Live data from Hacker News

Apple pulls data protection tool after UK government security row

bbc.com

551–560 of 1001 posts

Re: Apple pulls data protection tool after UK government security row

#551

Earlier quoted context omitted.

Presumably these keys live in a hardware security module on your phone called “secure enclave” and cannot be extracted

Is this module auditable though, or is "just trust us", like everything in the Apple world?

If someone has a reliable and workable secure enclave hack they can become a multi-millionaire for selling to state actors or become one of the most famous hackers in the world overnight (and possibly get a life changing amount of bounty from Apple)

Basically it's not a hack someone just throws on the internet for everyone to use, it's WAY too valuable to burn like that.

Re: Apple pulls data protection tool after UK government security row

#552
post #106

Too right, it was far more problematic than they ever made out. > The UK government's demand came through a "technical capability notice" under the Investigatory Powers Act (IPA), requiring Apple to create a backdoor that would allow British security officials to access encrypted user data globally. The order would have compromised Apple's Advanced Data Protection feature, which provides end-to-end encryption for iCl…

> One scenario would be somebody in an airport and security officials are searching your device No Heathrow connection necessary. “The law has extraterritorial powers, meaning UK law enforcement would have been able to access the encrypted iCloud data of Apple customers anywhere in the world, including in the US” [1]. [1] https://www.ft.com/content/bc20274f-f352-457c-8f86-32c6d4df8...

The US claims the same

https://en.wikipedia.org/wiki/CLOUD_Act

Lots of Americans in this thread seem to be talking down to other countries laws while being completely unaware of their own

Re: Apple pulls data protection tool after UK government security row

#553

>Online privacy expert Caro Robson said she believed it was "unprecedented" for a company "simply to withdraw a product rather than cooperate with a government. That is such a self serving comment. If Apple provides UK a backdoor, it weakens all users globally. With this they are following the local law and the country deserves what the rulers of the country want. These experts are a bit much. In the next paragraph t…

It's also just false. Google pulled out of China many years ago because they didn't want to bow to the Chinese government's demands.

And they didn't just withdraw a product, they withdraw their entire business.

Re: Apple pulls data protection tool after UK government security row

#554
post #106

Too right, it was far more problematic than they ever made out. > The UK government's demand came through a "technical capability notice" under the Investigatory Powers Act (IPA), requiring Apple to create a backdoor that would allow British security officials to access encrypted user data globally. The order would have compromised Apple's Advanced Data Protection feature, which provides end-to-end encryption for iCl…

> There's no time limit on when you may be searched, so all people who ever travelled through British territory could be searched by officials.

> Let that sink in for a moment. We're talking about the largest back door I've ever heard of.

Codename 'Krasnov' is the largest backdoor I have ever heard of. And, we only need to look at his behavior.

These E2EE from USA can be tainted in so many ways, and FAMAG sits on so much data, that codename 'Krasnov' can abuse such to target whoever he wants in West. Because everyone you know is or has been in ecosystem of Apple, Google, or Microsoft.

Whataboutism! Fair. From my PoV, as European, the UK government is (still) one of the good guys who will protect Europe from adversaries such as those who pwn codename 'Krasnov'. Such protection may come with a huge price.

Re: Apple pulls data protection tool after UK government security row

#555
post #488

Earlier quoted context omitted.

Just to be clear: Wallace is not a head of state, or even an MP any more. At one point, he was Secretary of State for Defence, a Cabinet position, however he resigned this in 2023. This doesn’t justify his position (it’s stupid) but he doesn’t speak for the current government.

To clarify a bit further, the UK head of state is King Charles III, as he is for a bunch of other countries in the Commonwealth. Head of state in the UK is a bit weird compared to countries that abolished or never had a monarchy.

Technically we did abolish the monarchy back in the 17th century, but the replacement was so bad we brought them back about 10 years later, which I think makes us a minority of one and even more weird.

Anyway, back on topic: this is a ridiculous law that is forcing services to erode their security while smart criminals can just use some nice free open-source software somewhere else for E2E communication. And a lot of this is definitely down to lawmakers not understanding technology.

Re: Apple pulls data protection tool after UK government security row

#556

Note that this doesn’t satisfy the government’s original request, which was for worldwide backdoor access into E2E-encrypted cloud accounts. But I have a more pertinent question: how can you “pull” E2E encryption without data loss? What happens to those that had this enabled? Edit: Part of my concern is that you have to keep in mind Apple's defense against backdooring E2E is the (US) doctrine that work cannot be comp…

> the (US) doctrine that work cannot be compelled

Is this actually a thing? Telecoms in the US are compelled to provide wiretap facilities to the US and state and local governments.

Re: Apple pulls data protection tool after UK government security row

#557
post #541

Earlier quoted context omitted.

“ They roll over without a peep.” What are you talking about? This is literally them doing the opposite, and there are multiple other public instances of them making a stand, not to mention in the design of their systems. Truly curious how you see this that way.

"Literally doing the opposite" would be keeping encryption on. Removing encryption for everyone is literally doing the opposite of making a stand

They had two paths to comply with the law. Silently backdoor the worldwide cloud serving every Apple device, or loudly tell people in the UK they don't get to have security because their government prohibits them. Between these two options, this is clearly "making a stand".

It's not as much "making a stand" as telling a major government that you have substantial seizable assets under their jurisdiction who is a major market you want to be in, that you're not going to do the thing that their laws say you are required to do, but it's hardly simple compliance either, instead of doing what the government wants them to do, they are making sure there is blowback.

Whether to try to fight it in court likely depends on details of case law and the wording of the laws they'd be contesting, I imagine much of the delay in their response to the demand was asking their lawyers how well they think they would fare in court.

Re: Apple pulls data protection tool after UK government security row

#558

I'm sympathetic to the J.D. Vance angle, which is that European governments are increasingly scared of their own people. This is not doing a lot to change my mind.

Governments should be scared of their people, though not in the way that I expect Vance means.

It's certainly better than the opposite, where citizens and residents are scared of their government, which wields the power to deprive them of their freedom, possessions, and life.

Re: Apple pulls data protection tool after UK government security row

#559

I have a naive question, and it's genuine curiosity, not a defence of what's happening here. This ADP feature has only existed for a couple of years, right? I understand people are mad that it's now gone, but why weren't people mad _before_ it existed? For like, a decade? Why do people treat iCloud as immediately dangerous now, if they didn't before? Did they think it was fully encrypted when it wasn't? Did people no…

i mainly use apple devices, but never put anything on icloud before adp came out.

Re: Apple pulls data protection tool after UK government security row

#560
post #106

Too right, it was far more problematic than they ever made out. > The UK government's demand came through a "technical capability notice" under the Investigatory Powers Act (IPA), requiring Apple to create a backdoor that would allow British security officials to access encrypted user data globally. The order would have compromised Apple's Advanced Data Protection feature, which provides end-to-end encryption for iCl…

> We're talking about the largest back door I've ever heard of.

Meh, I don't know. I can still decide to not go the UK and be fine. I think the CLOUD Act is much worse because it's independent from where I am.

Post reply on HN