Earlier quoted context omitted.
The unspoken part of that is Vance likely thinks that the people should fear their government.
[flagged]
Apple pulls data protection tool after UK government security row
801–810 of 1001 posts
Re: Apple pulls data protection tool after UK government security row
#802Too right, it was far more problematic than they ever made out. > The UK government's demand came through a "technical capability notice" under the Investigatory Powers Act (IPA), requiring Apple to create a backdoor that would allow British security officials to access encrypted user data globally. The order would have compromised Apple's Advanced Data Protection feature, which provides end-to-end encryption for iCl…
This is why, while I applaud what Apple is doing here, they need to allow us to supply our own E2E encryption keys.
Re: Apple pulls data protection tool after UK government security row
#803So instead of building a back door they're just completely removing the option to use E2E encryption altogether, thus making everything freely available to government by default? How is that not worse or at least equivalent to a back door?
Re: Apple pulls data protection tool after UK government security row
#804Re: Apple pulls data protection tool after UK government security row
#805Earlier quoted context omitted.
Perhaps Apple has a greater leverage in China due to its outsized manufacturing presence. And it's likely they already dont offer ADP to Chinese citizens.
> Perhaps Apple has a greater leverage in China due to its outsized manufacturing presence. Perhaps china has greater leverage over apple in this case... China had been an important area of growth for many companies during the 2010s. Apple bent over backwards to cater to that market. It was discussed in every financial release, and they obviously made tons of concessions for iCloud. The UK just comparatively isn't th…
and it is the same with european car companies (like volkswagon). Look at where they are now.
I don't believe for a second, that china will not oust apple the moment there's a good reason to.
Re: Apple pulls data protection tool after UK government security row
#806Earlier quoted context omitted.
When you disable ADP, your local encryption keys are uploaded to Apple's servers to be read by them. Apple could just lock you out of iCloud until you do this.
The hardware will not allow this, at least not without modifications. The encryption keys are not exportable from the Secure Enclave, not even to Apple's own servers.
This will be a "forced rotation", they just need to decide how to communicate to users and work out what happens to those who don't comply. Lockout until key rotation look like an option as someone said.
Re: Apple pulls data protection tool after UK government security row
#807Too right, it was far more problematic than they ever made out. > The UK government's demand came through a "technical capability notice" under the Investigatory Powers Act (IPA), requiring Apple to create a backdoor that would allow British security officials to access encrypted user data globally. The order would have compromised Apple's Advanced Data Protection feature, which provides end-to-end encryption for iCl…
Re: Apple pulls data protection tool after UK government security row
#808Earlier quoted context omitted.
When you disable ADP, your local encryption keys are uploaded to Apple's servers to be read by them. Apple could just lock you out of iCloud until you do this.
The hardware will not allow this, at least not without modifications. The encryption keys are not exportable from the Secure Enclave, not even to Apple's own servers.
Re: Apple pulls data protection tool after UK government security row
#809Earlier quoted context omitted.
> My assumption is that Google has keys to everything in its kingdom If that were true, then their claims to support E2E encrypted backups are simply false, and they would have been subject to warrants to unlock backups, just like Apple had been until they implemented their "Advanced Data Protection" in 2022. Wouldn't there have been be some evidence of that in the past 7 years, either through security research, or t…
A trivial method for circumventing code review is to simply push a targeted update of the firmware to devices subject to a government search order. There are no practical end-user protections against this vector. PS: I strongly suspect that at least a few public package distribution services are run by security agencies to enable this kind of attack. They can distribute clean packages 99.999% of the time, except for…
Re: Apple pulls data protection tool after UK government security row
#810Earlier quoted context omitted.
> you think Google didn't already sign up to this? My understanding is that Android's Google Drive backup has had an E2E encryption option for many years (they blogged about it at https://security.googleblog.com/2018/10/google-and-android-h... ), and that the key is only stored locally in the Titan Security Module. If they are complying with the IPA, wouldn't that mean that they must build a mechanism into Android to…
My assumption is that Google has keys to everything in its kingdom [1]. [1] https://qz.com/1145669/googles-true-origin-partly-lies-in-ci...
How much good does an encrypted device backup do when harvesting user data and storing it on your servers (to make ad sales more profitable) is your entire business model?