San Bernardino County tweets it reset attacker iCloud password at FBI's request
sbsun.com
sbsun.com
The Secret Service is extremely competent when it comes to computer forensics, and when they don't know what to do, they don't guess, the consult with experts.
The FBI is the opposite in every way, mostly because of budget constraints and the subsequent lack of training. I hope that this is a good learning opportunity for them and a chance for them to increase their training budget in this area.
Maybe that's what they wanted him to think. I refuse to believe the alternative...
I guess it depends on whether the hard drives were the target of the raid or just a collateral of "grab anything that may be useful" mindset. They could already have gathered enough evidence without needing to waste time/money on digital forensics. Hard to say without specifics.
The fact that they went out of their way to assure him that his own hard drives were empty reeks of manipulation.
Color me highly skeptical.
you would think that national level stuff would have people take more care, but if you're dealing with state or local police, they will have someone who has taken an 8 hours Encase or FTK class driving a GUI to gather evidence and if the tool doesn't support it, there's effectively no evidence to gather.
Or that they formatted them before returning them?
(And by "unknown" I mean of course "anything that is not FAT* or NTFS"...)
The moral of the story is for individuals, whom should implictly fear government overreach no matter whom is in office, one has to back their shit up and make it SWAT-proof, even if that means running several TahoeLAFS boxes in countries like Switzerland, because running a server (physical or Linode) or just replicating data to a friend's server just doesn't cut it and never did.
I wonder how would they handle full disk encryption.
Thanks for reminding me to set up Amazon glacier for my FreeNas today. Jesus Christ, the world is a messed up place.
Disclaimer: I work on GCP
I had imagined that computer forensics "experts" would make this mistake somewhere at some point, but I did not think I would actually hear that it had happened. Thanks for the affirmation, even if it is just hearsay.
It makes me curious about what goofs were made with the IRS hard drives that had "crashed" according to forensics "experts".
At which job were you working so closely with the FBI and SS that you were able to ascertain their technical abilities?
I can well imagine jedberg has had to deal with them just being a systems admin for such large deployments as reddit and paypal.
I started out teaching "Welcome to the Internet" classes once a week, and then was the first tech support guy at ioNet / Internet Oklahoma.
Worked my way up to assistant sysadmin before I moved to Austin to be a sysadmin for Texas.net. April 95 to September 96.
Talk about a hell of a first day... We pretty much switched into full "get news about the bombing online in some form or fashion, however possible" mode for about 48 hours. This was before CNN had a huge online presence, so we had stuff going like a RealVideo stream of a webcam pointed at local TV news, a couple of people went down to take pictures, etc, etc...
Started it in mid to late '96.
If it happened at ioNET after September '96, I wasn't involved.
All of Texas.Net's systems ran legit copies of Solaris; a large amount of them were brand new and came with OS entitlements. I remember going to the post office one day to pick up our brand new copies of Solaris 2.6.
Are you talking about me running SUNHELP.ORG, which started in '97? That was (and is) a third-party user community and resources, along with mailing lists. It did not provide Solaris downloads.
I happen to have a (personal) archive of Solaris releases, but it's not public access.
The closest thing to "piracy" I could ever be accused of was reposting design documents for an unreleased system that I found on Sun's own publicly-accessible website in 2000.
That whole scenario is explained in detail here: http://www.sunhelp.org/letters/
If anyone at Sun held me in bad regard, it was never mentioned to me by anyone, and I had a lot of contacts at the company.
- I was one of 250 people to be picked as an external pre-release beta tester / community liason for the release of OpenSolaris.
- In 2005, Sun donated a fully loaded T1000 server (8 cores, 8G RAM) for use by me in running the site. I'd think that if I was a huge software pirate the company wouldn't encourage it by giving me expensive hardware for free.
Pictures: https://www.flickr.com/photos/mrbill/sets/72057594124431136/
Thanks.
To be perfectly honest: I vaguely recall source of an older Solaris version being passed around the user/hobbyist community, but I wasn't the originator. I'm sure I downloaded it at one point, but don't remember ever doing anything with it OR putting it up for coworkers to browse.
Like the (released and quickly discontinued) version of Solaris 2.6 for PPC that ran on certain RS/6000s, it was "out there" and easily obtainable by anyone in the hobbyist community if you asked enough people.
No idea what was done at TN after I left; I had issues with how management treated the technical staff and resigned in late '98.
It's been 18 years, my memory is a bit fuzzy.
What's really weird is being called a "peer" by people who I looked up to when learning and just getting started. Massive case of impostor syndrome...
There are a ton of people out there, who are better talented and have contributed more to UNIX / Linux, open source, and the hobbyist/maker community in general that deserve recognition and fame.
I'm just a fat old fart sysadmin who's had a good run and was lucky to be able to enjoy most of it. The best I can hope for is to be thought well of by others.
Reddit is also a cesspool of activity from all sorts of people, so there might be some monitoring involved there.
That's assuming it wasn't all staged to take advantage of this situation to pass some backdoor law or set a precedent here, in which case, I don't expect the FBI to retract anything, because then their goal isn't to unlock this phone, but to set that precedent.
Besides the legal precedents and other associated drama, I think is one of Apple's major concerns, and one of the reasons they implemented the "we don't have the keys" approach to their encryption. If the FBI can always just call on Apple (or Google) to fix whatever mistakes they made, there is little motivation for training / getting better on this front, effectively making Apple the computer forensics arm of the government.
Maybe they were just competent at working around excuses from Apple.
If you think about it, consulting vendors is probably a better use of taxpayer money then RE-ing every stupid crypto system on the market.
They contacted Apple, did their homework and came up with specific and generally sane demands. They even went as far as suggesting to perform the hacking at Apple site to ensure that insecure firmware doesn't leak outside.
BTW, this last part looks very much like a response to concerns voiced by Apple, which means that the official statements from both sides are just a tip of the iceberg.
Closed-source may be a pet-peeve of yours, but it has nothing to do with any of this.
They've put themselves in a weird legal situation because they've made it so that they are the only ones who can actually write and sign the firmware the FBI is demanding. A judge would laugh them out of the courtroom if the FBI was technically capable of writing the firmware and demanded Apple's help because it was too hard.
No, not based on the interpretation of the all writs act that the FBI is attempting to use. As far as the FBI is concerned, they could force my Grandma to write a backdoor if they deemed her the best person to do so. Given that she can't answer the phone most days it'd be a lon wait, but I wouldn't put t past them.
--edit to correct auto-correct
This is an example of a non-free software feature. Why are the keys baked in and can't be disabled. And "write your own firmware" doesn't solve this problem -- they could just pay a developer to do it $X an hour. A better security model should've been used -- where updates have to be confirmed (read: signed) by the user before they are applied.
The only reasonable way for law enforcement to deal with even a single one of those factors is to request help from device vendor.
I think you absolutely nailed it!
For a high-profile investigation like this, Apple would have given the FBI access to the key developers in the security group. The developers are smart guys trying to be helpful. They are not thinking about Apple policy, or constitutional law, or the big picture of world liberty and privacy. They are tasked with finding the solution to a technical problem: How to get access to protected data.
What likely happened--exactly as you already suggested--is that the FBI asked the developers to explain how the security system could have been designed so as to permit easy government access in cases like this. The FBI was asking "hypothetically" of course. The developers happily gave a blueprint of how the system could have been designed.
The FBI now demands that blueprint be implemented.
Apple should have talked to the FBI through lawyers only.
You went from "would have" to "should have", turning your hypothesis into a certainty...
They do have the keys. A 4-digit pin is useless if you have Apple's private key.
Whereas SS had a number of excellent specialists who understood acquisition, the FBI seemed to be wearing clown-shoes most of the time. I'm not surprised at all that they botched this case so badly.
It's clear as day that Apple is on the right side of this argument. It's not their job to bail out the FBI for yet another colossal screwup. Especially not when it damages their product so severely.
Really, I teach a course in a local forensics program and have helped a couple local schools over the years. Any teenager with an iPhone could have explained that resetting the AppleID was a bad idea. There are plenty of very intelligent kids out there who need jobs. For the FBI to act in such a manner is inexcusable. Ditch some of these hack cops and hire some proper technology experts.
But then again obviously FBIs long term goal is to break in all the phones regardless of the circumstances.
Some are saying the password reset requested by the FBI prevented a backup and closed the "front door" they already had, forcing the Apple backdoor.
The simplest possible explanation for them shutting themselves out has to be incompetence rather than malice, right?
[1] http://www.wired.com/2016/02/apple-says-the-government-bungl...
It would still be relatively trivial to restore the connection so it's not a valid reason for requiring the backdoor, but I think that was the writer's intent.
Also, even if they didn't restore the broadband at the guy's apartment, couldn't they just take the router and plug it in back at the station, since the login credentials have already been established?
Even the mention of the reporters swarming the apartment highlights the absurdity of the FBI's logic. How can they justify needing to scour every last digital crevice when they couldn't even be bothered to secure and scour the physical space they had access to?
"Also, even if they didn't restore the broadband at the guy's apartment, couldn't they just take the router and plug it in back at the station, since the login credentials have already been established?"
However, the sibling comment below my original asserts that iOS won't re-connect to WiFi after booting until the pin has been entered (and thus no backup will occur). If that's true, and if the phone had been powered down at any point, then retrieving the router isn't a viable solution anyway.
Also, since Apple remembers old iCloud passwords to prevent reuse for a year, what stops them from setting it to the original value in their database? Even if there were information lost in their database when the password changed, surely they have backups, right?
PDF of the motion to compel (Page 18, footnote 7): http://www.wired.com/wp-content/uploads/2016/02/Apple-iPhone...
Or is this the FBI carefully parsing words by saying the owner of the phone (i.e. the attacker's employer) tried to reset the password, without mentioning that said reset was done at the FBI's request?
Let's not let the details get in the way.
The backdoor the FBI wants to exploit cannot be leaked. They are specifically requesting it be limited to the specific phone.
If it were possible to take an apple update, edit it, and then apply to other phones, they wouldn't need Apple's help.
It wouldn’t need editing. It’s intended to disable the timeout when brute forcing passwords. It’s incredibly dangerous software to even exist. And also insanely valuable. Even more incentive for someone to leak it, even at Apple.
If you can reprogram or electronically intercept and alter the ID as it is read by the firmware, the backdoor build could be run on any phone.
For example if it is tied to the UDID, the UDID = SHA1(serial + ECID + wifiMac + bluetoothMac). Here's an article where Apple says the ECID is alterable through the BPP (Baseband processor) [1] so perhaps exploitable by connecting to a BSE and hacking the BPP via LTE vulnerabilities. The serial number, WiFi and Bluetooth MACs can all be altered as well. So I'm not convinced UDID locked builds cannot be worked around by a motivated adversary.
Heck, finding a SHA1 hash collision by altering only the most easily set MAC addresses is computationally feasible and costs less than $1 million!
[1] - http://www.infoworld.com/article/2631100/mobile-security/app...
Apple already has the backdoor.
Are you willing to guarantee that Apple will never lose control over their signing keys, giving whoever acquires them the ability to end-run the security of a locked device and install software that you, the device owner, are sandboxed from inspecting?
No. But this doesn't mean I don't think there's ALSO harm in the FBI or any government agency being able to demand companies build tools that expand the use and usability of that backdoor to parties beyond the company holding the key.
It sucks that Apple has a one ring when it comes to iOS security. It's incredibly dangerous if a government can require them to wield that one ring for arbitrary purposes via a contortion of the All Writs Act. And it's just plain stupid for software professionals to base their opinions on a belief that anyone is capable of writing an unexploitable check for device identity.
It was the height of naivety to think otherwise; it's not like we lack historical examples of what happens when a small number of companies make themselves the linchpin of trust/security:
https://en.wikipedia.org/wiki/Communications_Assistance_for_...
https://en.wikipedia.org/wiki/Room_641A
Prior to this event, I had no idea that this generation of programmers seriously thought they could centralize so much information and control into their own hands, and somehow keep it out of the government's hands when they eventually came knocking.
Even if Apple wins this argument, they'll have to keep winning every argument, every network intrusion, every espionage attempt, forever. This particular argument is pointless; the high-value-single-point-of-failure security model is fundamentally flawed.
It seems obvious to me that we have to take the world as it is; yes, centralization of security is bad. Yes, we should fight to get away from this centralization of power in companies like Apple.
But as it stands now, it's incredibly important to support Apple's fight against this dramatic expansion of the All Writs Act's powers. The fight isn't "pointless", it's the exact opposite -- the security and privacy of hundreds of millions of people in the world, today, rests on the success of fights like these.
How much better it would be if we were all running Gnu/Debian Mobile on our OpenPhones is completely irrelevant. That's not the world we live in and better, open solutions are going to take years and decades to work toward.
We are never going to get to that world if Apple loses fights like these. We already have legislators working to make even the security offered by iOS today, for all its flawed dependence on Apple, illegal. Once these privacy and security rights are gone, that's the new normal, and open, truly securable phones won't even be legal to manufacture in the first place.
Your references to the GPL nonsense are a false dichotomy; All we need is ownership rights over the electronics we buy, like we've had -- even on Apple platforms -- for decades.
Supporting Apple now just ensures that when Apple does fall -- whether it's an expansion of CALEA, or espionage, or just a shift in their business priorities -- we may never know about it, and the impact on privacy/security is likely to be much worse.
If Apple loses this battle, there's no real impact to the risk profile. Apple already had the backdoor. The only change is that we're forced to be honest about that backdoor's existence, and start thinking real hard about how to avoid this kind of centralization of power, and its inevitable use, going forward.
Let's invert the use of the "ticking bomb" propaganda - say we've got a phone with data that can prevent an eminent attack. What person is going to say we shouldn't unlock the phone, because it would set a bad precedent? I'm a steadfast believer in the idea that computing devices should be private extensions of one's mind, but I would still say it's stupid to not hack into such a device if it can be done!
If you want a device that guarantees individual privacy against the manufacturer/USG, it has to be designed for such. You can't build an insecure system and then expect an A for effort.
Holy crap, you're right. The state is an ever-present inexorable threat to humans.
The state isn't really the problem, though -- centralization of authority is. The DoJ issue is basically moot; this is a lawful request made under public scrutiny and judicial review.
Whereas Apple could just change their business priorities at any point, and never even has to tell us.
I think that's an unreasonable burden on any company, but including users. This isn't just limited to Apple. Any company signing code is at risk of being asked to apply digital signatures to the code equivalent of malware, and to the free speech equivalent of falsehood. No.
Apple could ship encrypted backdoored binaries under an NSL gag order tomorrow, might not even know it themselves, and we'd never notice because we can't even introspect the device. In a few years, the federal government could extend CALEA to cover Apple, and there'd be little we could do because we can't override Apple's control over the software.
The security model is flawed; it requires Apple to fight and win every argument, every battle, every espionage attempt, in our favor, forever. The longer we propagate this security myth that putting absolute trust in the hands of the few is a viable security model, the worse things will be when it fails.
In the meantime, complying with this legal request doesn't meaningfully move the risk needle. The risk already existed. All it does is force Apple to admit that they hold a backdoor -- something they obviously are loathe to do, as noted by the US Attorney when she was forced to submit an additional court filing responding to Apple's public, calculated attempt to define the public debate before even responding to the court.
However, I agree that the security model they have has a weakness, which is that it requires them to keep fighting against sovereigns, not just the U.S. government, for all time. That's a problem, I'm sure they're coming to terms with what that means, as are other companies and even users and governments. Historically Apple has been a closed-hardware company, it's difficult to imagine they'll shed that anytime soon, and if that's true there'll always be something of a black box involved.
But they could still alter the OS and firmware to require an unlock code to do OS or firmware updates, and if one can't be provided that all keys on the phone are erased first. Short of unknown backdoors, that obviates the current government request that Apple change the software. A law could possibly prevent them from shipping such an OS or firmware update. So the next step is making the user passcode stronger, and its hash algorithm much more computationally expensive. Even if there's a backdoor in the future the ability of friend or foe getting into the equipment is probably just too expensive within a reasonable time frame.
But if you're stuck on open hardware being the end goal, I'd probably agree with that, even though I think Apple will go to great lengths to avoid that.
If you mean that Apple could leak it, that isn't a real risk. There is already a risk that Apple has it's key that it signs updates leak. If that leaks anyone can write the modified software.
Apple should just write the modified software to only work on that specific iphone (by serial number).
The software already exists. You just have to lightly modify the existing software to turn off security features. The problem is that we don't have apple's key.
Right now, Apple can argue undue burden. Someone needs to sit down, nop out a bunch of security measure in an older branch of iOS, add boot and installation tests that lock it down to a particular serial number in a way that isn't vulnerable to any easy spoofing, test it all, and finally sign it.
If they do all this now, the second time the FBI shows up at the door Apple can't decide to then start arguing undue burden. Any government lawyer could win the argument that Apple already did all the heavy lifting, and that merely changing the serial code checked for could obviously not now constitute an undue burden on the company.
Once they've started down this road it's just a slow frog boil of "obviously not undue burden" small changes to "here's a list of 500,000 potential terrorists whose data we may need to access. Push an OTA update to them that has bypassable security"
Since each of those 800 times will used after court issued a legal warrant, that is actually good.
This still leaves them the ability to remove their ability to do so in the future, by requiring the passcode to update the firmware on both the hardware itself and the secure enclave.
The master key is the court order to make it happen, or the NSL that has been made worthwhile after the first existence proof.
Which is technically true. But consider each event a black box, into which you throw a targeted phone, and it comes out unlocked. Whether that was through unique effort for each case, a general capability developed and archived by Apple, or even an actual backdoor/masterkey developed by Apple out of exasperation from the expense of being legally compelled in each individual case and others to come, the effect is the same, the phone is reliably opened.
"assuming they can code in the specification that it's only applicable to this device."
I think that's a big assumption.
What could possibly go wrong?
No way that would ever get released into the wild.
Once proven feasible, no way any one else would reverse engineer stuff and make their own.
It's dead simple to binary patch the code -- but you need Apple's signing key to make it work.
If you're worried about Apple's signing key being released into the wild, this one-off backdoor ought to be the least of your concerns.
Like the apologists for the FBI (and other enablers of authoritarians), I'm trying to gleen the real technical story from the public misinformation.
You may know about FileVault's password protected volumes. https://en.wikipedia.org/wiki/FileVault
Does the (pre-Secure Enclave) iPhone 5C which the FBI borked store its data the same way?
I now believe that by changing the password, the FBI also borked (lost) the recovery key, so now neither the iPhone nor its backups are readable.
You and the FBI want Apple to create a one-off patch to better crack the keys of an encrypted file, presumably one of the iCloud backups.
Um, good luck with that.
If you know better, please clarify with your understanding of the actual systems in use, vs arm waving apologia.
In addition to which, our security relies on Apple themselves never changing their business priorities and choosing to exploit their position of absolute authority.
The fact that they have that authority is why the government can compel them to do anything in the first place.
If you want to talk technical specifics, then no, your assessment is incorrect. The Apple ID password was changed, but that doesn't affect the on-device keying.
PIN numbers are the weakest link in the iPhone crypto chain. Apple strengthened that link through non-cryptographic means: tamper-resistent key derivation software that either runs on the main CPU, or in later devices, on the secure enclave CPU.
That software enforces a limited number of retries, essentially strengthening the PIN number. However, Apple also retained the ability to subvert the owner's lock on the device and install new key derivation code that does not include those security features; this applies to both the 5c and later devices with secure enclave.
If Apple hadn't retained that backdoor, the FBI would have nothing to ask for. Apple has, however, and has consistently made themselves the sole authority and gatekeeper of these devices.
How would relaxing the tamper-resistent key protection help here? One needs the PIN to reimage the device. Chicken & egg. Creating a one-off OS image can't help without first having the PIN.
And the goal is to get the data, not crack the phone. Why can't the FBI use the backups? And what do they hope to find that don't already know (by other means)?
Just sounds like CYA to me. The more I learn about this silliness, the less plausible the FBI's narrative becomes. The FBI screwed up, is now just finding scape goat.
---
Authoritarian already has a widely recognized definition.
https://www.wordnik.com/words/authoritarian
Playing Calvin Ball with vocabulary undermines your rhetoric.
If you would like to repurpose the word "authoritarian", I encourage you to petition the dictionary gatekeepers.
The weak link is that a PIN can be cracked very quickly; in hours or days. The search space just isn't very large.
The only thing preventing the FBI from doing so is the Apple-signed iOS code that erases data keys after too many unsuccessful retries.
So, if Apple uses their privileged backdoor to disable that check, the FBI can brute force the encryption key by trying as many PIN combinations as they like.
In effect, this means Apple already has the cryptographic backdoor necessary own any PIN-protected iPhone in the world.
That's small potatoes, though -- they can also install new software on locked devices, and push modified updates to applications distributed through the AppStore. After all, apps are resigned with Apple's signing key, discarding the original software authors' signatures.
When you factor in bitcode (in which Apple compiles the actual binaries server-side), application authors can't even verify that distributed binaries match what they uploaded, and the use of a relatively high-level bitcode allows Apple to much more easily patch/rewrite significant portions of the application.
In other words, Apple built a system in which they have almost absolute authority over every iPhone, and due to strict platform DRM, there's almost zero transparency into their use of it.
> Authoritarian already has a widely recognized definition.
"adj. Characterized by or favoring absolute obedience to authority, as against individual freedom: an authoritarian regime."
Can you install software on your iPhone that pre-empts Apple's authority over the device?
Can you install software without Apple's approval?
Can you prevent Apple from installing whatever software they like on your iPhone, including software that implements CALEA-compliant real-time surveillance?
The answer to all three is "no", and why I think this absolutely fits the "authoritarian" definition.
You can, of course, use a different vendor's phone. The situation there will be roughly the same. Eventually, if nothing else changes, we'll see CALEA expand to cover smart phones in the same way it expanded to cover internet traffic once the ISPs were sufficiently consolidated. The vendors' authority over the devices makes this easy.
At that point, there won't be a choice at all.
https://news.ycombinator.com/item?id=11151599
As for the rest, we're talking past each other, and I'm left wanting to know what outcome you advocate.
If so moved, please reply in the new thread. Thanks.
EDIT: add after the comma.
This is the most apt summary of this whole situation. I expect to see a family-friendly version of this phrase in the media over the coming days.
One of us should help them out. ;)
I don't know why so many people feel better about incompetence than they do about malice. Malicious parties can at least be expected to act in their own interests, even if in reprehensible fashion. Incompetent parties might do anything at all, e.g. permanently damaging our communications infrastructure for a chance at short-term political advantage.
You don't put rookies on this and I'd seriously be surprised if the NSA wasn't involved in this matter personally.
The government wants a back door installed into all iPhones period. I mean how do you expect apple to build a tool that can bypass the same security features the government is trying to deal with right now without them inadvertently letting everybody and their mother know that there is some fatal flaw in the security layer of every modern iphone and/or iTunes.
There's no magic way to fine tune a tool like this and if out spy agencies don't know this then god help us all. Isis is probably gonna win. rolls eyes
I mean jail breaking is one thing. This is vault busting and once people know there's a bug and where to look they will find it and exploit it.
And apple's only remedy will be to patch the backdoor. Which is obviously what the gov is trying to prevent apple from being able to do by getting a precedent established in the courts that wags a finger at Apple saying "ah, ah, ah you didn't say the magic word"
Please goddamnit!
The gov doesn't want to be Samuel l Jackson anymore. They want to reverse the roles and this case is the perfect cover. Just like the gov exploited the bombing on 9/11 to pass the patriot act. This is no different.
"The County was working cooperatively with the FBI when it reset the iCloud password at the FBI's request."
U.S. dollar is the criminal and terrorist currency of choice. We must therefore, of course, break the dollar.
Ok, fail.
From a technical perspective, it seems very simple and easy to replicate before actually doing it and locking yourself out completely like they seem to have done.
Straight amateur hour over at the FBI
The FBI cannot unlock the phone. By changing the iCloud password, they have made it so that the phone cannot even possibly sync without first being unlocked. Knowing the iCloud password is of no utility for them.
Also if the iCloud account in question was pointing at the perpetrator's work email address, the city would have been able to do an email reset.
That should be enough to get the FBI's request overturned.
But it probably won't be.
> Hope the judge recognizes the apparent level of incompetence demonstrated by this case.
I don't think competence is particularly relevant to the laws in this case....This would eliminate this vector and not drastically effect the usability of the device. Though it would also need a way to fully reset the device including the removal of this signing key in order to bring the device back to factory settings in the case of loss of the device specific signing key.
His intentions: good. His success probability: unlikely (unless they have knowledge of how the encryption key is built from the passcode)
Source: http://www.businessinsider.com/john-mcafee-ill-decrypt-san-b...
"Mr. Cook, it's John McAfee on line three, again. He says, quote, 'pretty pretty please.'"
My original question still stands
It does seem that if the FBI desoldered the security chip and subpoenaed the KDF algorithm, they could recover the raw encryption key using their own hardware. But perhaps I'm missing a detail.
> Apple encrypts your iCloud data in storage, but they encrypt it with their own key, not with your passcode key, which means that they are able to decrypt it to comply with government requests.
Not sure if things have changed since then.