Apple pulls data protection tool after UK government security row
681–690 of 1001 posts
Re: Apple pulls data protection tool after UK government security row
#682Hmmm how? How can they decrypt your already end-to-end encrypted and uploaded data without you entering the passphrase to do so? I can understand them removing the data from iCloud completely, or asking you to send the keys to Apple, but I don't understand how they can disable the feature for already uploaded data.
Re: Apple pulls data protection tool after UK government security row
#683Earlier quoted context omitted.
It is possible to set up end to end encryption where two different keys unlock your data. Your key, and a government key. I assume google does this. 1. encrypt data with special key 2. encrypt special key with users key, and 3. encrypt special key with government key Anyone with the special key can read the data.the user key or the government key can be used to get special key. This two step process can be done for g…
E2EE means only your intended recipients can access the plaintext. Unless you intend to give the government access to your plaintext, what you described isn’t E2EE.
Since you are sending the data to google, isn't google an intended recipient? Google has to comply with a variety of laws, and it is likely that they are doing the best they can under the legal constraints. The law just doesn't allow systems like this.
Re: Apple pulls data protection tool after UK government security row
#684Earlier quoted context omitted.
Well it’s important that the argument is correct. They view ending end-to-end encryption as a way to restore the effectiveness of traditional warrants. It isn’t necessarily about mass surveillance and the implementation could prevent mass surveillance but allow warrants. I oppose that because end to end encryption is still possible by anyone with something to hide, it is trivial to implement. I think governments shou…
> They view ending end-to-end encryption as a way to restore the effectiveness of traditional warrants. Traditional warrants couldn't retroactively capture historical realtime communications because that stuff wasn't traditionally recorded to begin with. > It isn’t necessarily about mass surveillance and the implementation could prevent mass surveillance but allow warrants. The implementation that allows this is the…
Re: Apple pulls data protection tool after UK government security row
#685Earlier quoted context omitted.
At one point in time, the entirety of web communication was completely unencrypted. Why were people not mad then? Do you think people would be angrier now, if HTTPS were suddenly outlawed? Among other valid answers, removing rights and privileges generally makes people angrier than not having those rights or privileges in the first place.
Counterpoint: when web communication was unencrypted it was before we did our banking, tax filing, sent medical records, and sent all other kinds of sensitive information over the internet. The risks today are not remotely the same as they once were.
Re: Apple pulls data protection tool after UK government security row
#686"Existing users' access will be disabled at a later date." Hmmm how? How can they decrypt your already end-to-end encrypted and uploaded data without you entering the passphrase to do so? I can understand them removing the data from iCloud completely, or asking you to send the keys to Apple, but I don't understand how they can disable the feature for already uploaded data.
These companies have to comply with so many laws and want cozy relationships with governments, so they play both sides. It likely does things differently, but if the keys are not secure, then its not secured
Re: Apple pulls data protection tool after UK government security row
#687Fundamentally, I think the issue is more about technical literacy amongst the political establishment who consistently rely on the fallacy that having nothing to hide means you have nothing to fear. Especially in the UK which operates as a paternalistic state and enjoys authoritarian support across all parties. On the authoritarianism: these laws are always worded in such a way that they can be applied or targeted va…
"Especially in the UK which operates as a paternalistic state and enjoys authoritarian support across all parties." What is a "paternalistic state". I studied Latin so obviously I understand pater == father but what is a father-like state? What on earth is: "authoritarian support across all parties". The UK has one Parliament, four Executives (England, Northern Ireland, Scotland, Wales) and a Monarch (he's actually q…
I suppose a paternalistic state functions to satisfy the needs of the people, and to define those needs. The people get what the state says is best for them.
Re: Apple pulls data protection tool after UK government security row
#688Earlier quoted context omitted.
International users that have Advanced Protection enabled would in theory be safe from all of the 3-letter agencies (like safe from those agencies getting the data from Apple...not safe generally). Realistically we are talking about FISA here, so in theory if the FBI gets a FISA court order to gather "All of the Apple account data" for a non-us person, Apple would either hand over the encrypted data OR just omit that…
Would your answer be the same if this encrypted data was stored in China instead of US? I don't think messages should ever leave the device, if you want to migrate to a different device this could be covered by that user flow directly. Maybe you want to sync media like photos or videos shared on a group chat and I'm fine with that compromise but I see more risks than benefits on backing up messages on the cloud, no m…
Know your threat model and what actions your trying to defend against.
Typical humans need trusted vendors that put in actual effort to make themselves blind to your personal data.
Re: Apple pulls data protection tool after UK government security row
#689Earlier quoted context omitted.
Signal can't evade this law either.
Why not? Signal was willing to run all kinds crazy setups to evade foreign laws, like domain fronting. https://signal.org/blog/doodles-stickers-censorship/
Re: Apple pulls data protection tool after UK government security row
#690Too right, it was far more problematic than they ever made out. > The UK government's demand came through a "technical capability notice" under the Investigatory Powers Act (IPA), requiring Apple to create a backdoor that would allow British security officials to access encrypted user data globally. The order would have compromised Apple's Advanced Data Protection feature, which provides end-to-end encryption for iCl…
> have an Android device beside me that regularly asks me to back my device up to the cloud But is that backup encrypted? If it's not, all they need is to access your data. This is about having access to backups that are theoretically encrypted with a key Apple doesn't have? > We're talking about the largest back door I've ever heard of. Doesn't the US have access to all the data of non US citizens whose data is stor…