Live data from Hacker News

Apple dropped plan for encrypting backups after FBI complained

reuters.com

391–400 of 734 posts

Re: Apple dropped plan for encrypting backups after FBI complained

#391
post #230

Earlier quoted context omitted.

As someone who has bought into that meme I will admit this feels like a pretty huge betrayal by Apple. So, yes, I think if Apple sticks with this, their whole privacy stance is going in the toilet now. And a very dirty toilet it is. Beyond just the facts of not protecting data, there is also the deception. This is some really very, very, nasty stuff for Apple's brand and the reputation of every person who works at Ap…

There is a plausible argument that Apple needed to give a little in order to avoid the creation of laws against any encryption. And/Or also avoid laws that required a backdoor to everything. I know I'm going to be called a fanboy or too generous to Apple, but given that the government has used every opportunity to call out Apple for not helping (when they have helped where they could) there is a line here that Apple…

What you say makes sense. Still, if that’s the case, then when they decided not to go down the user-is-in-full-and-absolute-control path for encryption of iCloud backups, they should have publicized it loudly and with extreme clarity on what exactly was happening and where the lines were. So that users could make informed choices.

Re: Apple dropped plan for encrypting backups after FBI complained

#392
post #253

Earlier quoted context omitted.

As in run an OSX vm so you can run a backup? You're only allowed to virtualize OSX on Apple hardware.

"You're only allowed to virtualize OSX on Apple hardware." Haha, good one. Who cares?

I mean, I do. It's a pain in the ass to legally integrate our MacOS app into our normal CI/CD pipeline because of this.

It also does put a shelf life on the underlying software in a way that even crazy old computer software like for an IBM 700 series doesn't have.

Re: Apple dropped plan for encrypting backups after FBI complained

#393
post #237

Earlier quoted context omitted.

They botched the original Windows Phone through a failure of management. They botched subsequent pushes on it because the bootstrapping problem around apps had grown too deep. At this point, if they tried to give it another go, there would be trust issues: "Am I investing in a phone ecosystem that's going to be dead in a few years?" Not to mention how much they've gone all-in on Android development. A Surface-branded…

Microsoft already announced a Surface Android phone: https://arstechnica.com/gadgets/2019/10/microsofts-first-and... It's supposed to come out later this year. There's definitely a differentiator, at least. Apparently they've forgotten what happened to the many previous attempts at dual-screen phones and tablets.

Yeah, I forgot about that one, although it's not really primarily "the Surface of Android phones"; it's an experimental form factor that happens to be lumped under the Surface brand because why not.

Re: Apple dropped plan for encrypting backups after FBI complained

#394
post #57

Apple has a list for that: https://support.apple.com/en-us/HT202303 These are end to end: Home data Health data (requires iOS 12 or later) iCloud Keychain (includes all of your saved accounts and passwords) Payment information QuickType Keyboard learned vocabulary (requires iOS 11 or later) Screen Time Siri information Wi-Fi passwords The messages also end to end but the backup contains the private key. The moral of…

Two things: 1) There is no way Apple would be allowed to sell iPhones in China, without China government having access to anything. So, I assume that Apple users in China have e2e encrypted exactly nothing. 2) I have a strong suspicion that those 'enter your Apple ID password because your account needs it' message really means 'a government has requested your data and even though it's encrypted, we will nag you about…

>1) There is no way Apple would be allowed to sell iPhones in China, without China government having access to anything. So, I assume that Apple users in China have e2e encrypted exactly nothing.

E2E works exactly the same in China. You can read more in my comments here:

https://news.ycombinator.com/item?id=20904857

The same "vulnerability" of being able to respond to legal requests for iCloud data that exists in China exists everywhere else in the world.

Re: Apple dropped plan for encrypting backups after FBI complained

#395
post #228

Wonder if this will help to kill a meme, about how much Apple cares about users and what great values they have, how they're going to stand for the user, fight with governments, etc. While iPhone itself is pretty secure as a device phone (and Apple makes sure to remind you about that in each ad, public speaking, attacks on competitors, etc), as an ecosystem it's not secure. And it's like that on purpose - there's no…

>While iPhone itself is pretty secure as a device phone I simply don't understand why people would blindly believe marketing material from a for-profit corporation. It's a device running closed source software. There is no way to prove this claim. If anything, Apple has been caught in the past sending very very personal sensitive information [1]. [1] https://www.theguardian.com/technology/2019/jul/26/apple-con...

> would blindly believe marketing material from a for-profit corporation

I am equally likely to believe or disbelieve marketing material from non-profits. Look at the malfeasance and lies from the Red Cross [1] -- or the sky-is-falling proclamations from the net neutrality crowd -- predictions of doom that never came to pass -- not to mention the lied-about motivations around net neutrality (the real motivation was about who pays for bandwidth.) [2]

[1] https://www.propublica.org/article/red-cross-ceo-has-been-mi... [2]

Re: Apple dropped plan for encrypting backups after FBI complained

#396

Earlier quoted context omitted.

That definately isn't meaningfully true, because MacOS devices without enclaves can function as iMessage clients.

This is a really good point; I don't use Messages on my Mac so I forget that's an option. Maybe the concept is the same, but on a Mac the private key is stored in the Keychain instead of a physical enclave?

I think it is in keychain, but my understanding is that Secure Enclave keys cannot be exported.

Re: Apple dropped plan for encrypting backups after FBI complained

#397
post #56

Earlier quoted context omitted.

You should look into the 'borg' backup tool - it has become the de facto standard for remote backups because it does everything that rsync does (efficient, changes only backups) but also produces strongly encrypted remote backup sets that only you have a key to ... your cloud provider has no access to the data. The borg website is here: https://borgbackup.readthedocs.io/en/stable/ and a good description of how it wor…

After looking at a few alternatives (Borg, Duplicacy etc.), I setup Arq on my Mac yesterday. One thing that irks me about these solutions is that they seem to scan my folders each time they want to backup. Are there tools that are smarter about this? For e.g., while running, they could keep a log of what's changing and only scan those while backing up.

I've been thinking about setting up a backup for my Mac for a while now. How long does it usually take to scan your folders during a backup?

Re: Apple dropped plan for encrypting backups after FBI complained

#398
post #384

Earlier quoted context omitted.

You'd have multiple trusted independent parties from multiple international jurisdictions reviewing the hardware design, not just one. And yes, obviously the X-Ray machines would need to be verified using similar techniques.

But how do I trust the independent parties?

The same way you trust anybody? If you're so paranoid that you believe literally everyone is out to get you, then you're not going to be able to function in any society, let alone one as interconnected and interdependent as our own.

Re: Apple dropped plan for encrypting backups after FBI complained

#399

Earlier quoted context omitted.

>Wonder if this will help to kill a meme, aboyt how much Apple cares about users and what great values they have, Probably not. The keyboards on their laptops are barely functional but it doesn't stop people from saying how great they are.

> The keyboards on their laptops are barely functional This must be some definition of "barely functional" I'm unfamiliar with. I've had a mid-2017 MBP since they were released. Yeah, I had to get the keyboard replaced when some keys failed after a year, but at least they did it for free. Actually, overall I prefer this keyboard to the 2013 I had previously. I think their failure rate is unacceptable, but they are ce…

On my second company issued MBP (with the touchbar) now, keyboard is starting to fail again. Stuck spacebar. Last time it was the period key.

Even crappy Acer laptops from the 2000s had longer lifespans.

Re: Apple dropped plan for encrypting backups after FBI complained

#400
post #337

Earlier quoted context omitted.

It could be signalling one is a far more attractive target to exploit, because e.g. harden shell, soft interior (M&M architecture). Or maybe Apple patches quicker and gets them out quicker, so exploit lifetime is shorter. Just to be clear, I don't know if that's true, but it's equally plausible explanation for the exploit price

That's a good point- there are nine times as many Android devices out there as iOS devices, making exploits for the former more valuable in certain ways.

The people with iOS devices probably have 9-times the money mind you?
Post reply on HN