Live data from Hacker News

Apple will notify users about state-sponsored cybersecurity threats

support.apple.com

51–60 of 166 posts

Re: Apple will notify users about state-sponsored cybersecurity threats

#51

Earlier quoted context omitted.

I assume they have iMessage metadata on what accounts the NSO accounts talked to. The contents are E2E encrypted, but unless they have explicitly promised not to keep logs, they probably have the metadata logged.

Apple claims in their lawsuit that they have over 100 false iCloud accounts that were created, and is confident in their identities to the degree they are going to use them for standing to prove that NSO signed a legal agreement in the lawsuit. In which case, NSO f!@#ed up and left iCloud Messages Backup enabled, which stores unencrypted copies of the End-to-End messages and makes it trivial for Apple to alert any pe…

Because the NSO group definitely used iMessage to communicate with one another...

Re: Apple will notify users about state-sponsored cybersecurity threats

#55

Earlier quoted context omitted.

Apple claims in their lawsuit that they have over 100 false iCloud accounts that were created, and is confident in their identities to the degree they are going to use them for standing to prove that NSO signed a legal agreement in the lawsuit. In which case, NSO f!@#ed up and left iCloud Messages Backup enabled, which stores unencrypted copies of the End-to-End messages and makes it trivial for Apple to alert any pe…

Because the NSO group definitely used iMessage to communicate with one another...

Not with one another. With targets

Re: Apple will notify users about state-sponsored cybersecurity threats

#56

I see a lot of people in the comments conflating legal requests and attacks. Regardless of your opinion on either of those issues, they are different things.

NSA surveillance is illegal. Will we be notified?

By "legal request" I mean requests made through channels of the law. These things aren't "attacks" because they're functionally not attacks. 'Cooperation' is the antithetical to 'attack'.

For example, when China demanded that iCloud for Chinese users was handed over to GCBD[0], and Apple complied, it was not, in any way, something that would be accurately described as an "attack". Apple cooperated with the demands that the legal environment presented.

[0] https://www.apple.com/legal/internet-services/icloud/en/gcbd...

Re: Apple will notify users about state-sponsored cybersecurity threats

#57

Earlier quoted context omitted.

No, I'm referring to Apple's continued cooperation with surveillance agencies across the United States and all associated governments through the FIVE EYES program. The fact that your Macbook's security keys are trivial for the government to acquire is besides the point, but potentially germane if you, well, trusted your laptop in the first place.

Can you provide citation for this? Also how they are different from any other tech company? My MacBooks security keys are not trivial to acquire because they aren’t in icloud. In some of the countries in five eyes nations, you don’t have a choice about cooperating or not. But what do 5 eyes have to do with Chinese users?

> Can you provide citation for this?

Apple's cooperation with PRISM[0] is well documented[1], but if you want to find the particularly damning details you'll need to do your own research. The dust has settled since the Snowden revelations, and many mentions of the program have been sterilized.

> Also how they are different from any other tech company?

It's not. But the claim that Apple puts extra effort into protecting you from your government is comical, especially if you live in a first-world country. It's also a false dichotomy, since there are definitely more secure devices you could be using. They're just not being manufactured by the largest, most valuable companies in the world.

> My MacBooks security keys are not trivial to acquire because they aren’t in icloud.

That is indeed what the US would like you to think. It's no coincidence that Macbooks force you to use NIST-designed crypto for all of their services though, and if you've got a healthy degree of skepticism towards the same institute that backdoored Dual_EC_DRBG, it's safe to assume the rest of these ciphers are also vulnerable to differential cryptanalysis. Or just take what the NSA says at face value, that certainly won't cause any problems in the future. /s

> But what do 5 eyes have to do with Chinese users?

Also nothing, they have their own bespoke surveillance program since China cannot cooperate with the US like Britain or Canada can. In lieu of being able to break their encryption, China demanded that all of Apple's domestic data get stored on domestic servers. While Google, Microsoft, Yahoo and every other big tech company shied away from that kind of compliance with a known abuser of human rights, Apple happily complied with the request.

[0] https://www.theguardian.com/world/2013/jun/06/us-tech-giants...

[1] https://web.archive.org/web/20130609061546/https://www.culto...

Re: Apple will notify users about state-sponsored cybersecurity threats

#58

Earlier quoted context omitted.

Apple claims in their lawsuit that they have over 100 false iCloud accounts that were created, and is confident in their identities to the degree they are going to use them for standing to prove that NSO signed a legal agreement in the lawsuit. In which case, NSO f!@#ed up and left iCloud Messages Backup enabled, which stores unencrypted copies of the End-to-End messages and makes it trivial for Apple to alert any pe…

Because the NSO group definitely used iMessage to communicate with one another...

[deleted]

Re: Apple will notify users about state-sponsored cybersecurity threats

#59

Earlier quoted context omitted.

No, I'm referring to Apple's continued cooperation with surveillance agencies across the United States and all associated governments through the FIVE EYES program. The fact that your Macbook's security keys are trivial for the government to acquire is besides the point, but potentially germane if you, well, trusted your laptop in the first place.

Can you provide citation for this? Also how they are different from any other tech company? My MacBooks security keys are not trivial to acquire because they aren’t in icloud. In some of the countries in five eyes nations, you don’t have a choice about cooperating or not. But what do 5 eyes have to do with Chinese users?

You shouldn't argue with @smoldesu, he has a history of trying to troll and spread FUD about Apple at every possible opportunity, even on completely unrelated topics. It's so ridiculous, a complaint about it is the #1 result on Google if you type "smoldesu" in. They also are not typically the most factual of complaints but they aren't interested in corrections. Beats me why the mods haven't sent warnings.
Post reply on HN