This would mean that when backed up in Apple’s servers l, they’d have to backup per device... maybe they do?
Backups are different. Those are not encrypted with device keys because obviously you want to recover from loss of device and restore to a brand new one. But if you’re not comfortable with that, you can do local encrypted backups with your own password via iTunes. And as noted the most sensitive data like HealthKit is only included in encrypted backups. White paper also discusses a special escrow service for backing up your keychain, incidentally.
My foggy understanding is that iCloud backups are encrypted with a key stored in iCloud Keychain, which is encrypted within the hardware security module escrow service they run, so after iOS 10 they can't actually decrypt your backup.
Edit: oh, I replied to you below as well. That video has the details but it's been awhile since I watched it.
It sounds like (although I'm not an expert) that it would still be impossible for them to encrypt files in higher data protection classes, since the iCloud backup keys are stored within iCloud Keychain, which is end-to-end encrypted.
Edit: and honestly if I'm misinterpreting that and it's an issue for a specific person, they should just use iTunes encrypted backups and not rely on iCloud.
“When files are created in Data Protection classes that aren’t accessible when the device is locked”
So not photos, most data.
https://www.apple.com/business/docs/iOS_Security_Guide.pdf -- pg. 29 under the Health Data subsection.
Edit: @bobwaycott points out the significance of this quote in the below child comment.
Unless I’m misunderstanding you, your quote disagrees with your assertion. Health data is only included in encrypted iTunes backups. It is not included in unencrypted iTunes backups or in iCloud backups.
Of course, that’s just backups. It does say it can be configured to be stored and synced between devices via iCloud, where it is encrypted in transit and at rest. That appears to indicate it is stored pre-encrypted, and does not indicate there is any way to access it outside ones devices.
I know they said they could have accessed that San Bernardino terrorist’s iCloud backup if only they had one. Not sure if they’ve change the security architecture since then.
> I know they said they could have accessed that San Bernardino terrorist’s iCloud backup if only they had one. Not sure if they’ve change the security architecture since then.
I actually think they have, the shooting was in 2015 and iOS 10 was released in 2016 and was first to have some of the features he talks about in the video.
iCloud Keychain Payment information Wi-Fi network information Home data Siri information
So everything else, pictures, notes etc. etc. part of the iCloud backup, are not. Please not spread misinformation about this.
It’s pretty obvious really, they need to know the key for encrypted at rest data in order to be able to reset your password if you desire. They absolutely do don’t currently offset end-to-end encryption on the majority of data in iCloud backups.
But you’re right, the paper doesn’t say they do encrypted iCloud backups yet. The infrastructure is there to store encrypted backup keys in the keychain and escrow them so they’re recoverable yet Apple never has access. It’s probably the same foundation for iMessages in iCloud which they are just rolling out. That lets them store your very sensitive messages in the cloud and restore them to new devices and reset your password, all without them ever having access to your keys.
See the section on keychain escrow and recovery for more detail. It’s a game changer and makes storing data in adversarial clouds feasible.
Part of the reason is that people sometimes forget their passwords and that would lock them out of their backups. So they want to allow email/other methods of resetting the password and giving access to data.
But it would be nice to have it as an option. It’s worrying though that even technical people seem to believe it is end-to-end encrypted. When it very obviously isn’t.
https://support.apple.com/en-us/HT202303
In particular a limited subset of data uses end-to-end encryption, none of which is super interesting:
These features and their data are transmitted and stored in iCloud using end-to-end encryption: iCloud Keychain (Includes all of your saved accounts and passwords) Payment information Wi-Fi network information Home data Siri information
They don’t claim to, but the same misinformation gets spread every time this topic comes up on HN. If you want end-to-end encrypted cloud based backups of photos and other data on iOS you presently need to use a third party app.