Live data from Hacker News

Apple pulls data protection tool after UK government security row

bbc.com

981–990 of 1001 posts

Re: Apple pulls data protection tool after UK government security row

#982
post #906
post #888

Earlier quoted context omitted.

These are important questions, particularly 2 because even a layover in London or Dublin puts you under UK jurisdiction. So now you have to put that into account when traveling. The precedent here is China. I spent a few days in China and, as far as I know, my region is still and ADP is still active.

How does a layover in Dublin put you in UK jurisdiction? I have seen advice in big companies to only take a burner phone when going to China on business. Perhaps the same will apply to the UK.

> How does a layover in Dublin put you in UK jurisdiction?

Heh that's embarrassing. Scratch that part.

Re: Apple pulls data protection tool after UK government security row

#983

Earlier quoted context omitted.

That would not be treason, by a long shot. Treason is the only crime defined in the constitution, and it is quite a high bar.

> Treason is the only crime defined in the constitution, and it is quite a high bar. Well, it's defined, or bounded above, in the constitution. It's not exactly a high bar: > Treason against the United States, shall consist only in levying War against them, or in adhering to their Enemies, giving them Aid and Comfort. So, if you happened to know Nicolas Maduro, thought he was looking stressed, and bought him some foo…

No. The Supreme Court has laid out well defined meanings for all the components of that phrase[0], and it is quite a high bar.

[0] https://constitution.findlaw.com/article3/annotation24.html

Re: Apple pulls data protection tool after UK government security row

#984
post #585

Earlier quoted context omitted.

What the politicians want is partial security: something they can crack but criminals can't. That is achievable in physical security, but not in cybersecurity. I have a feeling the politicians already know partial cybersecurity isn't an option, and don't care. Certainly, the intelligence community advising them absolutely does know. We don't even have to be conspiratorial about it: their jobs are easier in the world…

> That is achievable in physical security, but not in cybersecurity. Not with physical security either, I'm afraid.

Any physical lock can be manipulated, even the particularly high-security ones. But in practice, most locks are not even challenged because doing so requires actually walking up to the lock and trying. You can't try every physical lock in existence; but you can try every digital lock. So the effects of, say, an encryption backdoor key compromise would be far greater and far more immediate than, say, the compromise of the Travel Sentry master keys.

Re: Apple pulls data protection tool after UK government security row

#985

Earlier quoted context omitted.

A trivial method for circumventing code review is to simply push a targeted update of the firmware to devices subject to a government search order. There are no practical end-user protections against this vector. PS: I strongly suspect that at least a few public package distribution services are run by security agencies to enable this kind of attack. They can distribute clean packages 99.999% of the time, except for…

The end user protection is to sign updates and publish the fingerprints. It should not be possible for one device to get a different binary than everyone else.

How exactly do you plan on implementing this as an end user?

Even if you somehow manage to ensure 100% consistency with other users for updates you manually “pull” from the vendor, the vendor could simply have your device automatically reach out and update itself with a stealth update.

Or everyone can get the same exact binary, but it has a hash code check on it that activates the evil bits only on your device.

Etc…

Re: Apple pulls data protection tool after UK government security row

#986
post #879

Earlier quoted context omitted.

I never understand why people create petitions (targeted at the gov) on a non-official site.

I'm not familiar with UK law, but what's the matter? They're equally valid in jurisdictions that I know of, a signature is a signature no matter where it was put I'd personally just trust the government variant more with my government ID data than a third party but that's up to the petitioners to weigh and decide

In the UK, there's an official gov site for petitions, such that when a petition has >10k signatures, a government minister is required to write a response, and >100k triggers a parliamentary debate, iirc.

Whether the responses/parliamentary debates the person triggers end up being useful is up for debate.

Re: Apple pulls data protection tool after UK government security row

#987
post #882
post #645

Earlier quoted context omitted.

> one UK head of state What on earth are you talking about? Charles III is head of state, and before that, Liz II. The monarch absolutely does not get involved in politics.

>> The monarch absolutely does not get involved in politics. The monarch picks the Prime Minister, no? That seems pretty involved.

Good Lord man! Where are you finding this rubbish!

The Members of Parliament choose the Prime Minister. The role of the monarch in confining them is purely ceremonial.

Re: Apple pulls data protection tool after UK government security row

#988
post #106

Too right, it was far more problematic than they ever made out. > The UK government's demand came through a "technical capability notice" under the Investigatory Powers Act (IPA), requiring Apple to create a backdoor that would allow British security officials to access encrypted user data globally. The order would have compromised Apple's Advanced Data Protection feature, which provides end-to-end encryption for iCl…

What I fund 'amusing' is the swap between Left vs Right. 'Back in the day' it was the "Right" that wanted have total access/total control over everything. So people turned a bit "left". Now the "Left" government is seeking totalitarian-style control ('because paedophiles/drugs/etc.). As a reminder, both Right and Left extremes went from 'liberal/conservatives' to "we don't need elections ever again - trust me!". I sa…

If you go too far right or left, both types of authoritarianism are difficult to distinguish. I think this just makes the case that every election you need to be a swing voter, make sure your politicians still overlap with your ideals.

Apple today appear to be on the 'correct side of history', but even then you need to be swing consumer.

Re: Apple pulls data protection tool after UK government security row

#989
post #106

Too right, it was far more problematic than they ever made out. > The UK government's demand came through a "technical capability notice" under the Investigatory Powers Act (IPA), requiring Apple to create a backdoor that would allow British security officials to access encrypted user data globally. The order would have compromised Apple's Advanced Data Protection feature, which provides end-to-end encryption for iCl…

> One scenario would be somebody in an airport and security officials are searching your device under the Counter Terrorism Act No, it's much broader than that. The UK is asking for a backdoor to your data and backups in the cloud, not on your device. Why bother with searching physical devices when they can just issue a secret subpoena to any account they want? It's actually pretty amazing that Apple made ADP possibl…

> No, it's much broader than that. The UK is asking for a backdoor to your data and backups in the cloud, not on your device. Why bother with searching physical devices when they can just issue a secret subpoena to any account they want?

My point was that there was already a clear chain in place that would give them access to the data of foreign nationals. It's not just a "UK problem", but actually the ramifications are further reaching.

Another thing to consider is that these cookie alerts on sites were for EU countries only, but ended up everywhere. If Apple were to comply, this cloud backdoor could end up in other countries too, with the keys sitting there ready for collection.

To make things more complex still, they would need to support dual/multi nationality. It probably ends up looking like a dual key E2E system where there is a unique key for the end-user and then a third party. Key revocation would likely be difficult, so it would likely be the cloud provided decrypting and re-encrypting the files per request, throwing E2E out the window entirely.

Re: Apple pulls data protection tool after UK government security row

#990

Earlier quoted context omitted.

That’s a false dichotomy. Another choice, however unpalatable to all parties, would have been for Apple to stop doing business in the UK.

Why do pro-privacy tech folks on here act like Apple is some charity? Apple is a business. It won't fight a citizen's fight on your behalf. It is on citizens to use their democratic power to ensure their representatives act as the voting base wants. Apple's goal is to make money. The government is a representation of your will.

> Why do pro-privacy tech folks on here act like Apple is some charity...

Because Apple marketing keeps relentlessly bashing their customers skull that privacy is their advantage?

Post reply on HN