Live data from Hacker News

Apple will notify users about state-sponsored cybersecurity threats

support.apple.com

31–40 of 166 posts

Re: Apple will notify users about state-sponsored cybersecurity threats

#31

So something like PRISM that targets everybody won't trigger a warning?

I doubt it.

Keep in mind this will only work for non-court-gag-ordered instances. If the US subpoenas Apple about an individual they won't be allowed to notify them.

I have no idea how this applies to other countries.

I think this is more like: "We noticed unusual API usage and we don't have a gag order so whatever it is, it's not likely to be good"

Re: Apple will notify users about state-sponsored cybersecurity threats

#32
Will it let them know that their own phone has decided that they are a potential pedophile and their photos will be sent unencrypted to some tech centre god knows where where someone will decide whether to report them to authorities or not? Or is that ok to keep secret?

Re: Apple will notify users about state-sponsored cybersecurity threats

#33
It's only possible because Apple is too big too fail. Probably they won't notify about the US snooping, but smaller countries often have smaller budgets that this company, so they can't really do anything about Apple pulling strings. It's a shame that smaller companies cannot do that without risking being closed down.

Re: Apple will notify users about state-sponsored cybersecurity threats

#34
post #7

I'm surprised to see protection against state sponsored attacks implemented by a company as big as Apple. Is any other 'mainstream' company offering a similar feature? Warrant canary [0] comes to mind, but that is usually a message to all users, as opposed to notifying an individual user. [0]: https://en.wikipedia.org/wiki/Warrant_canary

> by a company as big as Apple

Would smaller company stand a chance against very much any state? If men in suits taken a CEO of a big company for "a talk" in the forest there would be a lot of fuss in the media, whereas small company would probably be scared to bits and never said a word.

Re: Apple will notify users about state-sponsored cybersecurity threats

#37
Has anyone put forward some theories as to how they are pulling this off? Are they tapping into iMessage Metadata, scanning crash logs, or something along those lines? While I totally understand the need for them to keep how they are doing this private, I do find it slightly concerning. Unless they are just flagging suspicious iCloud login attempts. If it’s relating to crash logs, it would be nice to know as I’m sure a bunch of privacy focused users have that disabled.

Re: Apple will notify users about state-sponsored cybersecurity threats

#38
post #37

Has anyone put forward some theories as to how they are pulling this off? Are they tapping into iMessage Metadata, scanning crash logs, or something along those lines? While I totally understand the need for them to keep how they are doing this private, I do find it slightly concerning. Unless they are just flagging suspicious iCloud login attempts. If it’s relating to crash logs, it would be nice to know as I’m sure…

I assume they have iMessage metadata on what accounts the NSO accounts talked to. The contents are E2E encrypted, but unless they have explicitly promised not to keep logs, they probably have the metadata logged.

Re: Apple will notify users about state-sponsored cybersecurity threats

#40

So something like PRISM that targets everybody won't trigger a warning?

It's rare that programmes like PRISM surface publicly. I don't see how Apple would gather top secret intel on national surveillance programmes on their own, so there is a good chance they aren't even aware.
Post reply on HN