Live data from Hacker News

Apple pulls data protection tool after UK government security row

bbc.com

781–790 of 1001 posts

Re: Apple pulls data protection tool after UK government security row

#781

Earlier quoted context omitted.

Also, I wondered if by complying with British law that they may somehow be breaking laws of another country? Hypothetically, if Apple just provide a back door to the data they have on US Senators for instance, then providing that information may be considered treason by the US. That's a totally made up example, and I have no idea, but it seems like it's possibly an issue. Which is all about the issues around data sov…

That would not be treason, by a long shot. Treason is the only crime defined in the constitution, and it is quite a high bar.

The king is a strict constitutionalist, who may disagree with you/ Pray he doesn’t.

Re: Apple pulls data protection tool after UK government security row

#782
post #289

Earlier quoted context omitted.

> how can you “pull” E2E encryption without data loss You can’t. The article says if you don’t disable it (which you have to do yourself, they can’t do it for you, because it’s E2E), your iCloud account will be canceled.

At this point, the right thing to do is allow for an alt-service.

How would an alt service help this situation? You’d just end up with backdoored services advertising E2EE, no? Apple’s move here is definitely the right one, introduce as much friction as possible to hopefully get the user pissed off at their government for writing such stupid laws.

Re: Apple pulls data protection tool after UK government security row

#783
post #608

Earlier quoted context omitted.

The government forced them to pull the feature. Would you rather they left a toggle-switch that doesn't actually do anything? Or are you thinking they should just pull out of the EU altogether?

Making a stand would be leaving UK (UK is not in the EU) altogether. This is almost as bad as building a backdoor. This is leaving your customer in the rain. Fortunately for Apple, most of them won't even know or realize it.

No, this tells the customer that backups to iCloud are not secure from the government. Adding the back door would make people think that there was more security than there was. Transparency is always better than deception.

Dropping the feature that the UK was targeting allows their customers to use all the other ways that Apple does things. Leaving the UK altogether is the nuclear option denying their customers of everything. “Apple should just leave the UK/China” never takes into consideration the millions of customers that bought or might want to buy in the future. Nobody would better off if Apple withdraws from a country.

Re: Apple pulls data protection tool after UK government security row

#784

Earlier quoted context omitted.

Presumably these keys live in a hardware security module on your phone called “secure enclave” and cannot be extracted

Is this module auditable though, or is "just trust us", like everything in the Apple world?

An HSM bypass (extracting keys, performing unauthenticated crypto ops) on any recent iOS device is worth 10s of millions, easily. Especially if combined with a one-click/no click. In that sense, it’s auditable, because it’s one of the biggest targets for any colour hat, and the people smart enough to find a bug/backdoor would only be slightly aided by a spec/firmware source, and a bit more by the verilog.

This is true for pretty much every “real” hsm on the planet btw. No one is sharing cutting edge enclave details, Apple isn’t unique in this regard.

Re: Apple pulls data protection tool after UK government security row

#785
post #106

Too right, it was far more problematic than they ever made out. > The UK government's demand came through a "technical capability notice" under the Investigatory Powers Act (IPA), requiring Apple to create a backdoor that would allow British security officials to access encrypted user data globally. The order would have compromised Apple's Advanced Data Protection feature, which provides end-to-end encryption for iCl…

> the largest back door I've ever heard of.

Do you know of the clipper chip? https://en.wikipedia.org/wiki/Clipper_chip

From what I recall, we were only spared from it by someone hacking it before it was deployed.

Re: Apple pulls data protection tool after UK government security row

#786
post #391
post #326

Earlier quoted context omitted.

> Doesn't the US have access to all the data of non US citizens whose data is stored in the US without any oversight? Totally agree. Having this discussion so US centred just makes us miss the forest for the trees. Apart from data owned by US citizens, my impression is that data stored in the US is fair game for three letter agencies, and I really doubt most companies would spend more than five minutes agreeing with…

Agree in principle, though WhatsApp backups are encrypted with a user provided password, so ostensibly inaccessible to Google or whoever you use as backup

What makes you think WhatsApp backups don’t have a secondary way to unlock the encryption key? Wouldn’t it be more logical to assume the encryption key for whatsapp backups can also be unlocked by an alternate “password”

If the US is willing to build an entire data center in Outback Australia to allow warrantless access to US citizen data, why wouldn’t they be forcing WhatsApp backups to be unlockable?

Re: Apple pulls data protection tool after UK government security row

#787
post #752

Earlier quoted context omitted.

> Apple is in a really tough position. You mean Apple is in a unique position to make a statement. No more Apple products in the UK. Mic drop. Exit stage left.

But… money

But customers. People keep saying they should just not be in that country. It is far better to have the choice of using an iPhone even if particular features are no longer available.

Re: Apple pulls data protection tool after UK government security row

#788

Earlier quoted context omitted.

> What concerns me more is that Apple is the only company audibly making a stand. But still Apple operates in China and Google does not. This is weird to me. Google left China when the government wanted all keys to the citizens data. Apple is making a stand when it's visible and does not threaten their business too much. Apple is not really in the business of protecting your data, they are just good at marketing and…

Perhaps Apple has a greater leverage in China due to its outsized manufacturing presence. And it's likely they already dont offer ADP to Chinese citizens.

> And it's likely they already dont offer ADP to Chinese citizens.

AFAIK before UK only region with ADP was China.

Re: Apple pulls data protection tool after UK government security row

#789

Earlier quoted context omitted.

> What concerns me more is that Apple is the only company audibly making a stand. But still Apple operates in China and Google does not. This is weird to me. Google left China when the government wanted all keys to the citizens data. Apple is making a stand when it's visible and does not threaten their business too much. Apple is not really in the business of protecting your data, they are just good at marketing and…

Perhaps Apple has a greater leverage in China due to its outsized manufacturing presence. And it's likely they already dont offer ADP to Chinese citizens.

> Perhaps Apple has a greater leverage in China due to its outsized manufacturing presence.

Perhaps china has greater leverage over apple in this case...

China had been an important area of growth for many companies during the 2010s. Apple bent over backwards to cater to that market. It was discussed in every financial release, and they obviously made tons of concessions for iCloud.

The UK just comparatively isn't that much revenue, and not worth the fallout.

Post reply on HN