Live data from Hacker News

Apple dropped plan for encrypting backups after FBI complained

reuters.com

641–650 of 734 posts

Re: Apple dropped plan for encrypting backups after FBI complained

#641

Earlier quoted context omitted.

Do you have any evidence that Apple rearchitected their system to have access to private keys that it doesn’t have access to anywhere, to have access to give it to China?

> And even though Chinese iPhones will retain the security features that can make it all but impossible for anyone, even Apple, to get access to the phone itself, that will not apply to the iCloud accounts. Any information in the iCloud account could be accessible to Chinese authorities who can present Apple with a legal order. > Apple said it will only respond to valid legal requests in China, but China’s domestic l…

Apple says the joint venture does not mean that China has any kind of “backdoor” into user data and that Apple alone – not its Chinese partner – will control the encryption keys. But Chinese customers will notice some differences from the start: their iCloud accounts will now be co-branded with the name of the local partner, a first for Apple.

Re: Apple dropped plan for encrypting backups after FBI complained

#642

Earlier quoted context omitted.

After looking at a few alternatives (Borg, Duplicacy etc.), I setup Arq on my Mac yesterday. One thing that irks me about these solutions is that they seem to scan my folders each time they want to backup. Are there tools that are smarter about this? For e.g., while running, they could keep a log of what's changing and only scan those while backing up.

Arq for Mac is great for backing up, though the restore util could use a little work. It's not exactly user friendly. I've used it on my macs for years without any issues at all. I switched after Time Machine broke down for the n'th time in a month saying it needed to recreate the backup, and not once in the 3-5 years i've been using it has it every given me any problems with broken repositories, and every integrity…

[deleted]

Re: Apple dropped plan for encrypting backups after FBI complained

#643

Earlier quoted context omitted.

After looking at a few alternatives (Borg, Duplicacy etc.), I setup Arq on my Mac yesterday. One thing that irks me about these solutions is that they seem to scan my folders each time they want to backup. Are there tools that are smarter about this? For e.g., while running, they could keep a log of what's changing and only scan those while backing up.

Arq for Mac is great for backing up, though the restore util could use a little work. It's not exactly user friendly. I've used it on my macs for years without any issues at all. I switched after Time Machine broke down for the n'th time in a month saying it needed to recreate the backup, and not once in the 3-5 years i've been using it has it every given me any problems with broken repositories, and every integrity…

> Duplicaty

Did you mean Duplicacy or Duplicati?

Re: Apple dropped plan for encrypting backups after FBI complained

#644
post #633

Earlier quoted context omitted.

> Apple has a balance to strike between the issues of encryption, privacy, and law enforcement [...] No, they do not. If Apple wants a reputation for privacy and respecting its customers, then it has to put them first. Don't apologize for them making this user-hostile choice. We could be merely a generation away from the hell hole that is social credit. We can't afford to keep ceding ground on privacy. We have to eng…

1. Yes, they have to. At least in the US any company has to cooperate with the law enforcement as you might know. The only choice to do business in the US or based on US governed soil is to comply with them. 2. Apple at least put some effort into this matter because otherwise there would not be so much media attention to breaking into iPhones. To get data from android on the other hand seems to be no problem at all.…

We do not have to cooperate with law enforcement. Encryption is still legal, even if law enforcement would prefer service providers not ever use it.

We have to comply with court orders. That’s it.

Re: Apple dropped plan for encrypting backups after FBI complained

#646
post #583

Earlier quoted context omitted.

You can back them up locally.

But you can't do so automatically. You have to open iTunes (or Finder) and explicitly click a button. If Apple is privacy-oriented, they should've allowed this long time ago. Unlike iCloud backups, this is certainly not a legal issue, as the "local" backups stored on one's computer are already fully encrypted.

If Apple were privacy-oriented then they would at least add a big red warning about reversible encryption when turning on cloud backups.

Re: Apple dropped plan for encrypting backups after FBI complained

#647
post #633

Earlier quoted context omitted.

> Apple has a balance to strike between the issues of encryption, privacy, and law enforcement [...] No, they do not. If Apple wants a reputation for privacy and respecting its customers, then it has to put them first. Don't apologize for them making this user-hostile choice. We could be merely a generation away from the hell hole that is social credit. We can't afford to keep ceding ground on privacy. We have to eng…

1. Yes, they have to. At least in the US any company has to cooperate with the law enforcement as you might know. The only choice to do business in the US or based on US governed soil is to comply with them. 2. Apple at least put some effort into this matter because otherwise there would not be so much media attention to breaking into iPhones. To get data from android on the other hand seems to be no problem at all.…

on 1.: Are there actually US laws that could prevent Apple from offering end-to-end encryption for backups to their user?

That is something very different from cooperating with a specific investigation.

Why did Apple not fight this in court?

Could Apple keep the backups outside the EU, like Microsoft did for email in the Dublin case?

Re: Apple dropped plan for encrypting backups after FBI complained

#648

Earlier quoted context omitted.

> And even though Chinese iPhones will retain the security features that can make it all but impossible for anyone, even Apple, to get access to the phone itself, that will not apply to the iCloud accounts. Any information in the iCloud account could be accessible to Chinese authorities who can present Apple with a legal order. > Apple said it will only respond to valid legal requests in China, but China’s domestic l…

Apple says the joint venture does not mean that China has any kind of “backdoor” into user data and that Apple alone – not its Chinese partner – will control the encryption keys. But Chinese customers will notice some differences from the start: their iCloud accounts will now be co-branded with the name of the local partner, a first for Apple.

From the same article:

> That means Chinese authorities will no longer have to use the U.S. courts to seek information on iCloud users and can instead use their own legal system to ask Apple to hand over iCloud data for Chinese users, legal experts said.

U.S. courts are highly unlikely to order Apple to release iCloud data to Chinese officials. Any cases would be public and attract international media attention. For Chinese iCloud users, that makes all the difference.

Re: Apple dropped plan for encrypting backups after FBI complained

#649

Wonder if this will help to kill a meme, about how much Apple cares about users and what great values they have, how they're going to stand for the user, fight with governments, etc. While iPhone itself is pretty secure as a device phone (and Apple makes sure to remind you about that in each ad, public speaking, attacks on competitors, etc), as an ecosystem it's not secure. And it's like that on purpose - there's no…

> Wonder if this will help to kill a meme, aboyt how much Apple cares about users and what great values they have, how they're going to stand for the user, fight with governments, etc. In this instance, Apple decided to continue to not encrypt iCloud backups because, according to one source, > […] the company did not want to risk being attacked by public officials for protecting criminals, sued for moving previously…

[deleted]

Re: Apple dropped plan for encrypting backups after FBI complained

#650

Earlier quoted context omitted.

Well said! I hope you have a similar principled stand on other pressing issues such as global poverty and health or factory farming. If we all focus on principles rather than just the convenient thing to do, the world would be a much better place for everyone :)

echelon did not claim to be someone who takes a principled stand on global poverty, health, or factory farming. https://en.wikipedia.org/wiki/Straw_man Meanwhile, Apple says: > Privacy is a fundamental human right. At Apple, it’s also one of our core values. Your devices are important to so many parts of your life. What you share from those experiences, and who you share it with, should be up to you. We design Apple…

Somehow it seems like you have mistaken my comment for sarcasm. I wasn’t straw manning anyone, I was simply lauding a principled stand and articulating my desire to see that in more places.

I certainly wasn’t defending Apple in this case.

Post reply on HN