Of course, Apple could be implementing things differently from as described but the whitepaper lays out what is and is not possible in the described system.
Of course, Apple could be implementing things differently from as described but the whitepaper lays out what is and is not possible in the described system.
The key section I think most people really should take a look at is "iCloud Backup" starting on page 42. Almost everything you do with your device will end up in an iCloud Backup if you have enabled that, and while the data is encrypted for transport, note well the following;
The backup set is stored in the user’s iCloud account and consists of a copy of the
user’s files, and the iCloud Backup keybag. The iCloud Backup keybag is protected by
a random key, which is also stored with the backup set. (The user’s iCloud password
is not utilized for encryption so that changing the iCloud password won’t invalidate
existing backups.)
In plain English, if you have enabled iCloud Backup, everything but your keychain itself is accessible in plaintext to Apple, and can be restored, without your password, to any new device that [you / the Feds] may provide.I would very much love for Apple to provide an opt-in where the iCloud backup key is tied to the account password with extremely aggressive key-stretching. I would take the risk of losing my iCloud Backup over the trade-off of having my backups accessible to Apple and anyone they can be compelled to share them with. But I do appreciate for the average user, it's not uncommon for iCloud Backup to be immediately preceded by a password reset (just look down-thread for an example).
Note, Apple says that they use a combination of S3 and Azure to actually store the iCloud data, but that they have an additional layer of encryption over the data before sending it out. So while backups technically reside on Amazon/Microsoft servers, it's a black box to them.
At a minimum, if the police get access to your email account, they can force a Apple ID password reset and then restore your data onto a new device without needing permission from you or Apple.
Note however it is still possible to backup your iphone locally using iTunes and Apple now supports encrypted local backups. If you are worried about this threat vector, encrypted local backups provides a large degree of the same usability with significantly stronger security guarantees.
That's an interesting assertion. I mean, yes, sure, they could do that, but it's an interesting question of whether they are legally allowed to do that. Effectively they'd be misrepresenting themselves to your email provider and to Apple as if they were you. Is that acceptable 'undercover policing'? Can they reset your banking password too? Can they do this only while they have you under arrest?
It's a broad, overarching, and highly vague statement that amounts to, in many cases, "I decided you do, so therefore I have the right to act as if you do".
iTunes has supported encrypted local backups since the beginning of iOS.
restore your data onto a new device without needing permission from you or Apple.
and that's a great reason to verify your iCloud backup is always disabled on all devices (if you care about privacy). You just have to be vigilant about not accidentally enabling it during any setup process since iOS wants you to enable the feature, but it's easy to disable everywhere.