Live data from Hacker News

U.K. orders Apple to let it spy on users’ encrypted accounts

washingtonpost.com

931–940 of 1001 posts

Re: U.K. orders Apple to let it spy on users’ encrypted accounts

#931

Earlier quoted context omitted.

By that use of the phrase, sovereign citizens try really hard to stay within the law.

But this is true, right? The whole movement is based on their legal theory giving them rights to behave in a certian way, and the idea that everyone else wastes that 'right' through ignorance and state manipulation. It's dumb, but not dishonest.

Let's consider it through a personal example. Suppose you are on a call rotation, and agree that the on-call engineer can wake you up at 4AM, but only if it's really important, and that the matter at hand has to involve some knowledge that you have, but didn't put on the wiki. Later, you are woken up at 4AM to discuss the results of a football game, and when challenged your coworker defends that they upheld their end of the bargain. They claim that it wasn't specified who it had to be important to, and that once you had been told who won, you had knowledge related to the call that you hadn't put on the wiki.

Would a fair manager consider them as having broken the agreement, or as having tried really hard to comply with the rules?

Re: U.K. orders Apple to let it spy on users’ encrypted accounts

#932

Earlier quoted context omitted.

Poland broke the Enigma code .. and built the first Bombes. Maybe you're thinking of William Thomas Tutte breaking the Tunny (sawfish) code?

Not quite right. The Poles built a simpler machine that they called a "Bomba", a pre-cursor to the Bombes. Named for a dessert in a cafe near the Polish intelligence service offices where those early codebreakers worked, and because the French also received the intelligence from Poland, they transposed the name. :-) In July 1939 the Poles had to hand everything over to the British because they knew it was all about t…

So in short: Poles did all the important parts, like actually breaking the code, Brits just throwed some money at the problem, helping to scale the Bombs.

Re: U.K. orders Apple to let it spy on users’ encrypted accounts

#933
I don't assume in general that any of cloud services in the US are free of government surveillance either. Your only hope for any kind of privacy is self-hosting, and using certs issued by your own CA (I strongly suspect Let's Encrypt is a honeypot). Likewise I strongly suspect Proton Mail and Signal are both honeypots. Tucker Carlson was spied on when arranging his interview with Putin, even though he uses Signal. This likely bypasses the protocol - you don't get to examine the binary that's installed on your phone. It could contain all sorts of Five Eyes special sauce, as could iOS, and the companies won't even be able to tell you about any of it. It's safe to assume that all VPNs are tapped, too, unless you run your own.

Re: U.K. orders Apple to let it spy on users’ encrypted accounts

#934

Democracies around the world are increasingly looking to surveil and expose private data of their citizens, and introducing laws where simple act of defiance will become criminal. I believe we should increasingly turn to steganography as a way to ensure our privacy (obviously, combined with encryption). Something that provides simple plausible deniability but lots of data to use as a carrying medium should become the…

> Something that provides simple plausible deniability but lots of data to use as a carrying medium should become the default selection (like "personal videos" — a great use for our phone cameras to build an extensive collection) [...]

No. I want all of my data end-to-end encrypted. In transit, at rest, everywhere and at all times. Privacy is a human right. Security of their citizens is what these governments vowed to protect. If they can't, these governments should be changed.

Re: U.K. orders Apple to let it spy on users’ encrypted accounts

#935
post #881

Earlier quoted context omitted.

In case you don't already know, if you don't encrypt an iPhone backup with macOS first the backup won't contain _all_ of your data. Apple says "Encrypted backups can include information that unencrypted backups don't" however the list they give is non-exhaustive. You might find yourself disappointed when trying to restore a non-encrypted backup that you've encrypted yourself in a disaster scenario.

Surely you can just open the archive and check whats in the backup yourself to satisfy that?

If it was that easy I wouldn't have bothered replying. Why don't you check in the backup and get back to me.

Re: U.K. orders Apple to let it spy on users’ encrypted accounts

#936
post #900

It's baffling to me that any sane, healthy person would advocate for invasion of not just one person's privacy (in the case of known or highly suspected criminal activity), but a whole country's people's privacy. (In this case, at least, the privacy of all Apple users in the UK.) Where does this problem start? Is it a basic education thing that valuing one's own and others' privacy needs to be taught to kids from a y…

[deleted]

Re: U.K. orders Apple to let it spy on users’ encrypted accounts

#937

Earlier quoted context omitted.

So, strictly speaking, that's not how UK law, at least, works. The court can absolutely compel you to say things you memorized - in fact, including encryption passwords. You can of course, physically, refuse, but you can be held in contempt of court, and jailed until you reveal the information, indefinitely. So not at all off limits.

Indefinitely jailing people to get a confession sounds like a midevil torture tactic. Is that a good balance of the Average Joe's right to privacy and privacy restrictions for fighting crime you speak of?

> Indefinitely jailing people to get a confession sounds like a midevil torture tactic.

That's very clearly not what I wrote. You can demand information this way, not a confession... People in the UK generally have a legal obligation to answer any questions the court has, unless they are themselves the accused. There are a small few other exceptions.

Re: U.K. orders Apple to let it spy on users’ encrypted accounts

#938
post #906

Earlier quoted context omitted.

Is it any different with Android phones? From what I've read it doesn't seem so. My comment applies just as much to the people working at Apple and Google as to the folks in the UK government.

It is, Android handsets are not prevented by Google from selecting an entirely different operating system if they distrust the one installed by the OEM. It is expressly the choice you would make if you expected userland encryption to be mandated broken. It doesn't protect against every attack (eg. Stingray or evil maid) but it absolutely would protect you from a situation like the one in the OP. Breaking your encrypt…

Well, except that Play Integrity will effectively prevent you from using any banking, payment or government ID app using a non-OEM operating system. I am writing this from LineageOS, so I am enduring the major inconvenience myself, but I do not expect the average person to do so.

Re: U.K. orders Apple to let it spy on users’ encrypted accounts

#939

In 10 years we'll all be shocked to discover this headline should have read "US Tells UK to Demand Apple Create Global iCloud Encryption Backdoor".

How does Apple have any interest building encryption back doors?

Here's Apple documenting the end-to-end encryption scheme for retrieving Push Notifications: https://developer.apple.com/documentation/usernotifications/...

Here's Apple admitting that they just bugged the Push Notification server so the NSA could read them without MITMing anything: https://arstechnica.com/tech-policy/2023/12/apple-admits-to-...

Suffice to say, they don't even have to backdoor the encryption to give the UK what they want. iOS users are like fish in a barrel, if you force some insecure paradigm on them they can either adopt it or leave.

Re: U.K. orders Apple to let it spy on users’ encrypted accounts

#940

Earlier quoted context omitted.

Why do you think 3 letters agencies care about the law? Ever heard of Snowden leaks?

Actually my takeaway from the Snowden leaks was that the government tried really hard to stay within the confines of the law, even if they wildly stretched the legal theory to get there. https://www.blankenship.io/essays/2020-07-13/ Doesn’t justify what they were doing, or make it legal, but it’s an important distinction when trying to reason about government surveillance programs.

I would call that wanting plausible deniability (in a different sense than how the phrase is normally used). "Yes we may have a done a bad thing but we believed it was allowed."
Post reply on HN