Amazon removes encryption from the software for Kindles, phones, and tablets
dailydot.com
dailydot.com
Of course this is purely speculation, but I see this sort of thing far more likely explanation than some nebulous collusion with NSA (Hanlon's razor etc)
I doubt collusion is occurring. More likely- Amazon sees Apple getting legally compelled in NY and CA to develop ways to bypass full disk encryption, and Amazon decided to avoid this battle altogether. I would be happy to be proven wrong though.
"In the fall when we released Fire OS 5, we removed some enterprise features that we found customers weren’t using," Amazon told Ars. "All Fire tablets’ communication with Amazon’s cloud meet our high standards for privacy and security including appropriate use of encryption."
http://arstechnica.com/gadgets/2016/03/amazon-removed-device...
Exhibit #13435245 for why Fire devices are purely consumption-oriented Amazon endpoints, not real tablets.
With moves like this, I'd guess it likely that Amazon continue to move in a direction unfriendly to users wanting full control over the devices they own.
If you put CM on your Fire, they would view that as if you defaced a billboard they paid for.
I would have to disagree. Users buying an Amazon device do not want full control, otherwise they would have bought something else. That's the implication Amazon is working under in order to be able to sell these products at the prices they're selling them. You're talking like Amazon and Apple are committing the same 'sin'
Given Amazon's stance here, I am disinclined to running infrastructure on their cloud. The USA is becoming less and less friendly as a place to operate a business.
A great example is the Wikileaks case. Wikileaks was running on EC2, but Joe Lieberman called Jeff Bezos and said "Hey, you want more of those sweet, sweet government contracts? Take Wikileaks offline." And Amazon immediately complied. http://www.theguardian.com/media/2010/dec/01/wikileaks-websi...
I mean, obviously, no law was passed, so it doesn't violate the letter of the law, but the spirit?
Fire OS doesn't run on Kindle e-readers.
I bet the wording in Amazon's amicus brief will be much weaker than that of Google and Facebook's.
The M7's specs were nothing to scoff at in 2013. Given the incredibly limited specs of Amazon's tablets, however, I would not be surprised if encrypting them could slow them down further to the point of being unusable.
[0] http://arstechnica.com/gadgets/2015/03/google-quietly-backs-... [1] http://www.androidpolice.com/2014/11/20/anandtech-posts-side...
And this is the real reason they killed encryption. Instead of optimizing FOS 5, they made it less secure.
1.) Making friends with the NSA. 2.) Improving performance on their devices.
Slow interface at a device or OS level is insta-garbage to me as a user.
It's more difficult to drop Amazon than you might think.
If Amazon hardware is compromised, there's no reason to assume their AWS platform isn't compromised. And that puts a backdoor in a lot of web applications.
The issue with the FBI-vs-Apple encryption situation is that the device itself can be secured, at least in theory, if the user memorizes a strong key (pay no attention to the "secure enclave" style of key escrow authenticated with a PIN or fingerprint, that's snake oil and will always be backdoorable!) and the hardware doesn't intercept the key entry (which, yeah, is sort of a hole). And devices that refuse to implement any encryption at all, like Amazon's, need to be avoided.
But I agree with the overall feeling. European developers already know (or should know) that the AWS model was tarnished by the PATRIOT Act pretty much since its inception, from a legal standpoint. If your data is handled by a US company, be it on US soil or anywhere else, the US government can get it at any time (without even the need to involve NSA-level skills) and nobody will be allowed to tell you. To be fair, in any other circumstance your data is just fair game for any NSA operation, so in practice you're basically screwed no matter what, but at least you can try to give them a challenge.
What is a good solution? Perhaps sensitive applications have to encrypt their own data, so that I can access most of the phone functionality with the short PIN, but need a longer password to access certain data. No dice with the address book, though :-(
(I don't trust finger prints, because they seem tricky to keep secret - my latest phone also says that fingerprints may be less secure than a good PIN).
Another alternative might be to look into Tasker. You might be able to write a script that will turn off the lock when you're at home and it's during this time range, for example.
My suggestion: Be an empiricist and run the experiment. I've been using strong 8+ character alphanumeric passwords on my devices for several years, and it’s rarely a bother.
Sometime ago, I even started using randomly generated complex passwords for my work account, and I was astonished by how effortless it is for me to memorize a new such password every 90 days.
As they say, your mileage may vary, but at least run the experiment, you might be surprised.
Fingerprints are not trivial to obtain, and are even harder to reproduce.
I use a hyper-complicated password on my phone with TouchID, so I only have to enter it once when the phone is booted. After that, I'm on fingerprints. If I were coerced into unlocking my phone, I would just use the wrong finger a few times in order to trigger the requirement to re-enter the password.
It's clear these comments are going to be a wave of negative speculation but I find it hard to believe that Amazon has done this to make their devices easier to hack by the three letter agencies.
I would love to hear some kind of comment from anyone at Amazon who knows why they did this.