Live data from Hacker News

Apple dropped plan for encrypting backups after FBI complained

reuters.com

541–550 of 734 posts

Re: Apple dropped plan for encrypting backups after FBI complained

#541

Wonder if this will help to kill a meme, about how much Apple cares about users and what great values they have, how they're going to stand for the user, fight with governments, etc. While iPhone itself is pretty secure as a device phone (and Apple makes sure to remind you about that in each ad, public speaking, attacks on competitors, etc), as an ecosystem it's not secure. And it's like that on purpose - there's no…

> Wonder if this will help to kill a meme, aboyt how much Apple cares about users and what great values they have, how they're going to stand for the user, fight with governments, etc. In this instance, Apple decided to continue to not encrypt iCloud backups because, according to one source, > […] the company did not want to risk being attacked by public officials for protecting criminals, sued for moving previously…

If unencrypted iCloud back ups is the price for us getting to keep fully encrypted devices, so be it

Re: Apple dropped plan for encrypting backups after FBI complained

#542
Unpopular opinion:

We users are better off if Apple is "compromising" on something like this at the stage we're in now - especially since nobody forces you to use iCloud Backups - than we'll be when/if the US gov makes Apple an offer it can't refuse and forces a real backdoor master-key on the whole system top to bottom.

Assumption: That not going full encrypted backups will prevent the government from having the political capital to enact a "crackdown" forcing a backdoor on the devices, iMessage, etc.

Re: Apple dropped plan for encrypting backups after FBI complained

#543
post #519

Earlier quoted context omitted.

That link says: Backup Encryption In Transit: Yes Backup Encryption On Server: Yes

So it seems like the data are encrypted both in transit and on the server and it means that nobody is able to get unencrypted data even if they can intercept the traffic or access the server.

Nobody except Apple, that is.

That's no different from me offering a remote backup service on a LUKS encrypted box, using sftp or whatever, and then making those claims.

Re: Apple dropped plan for encrypting backups after FBI complained

#544

Earlier quoted context omitted.

Sadly, I think you are absolutely correct. Lindsay said outright that either tech companies figure it out, or senate will do the figuring for them. I am not sure Apple made the right move, but.. average person does not seem to care and/or understand the ikplications. Now.. Apple could make them care. They are big enough to make waves and I am not certain goverment could deal with bad PR come election time. edit: corr…

Sure, but if iOS was open enough, users who cared could use some third party online backup that was actually secure. And it could rely on an app that users could obtain, regardless of whether it was legal or not.

The iPhone is plenty open for this. You just need a computer. The rest is fully open source.

https://www.libimobiledevice.org/

Re: Apple dropped plan for encrypting backups after FBI complained

#545
post #519

Earlier quoted context omitted.

That link says: Backup Encryption In Transit: Yes Backup Encryption On Server: Yes

So it seems like the data are encrypted both in transit and on the server and it means that nobody is able to get unencrypted data even if they can intercept the traffic or access the server.

The article says otherwise.

Re: Apple dropped plan for encrypting backups after FBI complained

#546
post #315

Earlier quoted context omitted.

> On the other hand, it's possible that because we have a smartphones duopoly, Apple only needs to maintain a position where people will say "well at least it's not as bad as Google". I'm upset about this personally, but I'm not ditching my iPhone. Of course, this does cement my decision to never pay for iCloud, for what that's worth (much less, but not nothing). Agreed, and I am likely going away from Android and in…

I'd argue that Android, without the Google stuff, is still the best option if you care about privacy and security. This is not accessible for average Joe, but I'm pretty certain the majority of readers here can use the tools to load an alternative ROM. That you can enable and use F-droid just fine. And are knowledgeable enough to know what apps to avoid.

Ironically, the best phones to do that are Google's own Pixels - to give credit where it's due, at least the phones have unlockable bootloaders (unless you buy the Verizon variants).

eg GrapheneOS currently only supports Pixel 2, 3 and 3a:

https://grapheneos.org/releases

Re: Apple dropped plan for encrypting backups after FBI complained

#547

Earlier quoted context omitted.

The iCloud keys exist on the iCloud servers (which are under CCP control in China). That's how you can search your mail and documents from any device. If you want to change the subject and talk about iMessage instead of iCloud, the architecture of that system allows for the government to intercept all messages as well. https://www.wired.com/2015/09/apple-fighting-privacy-imessag...

I have not changed the subject. Apple clearly delineates which data is e2e encrypted and which data is not. Those same standards apply in the US and China - unless you have evidence otherwise. I no more trust my privacy to the US government than a Chinese citizen should trust China.

> I have not changed the subject.

You started this thread by responding to somebody discussing the Chinese government's access to all iCloud data, but you changed the subject to talk about systems where the private key is on device, which does not apply to iCloud. You absolutely did change the subject.

> Those same standards apply in the US and China - unless you have evidence otherwise.

Those same standards don't actually protect your data from whoever controls the iCloud server or whoever controls the iMessage key server. In the US, that is Apple, so Apple has access to that data. In China, that is the Chinese government. Therefore, the Chinese government has access to all Chinese iCloud and iMessage data.

> I no more trust my privacy to the US government than a Chinese citizen should trust China.

Then you are unfamiliar with the laws of both countries.

Re: Apple dropped plan for encrypting backups after FBI complained

#548

Earlier quoted context omitted.

It would be trivial for the Chinese gov't to sniff RAM or the bus and get everything they need anyways.

What exactly are they going to “sniff”? Private keys never leave your device.

The keys that encrypt the iCloud data are never on your device. They don't even need to sniff the keys. They control them.

Re: Apple dropped plan for encrypting backups after FBI complained

#549

Earlier quoted context omitted.

If only iTunes worked reliably on Windows and didn't have a long track record of bugs, subtle usability issues causing catastrophic data loss, connection problems where it doesn't detect the device properly... Let me know when iPhones and iPads support standard plug and play protocols that work universally without relying on either Apple's proprietary and frequently broken software or someone else's commercial altern…

So there is a standard plug and play protocol that supports everything that iTunes does? iTunes hasn’t worked well on any platform in over a decade.

Is there a specialised protocol for all types of data stored on iOS devices? Probably not. But plenty of other models of phone, tablet, camera and other data-processing devices manage to communicate just fine with Windows (or Linux or macOS) using generic protocols as USB mass storage devices, there is little excuse for iOS devices not to. In fact, you actually can download your photos and videos from an iPhone to a Windows PC by just plugging it in and doing the same as you would with your camera, but ironically this only works if you haven't installed iTunes.

Re: Apple dropped plan for encrypting backups after FBI complained

#550

Earlier quoted context omitted.

What exactly are they going to “sniff”? Private keys never leave your device.

The keys that encrypt the iCloud data are never on your device. They don't even need to sniff the keys. They control them.

Apple clearly lists which data is e2e encrypted and which isn’t. The keys that encrypt e2e data is not stored on Apple’s servers.
Post reply on HN