Live data from Hacker News

Apple pulls data protection tool after UK government security row

bbc.com

641–650 of 1001 posts

Re: Apple pulls data protection tool after UK government security row

#641
post #106

Too right, it was far more problematic than they ever made out. > The UK government's demand came through a "technical capability notice" under the Investigatory Powers Act (IPA), requiring Apple to create a backdoor that would allow British security officials to access encrypted user data globally. The order would have compromised Apple's Advanced Data Protection feature, which provides end-to-end encryption for iCl…

Even more shocking that Germany - my country - leads the leaderboard with over ten times as much requests as the second place.

Re: Apple pulls data protection tool after UK government security row

#642

Earlier quoted context omitted.

Small arms are no match for drones and a fully armed military, a successful rebellion by any populace against a first world military is impossible unless the military lays their arms down voluntarily, full stop.

Rebels are able to use techniques that a government never could or would. I think you underestimate the usefulness of small arms in guerilla warfare.

I think you underestimate the lethality of remotely piloted drones with missiles and IR cameras and the futility of fighting against them.

Re: Apple pulls data protection tool after UK government security row

#643
post #556

Note that this doesn’t satisfy the government’s original request, which was for worldwide backdoor access into E2E-encrypted cloud accounts. But I have a more pertinent question: how can you “pull” E2E encryption without data loss? What happens to those that had this enabled? Edit: Part of my concern is that you have to keep in mind Apple's defense against backdooring E2E is the (US) doctrine that work cannot be comp…

> the (US) doctrine that work cannot be compelled Is this actually a thing? Telecoms in the US are compelled to provide wiretap facilities to the US and state and local governments.

>> Apple's defense against backdooring E2E is the (US) doctrine that [government can’t] be compelling work (or speech, if you prefer)

It’s really not "work” but speech. That’s why telecoms can be compelled to wiretap. But code is speech [2], signing that code is also speech, and speech is constitutionally protected (US).

The tension is between the All Writs Act (requiring “third parties’ assistance to execute a prior order of the court”) and the First Amendment. [1]

So Apple may be compelled to produce the iCloud drives the data is stored on. But they can’t be made to write and sign code to run locally in your iPhone to decrypt that E2EE data (even though obviously they technologically could).

[1]: https://www.eff.org/deeplinks/2015/10/judge-doj-not-all-writ...

[2]: https://www.eff.org/deeplinks/2015/04/remembering-case-estab...

Re: Apple pulls data protection tool after UK government security row

#644

Earlier quoted context omitted.

WhatsApp is closed source. They could backdoor it if they wanted to (or were forced to).

And so in Apple and iOS. What is your point?

His point was that it is technically possible for WhatsApp to add a backdoor. Apple could too.

Re: Apple pulls data protection tool after UK government security row

#645
post #358

Fundamentally, I think the issue is more about technical literacy amongst the political establishment who consistently rely on the fallacy that having nothing to hide means you have nothing to fear. Especially in the UK which operates as a paternalistic state and enjoys authoritarian support across all parties. On the authoritarianism: these laws are always worded in such a way that they can be applied or targeted va…

Furthermore, one UK head of state call everyone supporting encryption pedophiles https://x.com/BenWallace70/status/1892972120818299199

> one UK head of state

What on earth are you talking about?

Charles III is head of state, and before that, Liz II. The monarch absolutely does not get involved in politics.

Re: Apple pulls data protection tool after UK government security row

#646
post #106

Too right, it was far more problematic than they ever made out. > The UK government's demand came through a "technical capability notice" under the Investigatory Powers Act (IPA), requiring Apple to create a backdoor that would allow British security officials to access encrypted user data globally. The order would have compromised Apple's Advanced Data Protection feature, which provides end-to-end encryption for iCl…

I don't really understand your comment to be honest. Section 3 of the Regulation of Regulatory Powers Act 2000 allows for compelled key disclosure (disclosure of the information sought instead of the key is also possible). Schedule 7 of the Counter-Terrorism Act allows 9 hour detention, questioning and device search at the border. With these powers it isn't necessary to get access to iCloud backups, as you can get the device and/or the data.

I don't think the e2e icloud backup is problematic under existing legislation / before the TCN. While you can't disclose the key because it lives in the secure enclave, you can disclose the information that is requested because you can log into your apple account and retrieve it. IANAL, but I believe this to be sufficient (and refusing would mean jail).

The Investigatory Powers Act allows for technical capability notices, and the TCN in this case says (as far as we know) "allow us a method to be able to get the contents of any iCloud backup that is protected by E2EE for any user worldwide". This means that there is no need to ask the target to disclose information and if implemented as asked, also means that any user worldwide could be a target of the order, even if they'd never been to the UK.

Relevant info:

- https://wiki.openrightsgroup.org/wiki/Regulation_of_Investig...

Re: Apple pulls data protection tool after UK government security row

#648

Earlier quoted context omitted.

Would just upload the keys

Presumably these keys live in a hardware security module on your phone called “secure enclave” and cannot be extracted

Apple can push firmware updates to the HSM just like the device. So if they really wanted they could add an operation that extracted the keys (likely by encrypting them to a key that lives in Apple's cloud).

Re: Apple pulls data protection tool after UK government security row

#649

Earlier quoted context omitted.

opinion: any government that "needs" such control, is an enemy of the people and must be abolished, and anyone can morally and ethically do so

Well it’s important that the argument is correct. They view ending end-to-end encryption as a way to restore the effectiveness of traditional warrants. It isn’t necessarily about mass surveillance and the implementation could prevent mass surveillance but allow warrants. I oppose that because end to end encryption is still possible by anyone with something to hide, it is trivial to implement. I think governments shou…

> They view ending end-to-end encryption as a way to restore the effectiveness of traditional warrants.

Traditional warrants couldn't retroactively capture historical realtime communications because that stuff wasn't traditionally recorded to begin with.

> It isn’t necessarily about mass surveillance and the implementation could prevent mass surveillance but allow warrants.

The implementation that allows this is the one where executing a warrant has a high inherent cost, e.g. because they have to physically plant a bug on the device. If you can tap any device from the server then you can tap every device from the server (and so can anyone who can compromise the server).

Re: Apple pulls data protection tool after UK government security row

#650

Earlier quoted context omitted.

Small arms are no match for drones and a fully armed military, a successful rebellion by any populace against a first world military is impossible unless the military lays their arms down voluntarily, full stop.

Every time this argument comes up, I just feel like rolling eyes, it is so overplayed. Yes, in a direct confrontation and an all out war, the populace stands no chance against the US military (assuming the military will unwaveringly side against the populace), no argument there. But an all out war is not an option, the government wouldn’t be trying to pulverize an entire nation and leave a rubble in place. If you com…

A first world military that has remotely piloted drones with IR cameras and other surveillance tools will have no problem crushing any form of resistance. They don’t even need to field any troops, they can remotely kill the rebels. How on earth do you wage a rebellion against such a force?
Post reply on HN