Live data from Hacker News

Apple pulls data protection tool after UK government security row

bbc.com

691–700 of 1001 posts

Re: Apple pulls data protection tool after UK government security row

#691

Note that this doesn’t satisfy the government’s original request, which was for worldwide backdoor access into E2E-encrypted cloud accounts. But I have a more pertinent question: how can you “pull” E2E encryption without data loss? What happens to those that had this enabled? Edit: Part of my concern is that you have to keep in mind Apple's defense against backdooring E2E is the (US) doctrine that work cannot be comp…

> Any solution Apple develops that enables "disable E2E for this account" makes it harder for them to claim that implementing that would be compelling work (or speech, if you prefer)

I think it’s really speech [0], which is why it’s important to user privacy and security that Apple widely advertises their entire product line and business as valuing privacy. That way, it’s a higher bar for a court to cross, on balance, when weighing whether to compel speech/code (& signing) to break E2EE.

After all, if the CEO says privacy is unimportant [1], maybe compelling a code update to break E2EE is no big deal? (“The court is just asking you, Google, to say/code what you already believe”).

Whereas if the company says they value privacy, then does the opposite without so much as a fight and then the stock price drops, maybe that’d be securities fraud? [2]. And so maybe that’d be harder to compel.

[0]: https://news.ycombinator.com/item?id=43134235

[1]: https://www.eff.org/deeplinks/2009/12/google-ceo-eric-schmid...

[2]: https://www.bloomberg.com/opinion/articles/2019-06-26/everyt...

Re: Apple pulls data protection tool after UK government security row

#692

Earlier quoted context omitted.

I don’t think anyone is cheering this on.

Many people do, unfortunately, so long as it's framed as "only terrorists and pedophiles need encryption that cops can't break".

How do we actually beat this narrative? I've been proposing a E2EE-based chat application to my friend, and they asked me a similar question: won't it just be rife with pedophiles? How can you make a platform that will be used to that means?

I have strong views about privacy as a fundamental human right, but I don't know how to answer that question. I certainly don't want to make the world worse, but this feels like a lesser of two evils type of deal: either make it even harder to catch bad actors, such as child abusers, or make it plausible that your government take away your freedom forever.

Re: Apple pulls data protection tool after UK government security row

#693
post #608

Earlier quoted context omitted.

The government forced them to pull the feature. Would you rather they left a toggle-switch that doesn't actually do anything? Or are you thinking they should just pull out of the EU altogether?

Making a stand would be leaving UK (UK is not in the EU) altogether. This is almost as bad as building a backdoor. This is leaving your customer in the rain. Fortunately for Apple, most of them won't even know or realize it.

> This is leaving your customer in the rain.

vs. taking their phone away??? Idk if you're trolling or what but I would be incredibly pissed at Apple if they deprecated my phone over something like this.

Re: Apple pulls data protection tool after UK government security row

#694
post #619

Earlier quoted context omitted.

My assumption is that Google has keys to everything in its kingdom [1]. [1] https://qz.com/1145669/googles-true-origin-partly-lies-in-ci...

> My assumption is that Google has keys to everything in its kingdom If that were true, then their claims to support E2E encrypted backups are simply false, and they would have been subject to warrants to unlock backups, just like Apple had been until they implemented their "Advanced Data Protection" in 2022. Wouldn't there have been be some evidence of that in the past 7 years, either through security research, or t…

Would it be possible that they feel that the revelation of this backdoor would be too big of a loss so that any of these theoretical cases of the past 7 years have used parallel construction to avoid revealing the encrypted data was viewed?

Re: Apple pulls data protection tool after UK government security row

#696
post #401

Earlier quoted context omitted.

> Especially in the UK which operates as a paternalistic state and enjoys authoritarian support across all parties. This seemed strange to point out. It’s not really any more or less “paternalistic” than most western nations including the US.

Folks in the United States aren't routinely arrested for Facebook posts.

There are limits to speech in every country, including the US. What I always find baffling is the sheer arrogance of Americans, that the only way to be a free and democratic country is their way, to the extent that they send their elected representatives to Germany of all places to implicitly argue for the legalisation of the Hitler salute.

Meanwhile their country has slid into fascism. Sad and tragic.

Re: Apple pulls data protection tool after UK government security row

#697
post #553

Earlier quoted context omitted.

It's also just false. Google pulled out of China many years ago because they didn't want to bow to the Chinese government's demands. And they didn't just withdraw a product, they withdraw their entire business.

I wonder what the impact of Apple withdrawing from China will be. I know we are talking about UK, but this made me think. Not only their sales will reduce, but hey Chinese manufacturing cuts down. By how much? Will it be impactful? I would think so but wonder if it is quantifiable.

Almost all iPhones are made in China. They cannot pull out without shutting down.

They make on average 60,000 ios devices there every hour, 24 hours a day, 365 days a year.

Re: Apple pulls data protection tool after UK government security row

#698
post #106

Too right, it was far more problematic than they ever made out. > The UK government's demand came through a "technical capability notice" under the Investigatory Powers Act (IPA), requiring Apple to create a backdoor that would allow British security officials to access encrypted user data globally. The order would have compromised Apple's Advanced Data Protection feature, which provides end-to-end encryption for iCl…

What is going on in the UK? How do they stand for this?

Re: Apple pulls data protection tool after UK government security row

#699
post #619

Earlier quoted context omitted.

My assumption is that Google has keys to everything in its kingdom [1]. [1] https://qz.com/1145669/googles-true-origin-partly-lies-in-ci...

> My assumption is that Google has keys to everything in its kingdom If that were true, then their claims to support E2E encrypted backups are simply false, and they would have been subject to warrants to unlock backups, just like Apple had been until they implemented their "Advanced Data Protection" in 2022. Wouldn't there have been be some evidence of that in the past 7 years, either through security research, or t…

A trivial method for circumventing code review is to simply push a targeted update of the firmware to devices subject to a government search order.

There are no practical end-user protections against this vector.

PS: I strongly suspect that at least a few public package distribution services are run by security agencies to enable this kind of attack. They can distribute clean packages 99.999% of the time, except for a handful of targeted servers in countries being spied upon. A good example is Chocolatey, which popped up out of nowhere, had no visible source of funding, no mention of their ownership structure anywhere, and was incorporated along with hundreds of other companies in a small building in the middle of nowhere. It just screams of being a CIA front, but obviously that's hard to prove.

Re: Apple pulls data protection tool after UK government security row

#700
post #524

Earlier quoted context omitted.

It's not literacy. They don't care. They need control, and if establishing control means increased risks for you, it's not something they see as a negative factor. It's your problem, not theirs.

They don't even need control. They want control. Why? Either they're idiots who think they need control or they are tyrants who know they'll need control later on when they start doing seriously tyrannical things.

It's the latter.
Post reply on HN