Live data from Hacker News

U.K. orders Apple to let it spy on users’ encrypted accounts

washingtonpost.com

391–400 of 1001 posts

Re: U.K. orders Apple to let it spy on users’ encrypted accounts

#391
It's pretty funny that as the US implodes, UKGOV, instead of grasping the opportunity to show that they're the new good option for your internet service needs, decides to blow not one but both kneecaps clean off with the doubly whammy of the OSA/Ofcom debacle[0] and now this farce.

(I suppose the silver lining is that Starmer is merely sidling towards Trump as his new best mate rather than the full-throated slobbering that Johnson/Truss/Sunak would have given him.)

[0] I know this is primarily the fault of the last lot but this shower of onions haven't done anything to roll it back and/or clarify WTF is going on.

Re: U.K. orders Apple to let it spy on users’ encrypted accounts

#392
post #235

Earlier quoted context omitted.

This is the way that the UK has passed laws for a while now, make them so broad that they potentially criminalise everyone, then selectively prosecute. This is a very obvious setup for future totalitarianism. I’m surprised that the British public stands for it, but I guess they must not care.

People here are very passive and used to being pulled around. It's insane how far people's rights have eroded already. No right to protest, no right for privacy - what's next on the chopping block?

No right to be mean on social media, too.

Re: U.K. orders Apple to let it spy on users’ encrypted accounts

#393
post #47

I’m so ashamed to be a U.K. citizen and to have both legacy parties (Tories and Labour) staunchly supporting these horrendous breaches of privacy. We have had a number of bad laws over the last ten years that have entrenched state surveillance and presumption of guilt. The only party I can see taking a principled stance on civil liberties is Reform UK, whose policy document states: > A British Bill of Rights > Our fr…

In the past the Lib Dems were quite good at standing up for privacy and liberties when Lab and Con were both agreeing on more intrusion, but I'm not sure if that's still the case

Re: U.K. orders Apple to let it spy on users’ encrypted accounts

#394

Earlier quoted context omitted.

The EU has a law saying "don't transfer data out of the EU without the right paperwork, but of course if your American sysadmins have SSH access to servers in the EU to do maintenance that's no problem, just tell them not to copy the data off it" The US has a law saying "If our spies tell American sysadmins to SSH into a server in the EU and copy data off it, they must do it and they must keep it secret"

I’ve never worked in a company with data the gov’t cared about that wouldn’t have sirens going off. Why is Joe SSHing into the EU data center? And now why’s he trying to turn off the GuardDuty rule that caught him? And why is he trying to delete that from CloudTrail? And why is the SOC 2 auditor asking why he has access to delete things from CloudTrail in the first place?” You’d have to get a surprising number of peo…

That's why it's important to choose a sysadmin who has the authority to SSH to servers. Joe SSHes in all the time, it's not an anomaly.

If you think a SOC2 auditor would spot something like this, in a company the size of Apple or Google - you've probably never been through a SOC2 audit :)

Re: U.K. orders Apple to let it spy on users’ encrypted accounts

#395

Earlier quoted context omitted.

> prevent the UK authorities from interfering with their activities I'm still missing how this could be enforced ? To my layman understanding, this reads the same as if China said : "Meta, Tesla, Valve etc has entities in China therefore we get to see all data they store in the EU and the US. The UK has Zero jurisdiction in Ireland for example where a lot of EU data may be stored.

It can be enforced in this way: police raids the local headquarters and jail a bunch of people because their company didn't comply with the law. The only way to prevent that is not having any local office, no employees, nothing. Sell physical objects only by the means of local 3rd party resellers which will import goods. Same thing for services. Of course they can ban imports and services or go after those 3rd partie…

I suspect the UK government would back down way before Apple. People aren’t politically active as those of years pass, but brick their iPhones you’d have a riot.

Re: U.K. orders Apple to let it spy on users’ encrypted accounts

#396
post #90

Earlier quoted context omitted.

Apple still has legal entities in the UK. Pulling out cloud services would be insufficient to prevent the UK authorities from interfering with their activities.

More importantly, apple has customers in the UK. The business from captured apple users is more valuable than apple's privacy reputation. This all seems very similar to RIM and the aftermath of the riots in the UK. The backdoors became too obvious for customers to ignore. Did not go well for RIM in the market afterwards.

Who has more to lose though? I mean any government that would do something as stupid as banning Apple because Apple didn’t allow it to spy on its citizens wouldn’t be very popular or last that long..

I mean this would be even more stupid than Partygate and the whole Truss debacle put together.

Re: U.K. orders Apple to let it spy on users’ encrypted accounts

#397

Earlier quoted context omitted.

My gf doesn't have iCloud. She makes a backup from time to time by connecting her iphone to her macbook, encrypts the backup folder with 7z, and then I store the resulting file in my dropbox. I follow the same procedure with my Android phone, no google cloud. BTW anything I upload to Dropbox is encrypted first.

In case you don't already know, if you don't encrypt an iPhone backup with macOS first the backup won't contain _all_ of your data. Apple says "Encrypted backups can include information that unencrypted backups don't" however the list they give is non-exhaustive. You might find yourself disappointed when trying to restore a non-encrypted backup that you've encrypted yourself in a disaster scenario.

Thanks, will tell her to encrypt twice. Anyway, there is no critical info there, mainly photos.

Re: U.K. orders Apple to let it spy on users’ encrypted accounts

#399
post #325

Earlier quoted context omitted.

You're assuming that turning off ADP in the U.K. is sufficient to appease the British Government. The Investigatory Powers Act can also be interpreted to give the U.K. the right to ask for encrypted data from users outside of the U.K. (see Apple making this exact point in a filing here [1].) Turning off ADP in the U.K. doesn't end the controversy if that's what's at stake. [1] https://bsky.app/profile/matthewdgreen.b…

I mean, "Apple refuses to hand over private data to government at cost of UK business" is a pretty good headline.

Give Apple a big enough incentive to negotiate with and they may very well cave. If I've learned anything about corporations, it's that money and incentives always speak louder than their purported values.

Re: U.K. orders Apple to let it spy on users’ encrypted accounts

#400
post #79

> requires that Apple creates a back door that allows UK security officials unencumbered access to encrypted user data worldwide How could this even be enforced if Apple pulls out cloud services of the UK ? It's such a ridiculous request, the British Intelligence agencies must be bored coming up with new ways to make Apple look good.

MI6 probably gutted the cybersec division. Probably don’t have many viable sploits in their cache against Apple.

I suppose this is _good_ but more competent and well funded groups out of Israel, Israeli military complex, Cyprus don’t need to “ask” for a back door.

Post reply on HN