Live data from Hacker News

Apple pulls data protection tool after UK government security row

bbc.com

361–370 of 1001 posts

Re: Apple pulls data protection tool after UK government security row

#361

The nightmare continues. For now I am using 3rd party backup services that are (currently) promising me that my backups are encrypted by a key they do not have access to, or control over. But can this even be believed in an age where these secret notices are being served to any number of companies? I suppose the next step would be to ensure that files don't ever arrive in the cloud unencrypted, but I have yet to see…

IMO the only thing you can have a high level of trust in is your own *nix server. Backup those devices to it then encrypt there before being sent to the cloud.

> your own *nix server

Just be sure it's pre-Intel Management Engine / pre-AMD Platform Security Processor!

Re: Apple pulls data protection tool after UK government security row

#362
Devil's Advocate (meaning I don't agree with this, in fact I disagree with it, but I don't see this argument being made anywhere and think it would be interesting. If you're one of the people who are offended by this practice of people steel-manning "the other side" and only want to read comments that affirm your position, please don't read this comment).

Question: Wouldn't it be better for Apple to build a UK-only encryption that is backdoored but is at least better than nothing? If Apple really cared about people's privacy, why just abandon them?

My position: No because this is a war, not a battle. Creating a backdoored encryption would immediately trigger every government on the planet passing laws banning use of non-back-doored encryption, which would ultimately lead us to a much, much worse world. Refusing to do it is the right thing IMHO.

Re: Apple pulls data protection tool after UK government security row

#363

The UK wanted access to anyone's data. Not just UK citizens and then additionally added regulations forbidding apple to disclose this. UK is ~3-4% of apples income. While I appreciate Apples actions here, I wish they would make a real stand here and pull completely out of the UK.

I really wish they would sit down and negotiate this more openly. The silence from the other players is what really makes me uncomfortable. The fact that only Apple is making a stand against this ask is really scary.

Re: Apple pulls data protection tool after UK government security row

#364

Apple could have disabled iCloud completely for UK users. This would protect both UK users and other users who’s data would also been captured in an iCloud backup. They would lose some money on services, but would have been the better choice to stand up to the UK government and protect the UK users.

It's fine to continue providing the service as long as people know it's not encrypted. I am not worried about my photos being subpoenaed; I am worried about losing them. I'd rather have the service.

Re: Apple pulls data protection tool after UK government security row

#365

The smartphone is a terrible platform. Something like this could never happen on the PC, where you can install any encryption and backup software that you want. While Apple did the right thing by refusing to give the UK government a backdoor, they are responsible for getting users in this situation in the first place. I'm not familiar with the iPhone and maybe there is already an alternative to iCloud ADP, although t…

The smartphone platform is the most secure by default personal computer most people own, largely because of the control enforced by Apple.

But along with that also comes a massive pressure point for rogue states to take advantage of. With a diversity of services this would not be nearly as possible.

Re: Apple pulls data protection tool after UK government security row

#366

Earlier quoted context omitted.

This is Apple condeeding. Apple lost. UK Government got (almost) what they wanted - a backdoor into iCloud accounts. Apple's only consolation prize is that its limited to UK users for now. But it seems inevitable that ADP will gradually be made illegal all around the world.

Given that they’ve only prevented new signups it looks to me more like Apple is trying to apply pressure to the U.K. government to get them to back down. The law that permits this was passed in 2016 so the situation was default lost already.

They have said all existing ADP enabled accounts will be disabled or deleted in time. They need to give people time to migrate their data out before they nuke it.

Re: Apple pulls data protection tool after UK government security row

#367

Earlier quoted context omitted.

it's working really well, we don't get arrested for social media posts as far as I can tell

https://www.justice.gov/usao-edny/pr/social-media-influencer... https://www.bbc.co.uk/news/articles/c86l4p583y6o https://www.aljazeera.com/news/2021/1/19/holdindigenous-man-... Yes you do

That’s not the same thing. You know what he means.

Re: Apple pulls data protection tool after UK government security row

#368
post #82

Earlier quoted context omitted.

Only in the UK, everyone else should still do it. Not on by default

Apple should start prompting users to enable it.

probably avoiding the support issues of users losing access to encryption key recovery

Re: Apple pulls data protection tool after UK government security row

#370
post #358

Fundamentally, I think the issue is more about technical literacy amongst the political establishment who consistently rely on the fallacy that having nothing to hide means you have nothing to fear. Especially in the UK which operates as a paternalistic state and enjoys authoritarian support across all parties. On the authoritarianism: these laws are always worded in such a way that they can be applied or targeted va…

What the politicians want is partial security: something they can crack but criminals can't. That is achievable in physical security, but not in cybersecurity.

I have a feeling the politicians already know partial cybersecurity isn't an option, and don't care. Certainly, the intelligence community advising them absolutely does know. We don't even have to be conspiratorial about it: their jobs are easier in the world where secrets are illegal than in the world where hackers actually get stopped.

Post reply on HN