Live data from Hacker News

Apple dropped plan for encrypting backups after FBI complained

reuters.com

671–680 of 734 posts

Re: Apple dropped plan for encrypting backups after FBI complained

#671
post #589

Earlier quoted context omitted.

Or you can specifically turn off iCloud for iMessages in settings....

Maybe the fraction of users who do that is small enough that China won't push them on it. Or (this would be relatively easy to check) they could just hide that option in settings when the device region is China. Another factor to consider is that SMS and iMessage are rarely used in China due to SMS historically being more expensive than email/data over there.

> Or (this would be relatively easy to check) they could just hide that option in settings when the device region is China.

A placebo toggle is also an option.

Re: Apple dropped plan for encrypting backups after FBI complained

#672

Earlier quoted context omitted.

>Wonder if this will help to kill a meme, aboyt how much Apple cares about users and what great values they have, Probably not. The keyboards on their laptops are barely functional but it doesn't stop people from saying how great they are.

> The keyboards on their laptops are barely functional This must be some definition of "barely functional" I'm unfamiliar with. I've had a mid-2017 MBP since they were released. Yeah, I had to get the keyboard replaced when some keys failed after a year, but at least they did it for free. Actually, overall I prefer this keyboard to the 2013 I had previously. I think their failure rate is unacceptable, but they are ce…

> Yeah, I had to get the keyboard replaced when some keys failed after a year,

>This must be some definition of "barely functional" I'm unfamiliar with.

I agree.

Keyboards aren't exactly cutting edge technology, they shouldn't be failing after a year.

Re: Apple dropped plan for encrypting backups after FBI complained

#673
post #478

It turns over data more often in response to secret U.S. intelligence court directives, which sought content from more than 18,000 accounts in the first half of 2019, the most recently reported six-month period. When you think about it, that volume is staggering. 36,000 iDevice-using intelligence targets every year? Imagine the amount of analyst time required just to go through 36,000 iCloud backups every year!

Really makes you wonder what the criteria is for being investigated.

Maybe I’m naive, but I find it hard to believe that there are 36,000 yearly iCloud accounts with probable cause to be tied to terrorism activity and/or national security matters, especially if that’s only in the US.

As someone with a (half) Middle Eastern heritage and name (but born and raised in the US) I’ve experienced my fair share of nuanced discrimination at airports and one weird situation with what I assume was the FBI. There’s always the ignorant TSA agent who raises an eyebrow when you report coming back from the Middle East... like why would anyone ever travel there if it weren’t for terrorism?

I’m a pretty average techie so I’m not too worried about anyone going through my iCloud backups, but I feel like there should be some more transparency around this stuff. I feel like if you’re secretly investigated but discovered to be innocent, shouldn’t you deserve to know you were spied on? I guess that’s what FOIA requests are for.

The war on terrorism feels like a game of whack-a-mole sometimes.

Re: Apple dropped plan for encrypting backups after FBI complained

#674
post #600

Earlier quoted context omitted.

> Apple has a balance to strike between the issues of encryption, privacy, and law enforcement [...] No, they do not. If Apple wants a reputation for privacy and respecting its customers, then it has to put them first. Don't apologize for them making this user-hostile choice. We could be merely a generation away from the hell hole that is social credit. We can't afford to keep ceding ground on privacy. We have to eng…

> We could be merely a generation away from the hell hole that is social credit. I fear we have one foot there already. If you are so inclined, you can dig up a lot of dox on most people, all freely given to social media, or via scrapers like Spokeo. I guess it's all still optional, kinda. And there is no centralized clearinghouse. But it is scary.

You are very wrong about no central clearinghouse. There are many.

Re: Apple dropped plan for encrypting backups after FBI complained

#675
post #600

Earlier quoted context omitted.

> We could be merely a generation away from the hell hole that is social credit. I fear we have one foot there already. If you are so inclined, you can dig up a lot of dox on most people, all freely given to social media, or via scrapers like Spokeo. I guess it's all still optional, kinda. And there is no centralized clearinghouse. But it is scary.

Not to worry, you are free to post on Yandex, “down with Trump,” and you are free to post on Facebook, “down with Trump”.

Try the inverse and let me know how that works out

Re: Apple dropped plan for encrypting backups after FBI complained

#676

Earlier quoted context omitted.

The list of E2E above is quite transparent. The notion of building a special version of the OS to target an individual is just not how the infrastructure works, and totally goes against the entire spirit of privacy that pervades everything you do internally.

Sorry to be blunt (and I am a big fan of Apple's pro-privacy shift of late) but nobody outside Apple can know that with any certainty. Even the 2016 blackhat talk on youtube, which describes an elaborate signing mechanism for updates, doesn't preclude shipping targeted OS updates to individual users. Maybe I missed something though, and in that case I'd appreciate you pointing it out.

I can tell you that most people inside of Apple would be shocked if such a thing occurred. I doubt the code pathway / infrastructure even exists to do such a thing. There’s always the possibility of strange things happening that only the right 1-2 people know about.... although it’s probably have to be many more given the number of changes that would be needed to be made to propagate a special one off code signed OS OTA. That would likely have a whistleblower somewhere.

The reality is it’s way easier to just exploit a weakness that you can text someone [1].

But if you’re dressed in tin foil hat to toe, then there’s nothing that I can say to convince you. At that point I’d suggest not using any computing technology that you don’t personally build yourself and watch 24/7.

[1] https://www.nytimes.com/2020/01/21/technology/bezos-phone-ha...

Re: Apple dropped plan for encrypting backups after FBI complained

#677

Earlier quoted context omitted.

After looking at a few alternatives (Borg, Duplicacy etc.), I setup Arq on my Mac yesterday. One thing that irks me about these solutions is that they seem to scan my folders each time they want to backup. Are there tools that are smarter about this? For e.g., while running, they could keep a log of what's changing and only scan those while backing up.

I've been thinking about setting up a backup for my Mac for a while now. How long does it usually take to scan your folders during a backup?

I am backing up ~130 GB data (with a combination of large and small files) every 12 hours to S3. The first upload quite some time but all the later ones take ~10 minutes in total.

Re: Apple dropped plan for encrypting backups after FBI complained

#678

Earlier quoted context omitted.

> I have not changed the subject. You started this thread by responding to somebody discussing the Chinese government's access to all iCloud data, but you changed the subject to talk about systems where the private key is on device, which does not apply to iCloud. You absolutely did change the subject. > Those same standards apply in the US and China - unless you have evidence otherwise. Those same standards don't ac…

The laws of the US say a lot of things. But the facts are that all the government has to do is scream “terrorism”, “drugs”, “or think about the children” and they can easily get a warrant. The law states that one branch of government has to ask another branch of government for a warrant. You have to believe that the judicial branch actually would safe guard privacy and keep law enforcement from overreaching.

> You have to believe that the judicial branch actually would safe guard privacy and keep law enforcement from overreaching.

These warrants become public record. I don't have to blindly believe it. I can look at the records and see that the US is not even close to China as far as government access to user data.

Re: Apple dropped plan for encrypting backups after FBI complained

#679

Earlier quoted context omitted.

> If some of the data is e2e encrypted using private keys,China doesn’t have access to “all data” You have two mistakes in this sentence. 1. None of the iCloud data (mail, docs, drive, etc.) is E2E encrypted. Some of the data stored in iCloud (like keychain backups) is encrypted prior to being sent to iCloud (using symmetric encryption, not with asymmetric key pairs). China has access to the data that was ultimately…

The “key server” does not in fact “generate public keys”. It distributes public keys. But you can’t decrypt a message with public keys - that’s kind of the point... But after reading research from security experts you have found a citation where Apple is generating a key pair from its servers and sending the private key to the client?

> The “key server” does not in fact “generate public keys”.

That's the point. It should not, but the security model of iMessage allows the key server to get away with it, which is almost certainly happening in China right now. Try reading the article and following the example.

> But after reading research from security experts you have found a citation where Apple is generating a key pair from its servers and sending the private key to the client?

No, it sends the public key. Encrypting messages is done with the recipient's public key. Go read the Wikipedia article on asymmetric encryption. Because the owner of the keyserver can send its own public key, it can decrypt messages with its own private key before re-encrypting with the intended recipient's public key.

Re: Apple dropped plan for encrypting backups after FBI complained

#680
post #633

Earlier quoted context omitted.

> Apple has a balance to strike between the issues of encryption, privacy, and law enforcement [...] No, they do not. If Apple wants a reputation for privacy and respecting its customers, then it has to put them first. Don't apologize for them making this user-hostile choice. We could be merely a generation away from the hell hole that is social credit. We can't afford to keep ceding ground on privacy. We have to eng…

1. Yes, they have to. At least in the US any company has to cooperate with the law enforcement as you might know. The only choice to do business in the US or based on US governed soil is to comply with them. 2. Apple at least put some effort into this matter because otherwise there would not be so much media attention to breaking into iPhones. To get data from android on the other hand seems to be no problem at all.…

Re: 1

Google gives their customers the option for end-to-end encryption of uploaded data and I'm sure they have to play by the same rules as Apple.

Post reply on HN