Live data from Hacker News

Apple pulls data protection tool after UK government security row

bbc.com

581–590 of 1001 posts

Re: Apple pulls data protection tool after UK government security row

#581

I have a naive question, and it's genuine curiosity, not a defence of what's happening here. This ADP feature has only existed for a couple of years, right? I understand people are mad that it's now gone, but why weren't people mad _before_ it existed? For like, a decade? Why do people treat iCloud as immediately dangerous now, if they didn't before? Did they think it was fully encrypted when it wasn't? Did people no…

People learn stuff over time. If you are not living like RMS you probably are allowing something to spy on you. If that spying gets removed you become aware. You don't want it back.

It is like anything that gets better. Fight for the better. It is like aviation safety: who cares about a few crashes this year when people didn't complain in the 70s.

Re: Apple pulls data protection tool after UK government security row

#582
post #406

Earlier quoted context omitted.

At one point in time, the entirety of web communication was completely unencrypted. Why were people not mad then? Do you think people would be angrier now, if HTTPS were suddenly outlawed? Among other valid answers, removing rights and privileges generally makes people angrier than not having those rights or privileges in the first place.

> Why were people not mad then? Oh, we were. I am in the crowd who had been asking for generally used encryption since 1995. After all, we were already using SSH for our shell connections. The first introduction to SSL outside of internet banking and Amazon was for many online services to use encryption only for their login (and user preferences) page. The session token was then happily sent in the clear for all subs…

"We" is an special group. I am technical but never thought much about it back then. There is a boiling frog. The 90s internet was used for searching and silly emails. Now it has you life in the cloud. But that didn't happen in a day.

Re: Apple pulls data protection tool after UK government security row

#584

Earlier quoted context omitted.

> technical literacy amongst the political establishment who consistently rely on the fallacy that having nothing to hide means you have nothing to fear. That's an awfully generous assessment on your part. Kindly explain just what "technical literacy" has to do with the formulation you note. From here it reads like you are misdirecting and clouding the -intent- by the powerful here. Also does ERIC SCHMIDT an accompli…

I feel like the comment was clear, technical illiteracy leads politicians to believe that they'll be the only ones with access to this backdoor, which isn't true.

It isn't necessarily the case that they all care if criminals can get in to the average person's data so long as the authorities also can.

Re: Apple pulls data protection tool after UK government security row

#585
post #358

Fundamentally, I think the issue is more about technical literacy amongst the political establishment who consistently rely on the fallacy that having nothing to hide means you have nothing to fear. Especially in the UK which operates as a paternalistic state and enjoys authoritarian support across all parties. On the authoritarianism: these laws are always worded in such a way that they can be applied or targeted va…

What the politicians want is partial security: something they can crack but criminals can't. That is achievable in physical security, but not in cybersecurity. I have a feeling the politicians already know partial cybersecurity isn't an option, and don't care. Certainly, the intelligence community advising them absolutely does know. We don't even have to be conspiratorial about it: their jobs are easier in the world…

> That is achievable in physical security, but not in cybersecurity.

Not with physical security either, I'm afraid.

Re: Apple pulls data protection tool after UK government security row

#586
post #106

Too right, it was far more problematic than they ever made out. > The UK government's demand came through a "technical capability notice" under the Investigatory Powers Act (IPA), requiring Apple to create a backdoor that would allow British security officials to access encrypted user data globally. The order would have compromised Apple's Advanced Data Protection feature, which provides end-to-end encryption for iCl…

> you think Google didn't already sign up to this?

My understanding is that Android's Google Drive backup has had an E2E encryption option for many years (they blogged about it at https://security.googleblog.com/2018/10/google-and-android-h...), and that the key is only stored locally in the Titan Security Module.

If they are complying with the IPA, wouldn't that mean that they must build a mechanism into Android to exfiltrate the key? And wouldn't this breach be discoverable by security research, which tends to be much simpler on Android than it is on iOS?

Re: Apple pulls data protection tool after UK government security row

#588
post #562
post #524

Earlier quoted context omitted.

It's not literacy. They don't care. They need control, and if establishing control means increased risks for you, it's not something they see as a negative factor. It's your problem, not theirs.

The government put in restrictions against using certain powers in the Investigatory Powers Act to spy on members of parliament (unless the Prime Minister says so, section 26), so I think they're just oblivious to the risk model of "when hackers are involved, the computer isn't capable of knowing the order wasn't legal". https://www.legislation.gov.uk/ukpga/2016/25/section/26

That actually shows they understand and care because they don't want the law to apply to them. They don't care about its effects on other people.

Re: Apple pulls data protection tool after UK government security row

#589
post #414

Earlier quoted context omitted.

> that having nothing to hide means you have nothing to fear hopefully the US turning from leader of the free world to Russia's tool will give them the kick they need to realise that just because you trust the government now doesn't mean you trust the next government or the one after it.

> hopefully the US turning from leader of the free world to Russia's tool So much humour in one short phrase. Do you really believe your propaganda or is it just absentmindedly parroting pro permanent war talking points?

He demands $500bn of rare earth minerals, insists that Ukraine started the war by getting invaded and wants Zelensky to be replaced by a Russian puppet. It's amazing how the US went from the defender of the free world to just another thug.

Re: Apple pulls data protection tool after UK government security row

#590

Earlier quoted context omitted.

> technical literacy amongst the political establishment who consistently rely on the fallacy that having nothing to hide means you have nothing to fear. That's an awfully generous assessment on your part. Kindly explain just what "technical literacy" has to do with the formulation you note. From here it reads like you are misdirecting and clouding the -intent- by the powerful here. Also does ERIC SCHMIDT an accompli…

I feel like the comment was clear, technical illiteracy leads politicians to believe that they'll be the only ones with access to this backdoor, which isn't true.

Yeah. Not buying it. They know, or someone smart enough told them that backdoors can be accessed by anyone with enough skill. They just don't care because the people that are asking for this are criminals already and wanting profit off of other people's data.
Post reply on HN