Live data from Hacker News

iPhones send call history to Apple, security firm says

theintercept.com

71–80 of 85 posts

Re: iPhones send call history to Apple, security firm says

#71

I'm not sure how this is "secret". If you're using iCloud on your mac and your iPhone, and open up Facetime on the former, you'll see a call list (including regular phone calls, not just facetime). I agree it's undesirable that call history is sent to Apple - but it's pretty easy to notice if you use facetime across devices that the call history is synced.

The "secret" part is that they include information that is only interesting to law enforcement (timestamps and durations) in addition to pulling information from third part communication tools like WhatsApp.

Namely, Apple chose to provide this information to government surveillance when they could have (and indeed promised) to design it in a way that allows for the iPhone to be used in sensitive situations and by people who need security from state coercion and violence.

Re: iPhones send call history to Apple, security firm says

#72

I'm not sure how this is "secret". If you're using iCloud on your mac and your iPhone, and open up Facetime on the former, you'll see a call list (including regular phone calls, not just facetime). I agree it's undesirable that call history is sent to Apple - but it's pretty easy to notice if you use facetime across devices that the call history is synced.

The "secret" part is that they include information that is only interesting to law enforcement (timestamps and durations) in addition to pulling information from third part communication tools like WhatsApp. Namely, Apple chose to provide this information to government surveillance when they could have (and indeed promised) to design it in a way that allows for the iPhone to be used in sensitive situations and by peo…

This doesn't make sense to me. Law enforcement has been able to get that information easily for quite some time directly from telephony systems. Timestamps and durations have been a part of phone UIs for quite some time, which to me indicates that it is in fact interesting to more than law enforcement... unless phone manufacturers conspired to display that information to help LEOs when they confiscate phones.

Anyone who cares about state coercion and violence should know phone calls are about the least sensitive way to communicate.

Re: iPhones send call history to Apple, security firm says

#73

Earlier quoted context omitted.

The "secret" part is that they include information that is only interesting to law enforcement (timestamps and durations) in addition to pulling information from third part communication tools like WhatsApp. Namely, Apple chose to provide this information to government surveillance when they could have (and indeed promised) to design it in a way that allows for the iPhone to be used in sensitive situations and by peo…

This doesn't make sense to me. Law enforcement has been able to get that information easily for quite some time directly from telephony systems. Timestamps and durations have been a part of phone UIs for quite some time, which to me indicates that it is in fact interesting to more than law enforcement... unless phone manufacturers conspired to display that information to help LEOs when they confiscate phones. Anyone…

> Timestamps and durations have been a part of phone UIs for quite some time

This is not familiar to me at all. If true, note the remaining points: the manner in which this data was synchronized allowed this material to be provided to law enforcement (Apple had other options) and Apple also included information from third party communication tools used by some people (mistakenly) to avoid being surveilled.

Re: iPhones send call history to Apple, security firm says

#74
post #66

Earlier quoted context omitted.

What possible controls can Apple put in place though other than a checkbox for do/do not sync ? And remember Apple is a positioning iCloud as a cloud for dummies solution so adding choice comes with trade offs.

Couldn't I apply the same argument for while google needs to send your call history to its servers to perform number lookup? Yet people cry fowl (rightfully so) about privacy implications.

Google has a track record of disregarding user privacy. Apple has the opposite, a track record of protecting user privacy as much as they can.

Re: iPhones send call history to Apple, security firm says

#75

Earlier quoted context omitted.

This doesn't make sense to me. Law enforcement has been able to get that information easily for quite some time directly from telephony systems. Timestamps and durations have been a part of phone UIs for quite some time, which to me indicates that it is in fact interesting to more than law enforcement... unless phone manufacturers conspired to display that information to help LEOs when they confiscate phones. Anyone…

> Timestamps and durations have been a part of phone UIs for quite some time This is not familiar to me at all. If true, note the remaining points: the manner in which this data was synchronized allowed this material to be provided to law enforcement (Apple had other options) and Apple also included information from third party communication tools used by some people (mistakenly) to avoid being surveilled.

Timestamps and durations have been visible on the iPhone ever since it was released in 2007. I assume other smartphones do something similar. Integration with third parties is a more recent feature, it's what lets you use VoIP apps with the iPhone's native call interface, and those calls end up in the same call history that your "regular" phone calls do, which is why they're included in the syncing.

Re: iPhones send call history to Apple, security firm says

#76

Earlier quoted context omitted.

Maybe the password encrypts the actual encryption key? I don't know about iCloud but that's how LUKS works on Linux.

Except that would mean a password reset would involve losing access to all your data (unless you can remember the original).

You can have an HSM that encrypts the data with its own key, and merely verifies that the apple id & password match before decrypting anything, and you can destroy the private keys necessary to reprogram the HSM, so that way you can't be compelled to change it. The HSM would similarly do whatever verification is necessary when resetting the password to ensure that the rules are met.

That said, I don't know what Apple actually does. I know they use HSMs, but most of the info about how that works is about Keychain syncing, which is done a bit differently than other iCloud data syncing.

Re: iPhones send call history to Apple, security firm says

#77

Earlier quoted context omitted.

But everything on the iCloud can be obtained by the government and the law enforcement agencies. Right? (I don't care much, but apparently one of the reasons many people use iPhones instead of Android phones is that their data is perceived to be protected from the government, so might be important for them - and Apple does have a history of giving the iCloud data to them).

No.

Yes. Not sure why people reject things about their favorite company without checking facts, just like religion. Even the account for which Tim Cook became the privacy crusader, they had already given his iCloud data.

Also, here: http://www.apple.com/in/privacy/government-information-reque...

Re: iPhones send call history to Apple, security firm says

#78
post #52

i'm still using my trusty motorolla razr

A feature of the Razr that I desperately miss from modern phones: it would fire the alarms even when the phone was turned off. Somehow this ability has been lost on smartphones, and people behave as if it is a technical impossibility, but the Razrs managed it.

Yep, the old Nokias did that too

Re: iPhones send call history to Apple, security firm says

#79

Earlier quoted context omitted.

The "secret" part is that they include information that is only interesting to law enforcement (timestamps and durations) in addition to pulling information from third part communication tools like WhatsApp. Namely, Apple chose to provide this information to government surveillance when they could have (and indeed promised) to design it in a way that allows for the iPhone to be used in sensitive situations and by peo…

This doesn't make sense to me. Law enforcement has been able to get that information easily for quite some time directly from telephony systems. Timestamps and durations have been a part of phone UIs for quite some time, which to me indicates that it is in fact interesting to more than law enforcement... unless phone manufacturers conspired to display that information to help LEOs when they confiscate phones. Anyone…

leo can get those information about people abroad, using their phone on foreign soil, maybe even being foreigners.

Re: iPhones send call history to Apple, security firm says

#80

I'm not sure how this is "secret". If you're using iCloud on your mac and your iPhone, and open up Facetime on the former, you'll see a call list (including regular phone calls, not just facetime). I agree it's undesirable that call history is sent to Apple - but it's pretty easy to notice if you use facetime across devices that the call history is synced.

The "secret" part is that they include information that is only interesting to law enforcement (timestamps and durations) in addition to pulling information from third part communication tools like WhatsApp. Namely, Apple chose to provide this information to government surveillance when they could have (and indeed promised) to design it in a way that allows for the iPhone to be used in sensitive situations and by peo…

This is just plain wrong. Timestamps of course make sense in the context of call history.
Post reply on HN