Apple dropped plan for encrypting backups after FBI complained
31–40 of 734 posts
Re: Apple dropped plan for encrypting backups after FBI complained
#32This is also why you should never use cloud backups for iMessage or WhatsApp.
For some reason, I doubt Google would do that.
Re: Apple dropped plan for encrypting backups after FBI complained
#33Reminds me of WhatsApp claiming it had encryption everywhere and then this [0] dropped. Except, in this case, I'm actually surprised. Didn't Apple publicly claim that it wouldn't bow down to any demands from the agencies? [0]: https://www.theinquirer.net/inquirer/news/3061660/whatsapp-i...
That was a coordinated PR move between Apple and the government. The US administration went into heavy damage control mode with the large tech companies after the Snowden revelations about PRISM et c.
Re: Apple dropped plan for encrypting backups after FBI complained
#34Some companies are better than others but there's absolutely no reason to believe any one of them would ever be on "your side" for any reason. You can vote for who makes decisions in government, but you can't vote for who makes decisions in companies.
You vote every time you decide to buy or not to buy.
Re: Apple dropped plan for encrypting backups after FBI complained
#35Reminds me of WhatsApp claiming it had encryption everywhere and then this [0] dropped. Except, in this case, I'm actually surprised. Didn't Apple publicly claim that it wouldn't bow down to any demands from the agencies? [0]: https://www.theinquirer.net/inquirer/news/3061660/whatsapp-i...
Apple and Microsoft both tried to build ad businesses, but when they weren't as successful as Google, they turned lemons into lemonade by launching data privacy PR campaigns against Google.
Meanwhile, Apple and Microsoft quietly censor their products in China, surrender data to Chinese authorities, and now we find Apple is intentionally leaving iCloud data insecure.
Presumably Google was under the same pressure from US law enforcement, but somehow Google delivered end-to-end encrypted Android backups in October, 2018. And Google did it without all of Apple's self-congratulatory media hoopla.
e2ee: https://security.googleblog.com/2018/10/google-and-android-h...
Third party security audit: https://www.nccgroup.trust/us/our-research/android-cloud-bac...
Re: Apple dropped plan for encrypting backups after FBI complained
#36I stopped using GDrive about a year ago and I aim to be Google-free for 2020. I don't use Gmail for anything important any more.
Re: Apple dropped plan for encrypting backups after FBI complained
#37Reminds me of WhatsApp claiming it had encryption everywhere and then this [0] dropped. Except, in this case, I'm actually surprised. Didn't Apple publicly claim that it wouldn't bow down to any demands from the agencies? [0]: https://www.theinquirer.net/inquirer/news/3061660/whatsapp-i...
IIRC it said it wouldn't bow down on implementing back doors to unlock protected devices and encrypted content on them, which is specific enough not to cover this case.
Bowing down on implementing new security features doesn't go against the promise to not bow down on the security of existing ones, as written. It can be argued to go against the spirit of the earlier public statement of course, but that doesn't count for much in the eyes of a corporation being given a strong suggestion by a government agency.
Re: Apple dropped plan for encrypting backups after FBI complained
#38Privacy? Who needs it, amirite? I mean, I'm not up to anything illegal, and I don't actually care about people seeing my stuff, BUT... the concept as a whole of "government should have access to everything all the time, regardless of reasoning" does not sit well with me.
Re: Apple dropped plan for encrypting backups after FBI complained
#39What the... I was under the impression that iCloud backups are end-to-end encrypted. This is a HUGE problem.
Why would you think it was end-to-end encrypted? Did you never use icloud.com where you can simply access all your icloud data with a usernam+password?
As Mark Zuckerberg once opined: “They ‘trust’ me. Those dumbfucks.”
https://www.businessinsider.com/embarrassing-and-damaging-zu...
And it’s not just mere words, here is he actually set up a honeypot site to get people’s passwords and break into their emails to satisfy his burning curiosity when he first launched Facebook:
https://www.businessinsider.com/how-mark-zuckerberg-hacked-i...
Instead, he decided to access the email accounts of Crimson editors and review their emails. How did he do this? Here's how Mark described his hack to a friend:
Mark used his site, TheFacebook.com, to look up members of the site who identified themselves as members of the Crimson. Then he examined a log of failed logins to see if any of the Crimson members had ever entered an incorrect password into TheFacebook.com. If the cases in which they had entered failed logins, Mark tried to use them to access the Crimson members' Harvard email accounts. He successfully accessed two of them.
In other words, Mark appears to have used private login data from TheFacebook to hack into the separate email accounts of some TheFacebook users.
In a world where we are sending our Alexa data to “the cloud” and the companies are admitting people are listening to it, in a world where Facebook secretly records everything it can, why would you assume your password isn’t being sent?
To the downvoters... you may say that this was only when Mark Z was a young man and now Facebook the company is far more responsible. But then we have this from just a few months ago:
https://www.independent.co.uk/life-style/gadgets-and-tech/ne...
I can understand trusting a browser or a software release that can be tested by many people, and was signed with a checksum. But a website and all your extensions on every website?? Those can ship new code at any time.
(Am I wrong? Any counter-arguments?)
Re: Apple dropped plan for encrypting backups after FBI complained
#40Earlier quoted context omitted.
iPhone/iPad backups stored locally on iTunes (or Finder, in Catalina) are end-to-end encrypted. iCloud backups always were encrypted based on a key derived from your iCloud account credentials, since the beginning...
Do they happen re-encrypt if I change my credentials a bunch of times or do they use my first ever password which was 123456?