Too right, it was far more problematic than they ever made out. > The UK government's demand came through a "technical capability notice" under the Investigatory Powers Act (IPA), requiring Apple to create a backdoor that would allow British security officials to access encrypted user data globally. The order would have compromised Apple's Advanced Data Protection feature, which provides end-to-end encryption for iCl…
Apple pulls data protection tool after UK government security row
641–650 of 1001 posts
Re: Apple pulls data protection tool after UK government security row
#642Earlier quoted context omitted.
Small arms are no match for drones and a fully armed military, a successful rebellion by any populace against a first world military is impossible unless the military lays their arms down voluntarily, full stop.
Rebels are able to use techniques that a government never could or would. I think you underestimate the usefulness of small arms in guerilla warfare.
Re: Apple pulls data protection tool after UK government security row
#643Note that this doesn’t satisfy the government’s original request, which was for worldwide backdoor access into E2E-encrypted cloud accounts. But I have a more pertinent question: how can you “pull” E2E encryption without data loss? What happens to those that had this enabled? Edit: Part of my concern is that you have to keep in mind Apple's defense against backdooring E2E is the (US) doctrine that work cannot be comp…
> the (US) doctrine that work cannot be compelled Is this actually a thing? Telecoms in the US are compelled to provide wiretap facilities to the US and state and local governments.
It’s really not "work” but speech. That’s why telecoms can be compelled to wiretap. But code is speech [2], signing that code is also speech, and speech is constitutionally protected (US).
The tension is between the All Writs Act (requiring “third parties’ assistance to execute a prior order of the court”) and the First Amendment. [1]
So Apple may be compelled to produce the iCloud drives the data is stored on. But they can’t be made to write and sign code to run locally in your iPhone to decrypt that E2EE data (even though obviously they technologically could).
[1]: https://www.eff.org/deeplinks/2015/10/judge-doj-not-all-writ...
[2]: https://www.eff.org/deeplinks/2015/04/remembering-case-estab...
Re: Apple pulls data protection tool after UK government security row
#644Re: Apple pulls data protection tool after UK government security row
#645Fundamentally, I think the issue is more about technical literacy amongst the political establishment who consistently rely on the fallacy that having nothing to hide means you have nothing to fear. Especially in the UK which operates as a paternalistic state and enjoys authoritarian support across all parties. On the authoritarianism: these laws are always worded in such a way that they can be applied or targeted va…
Furthermore, one UK head of state call everyone supporting encryption pedophiles https://x.com/BenWallace70/status/1892972120818299199
What on earth are you talking about?
Charles III is head of state, and before that, Liz II. The monarch absolutely does not get involved in politics.
Re: Apple pulls data protection tool after UK government security row
#646Too right, it was far more problematic than they ever made out. > The UK government's demand came through a "technical capability notice" under the Investigatory Powers Act (IPA), requiring Apple to create a backdoor that would allow British security officials to access encrypted user data globally. The order would have compromised Apple's Advanced Data Protection feature, which provides end-to-end encryption for iCl…
I don't think the e2e icloud backup is problematic under existing legislation / before the TCN. While you can't disclose the key because it lives in the secure enclave, you can disclose the information that is requested because you can log into your apple account and retrieve it. IANAL, but I believe this to be sufficient (and refusing would mean jail).
The Investigatory Powers Act allows for technical capability notices, and the TCN in this case says (as far as we know) "allow us a method to be able to get the contents of any iCloud backup that is protected by E2EE for any user worldwide". This means that there is no need to ask the target to disclose information and if implemented as asked, also means that any user worldwide could be a target of the order, even if they'd never been to the UK.
Relevant info:
- https://wiki.openrightsgroup.org/wiki/Regulation_of_Investig...
Re: Apple pulls data protection tool after UK government security row
#647Re: Apple pulls data protection tool after UK government security row
#648Earlier quoted context omitted.
Would just upload the keys
Presumably these keys live in a hardware security module on your phone called “secure enclave” and cannot be extracted
Re: Apple pulls data protection tool after UK government security row
#649Earlier quoted context omitted.
opinion: any government that "needs" such control, is an enemy of the people and must be abolished, and anyone can morally and ethically do so
Well it’s important that the argument is correct. They view ending end-to-end encryption as a way to restore the effectiveness of traditional warrants. It isn’t necessarily about mass surveillance and the implementation could prevent mass surveillance but allow warrants. I oppose that because end to end encryption is still possible by anyone with something to hide, it is trivial to implement. I think governments shou…
Traditional warrants couldn't retroactively capture historical realtime communications because that stuff wasn't traditionally recorded to begin with.
> It isn’t necessarily about mass surveillance and the implementation could prevent mass surveillance but allow warrants.
The implementation that allows this is the one where executing a warrant has a high inherent cost, e.g. because they have to physically plant a bug on the device. If you can tap any device from the server then you can tap every device from the server (and so can anyone who can compromise the server).
Re: Apple pulls data protection tool after UK government security row
#650Earlier quoted context omitted.
Small arms are no match for drones and a fully armed military, a successful rebellion by any populace against a first world military is impossible unless the military lays their arms down voluntarily, full stop.
Every time this argument comes up, I just feel like rolling eyes, it is so overplayed. Yes, in a direct confrontation and an all out war, the populace stands no chance against the US military (assuming the military will unwaveringly side against the populace), no argument there. But an all out war is not an option, the government wouldn’t be trying to pulverize an entire nation and leave a rubble in place. If you com…