Live data from Hacker News

Apple pulls data protection tool after UK government security row

bbc.com

801–810 of 1001 posts

Re: Apple pulls data protection tool after UK government security row

#801

Earlier quoted context omitted.

The unspoken part of that is Vance likely thinks that the people should fear their government.

[flagged]

He likened Trump to Hitler and then ran with him. That reveals everything about Vance.

Re: Apple pulls data protection tool after UK government security row

#802
post #106

Too right, it was far more problematic than they ever made out. > The UK government's demand came through a "technical capability notice" under the Investigatory Powers Act (IPA), requiring Apple to create a backdoor that would allow British security officials to access encrypted user data globally. The order would have compromised Apple's Advanced Data Protection feature, which provides end-to-end encryption for iCl…

This is why, while I applaud what Apple is doing here, they need to allow us to supply our own E2E encryption keys.

But if you don't trust Apple, how to you get the key into the Secure Enclave to begin with? Doesn't Apple control the software on your device that provides the interface into the Secure Enclave from outside of it?

Re: Apple pulls data protection tool after UK government security row

#805

Earlier quoted context omitted.

Perhaps Apple has a greater leverage in China due to its outsized manufacturing presence. And it's likely they already dont offer ADP to Chinese citizens.

> Perhaps Apple has a greater leverage in China due to its outsized manufacturing presence. Perhaps china has greater leverage over apple in this case... China had been an important area of growth for many companies during the 2010s. Apple bent over backwards to cater to that market. It was discussed in every financial release, and they obviously made tons of concessions for iCloud. The UK just comparatively isn't th…

> China had been an important area of growth for many companies during the 2010s. Apple bent over backwards to cater to that market

and it is the same with european car companies (like volkswagon). Look at where they are now.

I don't believe for a second, that china will not oust apple the moment there's a good reason to.

Re: Apple pulls data protection tool after UK government security row

#806

Earlier quoted context omitted.

When you disable ADP, your local encryption keys are uploaded to Apple's servers to be read by them. Apple could just lock you out of iCloud until you do this.

The hardware will not allow this, at least not without modifications. The encryption keys are not exportable from the Secure Enclave, not even to Apple's own servers.

The Apple security paper describe how to disable ADP through a key rotation sequence.

This will be a "forced rotation", they just need to decide how to communicate to users and work out what happens to those who don't comply. Lockout until key rotation look like an option as someone said.

Re: Apple pulls data protection tool after UK government security row

#807
post #106

Too right, it was far more problematic than they ever made out. > The UK government's demand came through a "technical capability notice" under the Investigatory Powers Act (IPA), requiring Apple to create a backdoor that would allow British security officials to access encrypted user data globally. The order would have compromised Apple's Advanced Data Protection feature, which provides end-to-end encryption for iCl…

And now imagine for a second that the only thing the UK is doing here is getting the same direct access that the US (NSA) has already had for decades.

Re: Apple pulls data protection tool after UK government security row

#808

Earlier quoted context omitted.

When you disable ADP, your local encryption keys are uploaded to Apple's servers to be read by them. Apple could just lock you out of iCloud until you do this.

The hardware will not allow this, at least not without modifications. The encryption keys are not exportable from the Secure Enclave, not even to Apple's own servers.

Behind the scenes, it'd probably decrypt it locally piece-by-piece with the key in the Secure Enclave, and then reencrypt it with a new key that Apple has a copy of when you disable ADP.

Re: Apple pulls data protection tool after UK government security row

#809

Earlier quoted context omitted.

> My assumption is that Google has keys to everything in its kingdom If that were true, then their claims to support E2E encrypted backups are simply false, and they would have been subject to warrants to unlock backups, just like Apple had been until they implemented their "Advanced Data Protection" in 2022. Wouldn't there have been be some evidence of that in the past 7 years, either through security research, or t…

A trivial method for circumventing code review is to simply push a targeted update of the firmware to devices subject to a government search order. There are no practical end-user protections against this vector. PS: I strongly suspect that at least a few public package distribution services are run by security agencies to enable this kind of attack. They can distribute clean packages 99.999% of the time, except for…

The end user protection is to sign updates and publish the fingerprints. It should not be possible for one device to get a different binary than everyone else.

Re: Apple pulls data protection tool after UK government security row

#810
post #619

Earlier quoted context omitted.

> you think Google didn't already sign up to this? My understanding is that Android's Google Drive backup has had an E2E encryption option for many years (they blogged about it at https://security.googleblog.com/2018/10/google-and-android-h... ), and that the key is only stored locally in the Titan Security Module. If they are complying with the IPA, wouldn't that mean that they must build a mechanism into Android to…

My assumption is that Google has keys to everything in its kingdom [1]. [1] https://qz.com/1145669/googles-true-origin-partly-lies-in-ci...

Google didn't announce that they could no longer process geofence warrants because they no longer stored a copy of user location data on their servers until last October.

How much good does an encrypted device backup do when harvesting user data and storing it on your servers (to make ad sales more profitable) is your entire business model?

Post reply on HN