Live data from Hacker News

Chinese authorities detain Apple employees suspected of selling customer data

hongkongfp.com

81–90 of 112 posts

Re: Chinese authorities detain Apple employees suspected of selling customer data

#81
post #59
post #43

Earlier quoted context omitted.

It's technological negligence if you set out to protect customers privacy, but your employees decide to steal it anyway, because they can.

By that argument, all theft is negligence.

Technically speaking, you are correct, but so what?

It does kind of sound like victim blaming, but if you store a bunch of cash under your mattress, don't be surprised if someone tries to take it.

Likewise, if you store a bunch of customer data, someone will try to come and take it. If you make it accessible to anyone other than the customer, you can't act surprised if someone takes it.

Re: Chinese authorities detain Apple employees suspected of selling customer data

#82
post #24

Apple does not allow your iOS iCloud data to be encrypted in a manner where Apple cannot access it. As is alluded to in this article. Privacy advocates and privacy caring IT specialists have repeatedly asked Apple to offer such an option, but so far Apple has decided that regular people would turn such an option on, forget their password, then ask Apple for help and would be unhappy with their brand experience if App…

Correct me if I'm wrong but isn't this the same thing as turning iCloud backups off and doing local encrypted backups instead?

It seems like a reasonable choice to me, if you don't want to store in iCloud you can keep it locally with a different encryption model.

Re: Chinese authorities detain Apple employees suspected of selling customer data

#83
post #71
post #66

So now after forcing Microsoft to have a Chinese version of Windows 10 without spyware, Blizzard forced to show the Overwatch loot boxes odds and this, we are living in a World where China, "Great Firewall" China is now the biggest advocate of users privacy. What is happening?

oh, they can just quit the Chinese market by following what google did almost 10 years ago. look at google's share price & revenues, surely you don't need the Chinese market to be successful. fb is another good example.

Apple is huge in China. I agree that Apple doesn't need China to be successful, but that's a lot of money left on the table: for what purpose? For principles? For the subset of your customers who are concerned about privacy?

Re: Chinese authorities detain Apple employees suspected of selling customer data

#84

Earlier quoted context omitted.

Even the NSA has leakers.

And if the NSA championed themselves as the defenders of privacy, how hard would you roll your eyes?

For my point it doesn't matter what the nature of the information is. Both Apple and the NSA want their people to keep secrets secret. But I think the NSA goes a fair bit further to prevent their employees from leaking far more sensitive info, and leaks still occur.

Re: Chinese authorities detain Apple employees suspected of selling customer data

#85
post #26

Earlier quoted context omitted.

Did you report that?

I emailed security@apple.com and never received a response. Generally, when I need to get the attention of big tech corporations I talk to a friend who works there. Unfortunately, I don't really know anyone who works at Apple.

You don't have any contact details in your profile; check mine and send me any details you can. I'll ping the appropriate people.

Re: Chinese authorities detain Apple employees suspected of selling customer data

#86
post #24

Apple does not allow your iOS iCloud data to be encrypted in a manner where Apple cannot access it. As is alluded to in this article. Privacy advocates and privacy caring IT specialists have repeatedly asked Apple to offer such an option, but so far Apple has decided that regular people would turn such an option on, forget their password, then ask Apple for help and would be unhappy with their brand experience if App…

Roughly half the population has an IQ below 100. Let that sink in for a moment. Do you really think they are able to manage their digital keys such that they never ever lose them in a lifetime? Look, I am all for encrypted storage, it's the only thing I'd use (but I store everything on my own HDDs that are in my physical possession), but I see Apple's point here.

Re: Chinese authorities detain Apple employees suspected of selling customer data

#87
post #80

Earlier quoted context omitted.

>> Privacy advocates and privacy caring IT specialists have repeatedly asked Apple to offer such an option, but so far Apple has decided that regular people would turn such an option on, forget their password, then ask Apple for help and would be unhappy with their brand experience if Apple could not help them out. Were I an iCloud user, I would pay big $$$ for such a feature. But... they do have a point, and anyone…

>they do have a point, and anyone who's helped their friends and relatives with IT issues can confirm that. I think it's a pretty common state of affairs when dealing with complaints about Apple's choices. It's not that they're (necessarily) malicious, or that they don't care about security etc. It's prioritising the user experience of an average user over the concerns of a relative minority. I, personally, hope they…

You are correct, but the problem is that they tout themselves as the goto company for privacy and security. If you are focused on usability over security, maybe don't advertise yourself otherwise.

Re: Chinese authorities detain Apple employees suspected of selling customer data

#88
post #66

So now after forcing Microsoft to have a Chinese version of Windows 10 without spyware, Blizzard forced to show the Overwatch loot boxes odds and this, we are living in a World where China, "Great Firewall" China is now the biggest advocate of users privacy. What is happening?

The Microsoft case doesn't need to be surprising, because Microsoft is a part of PRISM and maybe other such programs. To China that means Microsoft products might as well be sending data directly to NSA datacenters. They probably don't like the NSA having that kind of view into their country.

Re: Chinese authorities detain Apple employees suspected of selling customer data

#89

Earlier quoted context omitted.

This does not necessarily imply that the data is unencrypted at rest. The query tool or the query backend could handle decryption seamlessly. S3 offers similar encryption at rest that is invisible to authorized requesters. If the story was that someone raided an Apple data center, stole hard drives, and leaked customer data, then we would have reason to assume that.

I assumed "encrypted at rest" to mean encrypted with the user's passcode, meaning it could only be decrypted from a properly authorized user session, not some internal apple tool.

From my understanding, that is how Apple encrypts on device. They don't use this with iCloud data at rest and instead maintain encryption keys themselves [1] so in the event of, for example, a user losing their credentials, they would still be able to assist.

[1]: https://support.apple.com/en-us/HT202303

Re: Chinese authorities detain Apple employees suspected of selling customer data

#90
post #24

Apple does not allow your iOS iCloud data to be encrypted in a manner where Apple cannot access it. As is alluded to in this article. Privacy advocates and privacy caring IT specialists have repeatedly asked Apple to offer such an option, but so far Apple has decided that regular people would turn such an option on, forget their password, then ask Apple for help and would be unhappy with their brand experience if App…

Correct me if I'm wrong but isn't this the same thing as turning iCloud backups off and doing local encrypted backups instead? It seems like a reasonable choice to me, if you don't want to store in iCloud you can keep it locally with a different encryption model.

The problem is the deep integration between iCloud and Apple devices.

Lots of stuff can't be just backed up to a different cloud provider/do locally.

Post reply on HN