Live data from Hacker News

Apple pulls data protection tool after UK government security row

bbc.com

861–870 of 1001 posts

Re: Apple pulls data protection tool after UK government security row

#861
post #358

Fundamentally, I think the issue is more about technical literacy amongst the political establishment who consistently rely on the fallacy that having nothing to hide means you have nothing to fear. Especially in the UK which operates as a paternalistic state and enjoys authoritarian support across all parties. On the authoritarianism: these laws are always worded in such a way that they can be applied or targeted va…

"Especially in the UK which operates as a paternalistic state and enjoys authoritarian support across all parties." What is a "paternalistic state". I studied Latin so obviously I understand pater == father but what is a father-like state? What on earth is: "authoritarian support across all parties". The UK has one Parliament, four Executives (England, Northern Ireland, Scotland, Wales) and a Monarch (he's actually q…

Government knows what’s best for the people (colloquially we call it the nanny state).

All our main political parties have an authoritarian slant so these policies have rarely received long-lasting opposition. Literally every government in office for the past 30-odd years has presented legislation like this.

Re: Apple pulls data protection tool after UK government security row

#862
post #358

Fundamentally, I think the issue is more about technical literacy amongst the political establishment who consistently rely on the fallacy that having nothing to hide means you have nothing to fear. Especially in the UK which operates as a paternalistic state and enjoys authoritarian support across all parties. On the authoritarianism: these laws are always worded in such a way that they can be applied or targeted va…

What the politicians want is partial security: something they can crack but criminals can't. That is achievable in physical security, but not in cybersecurity. I have a feeling the politicians already know partial cybersecurity isn't an option, and don't care. Certainly, the intelligence community advising them absolutely does know. We don't even have to be conspiratorial about it: their jobs are easier in the world…

> That is achievable in physical security, but not in cybersecurity

This isn't accurate though, and leads us down the path of trying to prevent these bad laws from a technical perspective when we should be fighting the principle of the bad law not just decrying it for being "unworkable".

It is possible to construct encryption schemes with a "backdoor key" while still being provably secure against anyone else.

This creates precisely the "partial security" you describe: Criminals can't crack the encryption, but the government can use their backdoor-key.

But like those who argue online age-consent schemes can't work, it doesn't help to argue against the technical aspects of such bad laws. The law, particularly UK law, doesn't care for what's technically possible. The bad laws can sit on the books regardless of the technical feasibility of enforcement. Eventually technology can catch up, or the law can simply be applied on a best endeavours / selective enforcement approach.

Re: Apple pulls data protection tool after UK government security row

#864

Earlier quoted context omitted.

Making a stand would be leaving UK (UK is not in the EU) altogether. This is almost as bad as building a backdoor. This is leaving your customer in the rain. Fortunately for Apple, most of them won't even know or realize it.

No, this tells the customer that backups to iCloud are not secure from the government. Adding the back door would make people think that there was more security than there was. Transparency is always better than deception. Dropping the feature that the UK was targeting allows their customers to use all the other ways that Apple does things. Leaving the UK altogether is the nuclear option denying their customers of ev…

I don't think we both have the same concept of "making a stand".

Yes, it would have been the nuclear option, but this is Apple. Probably most of the most influential people in the UK have an Apple phone. Just saying that you leave would cause an avalanche of influence targeted at this law. Maybe other companies would have joined them.

This, this is just cover dance and I wish they'd pay for this, but they won't and they know it. People locked into the Apple bubble only change if it REALLY hurts. This doesn't hurt the average Apple user, and those who really care moved onto a system they can control themselves.

Re: Apple pulls data protection tool after UK government security row

#865
post #693

Earlier quoted context omitted.

Making a stand would be leaving UK (UK is not in the EU) altogether. This is almost as bad as building a backdoor. This is leaving your customer in the rain. Fortunately for Apple, most of them won't even know or realize it.

> This is leaving your customer in the rain. vs. taking their phone away??? Idk if you're trolling or what but I would be incredibly pissed at Apple if they deprecated my phone over something like this.

Yes, imagine the outrage in the rich and influential in the UK if Apple would seriously threaten to leave the country about this. They would cause the law to be fixed which would help everybody.

But instead. They run away.

Selling this as "making a stand" is ridiculous. Nothing more.

Re: Apple pulls data protection tool after UK government security row

#866

Earlier quoted context omitted.

Making a stand would be leaving UK (UK is not in the EU) altogether. This is almost as bad as building a backdoor. This is leaving your customer in the rain. Fortunately for Apple, most of them won't even know or realize it.

Making a stand would be displaying a full-screen notification about why they cannot provide protection for British users' data and which party voted for this.

No. Making a stand would be to threaten to leave and watch all those influential iPhone users scramble to get this law rolled back. Everything else is marketing and cowardice.

Re: Apple pulls data protection tool after UK government security row

#867
post #532

>Online privacy expert Caro Robson said she believed it was "unprecedented" for a company "simply to withdraw a product rather than cooperate with a government. That is such a self serving comment. If Apple provides UK a backdoor, it weakens all users globally. With this they are following the local law and the country deserves what the rulers of the country want. These experts are a bit much. In the next paragraph t…

Fake privacy experts like Caro Robson need to be held accountable.

I often notice journalistic pieces interview people and then use maybe 30 seconds' worth of material from a 20-minute interview. The "expert" could have condemned it in any number of ways until the topic of applying data protection laws came up and she said that companies need to be held accountable (could be about GDPR, could be about snooping laws) which the journalist then quoted, not out of malice but because everyone already condemns it and this is the most interesting statement of the interview

Anyway, so while I don't think we should condemn people based on such a single quoted sentence... I took a look at her website and the latest video reveals at 00:38 that she worked for the UK crime agency, which does sound like the one of the greatest possible conflicts of interest for someone called upon for privacy matters rather than crime fighting. Watching the rest of that interview, she approaches it fairly objectively but (my interpretation of) her point of view seems to be on the side of "even with this backdoor, a warrant needs issuing every time they use it and so there's adequate safeguards and the UK crime fighters and national security people should just get access to anything they can get a warrant for"

Re: Apple pulls data protection tool after UK government security row

#868

Earlier quoted context omitted.

Given historical backups are the norm here, retention only does so much. Really, apps should encrypt their own storage with keys that aren't stored in the backups. That's how you get security/privacy back.

> That's how you get security/privacy back. Nothing an app does on a device guarantees you security or privacy if you don't trust or fully control the device.

Yes, but they'd have to issue another one of these snooping demands to either the app's developer (there's loads of developers so this would get out of hand quickly) or to Apple to patch the build or read the memory or something to get the unencrypted data

This current demand isn't blanket access to your device, it's access to things uploaded to Apple's online storage service. Having to get a backdoor that works with every app's encryption takes a lot more work while running the data through an authenticated encryption algorithm is relatively trivial for a developer

Re: Apple pulls data protection tool after UK government security row

#869
post #854

Earlier quoted context omitted.

You're an ignorant fool: https://www.theregister.com/Print/2009/11/24/ripa_jfl/

LOL literally a suspected terrorsit.

Being in court for something doesn't make you guilty of said thing. What's the "heavy evidence" you say they had before jailing this person?

Re: Apple pulls data protection tool after UK government security row

#870

Earlier quoted context omitted.

> What concerns me more is that Apple is the only company audibly making a stand. But still Apple operates in China and Google does not. This is weird to me. Google left China when the government wanted all keys to the citizens data. Apple is making a stand when it's visible and does not threaten their business too much. Apple is not really in the business of protecting your data, they are just good at marketing and…

China feels like an important difference here though. Google leaving China doesn't protect Chinese citizen's data any more than Apple turning off ADP in the UK does. As far as I know, Apple isn't pretending that the data of Chinese users is encrypted from their government, and the way they're complying with the Chinese laws shouldn't impact the security of users outside of China. Apple pulling ADP from UK users is si…

> Would you have been more satisfied if Apple just pulled out of the UK entirely? Bricked every iPhone ever purchased there?

The request/law would be rolled back in minutes in that case. They wouldn't dare though. (wouldn't even have to be bricking - just disable services like icloud)

Post reply on HN