Live data from Hacker News

Apple dropped plan for encrypting backups after FBI complained

reuters.com

381–390 of 734 posts

Re: Apple dropped plan for encrypting backups after FBI complained

#381
post #230

Wonder if this will help to kill a meme, about how much Apple cares about users and what great values they have, how they're going to stand for the user, fight with governments, etc. While iPhone itself is pretty secure as a device phone (and Apple makes sure to remind you about that in each ad, public speaking, attacks on competitors, etc), as an ecosystem it's not secure. And it's like that on purpose - there's no…

As someone who has bought into that meme I will admit this feels like a pretty huge betrayal by Apple. So, yes, I think if Apple sticks with this, their whole privacy stance is going in the toilet now. And a very dirty toilet it is. Beyond just the facts of not protecting data, there is also the deception. This is some really very, very, nasty stuff for Apple's brand and the reputation of every person who works at Ap…

There is a plausible argument that Apple needed to give a little in order to avoid the creation of laws against any encryption. And/Or also avoid laws that required a backdoor to everything.

I know I'm going to be called a fanboy or too generous to Apple, but given that the government has used every opportunity to call out Apple for not helping (when they have helped where they could) there is a line here that Apple is tip toeing around.

I also do not think this as bad as you are making it out to be. Apple has always been clear what is fully E2E encrypted and what is not. This article is about something Apple planned to do and decided against. The reasons are what's important and the article only speculates.

Re: Apple dropped plan for encrypting backups after FBI complained

#382

Earlier quoted context omitted.

This is false. This concern is addressed in the second paragraph of the linked article: > this passcode-protected key material is encrypted to a Titan security chip on our datacenter floor. The Titan chip is configured to only release the backup decryption key when presented with a correct claim derived from the user's passcode. Because the Titan chip must authorize every access to the decryption key, it can permanen…

But the source code of many important parts of android are nonfree, so google can update it to send your cleartext password and you would never know.

This is true for iOS as well as every other widely used computing platform. Android is better; unlike iOS you can build AOSP yourself without the Google proprietary parts, and unlike iPhones, Pixel phones have unlockable bootloaders so you can install your own OS builds.

Even most PCs running Linux have plenty of nonfree binaries in various firmwares and common peripheral drivers. I support efforts to make devices with fully open firmware on which you could run Android's AOSP or other open source operating systems.

Re: Apple dropped plan for encrypting backups after FBI complained

#383
post #353

Earlier quoted context omitted.

They botched subsequent pushes on it because the bootstrapping problem around apps had grown too deep. I don't really think that is necessarily accurate. Lots of smaller developers would be more than happy to have a green field for app development if another player were willing to put the effort into assuring the device isn't a POS, and is priced reasonably. Some of the larger apps (netflix for example) already have…

Microsoft literally paid developers to port their apps to Windows Phone: https://www.theverge.com/2013/6/15/4433082/microsoft-paying-... It's that chicken-and-egg problem where people don't want to use it because it doesn't have the apps they need, and developers don't want to make apps for it because it doesn't have enough users. Microsoft tried to throw money at the problem to middling success. But I think it was t…

I'm not sure why paying developers is a problem to bootstrap the ecosystem. Although, if they were paying for temple run (as the image might suggest) that seems odd. Mostly because presumably they should be targeting the apps everyone uses that don't have good replacements (aka netflix/prime streaming/etc).

I would guess that they aren't the only ones. Do you think LG/Sony/Samsung/roku/apple tv/firestic/etc all got the netflix app ported for free? Maybe. Plex probably isn't getting paid, and they do it too..

But MS was a special case, it seems to me that every time I looked at CE/Mobile/etc they were tossing existing app compatibility aside for the latest and greatest toolkit that went with some not particularly good set of phones.

Re: Apple dropped plan for encrypting backups after FBI complained

#384
post #328

Earlier quoted context omitted.

>With an open hardware design, periodically de-liding and examining a random sample of available consumer hardware would probably sufficient to protect the general consumer population, and targeted attacks become very difficult if you purchase your hardware from a store rather than order it by mail. How do you trust the person that verifies the CPU? Can you trust the X-Ray imaging machine? Is the X-Ray Machine verifi…

You'd have multiple trusted independent parties from multiple international jurisdictions reviewing the hardware design, not just one. And yes, obviously the X-Ray machines would need to be verified using similar techniques.

But how do I trust the independent parties?

Re: Apple dropped plan for encrypting backups after FBI complained

#385
post #56

Earlier quoted context omitted.

You should look into the 'borg' backup tool - it has become the de facto standard for remote backups because it does everything that rsync does (efficient, changes only backups) but also produces strongly encrypted remote backup sets that only you have a key to ... your cloud provider has no access to the data. The borg website is here: https://borgbackup.readthedocs.io/en/stable/ and a good description of how it wor…

After looking at a few alternatives (Borg, Duplicacy etc.), I setup Arq on my Mac yesterday. One thing that irks me about these solutions is that they seem to scan my folders each time they want to backup. Are there tools that are smarter about this? For e.g., while running, they could keep a log of what's changing and only scan those while backing up.

> After looking at a few alternatives (Borg, Duplicacy etc.)

I may have looked at Duplicacy. I'm sure that I looked at one of Duplicacy [1], Duplicati [2], and Duplicity [3]. Whichever one that was, I kept getting it mixed up with the other two when looking for information online, and finally said "screw this" and bought Arq.

[1] https://duplicacy.com/

[2] https://www.duplicati.com/

[3] http://duplicity.nongnu.org/

Re: Apple dropped plan for encrypting backups after FBI complained

#386
post #365

Earlier quoted context omitted.

Why do people care about phone backups anymore? I don't think I have any apps that don't store everything in the cloud. There's nothing of value that's only on my phone. I could toss it in the bin and set up a new one now and not lose anything.

Because if you turn on iCloud backup, Apple might give it to the FBI. (Which is the whole topic of this article...)

Right, so don't backup your phone, on iCloud or anywhere else. Use another cloud service to store your files and only sync to your phone, don't back it up.

Re: Apple dropped plan for encrypting backups after FBI complained

#387
post #206

> aboyt how much Apple cares about users No company cares about anything. A company is not a person. Apple, because of its privacy-marketing, is incentivized to be the privacy player in the market. But only so far as consumers keep them honest about it. They got away with this loophole because it stayed under the radar; if it gets enough attention and enough customers show that it matters to them, it could change. On…

> No company cares about anything

It's a common misconception that corporations are amoral incentive-driven machines impervious to ethics, morals or mission.

Corporations are run by leaders.

Many leaders choose to pursue unethical and immoral activities to maximize profit. They justify their actions by saying "it's just business", or "we have a fiduciary duty to the stockholders to maximize earnings per share by whatever means necessary".

Other leaders realize that an ethical purpose can often deliver outsized profits over the long term. Leaders with a moral mission make decisions that sometimes sacrifice short-term profits with the intent to build an organization and a brand for long term.

Re: Apple dropped plan for encrypting backups after FBI complained

#388
post #265

For comparison, Google end-to-end encrypts Android backups with your lock screen PIN/pattern (which isn't known to Google). Source - https://security.googleblog.com/2018/10/google-and-android-h...

So backups are insecure because they can be brute forced then?

Most PINs are 4 digits, and 50% of people use the most popular 25 PINs.

Pattern has 9! combinations (= 51840) but most people use four dots (987*6 combos) and most of those probably use one of a few popular patterns.

Re: Apple dropped plan for encrypting backups after FBI complained

#389
post #378

Wonder if this will help to kill a meme, about how much Apple cares about users and what great values they have, how they're going to stand for the user, fight with governments, etc. While iPhone itself is pretty secure as a device phone (and Apple makes sure to remind you about that in each ad, public speaking, attacks on competitors, etc), as an ecosystem it's not secure. And it's like that on purpose - there's no…

> there's no good and easy option to backup your phone other than iCloud. Just plug your phone, click "Backup up". You don't even have to open iTunes anymore, just open "Finder" window. Can't be easier than that.

Tell that to us Windows and Linux people

Re: Apple dropped plan for encrypting backups after FBI complained

#390

The ecosystem is incredibly insecure, despite what Apple's marketing department wants you to think. More than anything I'm surprised at how often their advertising talking points are parroted in tech circles, like here on HN.. in any thread hinting at Google vs Apple you're bound to find a long comment chain about how Apple is "secure" and "privacy oriented" and "cares about their users". Not that Google is any bette…

It all depends on your threat model. For the average person I’m not worried about the relatively unlikely occurrence of the government accessing their backups. I’m much more worried about the more likely occurrence of local malware or ad tracking by malicious apps including from big names like Facebook & other social media companies, and in that instance Apple is still ahead as the OS restricts what apps can do a lot…

Here's a threat model for you: how fucked would you be if your iCloud backups suddenly became searchable online? Ever say anything bad about your boss or company in an convo? Ever taken any photos you wouldn't want released? Ever downloaded any files you wouldn't want public?

The agencies have proven time and time again that they're pretty terrible at keeping secrets (see: all the leaks, data breaches, TSA master keys, etc). As long as they have a back door, it's inevitable that it'll happen -- it's effectively a ticking time bomb.

When I send a message over Signal, I can trust that it'll be kept private, barring some truly extraordinary incident. With Apple, it's kept accessible by design (storing the encryption key with the encrypted backup? really?).

It's not about the government accessing my messages, because I really don't care all that much, it's that I don't trust them to keep secrets. If the government has access to something of yours you must assume it'll eventually be made public... whether or not you're okay with that is up to you.

Post reply on HN