Live data from Hacker News

Apple pulls data protection tool after UK government security row

bbc.com

951–960 of 1001 posts

Re: Apple pulls data protection tool after UK government security row

#951

The smartphone is a terrible platform. Something like this could never happen on the PC, where you can install any encryption and backup software that you want. While Apple did the right thing by refusing to give the UK government a backdoor, they are responsible for getting users in this situation in the first place. I'm not familiar with the iPhone and maybe there is already an alternative to iCloud ADP, although t…

> Something like this could never happen on the PC, where you can install any encryption and backup software that you want. Microsoft wants to have a word with you regarding their Windows operating system that's installed on their device that you're renting.

I'm on arch. Still, while I agree that Windows is becoming more closed, you are still free to create and distribute Windows app without asking anyone for permissions.

Re: Apple pulls data protection tool after UK government security row

#952

The smartphone is a terrible platform. Something like this could never happen on the PC, where you can install any encryption and backup software that you want. While Apple did the right thing by refusing to give the UK government a backdoor, they are responsible for getting users in this situation in the first place. I'm not familiar with the iPhone and maybe there is already an alternative to iCloud ADP, although t…

Given that the most popular software of this kind is Dropbox I’m quite confident that nothing you’ve said is true.

My point is that if someone wants e2e encrypted backup, it is not difficult to set up on a PC even for non power-users.

Re: Apple pulls data protection tool after UK government security row

#953

Earlier quoted context omitted.

This is why, while I applaud what Apple is doing here, they need to allow us to supply our own E2E encryption keys.

But if you don't trust Apple, how to you get the key into the Secure Enclave to begin with? Doesn't Apple control the software on your device that provides the interface into the Secure Enclave from outside of it?

Yes Apple controls the device so you're right, you can never be sure what it's doing. My thinking is that an encryption backdoor means the key generation algo is compromised. In that case you want to bypass that by generating the key yourself.

If the backdoor is some other method of getting your key off the device then all bets are off.

Re: Apple pulls data protection tool after UK government security row

#954

Earlier quoted context omitted.

They will lock UK users out of iCloud until they manually disable ADP. When a user turns off ADP in settings, their device uploads the encryption keys to Apple servers.

What if the users don't agree to disable ADP? So if one pays for iCloud+, they'll be refunded? And what happens to their already uploaded data? Is it deleted?

I imagine if you choose to ignore the warning that iCloud syncing will cease to work unless you disable ADP, then at some point, the warning turns into an error and iCloud syncing will cease to work.

I can't imagine they'll cancel your iCloud+ subscription. ADP is not a feature of iCloud+ and iCloud+ has features beyond extra storage space. Nor can I imagine they'll delete your data preemptively as long as there's space to store it.

Hopefully they'll provide instructions on how to manually delete your iCloud data in case you don't want to use it any longer (I think you just turn off iCloud on all your devices).

Re: Apple pulls data protection tool after UK government security row

#955
post #782

Earlier quoted context omitted.

At this point, the right thing to do is allow for an alt-service.

How would an alt service help this situation? You’d just end up with backdoored services advertising E2EE, no? Apple’s move here is definitely the right one, introduce as much friction as possible to hopefully get the user pissed off at their government for writing such stupid laws.

An alt service located in another country could provide e2ee for a fee and not be under UK law.

Re: Apple pulls data protection tool after UK government security row

#956
post #702

Earlier quoted context omitted.

At this point, the right thing to do is allow for an alt-service.

Apple has an organization-wide mandate for services revenue. Every product must make money on an ongoing basis, every month. That's why you get constantly spammed to subscribe to things on iOS. Apple will never drop this anticompetitive practice of favoring their services until they are legally compelled to.

If they want to protest the government mandate, they should provide an alternative solution for the residents of this country

Re: Apple pulls data protection tool after UK government security row

#957

Earlier quoted context omitted.

The hardware will not allow this, at least not without modifications. The encryption keys are not exportable from the Secure Enclave, not even to Apple's own servers.

The Apple security paper describe how to disable ADP through a key rotation sequence. This will be a "forced rotation", they just need to decide how to communicate to users and work out what happens to those who don't comply. Lockout until key rotation look like an option as someone said.

Naive question: what prevents Apple from pushing a malicious software update that automatically disables ADP to UK users?

Re: Apple pulls data protection tool after UK government security row

#958
post #722
post #704

Earlier quoted context omitted.

I use a patched Signal client that disables retention deletion and remote delete messages.

and that's awfully rude of you, but if you were concerned about message retention you wouldn't do that. so what's your point?

Nothing rude about it -- if the protocol depends on client-side s/w to pinky-swear it respects message retention, then it's an insecure protocol.

I like signal and use it, but I already thought message retention was pointless. It seems at best a trusted informal protocol you can use with known parties but not something you can really rely on.

Re: Apple pulls data protection tool after UK government security row

#959
post #927

What's stopping Apple from launching an AppleTV-esque device that functions as personal iCloud storage? The design of ADP is that even taking control of the data centre won't allow access to the information held within. Decentralising the service makes it significantly harder to write ham-fisted legislation that aims to prevent tech companies from offering secure products. Additionally there isn't a technical need fo…

Commercial security is pure theatre at the end of the day. Apple could pretend to make a big stink, release a new encrypted Time Machine or leave the UK... but why? None of that makes them money. It's a band-aid for the user freedom that was amputated decades ago. I don't expect Apple to fight this like, say, the EU regulations. Without a profit incentive, it's hard to mobilize Apple to seek a solution.

>release a new encrypted Time Machine or leave the UK... but why? None of that makes them money.

Would this device be free?

Re: Apple pulls data protection tool after UK government security row

#960

The smartphone is a terrible platform. Something like this could never happen on the PC, where you can install any encryption and backup software that you want. While Apple did the right thing by refusing to give the UK government a backdoor, they are responsible for getting users in this situation in the first place. I'm not familiar with the iPhone and maybe there is already an alternative to iCloud ADP, although t…

> Something like this could never happen on the PC, where you can install any encryption and backup software that you want. Microsoft wants to have a word with you regarding their Windows operating system that's installed on their device that you're renting.

Veracrypt works just fine on M$ Windows 11 for FDE.
Post reply on HN