Live data from Hacker News

Apple pulls data protection tool after UK government security row

bbc.com

671–680 of 1001 posts

Re: Apple pulls data protection tool after UK government security row

#671
post #146

Earlier quoted context omitted.

If they are able to, then then can be compelled. Do you mean won't/wouldn't?

They can break a sync on server-side for your account. They can't disable it on device though.

They control the software running on your device, and said software ultimately has access to the encryption keys stored there (subject to the usual hoops; e.g. it might need you to do a FaceID unlock first, but it's not like you aren't already doing that many times every day).

Re: Apple pulls data protection tool after UK government security row

#672

Earlier quoted context omitted.

> My assumption is that Google has keys to everything in its kingdom If that were true, then their claims to support E2E encrypted backups are simply false, and they would have been subject to warrants to unlock backups, just like Apple had been until they implemented their "Advanced Data Protection" in 2022. Wouldn't there have been be some evidence of that in the past 7 years, either through security research, or t…

It is possible to set up end to end encryption where two different keys unlock your data. Your key, and a government key. I assume google does this. 1. encrypt data with special key 2. encrypt special key with users key, and 3. encrypt special key with government key Anyone with the special key can read the data.the user key or the government key can be used to get special key. This two step process can be done for g…

Would that still count as E2E-encrypted if another party has access? That would still count as lying to me.

Re: Apple pulls data protection tool after UK government security row

#673

They should of forced ADP on by default and this would of never happened.

The problem with that is that if the user loses their key, their account is no longer recoverable. As things are with ADP, enabling it comes with a bunch of warnings about that, and IIRC it also forces you to print out the recovery key for safe storage.

Re: Apple pulls data protection tool after UK government security row

#675
post #4

As someone currently a citizen of the UK, what are my best emigration opportunities?

If you value personal freedoms, you should go to East Europe. The more to the east, the better. Snowden went to Russia.

https://en.wikipedia.org/wiki/SORM

https://en.wikipedia.org/wiki/Roskomnadzor

Re: Apple pulls data protection tool after UK government security row

#676

Earlier quoted context omitted.

> My assumption is that Google has keys to everything in its kingdom If that were true, then their claims to support E2E encrypted backups are simply false, and they would have been subject to warrants to unlock backups, just like Apple had been until they implemented their "Advanced Data Protection" in 2022. Wouldn't there have been be some evidence of that in the past 7 years, either through security research, or t…

It is possible to set up end to end encryption where two different keys unlock your data. Your key, and a government key. I assume google does this. 1. encrypt data with special key 2. encrypt special key with users key, and 3. encrypt special key with government key Anyone with the special key can read the data.the user key or the government key can be used to get special key. This two step process can be done for g…

E2EE means only your intended recipients can access the plaintext. Unless you intend to give the government access to your plaintext, what you described isn’t E2EE.

Re: Apple pulls data protection tool after UK government security row

#677

It's the right choice: don't bow to government pressure, let the people pressure the government.

How? In the UK, there's no right to bear arms, so people are pretty helpless against their oppressing government.

> In the UK, there's no right to bear arms, so people are pretty helpless against their oppressing government.

When people want to revolt it doesn’t seem like the right to bear arms has much to do with it. Not having the right to bear arms certainly hasn’t stopped countless rebellions and revolutions across the world. It’s not like the French of the Russians had a right to bear arms before their successful revolutions.

Even in the UK, the lack of a right to bear arms didn’t stop Cromwell using firearms to defeat Charles II at the Battle of Worcester.

Re: Apple pulls data protection tool after UK government security row

#678

Earlier quoted context omitted.

It is possible to set up end to end encryption where two different keys unlock your data. Your key, and a government key. I assume google does this. 1. encrypt data with special key 2. encrypt special key with users key, and 3. encrypt special key with government key Anyone with the special key can read the data.the user key or the government key can be used to get special key. This two step process can be done for g…

Would that still count as E2E-encrypted if another party has access? That would still count as lying to me.

That depends on the definition of "end".

Re: Apple pulls data protection tool after UK government security row

#679
post #38
post #15

As a citizen, I don’t understand what the UK government thinks they are getting here - other than the possibility of leaks of the nation’s most sensitive data. Also is it not possible to set up my Apple account outside of the UK while living here?

> other than the possibility of leaks of the nation’s most sensitive data Amusing when you consider the National Cyber Security Centre (NCSC, a part of GCHQ), along with the Information Commissioners Office, both publish guidance recommending, and describing how to use, encryption to protect personal and sensitive data. Our government is almost schizophrenic in its attitude to encryption.

That's because GCHQ knows they can kill if you refuse to decrypt so they have no problem suggesting it to you.

Re: Apple pulls data protection tool after UK government security row

#680
post #358

Fundamentally, I think the issue is more about technical literacy amongst the political establishment who consistently rely on the fallacy that having nothing to hide means you have nothing to fear. Especially in the UK which operates as a paternalistic state and enjoys authoritarian support across all parties. On the authoritarianism: these laws are always worded in such a way that they can be applied or targeted va…

"Especially in the UK which operates as a paternalistic state and enjoys authoritarian support across all parties."

What is a "paternalistic state". I studied Latin so obviously I understand pater == father but what is a father-like state?

What on earth is: "authoritarian support across all parties".

The UK has one Parliament, four Executives (England, Northern Ireland, Scotland, Wales) and a Monarch (he's actually quite a few Monarchs).

Anyway, I do agree with you that destroying routine encryption is a bloody daft idea. It's a bit sad that Apple sold it as an extra add on. It does not cost much to run openssl - its proper open source.

Post reply on HN