[1]: https://www.nytimes.com/2018/01/23/opinion/apple-china-data....
Specifically HealthKit data "is stored in Data Protection class Complete Protection, which means it is accessible only after a user enters their passcode or uses Touch ID or Face ID to unlock the device." Furthermore, "When configured for iCloud storage, Health data is synced between devices and secured by encryption that protects the data both in transit and at rest. Health data is only included in encrypted iTunes Backups. It is not included in either unencrypted iTunes backups or iCloud Backup."[1]
You also provide zero evidence that "Apple will sell your data" even if they could get it. Nothing in that citation about using China-based servers supports it.
[1] https://www.apple.com/business/docs/iOS_Security_Guide.pdf
That will give a clue about whether it is possible for Apple to decrypt the data or not...
It is impossible to trust a closed source system that cannot be audited independently. If Apple caved to the Chinese government, perhaps they will in the future cave to your local government too? Or some insurance company too? They're a business after all!
However i’m pretty sure my data stored by doctors and hospitals is less secure than my pictures in my iPhone.
This would mean that when backed up in Apple’s servers l, they’d have to backup per device... maybe they do?
Backups are different. Those are not encrypted with device keys because obviously you want to recover from loss of device and restore to a brand new one. But if you’re not comfortable with that, you can do local encrypted backups with your own password via iTunes. And as noted the most sensitive data like HealthKit is only included in encrypted backups. White paper also discusses a special escrow service for backing up your keychain, incidentally.
My foggy understanding is that iCloud backups are encrypted with a key stored in iCloud Keychain, which is encrypted within the hardware security module escrow service they run, so after iOS 10 they can't actually decrypt your backup.
Edit: oh, I replied to you below as well. That video has the details but it's been awhile since I watched it.
It sounds like (although I'm not an expert) that it would still be impossible for them to encrypt files in higher data protection classes, since the iCloud backup keys are stored within iCloud Keychain, which is end-to-end encrypted.
Edit: and honestly if I'm misinterpreting that and it's an issue for a specific person, they should just use iTunes encrypted backups and not rely on iCloud.
“When files are created in Data Protection classes that aren’t accessible when the device is locked”
So not photos, most data.
https://support.apple.com/en-us/HT202303
In particular a limited subset of data uses end-to-end encryption, none of which is super interesting:
These features and their data are transmitted and stored in iCloud using end-to-end encryption: iCloud Keychain (Includes all of your saved accounts and passwords) Payment information Wi-Fi network information Home data Siri information
They don’t claim to, but the same misinformation gets spread every time this topic comes up on HN. If you want end-to-end encrypted cloud based backups of photos and other data on iOS you presently need to use a third party app.
I know they said they could have accessed that San Bernardino terrorist’s iCloud backup if only they had one. Not sure if they’ve change the security architecture since then.
> I know they said they could have accessed that San Bernardino terrorist’s iCloud backup if only they had one. Not sure if they’ve change the security architecture since then.
I actually think they have, the shooting was in 2015 and iOS 10 was released in 2016 and was first to have some of the features he talks about in the video.
iCloud Keychain Payment information Wi-Fi network information Home data Siri information
So everything else, pictures, notes etc. etc. part of the iCloud backup, are not. Please not spread misinformation about this.
It’s pretty obvious really, they need to know the key for encrypted at rest data in order to be able to reset your password if you desire. They absolutely do don’t currently offset end-to-end encryption on the majority of data in iCloud backups.
But you’re right, the paper doesn’t say they do encrypted iCloud backups yet. The infrastructure is there to store encrypted backup keys in the keychain and escrow them so they’re recoverable yet Apple never has access. It’s probably the same foundation for iMessages in iCloud which they are just rolling out. That lets them store your very sensitive messages in the cloud and restore them to new devices and reset your password, all without them ever having access to your keys.
See the section on keychain escrow and recovery for more detail. It’s a game changer and makes storing data in adversarial clouds feasible.
Part of the reason is that people sometimes forget their passwords and that would lock them out of their backups. So they want to allow email/other methods of resetting the password and giving access to data.
But it would be nice to have it as an option. It’s worrying though that even technical people seem to believe it is end-to-end encrypted. When it very obviously isn’t.
https://www.apple.com/business/docs/iOS_Security_Guide.pdf -- pg. 29 under the Health Data subsection.
Edit: @bobwaycott points out the significance of this quote in the below child comment.
Unless I’m misunderstanding you, your quote disagrees with your assertion. Health data is only included in encrypted iTunes backups. It is not included in unencrypted iTunes backups or in iCloud backups.
Of course, that’s just backups. It does say it can be configured to be stored and synced between devices via iCloud, where it is encrypted in transit and at rest. That appears to indicate it is stored pre-encrypted, and does not indicate there is any way to access it outside ones devices.
By all account iMessage is one of the few end to end encrypted messaging systems that works in China. You are almost right about China’s general stance but, if you actually did some research, you’d see so far they have tolerated Apple.
Like I said, technical people would be able to observe if Apple secretly changed their security architecture for China. Apple would also get sued if they didn’t disclose that your iMessages are no longer end to end encrypted when messaging someone in China. China just hasn’t cracked down on it because it’s not that popular.
China doesn't give two fucks about Apple or privacy. If you are in doubt, please travel there and experience the total blackout of services that refuse the share data with China. China DOESN'T need Apple, Apple needs China. And Apple needs to comply with their rules regardless of your delusions about Apple's piety. Be it health or selfies, the Chinese government shall have ALL data (on Chinese resents) accessible to them. Or Apple can get the fuck out of China - which Apple won't do because of it's fiduciary responsibilities colloquially called "greed". Welcome to reality
I repeat - your argument is based on cherry picking Apple propaganda. It's like saying "emails stored on Apple devices are encrypted". Which they most certainly are, but if subject to Chinese law, even if Apple's email service were end-to-end encrypted, they'd have to provide encryption keys to the government. So all this "email is encrypted on the iPhone" is marketing fluff
iOS devices literally have a hardware security module called the SEP that controls access to sensitive information such as Health data.
> Where does one backup the said data off the device, as is normal with all devices today.
You set a password for this data when you back it up, and the data is encrypted with that password.
Previous implementations have been crippled in ways that suggests that it could have been done on purpose. Limit the password to few characters and permit unlimited tries on the "secure" hardware. Data recovered in subseconds.
I suggest it was either done on purpose or they are incredibly incompetent. Which alternative do you believe to be true? Either way, why trust them?
Further, it makes complete sense to store Chinese user data in China, where it's subject to Chinese law and not American law.
I don't know for certain, but based on how Apple handles other sensitive user data I would hazard a guess of "no". Apple makes their money selling devices, not user data, so they tend to choose to implement solutions that protect user privacy first. (I am not claiming that this is always the case, nor am I claiming that they do not make any money from user data, but they do handle privacy very differently from the other major corporations.)
You can throw whatever fit, ethics, morals, yada yada, but China gives two full fucks for privacy, etc. Give data or get the fuck out of China. It applies to Chinese citizens/residents.
Where are you getting this idea of "walked away with some dignity and authenticity left"?
https://www.theatlantic.com/technology/archive/2016/01/why-g...
People in the industry have seen this coming for a while. The convenience of having your own centralized medical record and using it wherever you go will be dramatically different from the model we have now.
I notice that the Wallgreens app wants your 'step data' so it an offer your discounts for being healthy.
How much is this a jump to Cancer/HIV status for 'discounts'.
Some people have a big problem with governments accessing this data. For example, the US government has used brute-force to access data and bully both citizens and non-citizens.
https://www.nytimes.com/2017/09/13/technology/aclu-border-pa...
https://www.cnn.com/2017/02/13/us/citizen-nasa-engineer-deta...
I can find more individualized cases if you'd like.
I, for one, do not trust the organization known to send people to offshore prisons to be tortured with no judicial overview to "do the right thing" regarding my data, especially when that organization gets penetrated by data breaches so often.
We might not have a well-functioning justice system, but the alternative--when corporations could feel empowered to ignore it because they themselves are big and powerful--is much, much, much worse.
I actually do, but this would be quite unreasonable to ask. A practical middle-ground is making it so that any data they are forced to hand over is useless.
I trust my doctors and Belgium if something should happen, Apple should back off. If i want them to know my health, i'll install a heart monitor with bluetooth. Encrypted data is only one software update away from being unencrypted.
Just curious, what makes you put your trust in doctors instead of Apple? What's stopping your doctors from leaking your health data as well?
Apple on the other hand, is an organisation devoted to the sole purpose of making as much money as possible. Anything else is secondary. I think this is reason enough to be wary.
I'm not saying we are completely safe, there was a hospital here in Norway that used a foreign company to process health records and it was and still is a big scandal as data like that is is not allowed to leave the country.
My biggest regret today is that there’s not a 2nd device that I almost always have with me for doing 2FA. Watch may become that, or maybe there’s a future for jewelry.
Any security key, it's something else I have to carry around. I'm doing it now, but I regret it's an extra device with no other purpose.
Also, yubikey, as much as I like them for various reasons, don't work with iOS. I recently wrote about this wrt Google Advanced Protection Program: https://hackernoon.com/googles-advanced-protection-program-w...
Speaking of authentication and watches, I like the approach Apple uses, where it stays unlocked until it stops sensing a pulse, and then requires the passcode again. So it's convenient as long as you're wearing it, but it locks up when it's taken off.
Also, totp can be phished in principle. I'd very much like a fido/u2f device.
If the software can't be trusted it's not encryption, it's pointless. If you are going to pick a trust anchor, choose something that isn't also doing wireless updates, running third party apps, has a colorful interface that can trivially trick you into doing unintentional things..
All fine and convenient until it is compromised by some other application.
The encryption key management is performed in a hardware sandbox. iOS and apps running on the phone cannot access it.
I think that's the gist of it anyway. I'm too frugal for an iPhone so I haven't read up on it in detail.
I'm not sure why only Apple and Sony make decent, smaller phones.
So you pay your money for an iPhone and get Pegasus malware anyway ... or get a far cheaper device and use reasonable, sensible, security practices (no 3rd party, don't view unexpected payloads, etc.) and get a similar level of probability of infection.
I take it you don't browse the web or use apps at all?
Though granted the underlying OS might be more vulnerable once FF had been exploited. The homogeneity of Apple surely makes a greater target though, which I'd expect to balance it out.
Presumably you and the GP have done prior to the frugality claim - like people who don't just install any old shit get exploited in a financially more costly way on Android.
However: It’s dated now, almost two years, so keep an eye out for a potential successor. If they don’t release a successor, then they played their cards very well and roped tons of us into their system with a too-good-to-be-true model. There’s probably a name for this play in economy text books :p