Live data from Hacker News

Apple pulls data protection tool after UK government security row

bbc.com

441–450 of 1001 posts

Re: Apple pulls data protection tool after UK government security row

#441

I have a naive question, and it's genuine curiosity, not a defence of what's happening here. This ADP feature has only existed for a couple of years, right? I understand people are mad that it's now gone, but why weren't people mad _before_ it existed? For like, a decade? Why do people treat iCloud as immediately dangerous now, if they didn't before? Did they think it was fully encrypted when it wasn't? Did people no…

An E2E encrypted thing that later gets a special backdoor added is obviously much worse than a not E2E encrypted thing.

It's like when google suddenly decided that their on-device-only 2FA app Google Authenticator should get an opt-out unencrypted cloud backup.

It means people who don't pay a lot of attention can suddenly have much less protection than they were originally sold on.

Re: Apple pulls data protection tool after UK government security row

#442
post #106

Too right, it was far more problematic than they ever made out. > The UK government's demand came through a "technical capability notice" under the Investigatory Powers Act (IPA), requiring Apple to create a backdoor that would allow British security officials to access encrypted user data globally. The order would have compromised Apple's Advanced Data Protection feature, which provides end-to-end encryption for iCl…

> have an Android device beside me that regularly asks me to back my device up to the cloud But is that backup encrypted? If it's not, all they need is to access your data. This is about having access to backups that are theoretically encrypted with a key Apple doesn't have? > We're talking about the largest back door I've ever heard of. Doesn't the US have access to all the data of non US citizens whose data is stor…

> non US citizens whose data is stored in the US

They don't even care where it's stored...

See: CLOUD Act [1]

[1] https://en.wikipedia.org/wiki/CLOUD_Act

Re: Apple pulls data protection tool after UK government security row

#443
> Online privacy expert Caro Robson said she believed it was "unprecedented" for a company "simply to withdraw a product rather than cooperate with a government".

> "It would be a very, very worrying precedent if other communications operators felt they simply could withdraw products and not be held accountable by governments," she told the BBC.

Attributing this shockingly pro-UK-spy-agencies quote to an "online privacy expert" without pointing out she consults for the UN, EU and international military agencies is typical BBC pro-government spin. In fact, Caro, it would be "very, very worrying" if communications operators didn't withdraw a product rather than be forced to make it deceptive and defective by design.

Re: Apple pulls data protection tool after UK government security row

#444
post #106

Too right, it was far more problematic than they ever made out. > The UK government's demand came through a "technical capability notice" under the Investigatory Powers Act (IPA), requiring Apple to create a backdoor that would allow British security officials to access encrypted user data globally. The order would have compromised Apple's Advanced Data Protection feature, which provides end-to-end encryption for iCl…

> Apple is the only company audibly making a stand

Apples stand is false, they take with one hand and give with the other. There have been many times that Apple have been caught giving user data to governments at their request, lied about it, then later on admitted it once it had leaked from another source.

This whole 'we will never make a backdoor' is a complete whitewash marketing stunt, why do they need to make a backdoor when they are providing any and all metadata to any government on request.

https://www.macrumors.com/2023/12/06/apple-governments-surve...

Re: Apple pulls data protection tool after UK government security row

#445

Earlier quoted context omitted.

I asked if your Android backup is encrypted. Implies I'm talking about unencrypted data. > See, for example, the Las Vegas shooter case I am not in Las Vegas or anywhere else in the US. So as far as i know all the data about me that is stored in the US is easily accessible without a warrant unless it's encrypted with a key that's not available with the storage. > companies are not compelled to build systems which ena…

This is why Apple, and more recently Google, create systems where they don't have access to your unencrypted data on their servers. > Google Maps is changing the way it handles your location data. Instead of backing up your data to the cloud, Google will soon store it locally on your device. https://www.theverge.com/2024/6/5/24172204/google-maps-delet... You can't be forced to hand over data on your servers that you…

> You can't be forced to hand over data on your servers that you don't have access to, warrant or no.

But you can be forced to record and store that data even if you don't want to.

Re: Apple pulls data protection tool after UK government security row

#446

Earlier quoted context omitted.

Would just upload the keys

Presumably these keys live in a hardware security module on your phone called “secure enclave” and cannot be extracted

From the Advanced Data Protection whitepaper [0], it appears the keys are stored in the iCloud Keychain domain, so not the Secure Enclave:

> Conceptually, Advanced Data Protection is simple: All CloudKit Service keys that were generated on device and later uploaded to the available-after-authentication iCloud Hardware Security Modules (HSMs) in Apple data centers are deleted from those HSMs and instead kept entirely within the account’s iCloud Keychain protection domain. They are handled like the existing end-to-end encrypted service keys, which means Apple can no longer read or access these keys.

[0]: https://support.apple.com/guide/security/advanced-data-prote...

Re: Apple pulls data protection tool after UK government security row

#447
post #423

Earlier quoted context omitted.

Nope. I actually think that would bring more scrutiny and so I feel safer knowing it's not be cracked.

interesting and illogical reply

No more illogical than trusting Apple's security because it is ... Apple.

Re: Apple pulls data protection tool after UK government security row

#448
post #400
post #228

Earlier quoted context omitted.

> how can you “pull” E2E encryption without data loss? What happens to those that had this enabled? They'll keep your data hostage and disable your iCloud account. Clever, huh? So they are not deleting it, just disabling your account. "If you don't like it, make your own hardware and cloud storage company" kind of a thing.

More like "If you don't like it, talk to your local politicians", which is, IMO, a totally valid approach.

> "If you don't like it, talk to your local politicians",

Indeed people only noticed this because Apple tried to do the right thing and now it's somehow also Apple's fault. No good deed goes unpunished, I guess.

I think there is a feeling the government power is so overwhelming that they are hoping maybe some trillion dollar corporation would help them out somehow.

Re: Apple pulls data protection tool after UK government security row

#449
post #107

Earlier quoted context omitted.

> let the people pressure the government. Hopefully they will.

I can't imagine many here (UK) will really care, we've had multiple breeches of privacy imposed on us by the powers that be. - Removed incorrect assumption of this not being reported.

I agree, have an upvote.

Even though its making the media headlines today, 99% of UK citizens will forget this tomorrow and it will fade into the mists of time. Just like evey other security infringement that any government has imposed on its citizens.

Re: Apple pulls data protection tool after UK government security row

#450
Many people might not be aware of it, but Apple publishes a breakdown of the number of government requests for data that it receives, broken down by country.

The number of UK requests has ballooned in recent years: https://www.apple.com/legal/transparency/gb.html#:~:text=77%...

Much of this is likely related to the implementation and automation of the US-UK data access agreement pursuant to the CLOUD Act, which has streamlined this type of request by UK law enforcement and national security agencies.

Post reply on HN