Live data from Hacker News

Apple pulls data protection tool after UK government security row

bbc.com

741–750 of 1001 posts

Re: Apple pulls data protection tool after UK government security row

#741
post #552

Earlier quoted context omitted.

> One scenario would be somebody in an airport and security officials are searching your device No Heathrow connection necessary. “The law has extraterritorial powers, meaning UK law enforcement would have been able to access the encrypted iCloud data of Apple customers anywhere in the world, including in the US” [1]. [1] https://www.ft.com/content/bc20274f-f352-457c-8f86-32c6d4df8...

The US claims the same https://en.wikipedia.org/wiki/CLOUD_Act Lots of Americans in this thread seem to be talking down to other countries laws while being completely unaware of their own

Spot on, 727 comments, most probably by Americans, and only 2 (including yours) bringing up the CLOUD Act, the much worse US equivalent. Incredible ignorance.

Re: Apple pulls data protection tool after UK government security row

#742

I’m at the point where I’m ready to get a pixel and install graphene

I'm in a similar position. Strongly considering replacing my iPhone with a Pixel. But I realize I'm vulnerable via cloud services. GrapheneOS won't save me from someone poking through my Dropbox. I'll have to find another option for that too.

Re: Apple pulls data protection tool after UK government security row

#743
post #106

Too right, it was far more problematic than they ever made out. > The UK government's demand came through a "technical capability notice" under the Investigatory Powers Act (IPA), requiring Apple to create a backdoor that would allow British security officials to access encrypted user data globally. The order would have compromised Apple's Advanced Data Protection feature, which provides end-to-end encryption for iCl…

> you think Google didn't already sign up to this? My understanding is that Android's Google Drive backup has had an E2E encryption option for many years (they blogged about it at https://security.googleblog.com/2018/10/google-and-android-h... ), and that the key is only stored locally in the Titan Security Module. If they are complying with the IPA, wouldn't that mean that they must build a mechanism into Android to…

Could that be true and at the same time a 'vulnerability' exists that megacorp is party to?

Re: Apple pulls data protection tool after UK government security row

#744
post #619

Earlier quoted context omitted.

> you think Google didn't already sign up to this? My understanding is that Android's Google Drive backup has had an E2E encryption option for many years (they blogged about it at https://security.googleblog.com/2018/10/google-and-android-h... ), and that the key is only stored locally in the Titan Security Module. If they are complying with the IPA, wouldn't that mean that they must build a mechanism into Android to…

My assumption is that Google has keys to everything in its kingdom [1]. [1] https://qz.com/1145669/googles-true-origin-partly-lies-in-ci...

This would mean no independent security researcher has ever taken a look at Google Drive's E2EE on Android. Or those that did missed the part where the key is uploaded.

It's possible to decrypt this network traffic and see if the key is sent. It may be obfuscated though.

Re: Apple pulls data protection tool after UK government security row

#746
post #619

Earlier quoted context omitted.

My assumption is that Google has keys to everything in its kingdom [1]. [1] https://qz.com/1145669/googles-true-origin-partly-lies-in-ci...

> My assumption is that Google has keys to everything in its kingdom If that were true, then their claims to support E2E encrypted backups are simply false, and they would have been subject to warrants to unlock backups, just like Apple had been until they implemented their "Advanced Data Protection" in 2022. Wouldn't there have been be some evidence of that in the past 7 years, either through security research, or t…

> Wouldn't there have been be some evidence of that in the past 7 years, either through security research, or through convictions that hinged on information that was gotten from a supposedly E2E-protected backup?

I wouldn't count on it. The main way we'd know about it would be a whistleblower at Google, and whistleblowers are extremely rare. Evidence and court records that might expose a secret backdoor or that the government was getting data from Google that was supposed to be private could easily be kept hidden from the public by sealing it all away for "national security reasons" or by obscuring it though parallel construction.

Re: Apple pulls data protection tool after UK government security row

#747
post #465

Earlier quoted context omitted.

Who do you know that's been arrested for posting on social media? I don't know of anyone.

True. American police will shoot people dead in the streets with impunity, the military industrial complex engages in constant wars regardless of popular sentiment and the American government is currently being carved up by neo-nazis and oligarchs but you can legally be racist on the internet. I guess it truly is the land of the free. Also... wait six months.

[flagged]

Re: Apple pulls data protection tool after UK government security row

#748

Earlier quoted context omitted.

Rebels are able to use techniques that a government never could or would. I think you underestimate the usefulness of small arms in guerilla warfare.

I think you underestimate the lethality of remotely piloted drones with missiles and IR cameras and the futility of fighting against them.

The Taliban would argue otherwise.

Re: Apple pulls data protection tool after UK government security row

#749

Earlier quoted context omitted.

> have an Android device beside me that regularly asks me to back my device up to the cloud But is that backup encrypted? If it's not, all they need is to access your data. This is about having access to backups that are theoretically encrypted with a key Apple doesn't have? > We're talking about the largest back door I've ever heard of. Doesn't the US have access to all the data of non US citizens whose data is stor…

> non US citizens whose data is stored in the US They don't even care where it's stored... See: CLOUD Act [1] [1] https://en.wikipedia.org/wiki/CLOUD_Act

I honestly doubt they even limit themselves to the data of non-US citizens. They have no respect at all for the fourth amendment.

Re: Apple pulls data protection tool after UK government security row

#750

Earlier quoted context omitted.

Android data isn't encrypted at rest (or at least not in a way Google doesn't have the key). If the uk gov has a warrant, they can ask Google to provide your Google Drive content. The whole point of this issue is Apple specifically designed ADP so they couldn't do that.

Android backups are encrypted at rest using the lockscreen PIN or passphrase: https://developer.android.com/privacy-and-security/risks/bac... So not hugely secure for most people if they use 4-6 decimal digits, but possible to make secure if you set a longer passphrase. I don't know what Google's going to do about this UK business. edit: Ah it looks like they have a Titan HSM involved as well. Have to take Google's w…

I wonder how hard it would be for the US government to force Google to just get the lockscreen pin off of your device or for them to just infect your device with something to capture it themselves.
Post reply on HN