same category as the fake news sites that have been talked about recently.

> You're really playing with fire if you think it's a good idea to let other people classify things as "real" and "fake" for you.

You do this with literally every news source you read or watch. Most people consider CNN, BBC, The Guardian, New York Times etc. to be credible news sources with long-standing reputations. Sure, they are at times biased in their coverage, and selective on what they cover, but unless you're "on the ground" so to speak experiencing current events directly, you have to rely on a degree of trust in journalists and editors. I think the key is looking at the news with a healthy degree of skepticism, and getting your information from a range of different outlets.

Re: iPhones send call history to Apple, security firm says

#32
post #9

> Apple's Reply: >> Device data is encrypted with a user’s passcode, and access to iCloud data including backups requires the user’s Apple ID and password. Can't Apple ID password be reset? If so, how can it be a true encryption?

Maybe the password encrypts the actual encryption key? I don't know about iCloud but that's how LUKS works on Linux.

Except that would mean a password reset would involve losing access to all your data (unless you can remember the original).

Re: iPhones send call history to Apple, security firm says

#33
I'm not sure how this is "secret". If you're using iCloud on your mac and your iPhone, and open up Facetime on the former, you'll see a call list (including regular phone calls, not just facetime).

I agree it's undesirable that call history is sent to Apple - but it's pretty easy to notice if you use facetime across devices that the call history is synced.

Re: iPhones send call history to Apple, security firm says

#34

i'm still using my trusty motorolla razr

With the in-built BREW environment and the SIM "capabilities", it's probably a lot less "trusty" than an iPhone -- especially an iPhone with iCloud turned off.

More luddite doesn't always mean more secure.

Re: iPhones send call history to Apple, security firm says

#36
The key detail for me is that if you delete the call from the log on any device, the next sync will delete it in iCloud.

So the probably-good-enough-for-most-folks way to deal with this is to just delete calls from your log that you don't want to get archived in iCloud for 4 months.

The sure way is to disable iCloud entirely, but that reduces convenience in all sorts of ways (syncing iTunes music, for instance).

The ideal would be for Apple to figure out how to provide the services of iCloud in such a manner that they don't have access to user data. Apparently they are working on that but it would obviously be a major change, and risky too.

Most people don't care that Apple has to see their data in order to sync, but boy will they be pissed if Apple makes their data permanently unreadable. Most people want to be able to go into an Apple store and get problems fixed. Imagine being an Apple retail tech and explaining to some 50-something lawyer that because they lost their password there is absolutely nothing you can do. "Sorry man--encryption."

Re: iPhones send call history to Apple, security firm says

#38
post #14

Earlier quoted context omitted.

If you've recently set up iOS devices you'll have seen it ask for the passcode for another device before you can access iCloud data on the new one.

^ This. First time it happened I was a little confused, but once I realized what was happening I was ecstatic about it's implications for iCloud backup security.

Yep. iCloud security is fantastic. Here's a write up on how the keychain security works:

https://tidbits.com/article/14557

It involves hardware security modules, cross-device crypto signing and other fun stuff. Apple cannot access the data they store about you on their servers.

From Apple's documentation:

Apple designed iCloud Keychain and Keychain Recovery so that a user’s passwords are still protected under the following conditions:

- A user’s iCloud account is compromised.

- iCloud is compromised by an external attacker or employee.

- Third-party access to user accounts.

Re: iPhones send call history to Apple, security firm says

#40
post #38

Earlier quoted context omitted.

^ This. First time it happened I was a little confused, but once I realized what was happening I was ecstatic about it's implications for iCloud backup security.

Yep. iCloud security is fantastic. Here's a write up on how the keychain security works: https://tidbits.com/article/14557 It involves hardware security modules, cross-device crypto signing and other fun stuff. Apple cannot access the data they store about you on their servers. From Apple's documentation: Apple designed iCloud Keychain and Keychain Recovery so that a user’s passwords are still protected under the fol…

Note that the keychain security is a bit of an exception -- it's particularly strong, as it's protecting password data. (My favorite detail, not mentioned in the original white paper: To prevent the iCloud Keychain HSMs from being updated with a more lax policy, the smartcards that would have been required to update them were destroyed in a private ceremony involving a blender.)

Other data in iCloud is generally under less extreme levels of security. This isn't to say that it's insecure, merely that it's not as fanatically protected. Some of it may be accessible by resetting your account password.

Post reply on HN