Live data from Hacker News

Apple pulls data protection tool after UK government security row

bbc.com

791–800 of 1001 posts

Re: Apple pulls data protection tool after UK government security row

#791
post #401

Earlier quoted context omitted.

> Especially in the UK which operates as a paternalistic state and enjoys authoritarian support across all parties. This seemed strange to point out. It’s not really any more or less “paternalistic” than most western nations including the US.

Folks in the United States aren't routinely arrested for Facebook posts.

The AP News was just kicked out of press conferences for not using the government-preferred term for the Gulf of Mexico. The new director of the FBI is pledging to go after members of the press that he doesn't like. The US is jumping headfirst in the "bad speech isn't free" direction in the past month.

Re: Apple pulls data protection tool after UK government security row

#792

Earlier quoted context omitted.

> My assumption is that Google has keys to everything in its kingdom If that were true, then their claims to support E2E encrypted backups are simply false, and they would have been subject to warrants to unlock backups, just like Apple had been until they implemented their "Advanced Data Protection" in 2022. Wouldn't there have been be some evidence of that in the past 7 years, either through security research, or t…

Would it be possible that they feel that the revelation of this backdoor would be too big of a loss so that any of these theoretical cases of the past 7 years have used parallel construction to avoid revealing the encrypted data was viewed?

That’s a big and brittle conspiracy. You have to have little to no defectors. It’s not a stable equilibrium

Re: Apple pulls data protection tool after UK government security row

#793

Earlier quoted context omitted.

> My assumption is that Google has keys to everything in its kingdom If that were true, then their claims to support E2E encrypted backups are simply false, and they would have been subject to warrants to unlock backups, just like Apple had been until they implemented their "Advanced Data Protection" in 2022. Wouldn't there have been be some evidence of that in the past 7 years, either through security research, or t…

> Wouldn't there have been be some evidence of that in the past 7 years, either through security research, or through convictions that hinged on information that was gotten from a supposedly E2E-protected backup? I wouldn't count on it. The main way we'd know about it would be a whistleblower at Google, and whistleblowers are extremely rare. Evidence and court records that might expose a secret backdoor or that the g…

People are incredibly bad at keeping secrets. And there are a LOT of people at Google. I don’t buy it.

Re: Apple pulls data protection tool after UK government security row

#794

Earlier quoted context omitted.

> What concerns me more is that Apple is the only company audibly making a stand. But still Apple operates in China and Google does not. This is weird to me. Google left China when the government wanted all keys to the citizens data. Apple is making a stand when it's visible and does not threaten their business too much. Apple is not really in the business of protecting your data, they are just good at marketing and…

> Google left China when the government wanted all keys to the citizens data. Google left China after China started hacking into Google's servers. > In January, Google said it would no longer cooperate with government censors after hackers based in China stole some of the company’s source code and even broke into the Gmail accounts of Chinese human rights advocates. https://www.nytimes.com/2010/03/23/technology/23goo…

I'd imagine there were multiple factors that went into that business decision. Even if this was portrayed as the final straw.

Re: Apple pulls data protection tool after UK government security row

#795
post #484
post #475

Earlier quoted context omitted.

Looking at the ones for Germany, those seem like rookie numbers https://www.apple.com/legal/transparency/de.html#:~:text=77%...

It's also comparatively worse than the raw numbers suggest because the customer base of Apple phones in Germany is much smaller than in the UK.

I see numbers for USA and China very low as well.

Maybe they don't have/need to request? ;-) Just saying.

Re: Apple pulls data protection tool after UK government security row

#796
post #697

Earlier quoted context omitted.

Almost all iPhones are made in China. They cannot pull out without shutting down. They make on average 60,000 ios devices there every hour, 24 hours a day, 365 days a year.

Your math adds up to 525,600,000 iOS devices per year. That can't possibly be right

> In 2023, Apple shipped 234.6 million iPhones, capturing 20.1% market share and growing 3.7% year over year, according to IDC data. [0]

So, probably not 525.6 million iOS devices a year, but safe to assume it's going to be 300+ million for 2025.

35k devices an hour, give or take.

[0]: https://www.forbes.com/sites/johnkoetsier/2024/01/16/apple-1...

Re: Apple pulls data protection tool after UK government security row

#797
So many questions around this that need answering, such as:

1. What happens if I have ADP enabled and then visit the UK? Will photos I take there still be E2E encrypted? If not, will I be notified? I realize that at the moment the answer is yes, that for now, they are only disabling ADP enrollment. But they are planning to turn it off for everyone in the UK in the future. So what happens then?

2. If they make an exception for visitors, such as by checking the account region, then obviously anyone in the UK who cares about security will just change their account region - a small inconvenience. Maybe this will be a small enough group that the UK government doesn’t really care, but it could catch on.

3. Is this going to be retroactive? It’s one thing to disallow E2E encryption for new content going forward, where people can at least start making different decisions about what they store in the cloud. It’s an entirely different thing for them to remove the protection from existing content that was previously promised to be E2E encrypted. When they turn off ADP for people who were already enrolled, how is their existing data going to be handled?

This is bad news and it is going to be messy.

Re: Apple pulls data protection tool after UK government security row

#798

Earlier quoted context omitted.

It is possible to set up end to end encryption where two different keys unlock your data. Your key, and a government key. I assume google does this. 1. encrypt data with special key 2. encrypt special key with users key, and 3. encrypt special key with government key Anyone with the special key can read the data.the user key or the government key can be used to get special key. This two step process can be done for g…

E2EE means only your intended recipients can access the plaintext. Unless you intend to give the government access to your plaintext, what you described isn’t E2EE.

Manufacturers have lied about E2EE since the beginning. Some claim that having the key doesn't change that it's e2ee. Others claim that using https = e2ee, because it's encrypted from one end to the other, you see? (A recent example is Anker Eufy)

The point is that the dictionary definition of E2EE really doesn't matter. Being pedantic about it doesn't help. The only thing that matters is that the vendor describes what they call E2EE.

Re: Apple pulls data protection tool after UK government security row

#799
post #450

Many people might not be aware of it, but Apple publishes a breakdown of the number of government requests for data that it receives, broken down by country. The number of UK requests has ballooned in recent years: https://www.apple.com/legal/transparency/gb.html#:~:text=77%... Much of this is likely related to the implementation and automation of the US-UK data access agreement pursuant to the CLOUD Act, which has s…

Sad to see the home of the magna carta slowly spiraling down into fascism and 1984. The government should be required to have a specific warrant to get at your personal data.

Re: Apple pulls data protection tool after UK government security row

#800
Absolutely mental the kind of people that have power. Dealing with this like immature children.

“We don’t get what we want? We ruin it for everyone.”

Trying to backdoor a privacy feature for no real reason, just for the sake of having a backdoor. Pathetic

Post reply on HN