Live data from Hacker News

Apple pulls data protection tool after UK government security row

bbc.com

731–740 of 1001 posts

Re: Apple pulls data protection tool after UK government security row

#731

Earlier quoted context omitted.

Not exactly. It generates the keys for you and stores them on device in the Secure Enclave. You cannot "bring your own" encryption key, but the primary benefit of doing so--that Apple does not have access to it--is intentionally accomplished anyway by the implementation.

I’m not sure I appreciate the value of literally bringing your own keys. My device generating them on my behalf as part of a setup process seems sufficient. You’d use openssl or something and defer to software to actually do keygen no matter what.

I agree it seems sort of academic at first blush, but I'm going to venture a guess it's the idea that you own them, instead of Apple.

So you can eg. keep a backup on your own (secure) infrastructure. Transfer them when switching devices or even mirror on two different ones*. Extract your own secret enclave contents. Improve confidence they were generated securely. And depending on implementation, perhaps reduce the ease with which Apple might "accidentally" vacuum the keys up as a result of an update / order.

*Not sure how much these two make sense in the iOS ecosystem. I know on the Android side I'd absolutely love to maintain a "hot standby" phone that is an exact duplicate of my daily driver, so if I drop it in the ocean I can be up and running again in a heartbeat with zero friction (without need to restore backups, reliance on nerfed backup API's outside the ones Google uses, having to re-setup 2FA, etc. and without ever touching Google's creepy-feeling cloud).

Re: Apple pulls data protection tool after UK government security row

#732
post #106

Too right, it was far more problematic than they ever made out. > The UK government's demand came through a "technical capability notice" under the Investigatory Powers Act (IPA), requiring Apple to create a backdoor that would allow British security officials to access encrypted user data globally. The order would have compromised Apple's Advanced Data Protection feature, which provides end-to-end encryption for iCl…

Also, I wondered if by complying with British law that they may somehow be breaking laws of another country? Hypothetically, if Apple just provide a back door to the data they have on US Senators for instance, then providing that information may be considered treason by the US. That's a totally made up example, and I have no idea, but it seems like it's possibly an issue. Which is all about the issues around data sov…

That would not be treason, by a long shot.

Treason is the only crime defined in the constitution, and it is quite a high bar.

Re: Apple pulls data protection tool after UK government security row

#733

Devil's Advocate (meaning I don't agree with this, in fact I disagree with it, but I don't see this argument being made anywhere and think it would be interesting. If you're one of the people who are offended by this practice of people steel-manning "the other side" and only want to read comments that affirm your position, please don't read this comment). Question: Wouldn't it be better for Apple to build a UK-only e…

[deleted]

Re: Apple pulls data protection tool after UK government security row

#734
post #728

The more I live I’m less concerned about what are often described as “bad actors”. The bad actors are often the state, and this kind of information is collected without thought to the risk of future politicians who don’t follow the rules or who don’t have any respect for the laws.

States are not inherently good, they are just large organisations with a monopoly on certain social functions. All large organisations have the capacity to inflict terrible harm.

Re: Apple pulls data protection tool after UK government security row

#735
post #639
post #543

Earlier quoted context omitted.

> But the real abuse, that's done by - especially in the UK - rich and famous people like Jimmy Savile Jimmy Savile was a vile predator. He was protected by the inane customs of the British ruling class. He was not alone among the toffs of England. But do not be mistaken. It is not just the rich and powerful where you find sexual predators. They exist at all levels of society, all genders, most ages (I will except in…

Honestly if the UK wants to reduce sexual crimes against children and adults one of the easiest ways to achieve that would be to reform UK liable law. In the UK if you're raped by someone famous you'd be an utter idiot to say anything unless you're loaded or have a massive amount of hard evidence. You couldn't have a me to movement in the UK because everyone who came forward would be sued into bankruptcy. This is why…

The rules of evidence in court are important too.

It is the victim on trial, many times.

Re: Apple pulls data protection tool after UK government security row

#736

What are you actually supposed to do in the UK if you oppose this sort of thing to stop laws like this coming in? It feels like the government has been incredibly out of touch for the last number of years.

> It feels like the government has been incredibly out of touch for the last number of years.

Did you vote for any single one of them?

If you did, then what you're supposed to do is stop voting for Tory-lite governments (such as the current one).

If you didn't vote for any of these governments (including this one), everything else that you could do would be dangerous nowadays.

Re: Apple pulls data protection tool after UK government security row

#737

Earlier quoted context omitted.

it's working really well, we don't get arrested for social media posts as far as I can tell

If that’s the bar then I guess yes it’s a resounding success for freedom.

The UK seems to be actively covering up the mass rape of little girls and throwing dissidents in prison. They've sustained mass immigration for decades against their own peoples' will. The US just shook off, at least in part, the same mass immigration and the same clamping down of free speech in the US. It's not the only bar, but I would definitely consider it a resounding success. I can't help but think the 1st and 2nd amendment play a part because the 1st is obviously implicated and the 2nd is required to maintain the 1st.

Re: Apple pulls data protection tool after UK government security row

#738
post #702

Earlier quoted context omitted.

At this point, the right thing to do is allow for an alt-service.

Apple has an organization-wide mandate for services revenue. Every product must make money on an ongoing basis, every month. That's why you get constantly spammed to subscribe to things on iOS. Apple will never drop this anticompetitive practice of favoring their services until they are legally compelled to.

> you get constantly spammed to subscribe to things on iOS.

Ad companies are the worst

Re: Apple pulls data protection tool after UK government security row

#739

Earlier quoted context omitted.

Every time this argument comes up, I just feel like rolling eyes, it is so overplayed. Yes, in a direct confrontation and an all out war, the populace stands no chance against the US military (assuming the military will unwaveringly side against the populace), no argument there. But an all out war is not an option, the government wouldn’t be trying to pulverize an entire nation and leave a rubble in place. If you com…

A first world military that has remotely piloted drones with IR cameras and other surveillance tools will have no problem crushing any form of resistance. They don’t even need to field any troops, they can remotely kill the rebels. How on earth do you wage a rebellion against such a force?

[deleted]

Re: Apple pulls data protection tool after UK government security row

#740
post #619

Earlier quoted context omitted.

> you think Google didn't already sign up to this? My understanding is that Android's Google Drive backup has had an E2E encryption option for many years (they blogged about it at https://security.googleblog.com/2018/10/google-and-android-h... ), and that the key is only stored locally in the Titan Security Module. If they are complying with the IPA, wouldn't that mean that they must build a mechanism into Android to…

My assumption is that Google has keys to everything in its kingdom [1]. [1] https://qz.com/1145669/googles-true-origin-partly-lies-in-ci...

My assumption is that the NSA does too.
Post reply on HN