Live data from Hacker News

Apple pulls data protection tool after UK government security row

bbc.com

391–400 of 1001 posts

Re: Apple pulls data protection tool after UK government security row

#391
post #326

Earlier quoted context omitted.

> have an Android device beside me that regularly asks me to back my device up to the cloud But is that backup encrypted? If it's not, all they need is to access your data. This is about having access to backups that are theoretically encrypted with a key Apple doesn't have? > We're talking about the largest back door I've ever heard of. Doesn't the US have access to all the data of non US citizens whose data is stor…

> Doesn't the US have access to all the data of non US citizens whose data is stored in the US without any oversight? Totally agree. Having this discussion so US centred just makes us miss the forest for the trees. Apart from data owned by US citizens, my impression is that data stored in the US is fair game for three letter agencies, and I really doubt most companies would spend more than five minutes agreeing with…

Agree in principle, though WhatsApp backups are encrypted with a user provided password, so ostensibly inaccessible to Google or whoever you use as backup

Re: Apple pulls data protection tool after UK government security row

#392

I have a naive question, and it's genuine curiosity, not a defence of what's happening here. This ADP feature has only existed for a couple of years, right? I understand people are mad that it's now gone, but why weren't people mad _before_ it existed? For like, a decade? Why do people treat iCloud as immediately dangerous now, if they didn't before? Did they think it was fully encrypted when it wasn't? Did people no…

Hacker News is a small subsection of the internet. I think the majority of people, probably 90% or more, simply do not care that much.

Re: Apple pulls data protection tool after UK government security row

#393

Earlier quoted context omitted.

I asked if your Android backup is encrypted. Implies I'm talking about unencrypted data. > See, for example, the Las Vegas shooter case I am not in Las Vegas or anywhere else in the US. So as far as i know all the data about me that is stored in the US is easily accessible without a warrant unless it's encrypted with a key that's not available with the storage. > companies are not compelled to build systems which ena…

> all the data about me that is stored in the US is easily accessible without a warrant No, law enforcement needs a warrant to legally access any data. This is why Prism was illegal, and why companies like Google are pushing back against overly broad geofence search warrants.

All Encrochat evidence was illegal in at least three different ways. UK Law enforcement didn't care. They just lied.

Re: Apple pulls data protection tool after UK government security row

#394
post #4

As someone currently a citizen of the UK, what are my best emigration opportunities?

If you value personal freedoms, you should go to East Europe. The more to the east, the better. Snowden went to Russia.

Kremlin has full access to every service operating in Russia. If a service is banned in Russia, that's a service you should use. If it's not banned, it already has a backdoor.

Re: Apple pulls data protection tool after UK government security row

#395

I’m at the point where I’m ready to get a pixel and install graphene

Right but then you are jailed at Heathrow for not unlocking your phone. The UK has made it clear that Counter Terrorism legislation has no limits in UK law even if that means compromising all systems and leaving them vulnerable to state actor attacks. MPs will continue to use encrypted messaging systems that disappear messages during any inquiries of course.

Except no one has ever been jailed for simply refusing to unlock a phone unless there was heavy evidence there was something on the phone.

Stop spreading incorrect FUD

Re: Apple pulls data protection tool after UK government security row

#396
post #106

Too right, it was far more problematic than they ever made out. > The UK government's demand came through a "technical capability notice" under the Investigatory Powers Act (IPA), requiring Apple to create a backdoor that would allow British security officials to access encrypted user data globally. The order would have compromised Apple's Advanced Data Protection feature, which provides end-to-end encryption for iCl…

It's always hilarious to see how far people here are ready to go to twist some bad Apple news into something which might be considered good.

I mean seriously. Apple making a stand? What stand? They are ripping security out of their customers hands. Customers which are already dependent on the company's decision in their locked in environment.

There is absolutely nothing good about it, and you dragging Android into it and making it look like it's even worse is suspicious. You can have full control over your Android device. Something impossible on an Apple phone. You can make your Android device safer than your iPhone.

Re: Apple pulls data protection tool after UK government security row

#397
post #326

Earlier quoted context omitted.

> have an Android device beside me that regularly asks me to back my device up to the cloud But is that backup encrypted? If it's not, all they need is to access your data. This is about having access to backups that are theoretically encrypted with a key Apple doesn't have? > We're talking about the largest back door I've ever heard of. Doesn't the US have access to all the data of non US citizens whose data is stor…

> Doesn't the US have access to all the data of non US citizens whose data is stored in the US without any oversight? Totally agree. Having this discussion so US centred just makes us miss the forest for the trees. Apart from data owned by US citizens, my impression is that data stored in the US is fair game for three letter agencies, and I really doubt most companies would spend more than five minutes agreeing with…

International users that have Advanced Protection enabled would in theory be safe from all of the 3-letter agencies (like safe from those agencies getting the data from Apple...not safe generally).

Realistically we are talking about FISA here, so in theory if the FBI gets a FISA court order to gather "All of the Apple account data" for a non-us person, Apple would either hand over the encrypted data OR just omit that....

Based on the stance Apple is taking here, its reasonable to assume they would do the same in the US (disable the feature if USG asked for a backdoor or attempted to compel them to decrypt)

Re: Apple pulls data protection tool after UK government security row

#398

Earlier quoted context omitted.

Small arms are no match for drones and a fully armed military, a successful rebellion by any populace against a first world military is impossible unless the military lays their arms down voluntarily, full stop.

Every time this argument comes up, I just feel like rolling eyes, it is so overplayed. Yes, in a direct confrontation and an all out war, the populace stands no chance against the US military (assuming the military will unwaveringly side against the populace), no argument there. But an all out war is not an option, the government wouldn’t be trying to pulverize an entire nation and leave a rubble in place. If you com…

I roll my eyes when I see this blissfully naive LARP/mallninja imagined scenario, but I do have to remind myself that the US was founded on the basis of forming a milita etc. and I would probably say the same thing if I had that upbringing. You forget that the vast majority of people are stupid and easily scared (this is not a solvable problem)

Help me out - how can policing possibly work if no one is legally required to be policed? You just end up with murderers, rapists etc. expressing their right to "resist" with arms like in spaghetti westerns. It is totally symbolic, and would crumble at the first instance of serious government interest of arresting 'troublemakers', which would of course start with a well crafted PR campaign to get the rest of the public on their side. I think it's naive.

Re: Apple pulls data protection tool after UK government security row

#399
The current EU-UK adequacy decision[1] is up for review this 27 June [2] .

Aspects of the UK investigatory powers act is close enough to US FISA [2] that I think this might have some influence, if brought up. IPA 2016 was known at the time of the original adequacy decision, but IPA was amended in 2024 . While some things might be improvements, the changes to Technical Capability Notices warrant new scrutiny.

Especially seeing this example where IPA leads to reduced security is of some concern, I should think. The fact that security can be subverted in secret might make it a bit tricky for the EU to monitor at all.

[1] https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...

[2] ibid. Article 4

[3] FISA section 702 https://www.govinfo.gov/content/pkg/BILLS-110hr6304pcs/html/...

Re: Apple pulls data protection tool after UK government security row

#400
post #228

Note that this doesn’t satisfy the government’s original request, which was for worldwide backdoor access into E2E-encrypted cloud accounts. But I have a more pertinent question: how can you “pull” E2E encryption without data loss? What happens to those that had this enabled? Edit: Part of my concern is that you have to keep in mind Apple's defense against backdooring E2E is the (US) doctrine that work cannot be comp…

> how can you “pull” E2E encryption without data loss? What happens to those that had this enabled? They'll keep your data hostage and disable your iCloud account. Clever, huh? So they are not deleting it, just disabling your account. "If you don't like it, make your own hardware and cloud storage company" kind of a thing.

More like "If you don't like it, talk to your local politicians", which is, IMO, a totally valid approach.
Post reply on HN