Live data from Hacker News

Apple dropped plan for encrypting backups after FBI complained

reuters.com

731–734 of 734 posts

Re: Apple dropped plan for encrypting backups after FBI complained

#731

Earlier quoted context omitted.

Depending on what functionality you're willing to give up, an Android device can pretty easily be used as a more private option thanks to the latest iteration of Google's privacy settings. If you're willing to root your device, you can have the best of both the functionality and privacy worlds. That only applies to motivated and reasonably tech savvy users of course, out of the box iOS is still the better privacy opt…

If you can root your device, so can the bad guys.

On iOS it's called jailbreaking. In either case it's been a long time since anyone came up with an exploit that could do it remotely.

Re: Apple dropped plan for encrypting backups after FBI complained

#732
post #57

Apple has a list for that: https://support.apple.com/en-us/HT202303 These are end to end: Home data Health data (requires iOS 12 or later) iCloud Keychain (includes all of your saved accounts and passwords) Payment information QuickType Keyboard learned vocabulary (requires iOS 11 or later) Screen Time Siri information Wi-Fi passwords The messages also end to end but the backup contains the private key. The moral of…

Two things: 1) There is no way Apple would be allowed to sell iPhones in China, without China government having access to anything. So, I assume that Apple users in China have e2e encrypted exactly nothing. 2) I have a strong suspicion that those 'enter your Apple ID password because your account needs it' message really means 'a government has requested your data and even though it's encrypted, we will nag you about…

> companies can't protect us from a government we have put into power.

But.. the electoral college.

Re: Apple dropped plan for encrypting backups after FBI complained

#733

Earlier quoted context omitted.

You can set local auto backup over wifi in itunes right?

Yes, but that only works in local networks and after connecting via USB once – and the backup is always stored on a single computer. So it may be acceptable for personal usage, but not suited for an enterprise environment where you want to centrally manage hundreds of devices and provide some redundancy for your backup system.

I guess I don’t understand this point. This is exactly what ios mdm backup is for. Relying on users backing up their personal icloud accounts for work seems highly problematic. If they are work icloud accounts... usb should not be a problem since you are probably provisioning the devices, and the itunes backup approach over your intranet seems actually ideal.

Re: Apple dropped plan for encrypting backups after FBI complained

#734

Earlier quoted context omitted.

Not a solution for Linux users. There are ways to sync to Linux but I’ve had plenty of issues with it.

You don't need iTunes, you can use idevicebackup2 from https://www.libimobiledevice.org/ It's a command line suite for Mac, Linux, and Windows that interfaces with your iPhone through it's native protocols, including for encrypted local backups.

I’m familiar with this suite. It’s fantastic but at the same time it is often broken with a new iOS release. Apple seems to have no interest in maintaining compatibility. Recently I needed to copy some MP3s to my phone. I’ve done this before with my laptop with success. But that day it did not work. And neither did my Linux desktop. I ended up listening to the audiobook (a free audio book from Cory Doctorow) by pairing my laptop with my cars Bluetooth and playing from my laptop. Cumbersome.

I’ve also had instanced where the latest version of that library supposedly works, but it’s dependent on another library that hasn’t hit Debian mainline yet. So I’ve had to wait months just to get a version that works even though it was released much earlier.

It’s not a perfect solution by any means.

Post reply on HN