Live data from Hacker News

Apple dropped plan for encrypting backups after FBI complained

reuters.com

711–720 of 734 posts

Re: Apple dropped plan for encrypting backups after FBI complained

#711
post #618
post #41

Earlier quoted context omitted.

For local backup, iMazing is great. It also does other useful things. It costs money though and you can decide whether that's a feature or bug. https://imazing.com/

Does imazing restore a phone as it is? First party backups from Apple (iCloud/iTunes) restore a perfect replica of the phone, including app icon locations, arrangement, notifications, offloaded storage etc. I'm honestly skeptical that anyone else would be able to pull that off.

Who cares about this?

Yes, Apple has private APIs that it uses for its monopoly abuse benefit. That is why Apple's "Music" app can't be deleted from your computer ("'Music.app' can’t be modified or deleted because it’s required by macOS.") but Spotify can be deleted.

The solution is for Spotify to sue them on this specific issue and for other people to sue them similarly.

Re: Apple dropped plan for encrypting backups after FBI complained

#712

What the... I was under the impression that iCloud backups are end-to-end encrypted. This is a HUGE problem.

I don’t understand. Am I just tired or misreading? The table on this page clearly shows backups are encrypted in transit and at rest... https://support.apple.com/en-us/HT202303

"Encrypted" is a weasel word. There are many examples of "it's encrypted" even when encrypted refers to 8192-bit keys, where the system is not secure. Examples abound.

So claims of "encryption" are meaningless.

Instead, claims of "only X, Y and Z could access to this" are meaningful.

"Could" is a strong word because it includes unforeseen circumstances such as writs and court orders.

Re: Apple dropped plan for encrypting backups after FBI complained

#713
Even if you want nothing to do with iCould, you must still enable it for these features:

- Mac-to-Mac copy/paste (shared clipboard, continuity) - iPad sidecar

Once you enable it, it immediately begins uploading your contacts, photos and passwords to Apple. Then you need to disable those specific things. Even after you delete those things, every app on your phone can silently and without your explicit permission, start loading data into iCloud.

Re: Apple dropped plan for encrypting backups after FBI complained

#714
post #41

Earlier quoted context omitted.

iPhone/iPad backups stored locally on iTunes (or Finder, in Catalina) are end-to-end encrypted. iCloud backups always were encrypted based on a key derived from your iCloud account credentials, since the beginning...

For local backup, iMazing is great. It also does other useful things. It costs money though and you can decide whether that's a feature or bug. https://imazing.com/

Was this previously called iFunBox or something else?

Re: Apple dropped plan for encrypting backups after FBI complained

#715

Earlier quoted context omitted.

I'm not making any claim at all about "most people". I'm saying that iCloud isn't properly encrypted, which for some people and organisations will be a problem, and that it is then a greater problem for those people and organisations that it is unusually difficult to transfer data between iOS devices and other systems through other means because of the inhibiting choices that Apple has made. It's much like the argume…

If you’re part of an organization where security is important, you would force all of your employees to register with your MDM solution and prohibit any iCloud backups, you would probably have them using Office for iOS and tell them to save their files to OneDrive for Business and enable encryption. I doubt many businesses are using iWorks with iCloud.

There is no reason to assume any of that is true, nor that only organisations where "security is important" care about this issue.

Re: Apple dropped plan for encrypting backups after FBI complained

#716
post #644
post #633

Earlier quoted context omitted.

1. Yes, they have to. At least in the US any company has to cooperate with the law enforcement as you might know. The only choice to do business in the US or based on US governed soil is to comply with them. 2. Apple at least put some effort into this matter because otherwise there would not be so much media attention to breaking into iPhones. To get data from android on the other hand seems to be no problem at all.…

We do not have to cooperate with law enforcement. Encryption is still legal, even if law enforcement would prefer service providers not ever use it. We have to comply with court orders. That’s it.

Please tell me why do organizations use canaries[0] then to tell people they where not forced to cooperate?

The funny thing is that I just read a bit of the linked Wikipedia article to find this: Companies and organizations who no longer have warrant canaries

  The following is a list of companies and organizations whose warrant canaries no longer appear in transparency reports:
  * Apple
  * Reddit
  * Silent Circle

[0]: https://en.wikipedia.org/wiki/Warrant_canary

Re: Apple dropped plan for encrypting backups after FBI complained

#717
post #633

Earlier quoted context omitted.

1. Yes, they have to. At least in the US any company has to cooperate with the law enforcement as you might know. The only choice to do business in the US or based on US governed soil is to comply with them. 2. Apple at least put some effort into this matter because otherwise there would not be so much media attention to breaking into iPhones. To get data from android on the other hand seems to be no problem at all.…

on 1.: Are there actually US laws that could prevent Apple from offering end-to-end encryption for backups to their user? That is something very different from cooperating with a specific investigation. Why did Apple not fight this in court? Could Apple keep the backups outside the EU, like Microsoft did for email in the Dublin case?

I do not think so and AFAIK only the export of strong encryption is prohibited by law in the US.

But it is not about prohibiting encryption but the possibility and/or necessity that Apple has another key to decrypt your data with.

It does not matter where they keep the data as long as the companies headquarters are on US soil.

Re: Apple dropped plan for encrypting backups after FBI complained

#718
post #633

Earlier quoted context omitted.

1. Yes, they have to. At least in the US any company has to cooperate with the law enforcement as you might know. The only choice to do business in the US or based on US governed soil is to comply with them. 2. Apple at least put some effort into this matter because otherwise there would not be so much media attention to breaking into iPhones. To get data from android on the other hand seems to be no problem at all.…

Re: 1 Google gives their customers the option for end-to-end encryption of uploaded data and I'm sure they have to play by the same rules as Apple.

"... they have to play by the same rules as Apple"

Now this does not exactly help me feeling more comfortably about this issue.

Re: Apple dropped plan for encrypting backups after FBI complained

#719
post #26

What the... I was under the impression that iCloud backups are end-to-end encrypted. This is a HUGE problem.

Why would you think it was end-to-end encrypted? Did you never use icloud.com where you can simply access all your icloud data with a usernam+password?

You cannot see your device backups on iCloud.com, so that doesn't prove (or disprove) anything.

Re: Apple dropped plan for encrypting backups after FBI complained

#720
post #570

Earlier quoted context omitted.

I suppose even if you don't check the box to encrypt, you're still protected by FileVault.

> I suppose even if you don't check the box to encrypt, you're still protected by FileVault. FileVault too is optional: https://support.apple.com/en-us/HT204837

File Vault I think is enabled by default now on new Macs? Or at least, its in the initial setup wizard with a "dark pattern" to encourage enabling it?
Post reply on HN