Apple’s approach to privacy
apple.com
apple.com
As an aside I am finding it really difficult to delete my iCloud account, in fact it seems that is impossible.
If they haven't cracked your European email provider, then they're not doing what we pay and order them to do.
The difference is that European email providers are not cooperating, because they aren't obliged by your laws, whereas US companies are not only obliged to comply with requests, but they are also coerced to keep it a secret.
> ... then they're not doing what we pay and order them to do
That's a good thing to know, plus this is reason enough to pressure our governments and companies to not buy into US products or services. And in case you haven't noticed, this has tangible effects already, as fear of industrial espionage is spreading in big companies like fire and I've noticed this first hand in the German companies I'm in contact with. On the negative side, the US is positioned as the steward of the Internet and because your government fucked things up so badly, this is the perfect opportunity for the other countries to balkanize the Internet, to build firewalls, etc.
So I hope you're happy about how your taxes are being spent.
The NSA doesn't need cooperation. It can pwn sysadmins, plant covert operatives, and backdoor equipment in transit (including foreign-made equipment, so long as US intelligence can influence the shipping carrier, for example by recruiting employees or hacking ancient legacy software). If it can't, then it can pwn the other side of the conversation, or watch the SMTP in cleartext through a submarine-tapped undersea cable.
Disband the NSA and some other agency, some other country, will do the same thing.
You're bikeshedding. End-to-end encryption with HSMs and trusted execution environments everywhere, always. Verifiable, deterministic builds. A genuinely trustworthy, decentralized PKI. Better software engineering security practices, a professional barrier to entry, and an ethical system (ala the Bar or medical boards) with teeth that will reliably eviscerate people and companies who write and run irresponsibly sloppy code.
The cat's not going back in the bag because you avoid the US. Fighting over which service providers you send cleartext through, whose hard drives your unencrypted data sits on, who has the power to MITM you, is a waste of time and a distraction from the real challenge of developing and adopting security systems and practices that make doing what the NSA is doing actually difficult.
But of course it does. Security is not a black and white issue, but rather a matter of cost. And the fact is US companies are much easier and more cost effective to crack because they can be (legally) coerced and nobody has unlimited resources, not even the NSA.
> Disband the NSA and some other agency, some other country, will do the same thing
This is one of those logical fallacies that keeps popping up. So we should bend over and take it like a man, because if it's not the NSA, then it will be somebody else. Even if you're right, bad actors in society should get punished, otherwise they'll never learn. And indeed, it doesn't seem fair to punish US companies, many of whom really want to be good and faithful for their customers, but I've seen many signals that the american public approves and finances this behavior, which includes the above comment and the US government never apologized (to us, foreigners), therefore avoiding US services and products can become a matter of necessity.
> The cat's not going back in the bag because you avoid the US.
Yeah, but you see, I'm not an US citizen so I don't even get to vote on your laws and your government has made it clear that when it comes to foreigners then everything is allowed. And we do have intelligence agencies and they are cooperating even with the NSA and so on and so forth, but here there is no behemoth like the NSA is. And as an EU citizen at least I would have ways to fight it.
> developing and adopting security systems and practices that make doing what the NSA is doing actually difficult
Only a software developer would end up thinking that all political and social issues can be solved with technology. The world doesn't work that way. You want cryptography? It will eventually get outlawed and there is already precedent in the US.
Similarly, laws cannot force a company to divulge encrypted data if the company does not hold the encryption keys.
So as long as you trust the company, the country it's in is not relevant, at least for the situations outlined above.
Laws can and have been written that require companies to gather data.
> Similarly, laws cannot force a company to divulge encrypted data if the company does not hold the encryption keys.
Laws can and have been written that require companies to use weaker or broken encryption.
Not just that. Laws can (and probably have been) written that require companies to gather data and to explicitly lie about it.
Maybe I'm dense or naive, but I don't think there's any precedent for that. A gag order is one thing (and there are certainly places for it), but forcing someone to lie would hopefully violate the First Amendment.
It's well know about.
Apple has thus far been steadfast in resisting this sort of activity and in advocating against any such laws.
So for me at least, this is behavior that is worthy of trust.
Court rulings and legal authorisations to conduct surveilance can and have ... you guessed it ... been kept secret
Source? Example? I don't know an example of this. (At least in the US)
https://www.schneier.com/blog/archives/2015/03/can_the_nsa_b...
http://gizmodo.com/nsa-paid-security-firm-10-million-bribe-t...
Trusting the company has nothing to do with it - they could be legally compelled to do so in a secret court, and gagged with a NSL to keep them from revealing such an order. Sadly that's the reality we now live in.
In theory Apple could modify iMessage to MITM the key distribution server and enable eavesdropping. The only way to protect against that is to provide in-person validation mechanisms so users can directly compare keys. I hope they add such a thing, not that 99.99999% of their users would ever use it.
As far as the US legal system goes you'd need positive law to enforce wiretapping requirements. Courts (as a general rule) can't issue orders to force Apple to write new code or modify their silicon design to support something the government wishes it could have. Given the way SCOTUS has been approaching cell phone privacy I'm not sure such a law would pass muster.
- allows for "reconnaissance" on external networks, including breaking encryption or forcing targets to divulge keys. This "reconnaissance" apparently includes installing sniffers or data probes.
- allows for untargeted data collection on wired networks (including cell phone towers)
- has provisions for forcing data transit stations (including ISP's, but also AMS-IX) to comply with requests.
Only English source I've been able to find with a quick search is https://blog.cyberwar.nl/2015/07/dutch-intelligence-bill-pro...
Infiltrating foreign servers, installing backdoors and such don't require any warrant or court approval.
At least in theory, the NSA could allow a compliant US business to be secure. If the NSA could not get data from a foreign business the easy way, I'm sure they would get it the hard way.
Basically, unless they let me see what's happening with my data by allowing me access to the code, I can't and won't trust them.
Ta-da! Both the marketing and the NSA are happy as clams.
I agree, like Lavabit... Lavabit had all the best intentions but in the end the law screwed them over anyway.
Of course Apple has a lot more power than Lavabit, so it's nice they are taking this standpoint and being resistant. Hopefully they can contribute to a positive change.. Anyways at least they are trying, something i haven't seen from other big companies, like Google https://en.wikipedia.org/wiki/Criticism_of_Google#Privacy
Other companies should take this as an example. (Only problem: many other companies likely wouldn't want to tell in plain words how broad they are gathering and aggregating your (my) data)
"We don’t build a profile based on your email content or web browsing habits to sell to advertisers" but we do build profiles (bonus points for insinuating competition sells your information)
"we don’t read your email or your messages to get information to market to you." - but we do read and index your emails and messages, only to make our services and devices 'better' - by our definition
The sentences are built to sound like the italicized parts are not there, yet they totally change (negate) the meaning.
If I were a murderer, I could say "I do not kill men to eat their livers" and it would be 100% true, but it sounds like I'm not into killing at all.
1. Is that the word? Not a native speaker
Interesting note: "P. FaceTime FaceTime communications are end-to-end encrypted and Apple has no way to decrypt FaceTime data when it is in transit between devices. Apple cannot intercept FaceTime communications. Apple has FaceTime call invitation logs when a FaceTime call invitation is initiated. These logs do not indicate that any communication between users actually took place. Apple has no information as to whether the FaceTime call was successfully established or duration of a FaceTime call. FaceTime call invitation logs are retained up to 30 days. FaceTime call invitation logs are available only following receipt of a legally valid request"
iMessage is not mentioned. Does this mean they are capable of intercepting iMessage?
edit: in the FAQ it says "Can Apple intercept users’ communications pursuant to a Wiretap Order? Apple can intercept users’ email communications, upon receipt of a valid Wiretap Order. Apple cannot intercept users’ iMessage or FaceTime communications as these communications are end-to-end encrypted."
You know what the best way is to see who cooperates with law enforcement and to what level? Court documents!
I've been trawling court documents for the past few months (I'm writing a blog article on this) and I'm yet to find iMessage being used in court (unless the access to the conversation was given by one of the parties). iMessage really does seem secure from legal system point of view.
For a comparison, I've found dozens of court documents from Google, Facebook, Microsoft handing over chat logs from Hangouts, Whatsapp/FBMessenger, Skype.
Anyway, if you want to see the level of cooperation and want to double-check privacy policies, actual court documents are the best way.
Why? They've been using parallel construction to avoid violating NDAs and giving up their capabilities for years. http://www.wired.com/2014/03/harris-stingray-nda/
1) Police don't care that APPLE doesn't want to reveal its methods, and 2) Unlike the Stingray, it wouldn't be illegal for them to use iMessage evidence in court if Apple provided it to them (especially with the use of a warrant!)
So is privacy a good reason to use FaceTime Audio over say, a standard voice call?
How iMessage sends and receives messages
Users start a new iMessage conversation by entering an address or name. If they enter a phone number or email address, the device contacts the IDS to retrieve the public keys and APNs addresses for all of the devices associated with the addressee. If the user enters a name, the device first utilizes the user’s Contacts app to gather the phone numbers and email addresses associated with that name, then gets the public keys and APNs addresses from the IDS.
The user’s outgoing message is individually encrypted for each of the receiver’s devices. The public RSA encryption keys of the receiving devices are retrieved from IDS. For each receiving device, the sending device generates a random 128-bit key and encrypts the message with it using AES in CTR mode. This per-message AES key is encrypted using RSA-OAEP to the public key of the receiving device. The combination of the encrypted message text and the encrypted message key is then hashed with SHA-1, and the hash is signed with ECDSA using the sending device’s private signing key. The resulting messages, one for each receiving device, consist of the encrypted message text, the encrypted message key, and the sender’s digital signature. They are then dispatched to the APNs for delivery. Metadata, such as the timestamp and APNs routing information, is not encrypted. Communication with APNs is encrypted using a forward-secret TLS channel.
I'll give you P(spy) = .01, which feels plausible, around 140 incidents, but we have zero evidence. For something like P(spy) = .1, 1400 requests, I'd want more evidence. It dosn't need to be particularly good evidence, because i don't hold the NSA side to be particularly good.
But, you know, still more than vague comments about the state oppressing a vast number of people with undocumented shady tactics. They've been proven to use undocumented shady tactics in the past, but they also seem pretty bad at keeping that stuff secret for long.
Percentage is a convenient con used in some contexts.
We have no idea how easy it is for local law enforcement to pick up the phone and request "support" by having a NSL issued.
I'm comfortable assuming that my local beat officer probably can't signal to his superior to pull an NSL on me and start reading every piece of data my devices are streaming over TLS.
That would fit more in line with what we have heard about the tapping stations/rooms at AT&T/Verizon over the years.
I mean if they were really involved with back dooring the individual servers of google/apple/facebook that would involve hundreds of employees at each company to make that happen. Someone would have spoken out by now with some evidence to prove it.
To my knowledge that hasn't happened. Just this shitty looking powerpoint outlining when the data was starting to come in...
Those lines were for things like data replication so it was a goldmine for the NSA to tap. Those transmissions have since been encrypted.
> Prism in general was mischaracterized by the early reports. It was first reported as a persistent backdoor into servers, but it was actually just a way for NSA to automate requests for information through the FBI. This was detailed in later reports.
> Edit: for those skeptical about my comment above, here is more detail from a discussion about a year ago:
The slides imply Apple gives access to data on customers. Tim Cook says Apple does not give access to their servers. Is that really the point you're trying to make?
That's just semantics and weasel words, nothing more.
Apple, Microsoft, Adobe, Symantec, and a handful of other tech companies just began publicly lobbying Congress to pass Cyber Threat Information Sharing legislation, like CISA, a bill that would give corporations total legal immunity when they share private user data with the government and with each other. Many of these companies have previously claimed to fight for their users' privacy rights, but by supporting this type of legislation, they've made it clear that they've abandoned that position, and are willing to endanger their users' security and civil rights in exchange for government handouts and protection.
Did Apple ever provide any insight into what access the Prism program had? They denied knowing about it[1], so either they are lying or it was a mole. Did they ever follow up with an investigation or conclusion as to what exactly the government had access to?
[1]: https://www.apple.com/apples-commitment-to-customer-privacy/
Edit: for those skeptical about my comment above, here is more detail from a discussion about a year ago:
To answer what access the NSA has, the best case would be merely access to iCloud email, iTunes Store purchase records and other things Apple can't encrypt. The worst case is everything.
https://www.google.com/search?q=disable+spotlight+queries+se...
I've hoped somebody would have given an exact link to some competent and exact analysis. Google query it ain't.
I've got by Googling: "turn off 'Spotlight suggestions' and 'Bing Web Results'." Did both. Did that. Still got the web "suggestions" in my search results. I don't know it they are "Spotlight" "bing" or "Safari" but they are there, some server must have been involved as the results can't come from my phone. Clicked around a little more. Now looks better. Or not. I try to avoid the search page. I don't know what turns off what actually. And still don't know who reliably documented it.
It seems that other stuff can send the web queries as the result of what I type. Which stuff is that, what's going on, somebody will still have to find out and explain. Apple still haven't. Or I'm missing something and I'd be glad to learn.
And you'd be wrong. In fact when I did it, I did it with a similar Google query, checked the first 2-3 results, settled on one site with instructions (it's a very simple setting anyway, it's not like you're hacking anything) and went on with my life.
Likewise on MacOS, there's a 'About Spotlight Suggestions & Privacy' button on the Spotlight settings page. Again, it's on the same screen that contains the switches to turn off the feature.
You don't need internet access to find these options, and I can't think of a better place to put the help. Knowing that these options exist in the first place is another problem though...
And "Siri suggestions" appears on the spotlight search screen to the left / when dragging downwards, so it is not at all obvious what the difference between "siri" and "spotlight" is. Yes, even when I want to do a local spotlight search.
Add "iOS 9" to the query if you're running that, and obviously prefer well known domains, like MacWorld, Zdnet, etc.
This is documented in the 'About Spotlight Suggestions & Privacy' link at the bottom of the Settings->General->Spotlight Search panel. It's a shame that there's no switch in the actual Privacy panel though.
I know strong advocate of freedom and transparency will say Apple is closed-source, for-profit company yadi yada. The truth is most of things in our lives are: the cars we drive, the fridge, the TV, the watch we wear, and hardware we use (Intel or ARM chips aren't open source, right?) So years ago i decide this free software thingie isn't for me.
Translation: We set up this page to reference for the inevitable future articles and critcisms of our policies.
Not saying it's a bad idea, but it's very lawerly to me. Like this one:
We don’t build a profile based on your email content or web browsing habits to sell to advertisers. We don’t “monetize” the information you store on your iPhone or in iCloud.
That makes sense, and I figure it's a true statement as written. But, bear with me here, I feel like it could still also be true they build a profile based on X, Y, or Z for internal use by Apple in the name of "making services better" as it were.
What I'd like to see at the bottom of the letter - and don't see even after clicking through a couple of the links - is a link to review all stored content by Apple in a nice, clean two-factor authenticated dashboard, and settings for all devices to be managed in one central location. That would be rather helpful to individuals...a big gesture of that buzzword "transparency" and all that! Yet I highly doubt such a portal / review capability would be implemented by Apple without much metaphorical kicking and screaming.
There could also be hardware or software backdoors/exploits that Apple has no clue about-- I would say almost certainly, given how inventive the NSA has been with both of those angles.
That's a pretty bold statement.
There were Google security engineers that seemed to be in the dark about the level of NSA engagement.
* They were truly, actively committed to defending a user's privacy.
* They allowed using your own domains (I currently have around 30 domains pointed to the same GMail account).
If both of the above were true, I'd ditch my Cyanogenmod-running HTC One M8 and buy an iPhone today. My privacy is worth more to me than the ability to install whatever music player, keyboard, etc that I want or drop to a command line (though I do love having that ability and would miss it).Combine that with GMail. I pay for the business version, yet the privacy policy is still hard to understand and I still get suspicious ads popping up which seem to have come from no where else but my email. Could be wrong, but it's uncanny.
I have a hard time trusting Google.
I am still skeptical about any company in a hypothetical case where private information of its customers is sought by governments like China. BTW, I am living and going to live in China in future.
It is to the point I don't upgrade i devices until weeks after just to be sure.
My understanding was that some iCloud account login endpoints (associated with Find My iPhone) didn't have any rate limiting for password failures, and this allowed brute force to work for targetted accounts.
Apple also released a press release[1] saying that they “have discovered that certain celebrity accounts were compromised by a very targeted attack on user names, passwords and security questions, a practice that has become all too common on the Internet. None of the cases we have investigated has resulted from any breach in any of Apple’s systems including iCloud® or Find my iPhone.”
[1]: http://www.apple.com/pr/library/2014/09/02Apple-Media-Adviso...
The news on it has died down over the past year, with a recent items search bringing up only links to pron sites hosting the content. This is the best summary I could find: https://www.nikcub.com/posts/notes-on-the-celebrity-data-the...
It clearly shows that iCloud was very susceptible to basic social engineered attacks. Their statement on the subject is vague and misleading. There was no breach of iCloud passwords database, but if somebody just "guessed" the answers to the security questions, that counts as a breach for everybody else.
FBI has made one arrest and the investigation is still on going. We probably would not know until it's over, but at least one celebrity, Kirsten Dunst suggested her images were taken from the iCloud: https://twitter.com/kirstendunst/status/506553772114317312
Again, what most articles you have besides Apple's hand waving?
There was an iCloud hole that was discovered around the same time as The Fappening, but no evidence that it was used by them before it was patched by apple.
Edit: Why the downvote? If my understanding is false, please indicate so.