Live data from Hacker News

Apple pulls data protection tool after UK government security row

bbc.com

611–620 of 1001 posts

Re: Apple pulls data protection tool after UK government security row

#611

Earlier quoted context omitted.

> have an Android device beside me that regularly asks me to back my device up to the cloud But is that backup encrypted? If it's not, all they need is to access your data. This is about having access to backups that are theoretically encrypted with a key Apple doesn't have? > We're talking about the largest back door I've ever heard of. Doesn't the US have access to all the data of non US citizens whose data is stor…

Android data isn't encrypted at rest (or at least not in a way Google doesn't have the key). If the uk gov has a warrant, they can ask Google to provide your Google Drive content. The whole point of this issue is Apple specifically designed ADP so they couldn't do that.

Android backups are encrypted at rest using the lockscreen PIN or passphrase: https://developer.android.com/privacy-and-security/risks/bac...

So not hugely secure for most people if they use 4-6 decimal digits, but possible to make secure if you set a longer passphrase.

I don't know what Google's going to do about this UK business.

edit: Ah it looks like they have a Titan HSM involved as well. Have to take Google's word for it, but an HSM would let you do rate limits and lockouts. If that's in place, it seems all right to me.

Re: Apple pulls data protection tool after UK government security row

#612
post #106

Too right, it was far more problematic than they ever made out. > The UK government's demand came through a "technical capability notice" under the Investigatory Powers Act (IPA), requiring Apple to create a backdoor that would allow British security officials to access encrypted user data globally. The order would have compromised Apple's Advanced Data Protection feature, which provides end-to-end encryption for iCl…

> What concerns me more is that Apple is the only company audibly making a stand. But still Apple operates in China and Google does not. This is weird to me. Google left China when the government wanted all keys to the citizens data. Apple is making a stand when it's visible and does not threaten their business too much. Apple is not really in the business of protecting your data, they are just good at marketing and…

> Google left China when the government wanted all keys to the citizens data.

Google left China after China started hacking into Google's servers.

> In January, Google said it would no longer cooperate with government censors after hackers based in China stole some of the company’s source code and even broke into the Gmail accounts of Chinese human rights advocates.

https://www.nytimes.com/2010/03/23/technology/23google.html

They were working to reenter the China market on China's terms many years later, when Google employees leaked the effort to the press. Google eventually backed down.

Re: Apple pulls data protection tool after UK government security row

#613

I’m at the point where I’m ready to get a pixel and install graphene

Right but then you are jailed at Heathrow for not unlocking your phone. The UK has made it clear that Counter Terrorism legislation has no limits in UK law even if that means compromising all systems and leaving them vulnerable to state actor attacks. MPs will continue to use encrypted messaging systems that disappear messages during any inquiries of course.

Take a dumb phone (or none)?

Re: Apple pulls data protection tool after UK government security row

#615
Why can't governments simply compel every software developer to create a backdoor, or go to jail?

If even one government does it, then the backdoors exist globally. Here is an overview of the global situation: https://community.qbix.com/t/the-global-war-on-end-to-end-en...

Re: Apple pulls data protection tool after UK government security row

#616
post #562

Earlier quoted context omitted.

The government put in restrictions against using certain powers in the Investigatory Powers Act to spy on members of parliament (unless the Prime Minister says so, section 26), so I think they're just oblivious to the risk model of "when hackers are involved, the computer isn't capable of knowing the order wasn't legal". https://www.legislation.gov.uk/ukpga/2016/25/section/26

That actually shows they understand and care because they don't want the law to apply to them. They don't care about its effects on other people.

No, it shows they're thinking of computers like they think of police officers.

Computer literacy 101: to err is human, to really foul up requires a computer.

They don't understand that by requiring the capability for going after domestic criminals, they've given a huge gift to their international adversaries' intelligence agencies. (And given this is about a computer vulnerability, "international adversaries" includes terrorists, and possibly disgruntled teenagers, not just governments).

Re: Apple pulls data protection tool after UK government security row

#617
post #578

Earlier quoted context omitted.

You probably don't want to look up which US President tried to force Apple to insert an encryption back door into iPhones back in 2015. However, Google did only start moving to protect location data from subpoenas after people started to worry that location data could be used as a legal weapon against women who went to an abortion clinic, so your larger point stands.

That would be none, as it was the FBI, operating independently (as it's supposed to), which tried to force the issue. They even tried to go to Congress but found little support for their stunt. I'm not even sure Obama ever spoke in support of the backdoor, much less used any political power to make it a reality.

Sorry, but the FBI is part of the executive branch.

This is exactly like saying that President Trump has nothing to do with the actions of the executive branch agencies today.

Re: Apple pulls data protection tool after UK government security row

#618
post #438

Earlier quoted context omitted.

Presumably not, politicians have a way of excepting themselves in these types of laws. It's almost as if they understand the need for privacy, they just fail to apply that understanding to any scenarios beyond their own.

"Presumably not" Rubbish. Give me one example? They will have to abide as well.

Not a UK example, but Chat Control (2.0) explicitly exempts various politicians and government officials from being spied on.

Re: Apple pulls data protection tool after UK government security row

#619
post #106

Too right, it was far more problematic than they ever made out. > The UK government's demand came through a "technical capability notice" under the Investigatory Powers Act (IPA), requiring Apple to create a backdoor that would allow British security officials to access encrypted user data globally. The order would have compromised Apple's Advanced Data Protection feature, which provides end-to-end encryption for iCl…

> you think Google didn't already sign up to this? My understanding is that Android's Google Drive backup has had an E2E encryption option for many years (they blogged about it at https://security.googleblog.com/2018/10/google-and-android-h... ), and that the key is only stored locally in the Titan Security Module. If they are complying with the IPA, wouldn't that mean that they must build a mechanism into Android to…

My assumption is that Google has keys to everything in its kingdom [1].

[1] https://qz.com/1145669/googles-true-origin-partly-lies-in-ci...

Post reply on HN