Live data from Hacker News

Apple pulls data protection tool after UK government security row

bbc.com

831–840 of 1001 posts

Re: Apple pulls data protection tool after UK government security row

#831
post #414

Earlier quoted context omitted.

> that having nothing to hide means you have nothing to fear hopefully the US turning from leader of the free world to Russia's tool will give them the kick they need to realise that just because you trust the government now doesn't mean you trust the next government or the one after it.

You probably don't want to look up which US President tried to force Apple to insert an encryption back door into iPhones back in 2015. However, Google did only start moving to protect location data from subpoenas after people started to worry that location data could be used as a legal weapon against women who went to an abortion clinic, so your larger point stands.

Points about Russia or partisan politics aside, there are now at least 10M people living in the US who have a very strong incentive to hide all their data from the executive branch. That's to say nothing of the countless millions who might want to help them.

The demand for encryption just exploded, in a legal gray area (city, state, and federal laws seem to be in conflict here) it's just a question of whether governments allows the supply to follow.

Re: Apple pulls data protection tool after UK government security row

#832
post #414

Earlier quoted context omitted.

> that having nothing to hide means you have nothing to fear hopefully the US turning from leader of the free world to Russia's tool will give them the kick they need to realise that just because you trust the government now doesn't mean you trust the next government or the one after it.

> hopefully the US turning from leader of the free world to Russia's tool So much humour in one short phrase. Do you really believe your propaganda or is it just absentmindedly parroting pro permanent war talking points?

What would you call the ridiculous claim that Ukraine started the war? Who else does that serve but Russia?

Re: Apple pulls data protection tool after UK government security row

#834

Earlier quoted context omitted.

I'm an immigrant to the UK. I have lived here permanently for 21 successive years, though I was actually in and out of the UK for years before that. My current anecdotal feeling about the UK is at a pretty low point. If it was an option, I would seriously look to emigrate again, but I honestly don't know where. The most appealing option for me is Australia, but my age works against me. I know everywhere has its issue…

Australia is hardly any better. E.g. it forces software engineers to try to sneak backdoors into the software they're working on. Imagine hiring someone you didn't know had an Australian dual citizenship and two years later all your customers' data is leaked onto the net.

Australian law explicitly prohibits requests that have someone "implement or build a systemic weaknesses, or a systemic vulnerability, into a form of electronic protection" - including any request to "implement or build a new decryption capability", anything which would "render systematic methods of authentication or encryption less effective", anything aimed at one person but could "jeopardise the security or any information held by another person", anything which "creates a material risk that otherwise secure information can be accessed by an unauthorised third party".

This UK request as reported would not be legal in Australia.

Re: Apple pulls data protection tool after UK government security row

#835
post #616

Earlier quoted context omitted.

That actually shows they understand and care because they don't want the law to apply to them. They don't care about its effects on other people.

No, it shows they're thinking of computers like they think of police officers. Computer literacy 101: to err is human, to really foul up requires a computer. They don't understand that by requiring the capability for going after domestic criminals, they've given a huge gift to their international adversaries' intelligence agencies. (And given this is about a computer vulnerability, "international adversaries" include…

I think it could be for both reasons

Re: Apple pulls data protection tool after UK government security row

#836

Earlier quoted context omitted.

I don't really understand your comment to be honest. Section 3 of the Regulation of Regulatory Powers Act 2000 allows for compelled key disclosure (disclosure of the information sought instead of the key is also possible). Schedule 7 of the Counter-Terrorism Act allows 9 hour detention, questioning and device search at the border. With these powers it isn't necessary to get access to iCloud backups, as you can get th…

I imagine they want the ability to look at someone's iCloud backups without notifying the owner that they are doing so or they want to do it when the owner is unwilling or unable to provide keys. For the latter, there are a lot of cases where jail isn't much a threat (e.g. the person is dead or not in the country).

Also given automatic iPhone backup it might contain information they want as part of an investigation that they'd otherwise have to demand key disclosure for (if cloud backup didn't exist)... Absolutely.

The jail time for failure to comply with key disclosure is 2 years unless it is national security, then it is 5. But if you're organised crime and facing who knows what for being a snitch it might be better simply to do the time.

I can see why they want it. I just don't understand why the person I'm replying to said the feature (I think) was problematic. Not really a criticism, I'm just struggling to identify the tone and why 'too right' and 'more problematic than they let on'.

Re: Apple pulls data protection tool after UK government security row

#837
post #751

Earlier quoted context omitted.

The hardware will not allow this, at least not without modifications. The encryption keys are not exportable from the Secure Enclave, not even to Apple's own servers.

Are you gonna unlock that phone anytime soon? Thanks for opening the enclave, don't mind if I ship these keys back home. No notification needed, Apple has root access.

Unless I am making a mistake here, you still can't extract keys of an opened enclave. You can just run operations against those keys.

Re: Apple pulls data protection tool after UK government security row

#838

Earlier quoted context omitted.

Also, I wondered if by complying with British law that they may somehow be breaking laws of another country? Hypothetically, if Apple just provide a back door to the data they have on US Senators for instance, then providing that information may be considered treason by the US. That's a totally made up example, and I have no idea, but it seems like it's possibly an issue. Which is all about the issues around data sov…

That would not be treason, by a long shot. Treason is the only crime defined in the constitution, and it is quite a high bar.

> Treason is the only crime defined in the constitution, and it is quite a high bar.

Well, it's defined, or bounded above, in the constitution. It's not exactly a high bar:

> Treason against the United States, shall consist only in levying War against them, or in adhering to their Enemies, giving them Aid and Comfort.

So, if you happened to know Nicolas Maduro, thought he was looking stressed, and bought him some food, that would qualify as treason. There's no requirement that you act against the interests of the United States. The constitution will stop you from being prosecuted for treason for sleeping with Melania Trump. It won't stop you from being prosecuted for treason for completely spurious reasons.

Re: Apple pulls data protection tool after UK government security row

#839

Earlier quoted context omitted.

You can provide a self destroy PIN with GrapheneOS.

And that certainly wouldn't raise their suspicion. Surely, they'd immediately let you go after that stunt.

Of course they could throw a tantrum, but it wouldn't be nothing but that, and they will have to release you once they cool down.

What are they going to say? That they won't release you until you magically unerase the phone? There's nothing to wait for.

Re: Apple pulls data protection tool after UK government security row

#840
post #197

Think about it.. You don't even have to be an Apple user to be affected by this issue. If someone backs up their conversations with you to apple cloud, your exchange is now fair game. You get no say in it either. We all lose.

Very similar to sites like LinkedIn, which ask you to share your personal info & contact list. I don't want to share my contact details, but the second someone I know decides to opt in, I lose all rights to my own data as they've shared it on my behalf. Maybe they have other info, such as birthday, home address, other emails or phone #s, etc. stored for me, which is all fair game, as well.

If you are in EU, request your data be redacted.
Post reply on HN