Live data from Hacker News

Apple dropped plan for encrypting backups after FBI complained

reuters.com

531–540 of 734 posts

Re: Apple dropped plan for encrypting backups after FBI complained

#531

Wonder if this will help to kill a meme, about how much Apple cares about users and what great values they have, how they're going to stand for the user, fight with governments, etc. While iPhone itself is pretty secure as a device phone (and Apple makes sure to remind you about that in each ad, public speaking, attacks on competitors, etc), as an ecosystem it's not secure. And it's like that on purpose - there's no…

[deleted]

Re: Apple dropped plan for encrypting backups after FBI complained

#532

Earlier quoted context omitted.

I would urge you to read up on the Chinese cryptography law [1] which took effect on the 1st of this year. Essentially all companies foreign or not must provide unencrypted access to data to the Chinese government and must do so in secrecy. Prior to this, companies were being compelled to give up their data anyways but this just makes things easier. By the way, the source below is an official Chinese government media…

Do you have any evidence that Apple rearchitected their system to have access to private keys that it doesn’t have access to anywhere, to have access to give it to China?

> It is the latest development in a pattern of Apple acquiescing to Beijing’s demands. Last July, Apple deleted VPN apps from the App Store that let mainland Chinese internet users evade censorship. Apple’s lawyers have also added a clause in the Chinese terms of service that states both Apple and GCBD may access all user data. Apple has not responded to requests for comment.

> Meanwhile, Chinese laws do not protect internet users’ privacy from government intrusion. In 2015, China passed a National Security Law, which included a provision to give police the authority to demand companies let them bypass encryption or other security tools to access personal data. The National People’s Congress was not available to comment.

https://www.theverge.com/2018/2/28/17055088/apple-chinese-ic...

Re: Apple dropped plan for encrypting backups after FBI complained

#533

Earlier quoted context omitted.

Nothing about assymetric crypto mandates that a 3rd party cant manage the key. In this case, CCP has the key.

Do you have any proof that Apple rearchitected their system to send private keys that were only stored on their device back to Apple?

The iCloud keys exist on the iCloud servers (which are under CCP control in China). That's how you can search your mail and documents from any device.

If you want to change the subject and talk about iMessage instead of iCloud, the architecture of that system allows for the government to intercept all messages as well. https://www.wired.com/2015/09/apple-fighting-privacy-imessag...

Re: Apple dropped plan for encrypting backups after FBI complained

#534

Earlier quoted context omitted.

Apple has never marketed the idea that iCloud backups are encrypted.

You need to be extremely technical to understand the difference between "Encryption: Yes" and not end-to-end encrypted. To the lay user, Apple is explicitly telling you that they're encrypted. See https://support.apple.com/en-us/HT202303 .

Nice trick. The big table in the beginning has "Yes" almost everywhere but in fact the data are accessible by Apple. And they don't even have warnings like "Your data might be decrypted and given to law enforcement agencies". Absolutely deceiving article although Apple hasn't written a single untrue word.

Re: Apple dropped plan for encrypting backups after FBI complained

#535

Wonder if this will help to kill a meme, about how much Apple cares about users and what great values they have, how they're going to stand for the user, fight with governments, etc. While iPhone itself is pretty secure as a device phone (and Apple makes sure to remind you about that in each ad, public speaking, attacks on competitors, etc), as an ecosystem it's not secure. And it's like that on purpose - there's no…

Damn.

I had somehow assumed that iCloud backups could not be accessed by Apple.

So that pretty much kills the meme for me.

Re: Apple dropped plan for encrypting backups after FBI complained

#536

Earlier quoted context omitted.

There is a plausible argument that Apple needed to give a little in order to avoid the creation of laws against any encryption. And/Or also avoid laws that required a backdoor to everything. I know I'm going to be called a fanboy or too generous to Apple, but given that the government has used every opportunity to call out Apple for not helping (when they have helped where they could) there is a line here that Apple…

Sadly, I think you are absolutely correct. Lindsay said outright that either tech companies figure it out, or senate will do the figuring for them. I am not sure Apple made the right move, but.. average person does not seem to care and/or understand the ikplications. Now.. Apple could make them care. They are big enough to make waves and I am not certain goverment could deal with bad PR come election time. edit: corr…

Sure, but if iOS was open enough, users who cared could use some third party online backup that was actually secure. And it could rely on an app that users could obtain, regardless of whether it was legal or not.

Re: Apple dropped plan for encrypting backups after FBI complained

#537
post #519

Earlier quoted context omitted.

They have never hidden how iCloud backups or anything else related to iOS security works. This support document spells out clearly what data is end-to-end encrypted [1]. No one was actually misled into thinking all iCloud data was E2E. For one, most of Apple's customers don't know or care about the technical architecture of their products and services. The people who do would have known better when you can go to iclo…

That link says: Backup Encryption In Transit: Yes Backup Encryption On Server: Yes

So it seems like the data are encrypted both in transit and on the server and it means that nobody is able to get unencrypted data even if they can intercept the traffic or access the server.

Re: Apple dropped plan for encrypting backups after FBI complained

#538

Earlier quoted context omitted.

The page you've linked to has a table filled entirely with the word Yes , apart from iCloud.com which has a note and Mail which has a note. The first entry in the table is: Backup Yes Yes At a glance this looks, to me, as though iCloud backups are encrypted. What am I missing?

If you scroll down another line you'll see another section titled: End-to-end encrypted data

When the very first line of that table tells people that iCloud Backups are encrypted on the server... to then have the last few lines add effectively "Oh, but not end to end!" is just taking the piss.

Re: Apple dropped plan for encrypting backups after FBI complained

#539

Earlier quoted context omitted.

Do you have any proof that Apple rearchitected their system to send private keys that were only stored on their device back to Apple?

The iCloud keys exist on the iCloud servers (which are under CCP control in China). That's how you can search your mail and documents from any device. If you want to change the subject and talk about iMessage instead of iCloud, the architecture of that system allows for the government to intercept all messages as well. https://www.wired.com/2015/09/apple-fighting-privacy-imessag...

I have not changed the subject. Apple clearly delineates which data is e2e encrypted and which data is not. Those same standards apply in the US and China - unless you have evidence otherwise.

I no more trust my privacy to the US government than a Chinese citizen should trust China.

Re: Apple dropped plan for encrypting backups after FBI complained

#540

What the... I was under the impression that iCloud backups are end-to-end encrypted. This is a HUGE problem.

End to End encryption doesn't work very well when the government nationalizes the servers with the end data and the keys to decrypt it. https://techcrunch.com/2018/07/17/apples-icloud-user-data-in...

Surely in the context of "End to End backups" the user is the "End" on both ends. The servers shouldn't have the keys. They can be as compromised as they want, but the most they should be able to see is when, how much and where from you're backing up data, but not the actual data.
Post reply on HN