Live data from Hacker News

Apple pulls data protection tool after UK government security row

bbc.com

961–970 of 1001 posts

Re: Apple pulls data protection tool after UK government security row

#961
post #106

Too right, it was far more problematic than they ever made out. > The UK government's demand came through a "technical capability notice" under the Investigatory Powers Act (IPA), requiring Apple to create a backdoor that would allow British security officials to access encrypted user data globally. The order would have compromised Apple's Advanced Data Protection feature, which provides end-to-end encryption for iCl…

Your smartphone cannot be considered a private device. You as the owner don’t have sufficient control over its operating system and applications to ever make that claim.

Re: Apple pulls data protection tool after UK government security row

#962

What the UK government achieved: Lowering the data protection of it's citizens in comparison to the rest of the world. I was under the impression governments were supposed to protect their citizens.

>> Lowering the data protection of it's citizens in comparison to the rest of the world. I was under the impression governments were supposed to protect their citizens. This depends on whether you see "citizens" as individuals or as a group. In other words it's possible that to improve the security (and thus protect) the majority, the rights of individual citizens need to be eroded. For example, to protect vulnerable…

You restate my hypothesis adding your own words:

"also, making it easier to detect and prosecute criminals, and thus protect the citizens from physical harm."

Did this happen though? Whilst I agree with your philosophy, in reality the UK government are no closer to lawfully accessing our data, but our data are less protected from potential other threats (e.g. unlawful access to a data centre, rogue Apple employees).

It's what actually happened as opposed to the government intention that matters to the people affected.

So my statement "Lowering the data protection of it's citizens in comparison to the rest of the world" still stands, and I'd add "whilst the UK government achieved absolutely zero in its quest to lawfully access individual's data".

Re: Apple pulls data protection tool after UK government security row

#963
post #862

Earlier quoted context omitted.

What the politicians want is partial security: something they can crack but criminals can't. That is achievable in physical security, but not in cybersecurity. I have a feeling the politicians already know partial cybersecurity isn't an option, and don't care. Certainly, the intelligence community advising them absolutely does know. We don't even have to be conspiratorial about it: their jobs are easier in the world…

> That is achievable in physical security, but not in cybersecurity This isn't accurate though, and leads us down the path of trying to prevent these bad laws from a technical perspective when we should be fighting the principle of the bad law not just decrying it for being "unworkable". It is possible to construct encryption schemes with a "backdoor key" while still being provably secure against anyone else. This cr…

You are correct that we can engineer a cryptosystem with two sets of keys.

However, nothing prevents keys from being stolen by someone else. In a normal cryptosystem the security of the key is entirely up to you; but in a "law enforcement accessible" system now you have to worry about the feds getting hacked, too. And since the feds will have backdoor keys for many, many users; there is much more interest in stealing those keys.

Physical security has a different set of tradeoffs. Notably, you have to actually be physically present to manipulate and defeat a physical lock, which is what I was alluding to. Even then, it provides an example of how easily a backdoor can be compromised. The Travel Sentry system exists to allow TSA employees to unlock and inspect luggage. There are seven master keys in total; copies of which are spread around thousands of airports with tens to hundreds of TSA employees each. Suffice it to say, the master keys leaked decades ago and you can buy them off Amazon for a few bucks. Any such backdoor key will need similar levels of access to government employees and will likely leak for the same reasons as the TSA keys. Except that the consequence of an encryption backdoor key leaking will be much higher than someone being able to open luggage locks.

Politically, there is also an argument that we should be able to keep secrets from the state. Certainly, there is a reason why we have a 4th Amendment, and it is not because searches and seizures just so happen to be inconvenient.

As for age-of-consent checking, the problem is that existing age verification services would be able to track everyone who accesses an age-verified site. Which, given today's legal climate basically demanding age verification for everything[0], would give the verifier access to your whole browsing history.

Physical age verification is relatively privacy-preserving: I present my ID and that's that. The government that issued that ID does not learn where I presented it, because it's an offline credential. The people I'm doing business with do learn my identity, and they could sell that information, but that's something they didn't need an ID to do (so we should pass a law to prohibit that).

[0] There is also a political argument that the 1st Amendment precludes age verification on social media - aka "don't censor kids"

Re: Apple pulls data protection tool after UK government security row

#964

Earlier quoted context omitted.

> Again and again, 'Eu' is not pushing anything like that. A few Euparl MPs backed by those like Ashton Kutcher did.

The EU is pushing for this. The EU "Going Dark" group is pushing for this as well as per https://edri.org/our-work/high-level-group-going-dark-outcom... The fact of the matter is that if the EU was, as it's been said, for privacy this proposal would not have been on the table in the first place. It should have been stopped 3 years ago but here we are again fighting for our rights and our privacy. And it doesn't matte…

> The EU is pushing for this. The EU "Going Dark"

There is no official effort from the Eu related to this. Where are you pulling that out from. A proposal by a few MPs in the Euparl is not 'Eu pushing someting'. And that "Eu Going dark" group is not an official Eu organ.

Re: Apple pulls data protection tool after UK government security row

#965

Earlier quoted context omitted.

Again and again, 'Eu' is not pushing anything like that. A few Euparl MPs backed by those like Ashton Kutcher did. > Eu isnt 'planning' anything like that. Some Euparl MPs backed by people like Ashton Kutcher tried to push a law to spy on all chat apps. Then when the dirty web of American-style regulatory manipulation was exposed, they backed off. It was a proposal for a law by some MPs. Not something 'Eu' did.

How can you say EU isn't planning anything like that when the last meeting to introduce just that was a few weeks ago? https://www.parlament.gv.at/dokument/XXVIII/EU/9693/imfname_... Nobody backed off, it's still on the agenda. You are right however that the main lobby comes from US NGOs as exposed by documents coming from EU Commission.

> How can you say EU isn't planning anything like that when the last meeting to introduce just that was a few weeks ago?

I can say that because that PROPOSAL at the European PARLIAMENT was brought by a number of MPs. Its not an official Eu thing, it is not pushed by any official Eu organ. Any MP can bring ANY proposal to Euparl. It does not mean that Eu is 'pushing something'.

> Nobody backed off, it's still on the agenda

Its not on 'the agenda'. The MPs who pushed it backed off after their links to the American 'NGOs' were exposed. They said that they would bring it up again at a later time. That doesn't mean that its on 'the agenda'. Any MP in the Euparl can bring any proposal at any time. That does not mean that Euparl is doing it and there is notable support behind it.

Re: Apple pulls data protection tool after UK government security row

#966
post #950

Earlier quoted context omitted.

"Not making a stand" would be leaving everything as is, and handing your encryption keys over to the government. By loudly disabling ADP and saying this feature is illegal in the UK (they really should have said "illegal" instead of "unavailable" so people would know it was the government), they are at least making half a stand. By leaving it enabled in other regions and for visitors from other regions to the UK, the…

> By loudly disabling ADP and saying this feature is illegal in the UK They didn't say anything loudly, or said it was illegal in the UK. All they had was a single comment to a single (or perhaps a handful at most) comment to a media outlet that they disabled it. They didn't even bother with a press release, or notify their users. It's not even half a stand. It's a rollover

Is the UK law broadly against encrypted files?

For example if I encrypt a file locally, a zip file containing images, am I not permitted to upload that zip file to a cloud service in the UK?

Even if the UK's demands were "access to encrypted cloud services", does that also mean encrypted files within encrypted storage? It all seems so messy. Anyone who really wants to hide their files, can do so regardless of demands for backdoors.

Re: Apple pulls data protection tool after UK government security row

#967
post #135

Free speech already under threat and now y'all are giving up the right of private communication too? For anyone cheering this on, do you honestly think this will only affect the "bad people", and you'll never have your own neck under the government's boot? Even if you trust the government today, what happens when your neighbors elect a government you disagree with ideologically?

[dead]

Re: Apple pulls data protection tool after UK government security row

#968
post #484

Earlier quoted context omitted.

It's also comparatively worse than the raw numbers suggest because the customer base of Apple phones in Germany is much smaller than in the UK.

I see numbers for USA and China very low as well. Maybe they don't have/need to request? ;-) Just saying.

In the UK and Germany people get arrested for social media posts. This doesn't really happen in the USA (or China, to my knowledge)

Re: Apple pulls data protection tool after UK government security row

#969

Earlier quoted context omitted.

> What concerns me more is that Apple is the only company audibly making a stand. Meta also said they would make a stand if a similar request comes for WhatsApp. I'm not going to hold my breath though.

They wouldn't even be able to. WA is end-to-end encrypted.

It's all lip service, because the UK Govt wouldn't ask them that. WhatsApp messages are EE2E. They probably already handover all the metadata surrounding those messages.
Post reply on HN