Live data from Hacker News

Apple pulls data protection tool after UK government security row

bbc.com

381–390 of 1001 posts

Re: Apple pulls data protection tool after UK government security row

#381

Presumably this applies to the iPhones owned by UK government ministers, civil servants, personal devices of military personnel, UK businesses, etc. As a brit, I find that my government's stupidity is almost its only reliable attribute.

Presumably not, politicians have a way of excepting themselves in these types of laws. It's almost as if they understand the need for privacy, they just fail to apply that understanding to any scenarios beyond their own.

I meant that Apple's decision to withdraw ADP applies to them, not the Investigatory Powers Act. Or are you saying that Apple will give them a free exemption?

Re: Apple pulls data protection tool after UK government security row

#383
post #38
post #15

As a citizen, I don’t understand what the UK government thinks they are getting here - other than the possibility of leaks of the nation’s most sensitive data. Also is it not possible to set up my Apple account outside of the UK while living here?

> other than the possibility of leaks of the nation’s most sensitive data Amusing when you consider the National Cyber Security Centre (NCSC, a part of GCHQ), along with the Information Commissioners Office, both publish guidance recommending, and describing how to use, encryption to protect personal and sensitive data. Our government is almost schizophrenic in its attitude to encryption.

I mean, this is no different than one part of the government suggesting running laundry at night to reduce the environmental impact of energy use, while another suggests only running it while awake to reduce fire hazard. Governments and corporations rarely have complete internal alignment.

Re: Apple pulls data protection tool after UK government security row

#384

Note that this doesn’t satisfy the government’s original request, which was for worldwide backdoor access into E2E-encrypted cloud accounts. But I have a more pertinent question: how can you “pull” E2E encryption without data loss? What happens to those that had this enabled? Edit: Part of my concern is that you have to keep in mind Apple's defense against backdooring E2E is the (US) doctrine that work cannot be comp…

When you disable ADP, your local encryption keys are uploaded to Apple's servers to be read by them. Apple could just lock you out of iCloud until you do this.

That’s exactly the plan. Anyone with this enabled in the UK will need to manually disable it or they’ll get locked out of their iCloud account after a deadline.

Re: Apple pulls data protection tool after UK government security row

#385
post #303

Earlier quoted context omitted.

Scary - I try to use signal as much as possible now for this reason.

Signal can't evade this law either.

Why not? Signal was willing to run all kinds crazy setups to evade foreign laws, like domain fronting.

https://signal.org/blog/doodles-stickers-censorship/

Re: Apple pulls data protection tool after UK government security row

#386
post #4

As someone currently a citizen of the UK, what are my best emigration opportunities?

You do realise that the UK government is, and always has been, notorious for surveillance. They haven't changed since before WW2 and probably never will, even if Apple suddenly decides to play hardball with them.

And to be very, very honest, if you look across the Five Eyes nations, I don't think this is much different from what other countries deal with when it comes to access to data. You had PRISM, the trick of asking other countries for access to their own citizens data to avoid scrutiny, and Apple delaying the implementation of E2E in the US after federal agencies got pissed about it. The list goes on for a long time. At least in the UK, the government is so detached from commoners hurt feelings that they ask for what they want explicitly, with no fear of political consequences.

Re: Apple pulls data protection tool after UK government security row

#387
post #106

Too right, it was far more problematic than they ever made out. > The UK government's demand came through a "technical capability notice" under the Investigatory Powers Act (IPA), requiring Apple to create a backdoor that would allow British security officials to access encrypted user data globally. The order would have compromised Apple's Advanced Data Protection feature, which provides end-to-end encryption for iCl…

Your Android and Microsoft backup aren't encrypted. They are already fair game for a warrant.

Re: Apple pulls data protection tool after UK government security row

#389
post #341

Wow - how sad. To think the 2nd highest scoring post ever on hacker news is Apple's 2016 A Message to Our Customers . A display of intelligence, morality and courage under great pressure: https://hn.algolia.com How things have changed. > In a statement Apple said it was "gravely disappointed" So are we, Apple. So are we.

Apple did the right thing. I would much rather they were transparent, so that people can move services, rather than build a backdoor in secret, to appease the far-left Labour government.

Building a backdoor and telling us is better than building a backdoor and not telling us, but not building a backdoor at all is ideal.

Re: Apple pulls data protection tool after UK government security row

#390
post #106

Too right, it was far more problematic than they ever made out. > The UK government's demand came through a "technical capability notice" under the Investigatory Powers Act (IPA), requiring Apple to create a backdoor that would allow British security officials to access encrypted user data globally. The order would have compromised Apple's Advanced Data Protection feature, which provides end-to-end encryption for iCl…

> have an Android device beside me that regularly asks me to back my device up to the cloud But is that backup encrypted? If it's not, all they need is to access your data. This is about having access to backups that are theoretically encrypted with a key Apple doesn't have? > We're talking about the largest back door I've ever heard of. Doesn't the US have access to all the data of non US citizens whose data is stor…

> But is that backup encrypted? If it's not, all they need is to access your data.

Based on them mentioning the difficulty of opting out, I presume OOP does not use Google's cloud backup.

Post reply on HN