I don't get why the UK always does this. it's like GSM encryption all over again. Is it a particularly snoop-ey culture stemming from GCHQ or something?
UK citizens don't have a constitutional right to free speech, which tends to bleed over in unhealthy ways to the government prioritizing its own interests over citizens'.
UK backing down on Apple encryption backdoor after pressure from US
331–340 of 438 posts
Re: UK backing down on Apple encryption backdoor after pressure from US
#332Earlier quoted context omitted.
This is not just encryption in transit or simplistic client-side encryption. It is end-to-end encryption, where each device's key generation is handled by your phone's Secure Enclave. This article is a decent starting point in terms of what Advanced Data Protection is: https://support.apple.com/en-us/102651 If you want a deeper dive into the security engineering of iCloud Keychain, the second half of this Blackhat ta…
Does all of that matter if an attacker has access to your device and can take screenshots of your conversations, or read those conversations out of memory in their unencrypted state?
Advanced Data Protection is mostly concerned with protecting data from attackers on the server and in transit.
If you're interested in protections when an attacker has physical access to your device, you should read the "Encryption and Data Protection" section of Apple's Platform Security Guide.
Web: https://support.apple.com/guide/security/welcome/web
PDF: https://help.apple.com/pdf/security/en_US/apple-platform-sec...
Re: UK backing down on Apple encryption backdoor after pressure from US
#333Earlier quoted context omitted.
I agree that no one needs Facebook and if it disappeared off of the face of the earth, nothing of value would be lost. And even a simplified version of AWS shouldn’t be impossible to build that’s “good enough” [1] or another search engine that’s good enough (Google) and Google search sucks these days anyway. But Europe is not going to be able to replicate the ecosystem of Android like China did and definitely not App…
What I am wondering is if the complexity of AWS is required for 99 percentile. There are a lot of niche services and duplicated ones on AWS and a targeted replacement for the most popular ones would be enough for most.
https://www.joelonsoftware.com/2001/03/23/strategy-letter-iv...
Everyone needs a different 90%.
I’m not trying to wear “I worked at AWS” on my chest like a 22 year old posting on Blind. But my experience working at AWS ProServe before working at 3rd partner consulting company I’ve seen a lot of different implementations even though my focus was on cloud native applications.
These are all of AWS’s named specialties.
https://aws.amazon.com/professional-services/
Large companies aren’t going to go to a smaller provider. Yes I know about “hybrid cloud”. But modt companies don’t want to go that.
Re: UK backing down on Apple encryption backdoor after pressure from US
#334Earlier quoted context omitted.
This is not just encryption in transit or simplistic client-side encryption. It is end-to-end encryption, where each device's key generation is handled by your phone's Secure Enclave. This article is a decent starting point in terms of what Advanced Data Protection is: https://support.apple.com/en-us/102651 If you want a deeper dive into the security engineering of iCloud Keychain, the second half of this Blackhat ta…
I'm aware of what E2EE is, all the encryption in the world does not matter if either end of the conversation is confiscated or pwned by adversaries.
Yes of course, but it's not so simple to bypass the hardware-enforced protections that exist both device side and server side. As far as I can tell, it seems effort was made to design/architect everything in such a way such that the protections can't be retroactively circumvented even under legal compulsion.
Disclosure: I previously worked for Apple, but not on the design/implementation of any of this stuff and this is all my own opinions, not those of Apple.
Re: UK backing down on Apple encryption backdoor after pressure from US
#335Re: UK backing down on Apple encryption backdoor after pressure from US
#336That surprises me, honestly. Makes you wonder what the British government got in return for forgetting about the encryption loicence idea.
Probably nothing. they have neither leverage nor negotiating talent.
The Brexit negotiations proved to me that the UK government will simply assume they have leverage and try to assert it even when they have none. Combined with the lack of negotiating talent during a high stakes deal created a perfect storm.
Re: UK backing down on Apple encryption backdoor after pressure from US
#337Earlier quoted context omitted.
Even in the US, even if Apple doesn’t have a backdoor, isn’t NSA linked up into the telecom companies already?
What are the chances that the NSA has a useful zero-day on the TLS encryption standard?
Re: UK backing down on Apple encryption backdoor after pressure from US
#338> Apple did not respond to a request for comment. “We have never built a back door or master key to any of our products, and we never will,” Apple said in February. This must be some "technically correct" weasel words bullcrap, as without at least equivalent access there is no chance Apple would be operating in China.
Re: UK backing down on Apple encryption backdoor after pressure from US
#339Earlier quoted context omitted.
Even in the US, even if Apple doesn’t have a backdoor, isn’t NSA linked up into the telecom companies already?
If there's a properly implemented end-to-end encryption, then NSA cannot see anything, even having full access to telco-s.
Re: UK backing down on Apple encryption backdoor after pressure from US
#340Earlier quoted context omitted.
UK citizens don't have a constitutional right to free speech, which tends to bleed over in unhealthy ways to the government prioritizing its own interests over citizens'.
> UK citizens don't have a constitutional right to free speech They do. The UK has an uncodified constitution, and this includes the Human Rights Act, which guarantees freedom of expression to UK citizens.