Live data from Hacker News

Apple dropped plan for encrypting backups after FBI complained

reuters.com

601–610 of 734 posts

Re: Apple dropped plan for encrypting backups after FBI complained

#601
post #476

Wonder if this will help to kill a meme, about how much Apple cares about users and what great values they have, how they're going to stand for the user, fight with governments, etc. While iPhone itself is pretty secure as a device phone (and Apple makes sure to remind you about that in each ad, public speaking, attacks on competitors, etc), as an ecosystem it's not secure. And it's like that on purpose - there's no…

Do you have any personal recommendations on DIY iCloud alternatives?

Mega uses end-to-end encryption, and its clients are source-available. The hosting is fully managed, and there is no self-hosting option.

https://mega.nz

https://github.com/meganz

Seafile is end-to-end encrypted and open core. They offer a managed hosting option, and you can also self-host.

https://www.seafile.com

https://github.com/haiwen/seafile

Nextcloud is working on end-to-end encryption, but the feature is not yet stable. It is fully open source.

https://nextcloud.com/endtoend

https://github.com/nextcloud

Re: Apple dropped plan for encrypting backups after FBI complained

#602

Earlier quoted context omitted.

There is a plausible argument that Apple needed to give a little in order to avoid the creation of laws against any encryption. And/Or also avoid laws that required a backdoor to everything. I know I'm going to be called a fanboy or too generous to Apple, but given that the government has used every opportunity to call out Apple for not helping (when they have helped where they could) there is a line here that Apple…

There's no way to legislate backdoors now. They tried and failed with Clipper. The current status quo is good enough for the spooks. Zero regulation of data privacy allows third-party aggregators to do the desired collection activities without explicit government involvement. When they want something they know who to ask, warrant optional. Enacting laws that expose what the government is doing would risk a public bac…

Three things in the world are infinite:

- the universe

- human stupidity

- spooks' thirst for more data, backdoors, and monitoring ability

Re: Apple dropped plan for encrypting backups after FBI complained

#603
post #237

Earlier quoted context omitted.

> On the other hand, it's possible that because we have a smartphones duopoly, Apple only needs to maintain a position where people will say "well at least it's not as bad as Google". I'm upset about this personally, but I'm not ditching my iPhone. Of course, this does cement my decision to never pay for iCloud, for what that's worth (much less, but not nothing). Agreed, and I am likely going away from Android and in…

They botched the original Windows Phone through a failure of management. They botched subsequent pushes on it because the bootstrapping problem around apps had grown too deep. At this point, if they tried to give it another go, there would be trust issues: "Am I investing in a phone ecosystem that's going to be dead in a few years?" Not to mention how much they've gone all-in on Android development. A Surface-branded…

> A Surface-branded Android phone wouldn't be out of the question, but my gut tells me it would die a quiet death from thin margins and differentiators that aren't big enough for people to get excited.

It's coming.

https://www.theverge.com/2019/10/3/20895268/microsoft-surfac...

Re: Apple dropped plan for encrypting backups after FBI complained

#604

Earlier quoted context omitted.

I would urge you to read up on the Chinese cryptography law [1] which took effect on the 1st of this year. Essentially all companies foreign or not must provide unencrypted access to data to the Chinese government and must do so in secrecy. Prior to this, companies were being compelled to give up their data anyways but this just makes things easier. By the way, the source below is an official Chinese government media…

Do you have any evidence that Apple rearchitected their system to have access to private keys that it doesn’t have access to anywhere, to have access to give it to China?

> And even though Chinese iPhones will retain the security features that can make it all but impossible for anyone, even Apple, to get access to the phone itself, that will not apply to the iCloud accounts. Any information in the iCloud account could be accessible to Chinese authorities who can present Apple with a legal order.

> Apple said it will only respond to valid legal requests in China, but China’s domestic legal process is very different than that in the U.S., lacking anything quite like an American “warrant” reviewed by an independent court, Chinese legal experts said. Court approval isn’t required under Chinese law and police can issue and execute warrants.

https://www.reuters.com/article/us-china-apple-icloud-insigh...

Re: Apple dropped plan for encrypting backups after FBI complained

#605

Earlier quoted context omitted.

Regarding #1: iCloud in China is operated by a mainland Chinese company and subject to that company's terms and conditions. So you can pretty much assume iCloud data is completely accessible by the government. Source: https://support.apple.com/en-us/HT208351

Apple uses third party data centers, if it can't host encrypted data on a Chinese server without China having access to the data, there is something wrong with the encryption.

> On Wednesday, Apple officially handed over its iCloud operation in China to a local state-run company, along with all encryption keys to unlock local user data. The switch will give the Chinese government unfettered access to the photos, emails and contacts of over 240 million iPhone users in China.

https://observer.com/2018/03/apple-grants-china-full-control...

> "The simple fact is that once the encryption keys are stored on Chinese servers, they will be easier for Chinese authorities to access — with or without legal requests," says Sharon Hom, executive director of Human Rights in China, a US-based NGO. "Since Apple has declared its willingness to 'comply with Chinese law,' its reassurance that it, not its Chinese partner, would control the encryption keys is not exactly reassuring. In addition, Chinese authorities could bypass Apple to address their requests directly to Apple’s Chinese partner, a state-owned enterprise that, of course, would have to cooperate with Chinese authorities."

https://www.wired.co.uk/article/apple-icloud-china-iphone-da...

Re: Apple dropped plan for encrypting backups after FBI complained

#606

Earlier quoted context omitted.

Two things: 1) There is no way Apple would be allowed to sell iPhones in China, without China government having access to anything. So, I assume that Apple users in China have e2e encrypted exactly nothing. 2) I have a strong suspicion that those 'enter your Apple ID password because your account needs it' message really means 'a government has requested your data and even though it's encrypted, we will nag you about…

>1) There is no way Apple would be allowed to sell iPhones in China, without China government having access to anything. So, I assume that Apple users in China have e2e encrypted exactly nothing. E2E works exactly the same in China. You can read more in my comments here: https://news.ycombinator.com/item?id=20904857 The same "vulnerability" of being able to respond to legal requests for iCloud data that exists in Chi…

It was a reduction in security for Chinese iCloud users:

> The U.S. company is moving iCloud accounts registered in mainland China to state-run Chinese servers on Wednesday along with the digital keys needed to unlock them.

> In the past, if Chinese authorities wanted to access Apple's user data, they had to go through an international legal process and comply with U.S. laws on user rights, according to Ronald Deibert, director of the University of Toronto's Citizen Lab, which studies the intersection of digital policy and human rights.

> "They will no longer have to do so if iCloud and cryptographic keys are located in China's jurisdiction," he told CNNMoney.

https://money.cnn.com/2018/02/28/technology/apple-icloud-dat...

Re: Apple dropped plan for encrypting backups after FBI complained

#607

Earlier quoted context omitted.

What other devices perform all of the backup, restore, and os upgrade, functionality of iTunes. I've never claimed anything about any other functions of iTunes. I just said it was a problem that Apple devices make it difficult to get your data off using only local transfer. The iPhone doesn’t use the standard “usb mass storage” protocol to allow you to download pictures. It uses the picture transfer protocol. Yes, ex…

So it’s difficult to get data off of your device - even though you can get pictures and video off of your device like any camera and most other documents are stored in their own folders on iCloud - that you can get to either using the iCloud Drive app for Macs or Windows or by logging into iCloud.com.

Have you forgotten that the entire point of this discussion was that iCloud is not properly encrypted, which is why it is such a problem that local transfer of all data is so difficult?

Re: Apple dropped plan for encrypting backups after FBI complained

#608

Earlier quoted context omitted.

> Wonder if this will help to kill a meme, aboyt how much Apple cares about users and what great values they have, how they're going to stand for the user, fight with governments, etc. In this instance, Apple decided to continue to not encrypt iCloud backups because, according to one source, > […] the company did not want to risk being attacked by public officials for protecting criminals, sued for moving previously…

>Most people, including technically knowledgable users here on HN, were unaware iCloud backups have always been unencrypted. iCloud backups are definitely encrypted. They just aren't end-to-end encrypted. That should have been plainly obvious to any technically knowledgeable user because you don't lose your data forever when you forget your Apple ID password. Or the fact that you can see your photos through a web bro…

> That should have been plainly obvious to any technically knowledgeable user

As you can see from this discussion, there are a lot of technically knowledgeable people who did not find this "plainly obvious". It's disingenuous to blame users for Apple's misleading marketing.

Re: Apple dropped plan for encrypting backups after FBI complained

#609

Earlier quoted context omitted.

> Do they even let you disable location tracking any more? You're confusing iOS with Android. On iOS, every time you get your location, that location is also sent to Apple, and there is no way to disable this. Android's collection of this data is gated by a checkbox that is shown to every user on device setup.

Last time I used android there as no option for disabling location tracking as they had removed it a few major versions prior. Instead you had "enabled" and "kind of disabled, but not really" options

I have used Android devices since 1.0. They have all had the ability to disable location history and the ability to disable Google Location Services (under various names). Apple doesn't even give you the option of not sending GPS locations to Apple. If any app requests your location, Apple gets it too. https://support.apple.com/en-us/HT207056

Re: Apple dropped plan for encrypting backups after FBI complained

#610

Earlier quoted context omitted.

This is a really good point; I don't use Messages on my Mac so I forget that's an option. Maybe the concept is the same, but on a Mac the private key is stored in the Keychain instead of a physical enclave?

I think it is in keychain, but my understanding is that Secure Enclave keys cannot be exported.

It's not uncommon for software to claim to offer this feature. Windows does it for example, and it was a bug in such a feature for WebCrypto in Firefox that made the news recently here.

Invariably such features are weak and a sufficiently capable attacker can override them. In Windows for example you could reach into the opaque data structure and toggle the Boolean that forbids exporting keys...

Post reply on HN