Apple dropped plan for encrypting backups after FBI complained
reuters.com
reuters.com
While iPhone itself is pretty secure as a device phone (and Apple makes sure to remind you about that in each ad, public speaking, attacks on competitors, etc), as an ecosystem it's not secure. And it's like that on purpose - there's no good and easy option to backup your phone other than iCloud.
You have to be a tech person to know how to keep an iPhone secure. Average Joe buys iPhone and pays for iCloud. They Apple first $1k to get (on top of other things) a secure device, and then they Apple monthly fee to give Apple all their data and make insecure. Pretty genius business strategy.
By the way, People have come to hate Google all the way for some advertising and easily switch-able data collection. But one should at same time hesitate to vote to apple with their wallets, they are a monster company which patents rounded corners of phones and things like optional chaining in Swift. That just goes unnoticed in circles like HN. IMO apple has always been more evil than Google.
Probably not. The keyboards on their laptops are barely functional but it doesn't stop people from saying how great they are.
This must be some definition of "barely functional" I'm unfamiliar with.
I've had a mid-2017 MBP since they were released. Yeah, I had to get the keyboard replaced when some keys failed after a year, but at least they did it for free. Actually, overall I prefer this keyboard to the 2013 I had previously. I think their failure rate is unacceptable, but they are certainly not "barely functional" by even the remotest interpretation of the phrase.
Even crappy Acer laptops from the 2000s had longer lifespans.
I wouldn't call it "barely functional" either since I can clearly still type on that keyboard, but the combination of mechanical failure rate and personal accuracy issues means that I buy the MBP despite the keyboard.
Personally, I find it to be an improvement over the previous generation in almost all respects except for, obviously, the failure rate. I hate that I am expecting the keyboard to fail again within a year or two, but perhaps I will be surprised and this particular one will last long enough that it won't be a problem for me.
As a person who had to replace a microsoft ergonomic keyboard after 14 years and has never had to replace a laptop keyboard I would consider a laptop keyboard that was replaced after a year due to failed keys to qualify as 'barely functional.'
It's the 21st century. keyboards are a solved problem that should never fail. It's abject failure on the part of Apple for releasing a flagship laptop with such a comparatively shitty keyboard.
No keyboard should be failing at this point. Keyboards are a mature technology.
Does it fail more than the average keyboard? Yes. Am I pleased about its failure rate? Absolutely not. Would I rather have a different keyboard? Uhhh probably? I like the way the keys feel, such as the fact that they don't wobble in place like the previous generation, and I find that I do not type any slower or make more mistakes than I did previously. Probably this keyboard was designed for somebody who types like I do, and perhaps this is not the way most people type. (I say this because most people complain about the reduced travel, about the keys not registering presses all the time, and other issues.)
So my point is: the keyboard is bad as measured by multiple metrics, and Apple should feel bad about it, but there is no conceivable definition of "barely functional" that applies to this keyboard. Most of the time I have not had to worry about its failure rate because it does not affect me on a daily basis, even though I use it for typing everyday.
>This must be some definition of "barely functional" I'm unfamiliar with.
I agree.
Keyboards aren't exactly cutting edge technology, they shouldn't be failing after a year.
I simply don't understand why people would blindly believe marketing material from a for-profit corporation. It's a device running closed source software. There is no way to prove this claim. If anything, Apple has been caught in the past sending very very personal sensitive information [1].
[1] https://www.theguardian.com/technology/2019/jul/26/apple-con...
Is Apple perfect? No, of course not. Are there things I think they should do better? Yes. E2E encryption with user keys stored in Secure Enclave, etc, etc. However, for Joe Consumer, I think they make the most secure, easiest to use platform.
Surely their tax status is orthogonal to their trustability.
Under capitalism, encouraging repeat business from a customer is a successful long-term strategy, and maintaining customer satisfaction by not selling them food that will make them sick, cars that have faulty brakes, clothes that deteriorate in the rain, or so on is part of that. So if I purchase a product from a company that's been around for a while, I can have a reasonable expectation - a trust - that that product will be of some quality.
Indeed, that's why customer protection laws exist.
> So if I purchase a product from a company that's been around for a while, I can have a reasonable expectation - a trust - that that product will be of some quality.
That's pretty naive. Companies that used to produce quality products often switch to producing garbage once they have established a brand people trust.
For-profit companies kinda work when they are being watched and it's easy to judge the quality of their products – i.e. when you don't need to trust them.
Apple is specifically hard to reason about because some aspect of their value is based on their products being a status symbol, and some value is based on their functionality (this is true to a degree for most products, but is skewed quite high in the status symbol ratio for a tech product for Apple).
On the one hand, Apple has been fairly straightforward in their communication and not lied often, and also has a business model that has less conflicting interests when it comes to consumer privacy, but at the same time they could conceivably get away with more because of their position as a status symbol.
What this means for me is that I take Apple's claims about consumer protection fairly seriously in most cases, but for anything important I would not rely on them. They've banked a lot of good will, and at some point they might see it as worthwhile to make a withdrawal on it (if they hopefully haven't already), and I would rather not be in a poor position if/when that happens.
I am equally likely to believe or disbelieve marketing material from non-profits. Look at the malfeasance and lies from the Red Cross [1] -- or the sky-is-falling proclamations from the net neutrality crowd -- predictions of doom that never came to pass -- not to mention the lied-about motivations around net neutrality (the real motivation was about who pays for bandwidth.) [2]
[1] https://www.propublica.org/article/red-cross-ceo-has-been-mi... [2]
Beyond just the facts of not protecting data, there is also the deception. This is some really very, very, nasty stuff for Apple's brand and the reputation of every person who works at Apple. I don't know how to state it strongly enough.
Huge Apple fan until today... see my comment history... this is devastating for them amongst the sliver of their users who pay attention to this stuff. And they should realize that even though we may be just a sliver, we can lead other customers away from them if we want to.
I mean if they started tracking your behavour and location, and mining it to better sell ads, maybe that would.
The best you can do if you're technically inclined is to use open source as much as possible (AOSP, postmarketOS, PureOS, etc.), minimize use of untrusted software and services (from all major corporations, no social media, no proprietary software in general), use network-level ad blockers, Tor if you think it helps, VPNs, encrypt everything, etc. And you'd still be tracked and profiled.
If you're not technically savvy, forget about it.
In either case if privacy is really a concern vote to elect politicians that are willing to enact laws that regulate the way companies can use personal data. Though considering both companies and governments benefit from the status quo, I don't foresee things improving in the near future, barring some kind of revolution where the majority wakes up, which is also unlikely. If the Snowden revelations didn't do it, I doubt anything will.
So much for fighting 1984, Apple.
If you're willing to root your device, you can have the best of both the functionality and privacy worlds.
That only applies to motivated and reasonably tech savvy users of course, out of the box iOS is still the better privacy option.
You're confusing iOS with Android. On iOS, every time you get your location, that location is also sent to Apple, and there is no way to disable this. Android's collection of this data is gated by a checkbox that is shown to every user on device setup.
Citation needed.
> I am working with androids even before 1.0, but does this really matter?
It matters if I am claiming that there is no point at which GGP's statement was true, which I am. If I am not, GGP could say that the version of Android he used "last time [he] used Android" did not allow him to disable location collection and that it predates my experience with Android's location settings.
I know I'm going to be called a fanboy or too generous to Apple, but given that the government has used every opportunity to call out Apple for not helping (when they have helped where they could) there is a line here that Apple is tip toeing around.
I also do not think this as bad as you are making it out to be. Apple has always been clear what is fully E2E encrypted and what is not. This article is about something Apple planned to do and decided against. The reasons are what's important and the article only speculates.
The difference between E2E and 'yup we're encrypted!' isn't understood by laypeople. Let's not do ourselves or the average folks out there a disservice by letting Apple off the hook for bad communication and the intentional misleading of users.
The first entry in the table is:
Backup Yes Yes
At a glance this looks, to me, as though iCloud backups are encrypted.
What am I missing?
>iCloud secures your information by encrypting it when it's in transit, storing it in iCloud in an encrypted format, and using secure tokens for authentication. For certain sensitive information, Apple uses end-to-end encryption. This means that only you can access your information, and only on devices where you’re signed into iCloud. No one else, not even Apple, can access end-to-end encrypted information.
Backup Encryption In Transit: Yes
Backup Encryption On Server: Yes
That's no different from me offering a remote backup service on a LUKS encrypted box, using sftp or whatever, and then making those claims.
That's a false dichotomy. I'd say both are true. Both are usually true.
I am not sure Apple made the right move, but.. average person does not seem to care and/or understand the ikplications. Now.. Apple could make them care. They are big enough to make waves and I am not certain goverment could deal with bad PR come election time.
edit: corrected grammar
And it's not remote, and you must connect via USB-C, right?
The current status quo is good enough for the spooks. Zero regulation of data privacy allows third-party aggregators to do the desired collection activities without explicit government involvement. When they want something they know who to ask, warrant optional. Enacting laws that expose what the government is doing would risk a public backlash like the mass mobilization to deploy HTTPS.
- the universe
- human stupidity
- spooks' thirst for more data, backdoors, and monitoring ability
Did we really think that Apple was just so incompetent they could run online file services for 20+ years and have almost a billion users, and not have encryption only because they hadn’t figured it out yet?
I’m turning off iCloud backup — the only reason I have it on actually is to turn off the annoying backup nags. My photos are in iCloud, and so are my messages - I actually can’t think of anything valuable outside of those that I’d actually need iCloud backup for ...
It doesn’t seem worth the risk
I really want the iOS Time Capsule Option. Even if it is expensive.
In this instance, Apple decided to continue to not encrypt iCloud backups because, according to one source,
> […] the company did not want to risk being attacked by public officials for protecting criminals, sued for moving previously accessible data out of reach of government agencies or used as an excuse for new legislation against encryption. [0]
Apple's stance on privacy is more than mere marketing and more than a meme, but their legal team decided that encrypting formerly unencrypted backups, which had already been used as evidence in previous cases, is ill-advised.
Most people, including technically knowledgable users here on HN, were unaware iCloud backups have always been unencrypted. Many of us concerned about privacy have avoided iCloud backups because they are subject to subpoena.
I wish Apple would (have) offered encrypted iCloud backup as an option, and I understand why they chose not to. However, I disagree that their stance on privacy is mere marketing. Apple has a balance to strike between the issues of encryption, privacy, and law enforcement, and their products are not perfect for either users or law enforcement.
That doesn't mean Apple doesn't care about its users and their privacy.
[0] https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...
I believe Apple changed how operating system updates were installed after this point so that they did not have the capability to upgrade the phone's operating system without access to the device passcode.
If Apple is privacy-oriented, they should've allowed this long time ago. Unlike iCloud backups, this is certainly not a legal issue, as the "local" backups stored on one's computer are already fully encrypted.
* My memory says I spent way too much on an iPhone. My ego says that can't be true, and in the end memory yields. -nietzsche
This is cliche as can be, but the trade off is security for convenience.
Fact is, iOS is consumed largely by people who want convenience. They don’t want to lose all of their data if they forget their passwords.
But for those people who are ok with that type of unforgiving paradigm, then don’t use iCloud backups, and you’re all set.
I see this in the thread. What does that mean? Do they have to? Are they being forced? What is the balance between?
Why aren't iCloud backups e2e encrypted?
>Starting in Android Pie, devices can take advantage of a new capability where backed-up application data can only be decrypted by a key that is randomly generated at the client. This decryption key is encrypted using the user's lockscreen PIN/pattern/passcode, which isn’t known by Google.
>By design, this means that no one (including Google) can access a user's backed-up application data without specifically knowing their passcode.
https://security.googleblog.com/2018/10/google-and-android-h...
iCloud backups are definitely encrypted. They just aren't end-to-end encrypted.
That should have been plainly obvious to any technically knowledgeable user because you don't lose your data forever when you forget your Apple ID password. Or the fact that you can see your photos through a web browser on icloud.com
But when you send a backup, it's decrypted, sent to Apple, and then re-encrypted with a key that Apple controls, and has nothing to do with any of the "things I personally know"? IOW, I couldn't myself decrypt my Apple backup stored on their servers?
My phone, my data.
Back up my data to their computer, their control.
This is perfect plausible deniability for them.
"Hey, we gave them a secure device. But they chose to upload their data to us, and we made it clear how we handle it in our terms of service."
Which it is.
As you can see from this discussion, there are a lot of technically knowledgeable people who did not find this "plainly obvious". It's disingenuous to blame users for Apple's misleading marketing.
You could build a system where there's a key stored on each of your devices, and your password also acts like a key. In that case, you could
- Lose all your devices, but unlock with password
- Forget your password, but unlock with any device
- Lose one device, but unlock with your password or any other device
Of course, most people's passwords would probably be way to weak, no matter how much time Apple spends stretching it into a key, but for people who use a decent password this would be fairly secure.
No, they do not. If Apple wants a reputation for privacy and respecting its customers, then it has to put them first. Don't apologize for them making this user-hostile choice.
We could be merely a generation away from the hell hole that is social credit. We can't afford to keep ceding ground on privacy. We have to engender a sense of importance and urgency.
I'll be very mad at the rest of you lot that choose convenience over privacy, rights, and autonomy if 2030 sees our freedoms and liberties eroded further.
Our collective choices matter, and that's why I'm calling you out.
"or used as an excuse for new legislation against encryption."
By not making iCloud backups end-to-end encrypted, they likely did exactly that.
Although I'd find it funny if by doing so they caused a backlash from governments with new laws that ruined encryption for everybody. It'd be dystopian but also funny.
I fear we have one foot there already. If you are so inclined, you can dig up a lot of dox on most people, all freely given to social media, or via scrapers like Spokeo.
I guess it's all still optional, kinda. And there is no centralized clearinghouse. But it is scary.
2. Apple at least put some effort into this matter because otherwise there would not be so much media attention to breaking into iPhones. To get data from android on the other hand seems to be no problem at all.
3. We are already in hell but we do not yet see the flames surrounding us.
4. If collective choice matters so much we are all doomed and you know it. Try telling the Joneses about encryption etc. - they will still use WhastApp, Facebook and the likes because it is so convenient over a way of burden and hard work to get there or even live without all these "magical devices and services".
We have to comply with court orders. That’s it.
The funny thing is that I just read a bit of the linked Wikipedia article to find this: Companies and organizations who no longer have warrant canaries
The following is a list of companies and organizations whose warrant canaries no longer appear in transparency reports:
* Apple
* Reddit
* Silent Circle
[0]: https://en.wikipedia.org/wiki/Warrant_canaryThat is something very different from cooperating with a specific investigation.
Why did Apple not fight this in court?
Could Apple keep the backups outside the EU, like Microsoft did for email in the Dublin case?
But it is not about prohibiting encryption but the possibility and/or necessity that Apple has another key to decrypt your data with.
It does not matter where they keep the data as long as the companies headquarters are on US soil.
Google gives their customers the option for end-to-end encryption of uploaded data and I'm sure they have to play by the same rules as Apple.
Now this does not exactly help me feeling more comfortably about this issue.
> Our collective choices matter, and that's why I'm calling you out.
I'll be direct and say that your passion inspires me and your articulation of the issue is very close to my deep feelings about privacy, encryption, and law enforcement. Of course, human brains are complicated pieces of kit and the rational part of me tempers "my deep feelings" with the context I elaborated in the parent comment.
Still, I wanted to take the time to thank you for expressing this in precisely the way you did. Thank you.
I also want to take a moment to recommend an article by John Gruber (Daring Fireball), "Regarding Reuters’s Report That Apple Dropped Plan for Encrypting iCloud Backups" which critiques the basis of the Reuter's article. [0] (I'd have made it a post except for being a bit overactive this morning with submitting Daring Fireball-sourced links to HN.)
You might feel less disillusioned considering Gruber's points, many of which are excellent.
[0] https://daringfireball.net/2020/01/reuters_report_on_apple_d...
Just plug your phone, click "Backup up". You don't even have to open iTunes anymore, just open "Finder" window. Can't be easier than that.
Seafile is end-to-end encrypted and open core. They offer a managed hosting option, and you can also self-host.
https://github.com/haiwen/seafile
Nextcloud is working on end-to-end encryption, but the feature is not yet stable. It is fully open source.
This is false. You can back it up with Finder (since Catalina) or iTunes on Windows or previous macOS versions. You can even do wireless syncing over your local network.
All of the infrastructure that Apple built out before iCloud still exists. You can sync your photos with the Photos app locally. It’ll one-click import everything and you can have it automatically clear out storage on your phone after the import has completed as well. You can then back up your computer however you want - locally, encrypted with Time Machine is an easy option.
I had somehow assumed that iCloud backups could not be accessed by Apple.
So that pretty much kills the meme for me.
Except plugging it into a PC or Mac with iTunes, toggle a checkbox and set a password. No, it's not effortless, but it's not bad and it's not difficult
I interpret this opinion as Black/White thinking or all-or-nothing thinking: https://en.wikipedia.org/wiki/Splitting_(psychology)
THIS is why open source matters. The government can't control people when money isn't what motivates them.
of course, there is. You can easily back it up to your computer, and then transfer it to anywhere else.
iCloud backups always were encrypted based on a key derived from your iCloud account credentials, since the beginning...
Edit: or since it is "derived" and not really password which is used for encryption -- the derived thing could well be the hashed password. We are doomed. They might as well serial number their user and use that as key then. Never mind.
Does that clear it up at all?
FYI these concepts are originated from military crypto. The foundations are solid. Implementation... well you know how that always is.... one CVE away from perfect!!
But of course, we are talking about local backups so if you have full-disk encryption or back them up to an encrypted virtual drive, you don't even need whatever encryption comes with them.
First party backups from Apple (iCloud/iTunes) restore a perfect replica of the phone, including app icon locations, arrangement, notifications, offloaded storage etc. I'm honestly skeptical that anyone else would be able to pull that off.
Yes, Apple has private APIs that it uses for its monopoly abuse benefit. That is why Apple's "Music" app can't be deleted from your computer ("'Music.app' can’t be modified or deleted because it’s required by macOS.") but Spotify can be deleted.
The solution is for Spotify to sue them on this specific issue and for other people to sue them similarly.
Optionally encrypted: https://support.apple.com/sl-si/HT205220
FileVault too is optional: https://support.apple.com/en-us/HT204837
As Mark Zuckerberg once opined: “They ‘trust’ me. Those dumbfucks.”
https://www.businessinsider.com/embarrassing-and-damaging-zu...
And it’s not just mere words, here is he actually set up a honeypot site to get people’s passwords and break into their emails to satisfy his burning curiosity when he first launched Facebook:
https://www.businessinsider.com/how-mark-zuckerberg-hacked-i...
Instead, he decided to access the email accounts of Crimson editors and review their emails. How did he do this? Here's how Mark described his hack to a friend:
Mark used his site, TheFacebook.com, to look up members of the site who identified themselves as members of the Crimson. Then he examined a log of failed logins to see if any of the Crimson members had ever entered an incorrect password into TheFacebook.com. If the cases in which they had entered failed logins, Mark tried to use them to access the Crimson members' Harvard email accounts. He successfully accessed two of them.
In other words, Mark appears to have used private login data from TheFacebook to hack into the separate email accounts of some TheFacebook users.
In a world where we are sending our Alexa data to “the cloud” and the companies are admitting people are listening to it, in a world where Facebook secretly records everything it can, why would you assume your password isn’t being sent?
To the downvoters... you may say that this was only when Mark Z was a young man and now Facebook the company is far more responsible. But then we have this from just a few months ago:
https://www.independent.co.uk/life-style/gadgets-and-tech/ne...
I can understand trusting a browser or a software release that can be tested by many people, and was signed with a checksum. But a website and all your extensions on every website?? Those can ship new code at any time.
(Am I wrong? Any counter-arguments?)
Also, all your photos and notes and email and other stuff in iCloud are available to Apple (and by extension the FBI et al) as well. Even Apple CSRs have a ton of access to the contents of a lot of iCloud services.
The situation is a lot better if you have all recent devices and 2FA turned on, then it can use iCloud Keychain for some stuff which is trust-circle based. You can read more in Apple’s latest platform security doc released late last year.
The borg website is here:
https://borgbackup.readthedocs.io/en/stable/
and a good description of how it works and why you should use it is here:
For linux servers, borg is great, and me and my companies are happy users.
Rclone simply copies data. If you `sync` `~/Documents` to your remote it will keep an exact copy.
This is a simple backup since you only have one version. Anything deleted, the next time it syncs, gets deleted.
Borg is a backup tool. Versioning is at its core. It does that efficiently by deduplicating file (chunks really) even if they’re not in the same location.
So with Borg, if you create a backup 1 of `~/Documents` today and a backup 2 tomorrow of `~/Documents` you can see both backups and work with each snapshot. The size it takes should be close to the amount of data changed in the whole source.
If you move directories or files inside, rclone has to reupload them. Borg detects but doesn’t have to store it again.
With rclone some remotes have versioning (Google Drive, Dropbox). This could help in this case, but it depends on the remote. With Borg this is built in and you can change the underlying storage and migrate without loosing any data. Using versioning with crypt would probably be a pain too due to the file names. Not sure if rclone has commands/flags to help with this that I simply don’t know about.
...
"This is a simple backup since you only have one version. Anything deleted, the next time it syncs, gets deleted."
This is correct. It is widely advised to not consider a "sync" like this a proper backup.
However, for what it's worth, rsync.net does support rclone[1] and because of the ZFS snapshots that are created and maintained[2] in your account, you can just do a dumb sync because the retention is handled by the snapshots.
I am not sure if rclone is really the right tool for plain old cloud backups - I think rclone distinguishes itself for the ability to transfer data between cloud providers.[3]
[1] https://rsync.net/products/rclone.html
[2] ZFS snapshots reside in the .zfs/snapshot directory inside your rsync.net account.
[3] ssh user@rsync.net rclone file/in/rsync/net/account s3:/some/bucket
One thing that irks me about these solutions is that they seem to scan my folders each time they want to backup. Are there tools that are smarter about this? For e.g., while running, they could keep a log of what's changing and only scan those while backing up.
I've found arq backup overall slow once you start hitting 0.5TB overall. It's a design issue.
I believe most operating systems have a mechanism for this. E.g. on macOS it's called fsevents, Linux has inotify
I may have looked at Duplicacy. I'm sure that I looked at one of Duplicacy [1], Duplicati [2], and Duplicity [3]. Whichever one that was, I kept getting it mixed up with the other two when looking for information online, and finally said "screw this" and bought Arq.
I've used it on my macs for years without any issues at all. I switched after Time Machine broke down for the n'th time in a month saying it needed to recreate the backup, and not once in the 3-5 years i've been using it has it every given me any problems with broken repositories, and every integrity check/restore has succeeded.
Arq on Windows is a different beast though. I'm sure it's technically solid, but the UI leaves a lot to be desired. On windows boxes i default to Duplicaty.
Did you mean Duplicacy or Duplicati?
On my servers i use Borg like any sane person would, but the lack of a good client UI makes scheduling backups on a personal computer a lot more work than i'm willing to put in.
Quickly looking at Borg's website (thanks for the heads up - great tool/option) I see it doesn't support iOS or backing up an iOS device.
I assume you're just suggesting it as a general purpose option for general backups on the desktop?
I wonder how efficient Borg would be with this setup.
What did suck on Apple's part was that they wouldn't allow you to disconnect the actually end-to-end encrypted iMessages from the iCloud backups for many years.
So since most people kept their iCloud enabled, that meant their "iMessage end-to-end encryption" was nothing of the sort, as all messages had a copy that Apple could read on its servers.
I actually don't know if this is still true since I haven't used an iPhone in some time, but I sure hope it isn't anymore.
I don't think the general public would understand end-to-end encrypted backups. It would probably hurt their company if all backups were totally unrecoverable.
I imagine you're right; it would still be nice for individuals and organizations to have the _option_ though.
You can’t even turn off the backup password on an existing device for a new backup without knowing the old password (protecting against Evil Maid problem).
I’ve had to reset a device when I forgot my local iPhone backup password to get it back to unencrypted backups.
I had in mind an e2e encrypted backup on Apple's servers, which would be far more convenient than doing it locally. That's all.
> More than two years ago, Apple told the FBI that it planned to offer users end-to-end encryption when storing their phone data on iCloud, according to one current and three former FBI officials and one current and one former Apple employee.
> Under that plan, primarily designed to thwart hackers, Apple would no longer have a key to unlock the encrypted data, meaning it would not be able to turn material over to authorities in a readable form even under court order.
https://www.alexa.com/siteinfo/mega.nz
https://play.google.com/store/apps/details?id=mega.privacy.a...
Well, you can choose not to use iCloud for that reason (as some of us do).
A bigger problem is that Apple deliberately locks up iDevices so it's hard to get your data off them using only local means, particularly if you don't also want to buy an Apple laptop just to do it.
Let me know when iPhones and iPads support standard plug and play protocols that work universally without relying on either Apple's proprietary and frequently broken software or someone else's commercial alternative that attempts to do what Apple should have been doing all along.
iTunes hasn’t worked well on any platform in over a decade.
What other devices perform all of the backup, restore, and os upgrade, functionality of iTunes.
The iPhone doesn’t use the standard “usb mass storage” protocol to allow you to download pictures. It uses the picture transfer protocol.
I've never claimed anything about any other functions of iTunes. I just said it was a problem that Apple devices make it difficult to get your data off using only local transfer.
The iPhone doesn’t use the standard “usb mass storage” protocol to allow you to download pictures. It uses the picture transfer protocol.
Yes, exactly like your camera, as I said.
We already have a good, properly secured backup system that we use for all our workstations and servers. We just want to be able to export data from any mobile devices we use and manage that data using the same policies and tools. In most cases, that is straightforward. The one big exception is the iOS devices.
And this is the same myopic geek viewpoint that came out with the iPod “Less space than the Nomad. No wireless lame.”
Do you actually believe that most people have a good backup solution at all? Is that really what you are suggesting for a general backup solution?
That’s just like when DropBox was introduced and people on HN came up with a convoluted Rube Goldberg solution that they could do themselves.
I'm saying that iCloud isn't properly encrypted, which for some people and organisations will be a problem, and that it is then a greater problem for those people and organisations that it is unusually difficult to transfer data between iOS devices and other systems through other means because of the inhibiting choices that Apple has made.
It's much like the argument that the default behaviour for consumer software should normally be to install security updates automatically, but installation of updates should still be configurable for those who do know what they're doing and need more control over their systems.
I doubt many businesses are using iWorks with iCloud.
But this makes me wonder if they have our local boxes totally owned already which is why the local encrypt feature would not hamper investigations?
https://techcrunch.com/2018/07/17/apples-icloud-user-data-in...
To answer your question directly. TLS encryption from your phone to apple's servers means they terminate encryption at the other end when they receive your data. This means "they decrypt the information that was in transit". Then they explicitly apply another encryption to the received and decrypted data before storing it on disk. Since these are two separate steps, you have no protection what-so-ever since apple will have a registry of all decryption keys for the disk backups that they'll happily use for whatever reason when they want to get hold of your data.
The only thing their disk encryption protects against is if someone were to walk away with the physical disks. It protects squat against the threats customers actually care about (unauthorized access to the data by someone other than the customer owning that data).
And seeing as they run on AWS, physical security means that the only way metal leaves the data center is if it's in millimeter sized shredded metal grain. So the threat model of concern here is exactly what apple has decided not to provide customers any protection against.
So claims of "encryption" are meaningless.
Instead, claims of "only X, Y and Z could access to this" are meaningful.
"Could" is a strong word because it includes unforeseen circumstances such as writs and court orders.
~/Library/Application Support/MobileSync/Backup
I was thinking of creating a symlink to Dropbox, for instance and having my cloud backup there. I don't know if the backups are incremental which could be a storage problem, but that can be managed through some scripting.Since we hold the key it's a blob nobody can get to without brute forcing it.
These are end to end:
Home data
Health data (requires iOS 12 or later)
iCloud Keychain (includes all of your saved accounts and passwords)
Payment information
QuickType Keyboard learned vocabulary (requires iOS 11 or later)
Screen Time
Siri information
Wi-Fi passwords
The messages also end to end but the backup contains the private key.
The moral of the story is that if you want real protection, do local backups.
Should this even be called E2E? I suppose it is, technically, but clearly not in spirit.
It can also read iCloud backups of conversation content, which are created by the client device after decrypting the message. But that's not the same as storing the private key itself in the backup.
Happy to have my understanding updated...
There’s no way to accomplish this without having the private key in the backup.
EDIT: When I say there is no way to accomplish this, I’m talking specifically about the process that exists today where the user doesn’t have to remember a password other than their iCloud password (which today, can also be reset).
Uh, no. There's no way to accomplish that without some kind of user-managed escrow (even a pass phrase would be fine). It's maybe not the seamless experience Apple wants to offer, but it's certainly not impossible.
Frankly the kind of dummyproof restore being offered is fundamentally incompatible with private backups.
1) To send you a new iMessage, someone else's iPhone Z encrypts it with your public key and sends it through the iMessage network. Apple can't read this message since they don't have your iMessage private key, which is only on your device.
2) Your iPhone A receives the encrypted iMessages and decrypts them with your iMessage private key on your device.
3) iPhone A stores the decrypted iMessage content in its filesystem, which is encrypted locally with the device private key (derived from your device passcode).
4) Time to backup... iPhone A decrypts its filesystem with your device private key, and sends filesystem contents as plaintext, through an encrypted tunnel, to an iCloud backup server, which encrypts the backup locally with an iCloud server private key, and stores it.
5) You get a new iPhone, let's call it iPhone B. iPhone B asks iCloud for a restore. The iCloud server locally decrypts the backup, and sends it to iPhone B as plaintext through an encrypted tunnel. iPhone B receives the backup as plaintext and stores it locally, encrypting it locally with the device private key.
6) iPhone B iMessage client loads the plaintext old iMessages into the Messages client for you to read.
At no point in this process would Apple have or store your iMessage private key or your device private key.
Example policies from the Secure Enclave would be that a private key is available on first unlock, only while unlocked, only while a PIN is set, and/or whether the key should be shared with other trusted devices.
The base filesystem is encrypted with a key released on boot, while individual files can be encrypted with some set of these policies. I believe this can be done either on individual files in an app's data, or as an entitlement to apply by default to the entire app. https://developer.apple.com/documentation/bundleresources/en...
My understanding is that files set with a policy that they are only available while the device is unlocked will still be backed up in the locally encrypted form. So, assuming Signal/WhatsApp/etc set a single flag their data is stored encrypted in iCloud.
Further, per your list I suspect that the backup data is sent to/from iCloud already encrypted by a secret - but that secret is shared with iCloud for recovery and shared further on official government request. The goal there is to limit the amount of unencrypted user data sent to third party servers (in this case in the US I believe Azure-hosted storage for backups).
The keys are separately stored on Apple-controlled servers in non-China countries. In China, I believe they were required by law to have the key storage instead hosted by a Chinese data center.
Your messages are returned via the backup, not via the "iMessage servers". Once the messages are at rest on your device, they're no longer encrypted using your "iMessage private key".
> Messages in iCloud also uses end-to-end encryption. If you have iCloud Backup turned on, your backup includes a copy of the key protecting your Messages. This ensures you can recover your Messages if you lose access to iCloud Keychain and your trusted devices. When you turn off iCloud Backup, a new key is generated on your device to protect future messages and isn't stored by Apple.
But wait does it mean that if you haven't iCloud backup activated but use local backup you can actually sync message without storing private key... the wording here is important would be nice if someone clarify.
iMessage doesn’t use the backup for syncing. If you want to sync then both devices need to be logged into your account.
You can turn off iCloud backup for messages (with or without a local backup).
Maybe the concept is the same, but on a Mac the private key is stored in the Keychain instead of a physical enclave?
Invariably such features are weak and a sufficiently capable attacker can override them. In Windows for example you could reach into the opaque data structure and toggle the Boolean that forbids exporting keys...
I think a better way to look at what they're selling you is a device that provides you pretty-to-very good protection from casual hacking and theft. But in the event of a government knocking on their door for more information, they'll quietly hand over what they can which probably is quite a bit more than the average consumer thinks it is. All bets are off as to what the full story is when the government/jurisdiction involved is not the United States.
NOTE: Logging in via the SpiderOak website does temporarily allow SpiderOak employees access to your password.
https://spideroak.support/hc/en-us/articles/115001854583-ONE...
Apple could (have) issue(d) an update with code to steal yr anything, without you knowing, so FBI-or-whatever does not "complain".
I currently use one e2e service, BitWarden as keychain, that ticks the boxes (e2e AND open source client).
/s
Even so I agree that examining all hardware in that manner is impractical. A better approach might be having a small, simpler core of secure open-source hardware managing your root of trust, and trying our best to mitigate the impact of compromises in the more complicated components (like the motherboard, CPU, etc) with approaches such as requiring open source firmware, sandboxing individual components by filtering their external communications through open hardware, and limiting their access to sensitive data like encryption keys. Obviously there's only so far you can go with that, but I don't think it's an entirely hopeless battle either.
It's a very interesting problem for sure.
How do you trust the person that verifies the CPU? Can you trust the X-Ray imaging machine? Is the X-Ray Machine verified to be open source and not backdoored to hide backdoors (aka bootstrapping trust).
You can hash the source code and verify that what you have is the same that the developer shipped.
There is no hash function for hardware.
IMO if you're at the point where you believe you can't trust multiple decentralized, independent, multi-jurisdictional bodies all telling you the same thing: that the hardware they've tested matches the published design, you've reached a level of paranoia where no amount of reassurance, technological or otherwise, will satisfy you.
I suppose if you really wanted to you could build your own X-Ray machine from scratch and check the design yourself. That's probably not much more difficult than going line-by-line and manually verifying the source code of your entire software tool chain because you don't trust anyone else who's read the source code enough to believe them when they tell you they've already verified that everything looks correct and that your text editor probably isn't lying to you about the contents of your source files. Which is to say probably totally impractical, but again, that's kinda my point.
While I'm not saying maintainers & users are checking all changes in packages, all the work happens in the open & all the source is compiled on distro infrastructure.
So once you actually do an atack like this and it is discovered, you can be sure anything done by the maintainer will be combed with a very fine brush & the account disabled.
Given that it can take years to build the trust needed to become mainatiner of an important package, only to loose it all once you atack is known, I really can't see this used for anythin else than very targetted high stakes attack omce off attack, definitelly not for any long term dragnet surveilance.
1) There is no way Apple would be allowed to sell iPhones in China, without China government having access to anything. So, I assume that Apple users in China have e2e encrypted exactly nothing.
2) I have a strong suspicion that those 'enter your Apple ID password because your account needs it' message really means 'a government has requested your data and even though it's encrypted, we will nag you about entering a password, and if you give it, you're a free game'.
I don't blame Apple for this, I'm sure they're doing what they can, but when a government says 'give us this data', they can't not comply. Vote responsibly - companies can't protect us from a government we have put into power.
> Chinese users of Apple’s iCloud service will see their data–along with that data’s cryptographic keys–stored inside the country beginning Wednesday, Reuters reports. The move will mean that Chinese authorities will have easier access to Chinese users’ iCloud data than before when that data was stored in the U.S. The move is a contentious one, as human rights activists say Chinese authorities will now have an easier means of obtaining dissidents data since it no longer needs to go through the U.S. legal system to get Apple to hand over its cryptographic keys for Chinese users.
https://www.fastcompany.com/40535933/apple-will-store-icloud...
Haha I hadn’t thought of that. If true, I must have every government requesting my data frequently as I constantly get bombarded to enter my iCloud password.
That’s just for domestic surveillance keep in mind.
By the way, the source below is an official Chinese government media source.
[1] http://www.xinhuanet.com/english/2019-10/26/c_138505655.htm
If your boss asks you to build a machine that produces a widget, does he really care what your code looks like? Probably not. In the same vein, Apple can figure out whatever solution they want, whether it involves conventional use of encryption keys or not, to provide a system where the Chinese government can get access to their users' data.
It's really not that hard.
> Meanwhile, Chinese laws do not protect internet users’ privacy from government intrusion. In 2015, China passed a National Security Law, which included a provision to give police the authority to demand companies let them bypass encryption or other security tools to access personal data. The National People’s Congress was not available to comment.
https://www.theverge.com/2018/2/28/17055088/apple-chinese-ic...
Apple says the joint venture does not mean that China has any kind of “backdoor” into user data and that Apple alone – not its Chinese partner – will control the encryption keys. But Chinese customers will notice some differences from the start: their iCloud accounts will now be co-branded with the name of the local partner, a first for Apple.
> Apple said it will only respond to valid legal requests in China, but China’s domestic legal process is very different than that in the U.S., lacking anything quite like an American “warrant” reviewed by an independent court, Chinese legal experts said. Court approval isn’t required under Chinese law and police can issue and execute warrants.
https://www.reuters.com/article/us-china-apple-icloud-insigh...
> That means Chinese authorities will no longer have to use the U.S. courts to seek information on iCloud users and can instead use their own legal system to ask Apple to hand over iCloud data for Chinese users, legal experts said.
U.S. courts are highly unlikely to order Apple to release iCloud data to Chinese officials. Any cases would be public and attract international media attention. For Chinese iCloud users, that makes all the difference.
Every company in the US has to comply when it’s ordered by the court to give up user data. The US justice system is not exactly a shining light on the hill when it comes to needing a high bar to give investigators search warrants. All someone has to do is say “terrorism”, “drugs” or “protect the children” and courts will fall over backwards.
Also from the same article:
Until now, Apple appears to have handed over very little data about Chinese users. From mid-2013 to mid-2017, Apple said it did not give customer account content to Chinese authorities, despite having received 176 requests, according to transparency reports published by the company. By contrast, Apple has given the United States customer account content in response to 2,366 out of 8,475 government requests.
You have much more faith in the US justice system than I do.
> Until now, Apple appears to have handed over very little data about Chinese users. From mid-2013 to mid-2017, Apple said it did not give customer account content to Chinese authorities, despite having received 176 requests, according to transparency reports published by the company.
By moving iCloud data and keys to China, the amount of data Apple handed to Chinese authorities on Chinese iCloud users went from zero to a nonzero amount. Therefore, Apple degraded the security and privacy of Chinese iCloud users by making the switch to Chinese servers.
Due process is much more frequently ignored in China than in the United States, but that fact isn't even necessary to establish that Apple's switch to Chinese servers negatively affected Chinese iCloud users. The above is sufficient.
https://web.archive.org/web/20111019034145/http://www.law.ya...
>all companies foreign or not must provide unencrypted access to data to the Chinese government and must do so in secrecy
either plainly stated or implied.
Can you provide a source for this claim? I don't doubt that this may occur, but I'd like to speak with _my own_ managers about my china & encryption concerns in an informed way.
[1] http://www.xinhuanet.com/english/2019-10/26/c_138505655.htm
[2]https://www.insideprivacy.com/data-security/china-enacts-enc...
[3]https://thediplomat.com/2019/10/decoding-chinas-cryptography...
[4]https://www.iflr.com/Article/3907570/PRIMER-Chinas-cryptogra...
Edit: Apple itself has stated that the keys are in China. The option of having Apple devices talk through the Great Firewall to servers in the US that then encrypt the data for storage in China (and on the querying end, request encrypted data from China to decrypt and process in the US to serve back to devices through the Great Firewall) that Apple apologists wishfully theorize is every bit as ridiculous as it sounds. https://www.reuters.com/article/china-apple-icloud/rpt-insig...
If you want to change the subject and talk about iMessage instead of iCloud, the architecture of that system allows for the government to intercept all messages as well. https://www.wired.com/2015/09/apple-fighting-privacy-imessag...
I no more trust my privacy to the US government than a Chinese citizen should trust China.
You started this thread by responding to somebody discussing the Chinese government's access to all iCloud data, but you changed the subject to talk about systems where the private key is on device, which does not apply to iCloud. You absolutely did change the subject.
> Those same standards apply in the US and China - unless you have evidence otherwise.
Those same standards don't actually protect your data from whoever controls the iCloud server or whoever controls the iMessage key server. In the US, that is Apple, so Apple has access to that data. In China, that is the Chinese government. Therefore, the Chinese government has access to all Chinese iCloud and iMessage data.
> I no more trust my privacy to the US government than a Chinese citizen should trust China.
Then you are unfamiliar with the laws of both countries.
If some of the data is e2e encrypted using private keys,China doesn’t have access to “all data”
Those same standards don't actually protect your data from whoever controls the iCloud server or whoever controls the iMessage key server.
If the private key is generated by the same entity or “key server” that generates the public key, and then transmitted to the client. That kind of defeats the entire purpose of public/private key encryption.
I’ve never seen an implementation of public/private key encryption where the client device doesn’t create the key pair and send only the public key to encrypt data.
You have two mistakes in this sentence.
1. None of the iCloud data (mail, docs, drive, etc.) is E2E encrypted. Some of the data stored in iCloud (like keychain backups) is encrypted prior to being sent to iCloud (using symmetric encryption, not with asymmetric key pairs). China has access to the data that was ultimately sent to iCloud.
2. The way Apple implements E2E encryption for services like iMessage that are E2E encrypted allows China access to that data.
> If the private key is generated by the same entity or “key server” that generates the public key, and then transmitted to the client.
That's the point. Since Apple's implementation relies on a key server to distribute public keys, it is straightforward for the key server to generate its own key pair and serve a fraudulent public key to the recipient, decrypting and re-encrypting messages that the iMessage servers relay. Apple relies on the technical illiteracy of its users to get away with its deceptive and often plain false marketing claims. Now you know better.
But after reading research from security experts you have found a citation where Apple is generating a key pair from its servers and sending the private key to the client?
That's the point. It should not, but the security model of iMessage allows the key server to get away with it, which is almost certainly happening in China right now. Try reading the article and following the example.
> But after reading research from security experts you have found a citation where Apple is generating a key pair from its servers and sending the private key to the client?
No, it sends the public key. Encrypting messages is done with the recipient's public key. Go read the Wikipedia article on asymmetric encryption. Because the owner of the keyserver can send its own public key, it can decrypt messages with its own private key before re-encrypting with the intended recipient's public key.
But since it’s in a Wikipedia article, I guess that kind of closes the case.
You once again misunderstand the vulnerability. The vulnerability is that China does this because China controls the keyservers in China.
As far as anybody discovering this, that would be very difficult because Apple does not let you install your own apps on the device and would not approve an app designed to detect this.
But even more, why would they bother? People who care about their privacy will simply avoid closed source software and especially closed systems like Apple's instead of trying to use a known compromisable system safely.
>But since it’s in a Wikipedia article, I guess that kind of closes the case.
I was pointing you to a place where you could learn about cryptography because you seem not to understand the basic concepts. The Wikipedia article does not describe this particular vulnerability.
Seeing as how Apple complies with FBI and law enforcement requests to get iCloud data, that is definitely not the case in the US.
These warrants become public record. I don't have to blindly believe it. I can look at the records and see that the US is not even close to China as far as government access to user data.
Unless the government screams “terrorism”. Ever heard of a FISA warrant?
https://www.ajc.com/news/national/what-fisa-warrant/WqP428Eg...
https://observer.com/2018/03/apple-grants-china-full-control...
> "The simple fact is that once the encryption keys are stored on Chinese servers, they will be easier for Chinese authorities to access — with or without legal requests," says Sharon Hom, executive director of Human Rights in China, a US-based NGO. "Since Apple has declared its willingness to 'comply with Chinese law,' its reassurance that it, not its Chinese partner, would control the encryption keys is not exactly reassuring. In addition, Chinese authorities could bypass Apple to address their requests directly to Apple’s Chinese partner, a state-owned enterprise that, of course, would have to cooperate with Chinese authorities."
https://www.wired.co.uk/article/apple-icloud-china-iphone-da...
The libertarian party surely would but most people don't even know it exists, i would guess.
E2E works exactly the same in China. You can read more in my comments here:
https://news.ycombinator.com/item?id=20904857
The same "vulnerability" of being able to respond to legal requests for iCloud data that exists in China exists everywhere else in the world.
The fact is that Apple has said multiple times (and even under oath) that end-to-end encryption applies to iPhones and iMessage in China, the same as it does everywhere else.
And once again Erik Neuenschwander, an Apple privacy exec, told Congress in a hearing in December that this was still the case.
At 02:10:46
https://www.judiciary.senate.gov/meetings/encryption-and-law...
I think instead of researching how Apple works in China, you need to start doing some research on how the Chinese government works and their track record on legal matters and rule of law.
Also, the segment in the Senate hearing you referenced shows a senator who obviously does not have a good grasp on encryption technology asking bumbling questions about encryption. I have paraphrased the section here:
> Senator: Do you sell phones in China? Are they encrypted? > Apple: The phones are the same and all of our phones are encrypted across the world
Yes, obviously all phones have encryption but the Senator did not clarify what was being encrypted here and Apple took advantage of this in the response.
> Senator: You're telling me that they [China] allows you to sell devices without you allowing them to breach the encryption and gain information about the users? > Apple: You're 100% correct
Once again, the question posed was incoherent. Of course there is no "breaching of encryption" here - the Chinese government just asks for the keys or the data. It's all about language here.
If this Senate hearing is your case for why data is safe in China, I honestly fear for all the political and religious dissidents that are trusting Apple for their safety.
> The same "vulnerability" of being able to respond to legal requests for iCloud data that exists in China exists everywhere else in the world.
And an article on Apple's site [1] confirms that most data in the cloud are "encrypted", but without E2E encryption, possibly in a reversible way. That article also notes that while messages are E2E encrypted, a cloud backup might contain a key to decrypt them:
> Messages in iCloud also uses end-to-end encryption. If you have iCloud Backup turned on, your backup includes a copy of the key protecting your Messages. This ensures you can recover your Messages if you lose access to iCloud Keychain and your trusted devices.
So it is possible that the data on the phone are encrypted, the data in transit are encrypted, the data in the cloud are encrypted for every user in the world, but the cloud operator has the encryption keys for some of the encrypted data: Chinese operator for data of Chinese users and Apple for everyone else. This doesn't contradict neither with Apple's statement nor with the article nor with that comment above.
> The U.S. company is moving iCloud accounts registered in mainland China to state-run Chinese servers on Wednesday along with the digital keys needed to unlock them.
> In the past, if Chinese authorities wanted to access Apple's user data, they had to go through an international legal process and comply with U.S. laws on user rights, according to Ronald Deibert, director of the University of Toronto's Citizen Lab, which studies the intersection of digital policy and human rights.
> "They will no longer have to do so if iCloud and cryptographic keys are located in China's jurisdiction," he told CNNMoney.
https://money.cnn.com/2018/02/28/technology/apple-icloud-dat...
As for the End-to-End encryption of iMessage it is a bit overrated. Apple does the key management for you. So theoretically they could pretend that the key of your interlocutor recently changed (because new phone or something), it would just work transparently. So if a "nefarious" entity were to gain access to iMessage servers, they could use that technique to decrypt, "on the fly", the messages of whoever they want to spy on, without the clients knowing that this even occurred.
When you use "WhatsApp" you have the ability to get some kind of warning when the interlocutor's key has been updated. It's also possible to check each others' identity by scanning some kind of QR Code. But the app does not really put any emphasis on which accounts have been verified. Signal is about as bad as WhatsApp. My guess a government that wants to spy on your WhatsApp/Signal messages probably could, because most people would notice the key change warning nor understand what it means.
Only Apps which makes a big fuss about key management (Threema for example) are properly End to End encrypted, with no possibility for Big Gov to hack into servers and spy on you by adding their keys to conversations. But then they would probably just hack the OS on your phone at this stage. In fact that method, is probably better than messing around with iMessage/WhatsApp servers. You bypass ALL forms E2E encryption, and you get access to everything else, with one swift hack. I bet the NSA and their Chinese equivalents have such hacks in reserve for very juicy targets they want to spy on.
With the kind of unlimited budget the NSA has, it's hard to imagine something they cannot hack. That is why big A-list targets like Bin Laden went totally off-grid for communication.
But.. the electoral college.
Yes, this is unfortunately true and unfortunately complicated compared to iCloud backups.
I backup locally to my mac (encrypted), then I have my mac do time machine backups to my Synology NAS (encrypted) and then I have my NAS backup to BackBlaze (encrypted). I do that to satisfy the two pronged backup strategy: local (fast) and remote (slow, but useful in catastrophic local situations such as fire, flood, theft, etc).
Yes exactly, this is what I'm using. There is a time machine folder on the NAS, the Synology tool mirrors that encrypted folder to backblaze. I have the backblaze sync set to run at 1am so it's not uploading and affecting my bandwidth while I'm (typically) awake. Yes, my remote backup is up to 24 hours behind my local time machine backup, but this is acceptable to me since it's only for catastrophic recovery.
[0]: https://www.theinquirer.net/inquirer/news/3061660/whatsapp-i...
Put yourself in their shoes. These companies stand to lose tens or perhaps hundreds of billions of dollars in foreign sales if there isn’t a counter-narrative to “well of course they spy for their national military, just look at these Snowden slides”. Making it seem like they are fighting for their customers at odds with the FBI is a perfect counterpoint.
Meanwhile, it’s business as usual for US military intelligence, as evidenced by TFA. Excellent reporting!
Apple and Microsoft both tried to build ad businesses, but when they weren't as successful as Google, they turned lemons into lemonade by launching data privacy PR campaigns against Google.
Meanwhile, Apple and Microsoft quietly censor their products in China, surrender data to Chinese authorities, and now we find Apple is intentionally leaving iCloud data insecure.
Presumably Google was under the same pressure from US law enforcement, but somehow Google delivered end-to-end encrypted Android backups in October, 2018. And Google did it without all of Apple's self-congratulatory media hoopla.
e2ee: https://security.googleblog.com/2018/10/google-and-android-h...
Third party security audit: https://www.nccgroup.trust/us/our-research/android-cloud-bac...
It would be nice if Apple was more forthcoming with that fact but there is some onus on the customer these days to understand what's private and what is not.
https://support.apple.com/en-us/HT202303
iCloud backups are not on the list of end-to-end encrypted.
If “backup”, photos, messages, contacts, calendars, iCloud Drive, notes, and safari data (and a few more) are end-to-end encrypted what else is there?
The list of E2E is further down, separate from the table, and includes: Home data, Health data (requires iOS 12 or later), iCloud Keychain (includes all of your saved accounts and passwords), payment information, QuickType Keyboard learned vocabulary (requires iOS 11 or later), Screen Time, Siri information, and Wi-Fi passwords. So virtually nothing, by comparison.
Messages, probably the most personal and relevant for legal cases, are end-to-end-encrypted as well, but if you have iCloud Backup enabled, the key is stored in the backup, making this useless.
“For certain sensitive information, Apple uses end-to-end encryption.”
“These features and their data are transmitted and stored in iCloud using end-to-end encryption:”
* Home data
* Health data (requires iOS 12 or later)
* iCloud Keychain (includes all of your saved accounts and passwords)
* Payment information
* QuickType Keyboard learned vocabulary (requires iOS 11 or later)
* Screen Time
* Siri information
* Wi-Fi passwords
Apple will store some iCloud encryption keys in China, raising security concerns https://www.theverge.com/2018/2/26/17052802/apple-icloud-enc...
> Injustice anywhere is a threat to justice everywhere.
So I 100% agree.
I didn't say that Apple is right to do it in China or elsewhere. I merely pointed out that it's happening in one place and asked why that would make it moot elsewhere. I agree with everything you said except for the phrasing of your first sentence.
Apple says the joint venture does not mean that China has any kind of “backdoor” into user data and that Apple alone – not its Chinese partner – will control the encryption keys.
"iCloud services and all the data you store with iCloud, including photos, videos, documents, and backups, will be subject to the new terms and conditions of iCloud operated by GCBD."
And since all Chinese companies are bound by local laws, you can be assured that your data is readily available for access by the government.
The data that is available in China is not encrypted and would also be available to US authorities.
Can you quote the part of the article that states that Apple must give China private keys? Can you find a citation where a third party has found proof that Apple changed the iMessage architecture?
> Can you quote the part of the article that states that Apple must give China private keys? Can you find a citation where a third party has found proof that Apple changed the iMessage architecture?
Apple is smarter than to put some text on their official website saying that the Chinese government has access to all your data. The key here is that their Terms and Conditions state that they operate "...in accordance to local laws". This is a cop-out legalese way of saying "We abide by whatever the Chinese government tells us to do".
Apple doesn’t control “private keys” you use to encrypt data. The keys wouldn’t be very private if that were the case.
The entire idea behind public/private keys is that you keep access to your private key.
While technically they could do that, do you realize how much legal trouble they would be in in the US if they did so without disclosing it?
Alternatively, they would have to have a special build of iOS for China.
Also, none of the “citations” make mention that the Chinese law forces Apple to give private keys to China.
Home data
Health data (requires iOS 12 or later)
iCloud Keychain (includes all of your saved accounts and passwords)
Payment information
QuickType Keyboard learned vocabulary (requires iOS 11 or later)
Screen Time
Siri information
Wi-Fi passwords
You might say "what about iMessage". The link has that answer, too:>Messages in iCloud also uses end-to-end encryption. If you have iCloud Backup turned on, your backup includes a copy of the key protecting your Messages. This ensures you can recover your Messages if you lose access to iCloud Keychain and your trusted devices.
This means Apple can produce the data a government is looking for in virtually all cases, and that's probably good enough for China.
Another factor to consider is that SMS and iMessage are rarely used in China due to SMS historically being more expensive than email/data over there.
Email is the least secure method of sending data and always has been.
Email is the least secure method of sending data and always has been.
I’ve never paid attention to it until now, but you can selectively disable iCloud backups for any of the built in apps and third party apps in settings.
A placebo toggle is also an option.
But distinguishing PR bullshit from actual practice is essential when navigating the dystopia.
And, well, Apple have confirmed that they‘re matching on your data[1]. So, guess what?
[1] https://www.scmagazine.com/home/security-news/apple-scans-ic...
Even the 2016 blackhat talk on youtube, which describes an elaborate signing mechanism for updates, doesn't preclude shipping targeted OS updates to individual users. Maybe I missed something though, and in that case I'd appreciate you pointing it out.
The reality is it’s way easier to just exploit a weakness that you can text someone [1].
But if you’re dressed in tin foil hat to toe, then there’s nothing that I can say to convince you. At that point I’d suggest not using any computing technology that you don’t personally build yourself and watch 24/7.
[1] https://www.nytimes.com/2020/01/21/technology/bezos-phone-ha...
Edit: Also, it's compelled speech though.
IIRC it said it wouldn't bow down on implementing back doors to unlock protected devices and encrypted content on them, which is specific enough not to cover this case.
Bowing down on implementing new security features doesn't go against the promise to not bow down on the security of existing ones, as written. It can be argued to go against the spirit of the earlier public statement of course, but that doesn't count for much in the eyes of a corporation being given a strong suggestion by a government agency.
It is a front door convenience feature which has distinct privacy/security trade-offs.
There exists no magical way to provide a means of lost password/device recovery which doesn’t grant Apple access to decrypt your data. It turns out that a lot of users want to have a way to recover from a lost device/password and are willing to let Apple decrypt their data.
You do this by ticking the ‘iCloud Backups’ toggle on your iPhone.
A backdoor by definition is not a user facing and configurable feature which is thoroughly explained in end-user documentation.
In modern times your face and your fingerprints could be that magic.
The thing doing the authentication can be your local device, or a cloud-device. That thing must necessarily store a validator for your face/fingerprints which it can use to decide your submitted capture is “close enough” to consider a match, after which it grants access to the key, usually indirectly, by allowing certain cryptographic operations with the key.
Apple takes pains to ensure the biometric validators never leave the Secure Enclave of a local device. Possibly they could allow syncing these validators between Secure Enclaves of paired devices but I think you have to re-enroll. Absolutely never do they transmit these biometric validators to the Cloud in a readable form.
So in a lost-device scenario, you are also losing the biometric validators as well as the keys which were unlocked by the validators.
I think storing decryptable biometric validators is worse than storing decryptable device backups. Such a fingerprint database would almost certainly be abused by a government (forced to match a terrorist’s fingerprint against their users).
The singular reason I am willing to use biometric authentication on my phone is because the authentication is done locally.
For example Amazon’s recently announced project to link Amazon Pay to a palm print in stores is a total non-starter for me. Besides the fact that it’s a clumsy and bad idea to begin with, no way I want them having my palm print validator sitting in the Cloud.
My assumption is that device recovery is such a special case, that it can use very different algorithms than those used in phones today, they could be very computationally expensive and turn fingerprints into usable keys. And of course there is no need for anyone to store them or being able to match them individually or even just tie to an identity of a person.
Encryption keys are precise integer values (or can be represented as such) and they gain a large part of their security from two facts; a key that is wrong by even one bit will appear totally wrong / disclose zero information, and two, the key space is unfathomably large.
To turn a fingerprint directly into an encryption key would require first; some sort of mapping between the analog representation of the finger/face (which could be two or 3 dimensional) into a digital value, and second; for that value to be absolutely repeatable over time.
The biggest problem is that of course neither your face, nor your fingerprints, are absolutely unchanging over time.
So the first thing you would somehow need to accomplish is a way to map the biometric scan to a repeatable precise integer value. Such a mapping would require, by definition, a loss of precision.
How much precision? Well, it’s directly a result of how resilient you want the algorithm to be in the face of things like scanning error, micro-abrasions on the finger, body fat percentage, the temperature of your hand, swelling, hair growth, etc...
The less precise you make it, the more different fingers (or different scans of the same finger) must necessarily resolve to the same key.
This is the same thing as saying that we are reducing the key-space.
Once you have reduced the precision of the mapping from a biometric scan into a key that will reliably generate the same key over time, you have, by definition, reduced the key space to the point where the encryption is fundamentally unsound.
The only exception to this would be perhaps using DNA sequences, but even then, I believe DNA is not actually perfectly unchanging over time, and is also not at all random [1]. But assuming you could probably handle the minute coding changes that do occur, and reliably scan the same part of the genome, I think you could end up with enough entropy to generate a secure key. Assuming you are willing to precisely sequence a chunk of DNA in order to generate your key. This is rapidly becoming feasible, if not somewhat dystopian and entirely impractical.
But you still have the fundamental problem that the key is not being generated as a uniformly random value in the key space. This happens to be extremely important to the security of encryption algorithms. You wouldn’t want, for example, a close relative to be able to cut your entropy from 512-bits down to 64-bits and into the realm of brute force.
In short, biometrics will remain an authentication method rather than a direct encryption method, likely indefinitely.
Refreshing it every few years isn't a big deal (as obviously none of it will be used directly as an encryption key for all of your data, but only to encrypt an actual encryption key).
[1] https://backend.orbit.dtu.dk/ws/portalfiles/portal/180163248...
It doesn’t seem like you read my reply at all.
It’s not a question of raw entropy from the sensor, which is what the paper is discussing. It’s an issue of repeatability.
It isn't a deliberately implemented backdoor. It is a deliberate decision to not install doors at all, just empty frames. I know we are arguing semantics here, and it doesn't make it right, but it doesn't go against the letter of how they've claimed they'll behave.
Disclaimer: I work for Apple.
It’s not just marketing.
This is a crappy place to turn around and tell your customers, “should’ve read the fine print!”
The ambiguous position on true end-to-end encryption shows once again that Apple is in for the marketing (both to consumers—predatory and dangerous, and to engineering talent—dishonest). Same hypocrisy as on the China issue. Not that there is an easy solution when you are one of the biggest companies on the planet and that shareholders essentially expect you to grow forever while playing nice with everyone.
There's no business case for keeping backups around for Apple, unless they suddenly became an ad company and started mining your backups for personalization data.
For the longest time Facebook couldn't actually delete photos that you requested the deletion of. They could remove it from indexes so it couldn't be found, but if you had the link it would still be available (akamai cdn). Because, to them, either the cost of the hosting was miniscule compared to the cost of writing the software to ensure things actually got purged from the CDN.
Outside the EU, small companies, or non-tech companies might we'll keep it forever.
In contrast, iCloud Backup is pretty much an open door: https://www.apple.com/legal/transparency/account.html
If Apple splits up the server into a web server and a storage server, then uses "encrypted on the server" to refer only to the storage server, that is entirely disingenuous.
Encryption at rest doesn't protect users from the company, since the company has the decryption key. It protects your data if the company misplaces the storage drive.
It's common in corporate environments to check compliance boxes, which is why AWS offers encryption at rest:
https://aws.amazon.com/blogs/aws/new-amazon-s3-server-side-e...
Apple already conceded to hosting Chinese iCloud data on Chinese servers, and that news came out about 2 years ago... which is also the timeframe reported for this decision to forego end-to-end encryption of iCloud backups.
I'm guessing here, but I think it's safe to assume that China was not going to permit such encryption (for the same reason they insist on hosting the data) and thus to provide it for the U.S., Apple would have had to fork iCloud. Add in the political risk in the U.S. and you have a recipe for "maybe not."
Source - https://security.googleblog.com/2018/10/google-and-android-h...
> this passcode-protected key material is encrypted to a Titan security chip on our datacenter floor. The Titan chip is configured to only release the backup decryption key when presented with a correct claim derived from the user's passcode. Because the Titan chip must authorize every access to the decryption key, it can permanently block access after too many incorrect attempts at guessing the user’s passcode, thus mitigating brute force attacks. The limited number of incorrect attempts is strictly enforced by a custom Titan firmware that cannot be updated without erasing the contents of the chip. By design, this means that no one (including Google) can access a user's backed-up application data without specifically knowing their passcode.
Even most PCs running Linux have plenty of nonfree binaries in various firmwares and common peripheral drivers. I support efforts to make devices with fully open firmware on which you could run Android's AOSP or other open source operating systems.
Most PINs are 4 digits, and 50% of people use the most popular 25 PINs.
Pattern has 9! combinations (= 51840) but most people use four dots (987*6 combos) and most of those probably use one of a few popular patterns.
My ultimate plan is to build my own phone; yes, I'll still be stuck with a carrier (I use t-mobile, and I haven't had a problem with them over 10+ years I've used them), and the hardware won't be completely "open source", but the software and OS will at least be what I make of it myself.
In the meantime, I'll be playing with one of the Pine64 phones; hopefully it will give me most if not all of everything I want and need, and maybe I can help with bug testing or perhaps software development? At any rate, it won't be Apple or Google.
There are times that I have when I sometimes think to myself that going back to simple email on a text screen, and not much else, would be a better thing than what the web has become. Maybe go back to BBS's over ssh or something? "Dial In" using my TRS-80 Model 100 "laptop" and move out to the boonies...
I don’t know why anyone would down vote your comment. On “hacker news” it’s no longer considered cool to hack together your own tech?
When did HN become a corporate bootlicking dump?
https://www.switchingtomac.com/tutorials/ios-tutorials/backu...
When average people care about privacy, the large players will respond. Until then, pressure from the state can be accommodated without irking customers, so Big Tech will play along.
There's an assumption that laws and safeguards are in place so technology in general can be trusted and transacted on.
In other words they trust in us "the tech circle" to police ourselves and assert security and privacy. It's not circle jerk about privacy. It's a duty we have by being in the frontlines.
Surveillance and privacy aren't the same thing but this is the FBI and people are bringing up snowden. In general I think you're right privacy is just expected for personal messages, but at some point when it's just data I don't think most people care, and may in fact support some level of surveillance.
Cypherpunks tried to sound the alarm around the time email got popular and had similar difficulty then - the barrier to adoption was too high and laypersons didn't really understand why they should care enough to overcome that barrier.
See Wired coverage from 1993 as one example of this view from the techno-savvy thinking things should be one way but acknowledging that reality is much different. https://www.wired.com/1993/02/crypto-rebels/
From the article Crypto Anarchy, he believes, is inevitable, despite the forces marshaled against it. "I don't see any chance that it will be done politically," says the Cypherpunk. "[But] it will be done technologically. It's already happening."
Rather than some digital utopia where personal information is heavily protected and not linked, we have a generation of programmers working to persist tracking cookies across browsing sessions, whether anonymous or not and law enforcement leveraging a scraped database of three billion photos to identify people whether they choose to be identified or not.
By following the electronic links we make, one can piece together a depressingly detailed profile of who we are: Our health records, phone bills, credit histories, arrest records, and electronic mail all connect our actions and expressions to our physical selves. Crypto presents the possibility of severing these links. It is possible to use cryptography to actually limit the degree to which one can track the trail of a transaction.
Of course that didn't happen beyond https everywhere for point-to-point encryption and regular leaks of consumer data proves once collected data is often not protected from public scrutiny, much less encrypted at rest, anonymized, etc. So even if you do protect your data perfectly there's still a chance it'll be discovered elsewhere. Rather than trying to create backdoors, government should be trying to enforce much more stringent regulations on use and protection of consumer data. However given the political zeitgeist I don't really see that happening.
Privacy is just like your personal health everyone wants a convenient solution but no company can honestly offer it. (Doesn't stop then from pretending they do)
Immediate giveaway that its just PR...
Actually yes. Some even have bought into VPN services without me recommending it and without any missionary ambitions from my part. Generally these are also not people using services of the largest offenders too much though.
I would even say the majority in my circle cares about it. They just have no real clue how to mimimize data exposure. There certainly is an effect that influences consumption though.
From the techies within my cirlce everybody cares, most to a pretty large degree.
At least their marketers seem to believe that there is a large enough groundswell to justify a campaign.
"And if we actually think about it, it doesn’t make sense. Because privacy isn’t about something to hide. Privacy is about something to protect. That’s who you are. That's what you believe in. Privacy is the right to a self. Privacy is what gives you the ability to share with the world who you are on your own terms. For them to understand what you’re trying to be and to protect for yourself the parts of you you’re not sure about, that you’re still experimenting with.
"If we don’t have privacy, what we’re losing is the ability to make mistakes, we’re losing the ability to be ourselves. Privacy is the fountainhead of all other rights. Freedom of speech doesn’t have a lot of meaning if you can’t have a quiet space, a space within yourself, your mind, your community, your friends, your family, to decide what it is you actually want to say.
"Freedom of religion doesn’t mean that much if you can’t figure out what you actually believe without being influenced by the criticisms of outside direction and peer pressure. And it goes on and on.
"Privacy is baked into our language, our core concepts of government and self in every way. It’s why we call it 'private property.' Without privacy you don’t have anything for yourself."
As I posted before, then you get into the so called adult realm and many of them will trade away privacy if it gets them money off their coffee, coupons for grocery, or just to brag about their latest get away. it does not matter if its private or government channels, give them a reward and they want it.
Privacy also tends to be highly associated with identity theft not realizing that not only is privacy important for reasons of protecting your stuff but your person and your interest also need protecting both from government and private parties.
Also, some here seem to think they have more to lose than they do. It seems more about wanting to be part of a victim class as long as people and organizations they don't like are punished
tl;dr no, most don't care, give them a cookie and you can get their email and more
I've spoken to many in security, selling E2E enablement for the enterprise, and even among CIOs, there is no urgency to implement this. You can imagine the indifference among the less tech savvy
It turns out most people _do_ care about privacy. You just have to frame it in relatable terms.
I don't want anyone else watching me take a dump because that's private, and it's not any of their business. Likewise, I don't want other people knowing what articles I read on the internet, or what music I listen to, or reading the contents of my business plan, or scoping out my dick pics, or any of a thousand other things, because those things are also private and they aren't anyone else's business unless I choose to share them.
Restrooms have doors, and most people close them for privacy. Data has a privacy door, too, and it's called encryption.
This is a pretty bad question and a hyperbole. Most people would want no one (including people who they are usually intimate with) to watch them defecate. And that is not the same thing as government snooping on its own citizens. Arguments for massive surveillance given by governments is not so much about invading the personal privacy of people than it is about protecting national "security" or preventing "terrorism". For this reason, few people are going to get convinced if you equate the privacy to use the lavatory without anyone watching to the privacy of being able to communicate without the government monitoring you. The best argument against massive surveillance is the one that Snowden gave during a Reddit AMA:
> "Some might say "I don't care if they violate my privacy; I've got nothing to hide." Help them understand that they are misunderstanding the fundamental nature of human rights. Nobody needs to justify why they "need" a right: the burden of justification falls on the one seeking to infringe upon the right. But even if they did, you can't give away the rights of others because they're not useful to you. More simply, the majority cannot vote away the natural rights of the minority.
> "But even if they could, help them think for a moment about what they're saying. Arguing that you don't care about the right to privacy because you have nothing to hide is no different than saying you don't care about free speech because you have nothing to say.
> "A free press benefits more than just those who read the paper."
When you think about it, that volume is staggering. 36,000 iDevice-using intelligence targets every year? Imagine the amount of analyst time required just to go through 36,000 iCloud backups every year!
Maybe I’m naive, but I find it hard to believe that there are 36,000 yearly iCloud accounts with probable cause to be tied to terrorism activity and/or national security matters, especially if that’s only in the US.
As someone with a (half) Middle Eastern heritage and name (but born and raised in the US) I’ve experienced my fair share of nuanced discrimination at airports and one weird situation with what I assume was the FBI. There’s always the ignorant TSA agent who raises an eyebrow when you report coming back from the Middle East... like why would anyone ever travel there if it weren’t for terrorism?
I’m a pretty average techie so I’m not too worried about anyone going through my iCloud backups, but I feel like there should be some more transparency around this stuff. I feel like if you’re secretly investigated but discovered to be innocent, shouldn’t you deserve to know you were spied on? I guess that’s what FOIA requests are for.
The war on terrorism feels like a game of whack-a-mole sometimes.
For some reason, I doubt Google would do that.
Cambridge Analytica didn't ruin facebook, but it did enable CCPA, and it probably changed how FB users think of / trust the product. Ashley Madison / equifax breaches completely ruined their cos.
Snowden disclosures were a weird middle case that meant all things to all people.
Weakening aapl's privacy claims may not matter to a post-truth public but I suspect it will further drive demand for actual consumer privacy products, when and if they enter the market.
But I can see how many users would assume that, given Apple's dishonest/brash marketing about how "what happens on your iPhone stays on your iPhone".
- Mac-to-Mac copy/paste (shared clipboard, continuity) - iPad sidecar
Once you enable it, it immediately begins uploading your contacts, photos and passwords to Apple. Then you need to disable those specific things. Even after you delete those things, every app on your phone can silently and without your explicit permission, start loading data into iCloud.
Then, even in iCloud Backups, you'd still not have the key to decrypt specific app data without having unlocked the device.
I realize you could do this right now (in theory) with your own encryption solution and Keychain, but a first party solution that's as easy use as the Data Protection features/apis would be really nice.
Apple has plenty of data that I wish was E2E encrypted, but if many/most of my 3rd party apps had their own data locked, that would go a long way in the right direction.
My project list has implementing a WiFi backup Windows/iTunes VM for this specific case. Does anyone know how iOS backups will be handled on personal PCs once iTunes is discontinued?
https://www.libimobiledevice.org/
Not excusing Apple. This is a disgrace, first in China now here.
Doing so I was able to read the SQLite database Photos uses on my girlfriend's iPhone to migrate only photos she had favourited to her new phone; she hated the idea of moving them all over so much that she was ready to let the best ones perish.
My understanding is that encryption is happening on the client-side and that you need to enter your password to unlock.
When Messages in iCloud is enabled, iMessage, Business Chat, text (SMS), and MMS messages are removed from the user’s existing iCloud Backup, and are instead stored in an end-to-end encrypted CloudKit container for Messages. The user’s iCloud Backup retains a key to that container. If the user subsequently disables iCloud Backup, that container’s key is rolled, the new key is stored only in iCloud Keychain (inaccessible to Apple and any third parties), and new data written to the container can’t be decrypted with the old container key.
https://support.apple.com/guide/security/icloud-backup-conte...
Assuming this is true, you still don't know what people on the other end will do, meaning it is never actually E2E encrypted.
https://blog.cryptographyengineering.com/2012/04/05/icloud-w...
The fact that they started working on the problem then abandoned it after the FBI complained is disappointing, especially to Apple consumers. But all it means is the status quo marches on.
Headlines like this vindicate my decision to never purchase an Apple product.
What else can you buy? Surely not Android...do you live without a smartphone (serious question, not judging)?
That's a very judgmental way to ask that question if you're trying to not be judging.
My phone hardware would fall under the Android classification, but I run LineageOS.
I wish I had more options, but we're stuck in a hellish duopoly for the time being.
With Google Play Services surveillance rootkit? :)
Why do I have to use a phone in its place? Apple products aren't a basic human necessity. I like to think I can just use a phone for the sake of wanting a phone, not to replace the void that not being an Apple consumer leaves in my soul, or something.
What exactly do you mean by "basic aspects of modern life"?
I have a desktop PC, a laptop, a work laptop, a LineageOS (Android-based) phone, and a VR headset for gaming. Anything I want out of modern tech, I either already have or doesn't exist yet.
I couldn't get push notifications on Slack because they went through gapps.
I couldn't use several online dating services because they were only on mobile, and their mobile apps broke without gapps.
I couldn't check my bank account from my phone because I couldn't get a hold of its app outside of the Play store, and because its mobile site locked my account for suspicious activity because I roamed between cell towers while using it.
I couldn't find places because there was no reasonable mapping option (OSMAnd, at least at the time, was abysmal to the point of being almost useless).
I once bought a pair of headphones that I couldn't use at all because you had to use Bose's app to set them up, and - you guessed it - the app was broken without gapps.
Even Signal - the OSS encrypted messenger - was partially hampered without gapps.
We can talk all day about how we got to this status quo and what can or can't be done about it, but the reality is that if you want to live a real, modern, urban life in 2020, so many people and organizations just assume you to have a fully-functional smartphone that you will be actively hampered without one.
And for that, you can also get a stock Android phone like 80% of the world and still not be an Apple consumer. :)
1. This isn't news about Apple's encryption, it's just that the status quo is here to stay. Your Apple device is as secure/private as it has been, and will probably not get any better. It's disappointing, but not really much of a revelation to anyone who's been paying attention since 2012 (or earlier).
2. The way the headline is phrased vindicates an orthogonal personal decision I made to not purchase hardware or software from Apple.
Given your most recent comment, at some point, you must have assumed a lot of things that a) aren't true and b) I never stated or implied.
We users are better off if Apple is "compromising" on something like this at the stage we're in now - especially since nobody forces you to use iCloud Backups - than we'll be when/if the US gov makes Apple an offer it can't refuse and forces a real backdoor master-key on the whole system top to bottom.
Assumption: That not going full encrypted backups will prevent the government from having the political capital to enact a "crackdown" forcing a backdoor on the devices, iMessage, etc.
“ Reuters could not determine why exactly Apple dropped the plan.
“Legal killed it, for reasons you can imagine,” another former Apple employee said he was told, without any specific mention of why the plan was dropped or if the FBI was a factor in the decision.”
And further on: “ However, a former Apple employee said it was possible the encryption project was dropped for other reasons, such as concern that more customers would find themselves locked out of their data more often.”
So 4 of the 6 sources were speculating (FBI), and one actively admits they don’t know the reason, but the lede says 6 sources confirmed this. Hmmm...
It's true this kind of wording is often used in low quality journalism to float the idea of a causal link when there is no good reason to suspect one, but this is not one of those cases.
This. It's also the reason why photos are not E2E encrypted on iOS: Apple really doesn't want to be in the position of saying "sorry, you lost all your data" or "sorry, it's sad that Grandma just died, but all of her photos are gone and there's nothing you can do about it."
Already, people who don't use iCloud Photo Library and lose their phones, or forget their passwords, lose the photos that were on the phones.
Anyway, I think the customer experience issues weigh pretty heavily here.
I stopped using GDrive about a year ago and I aim to be Google-free for 2020. I don't use Gmail for anything important any more.
It could be for many reasons too, including average people forgetting iCloud passwords and wanting their data back. Does Apple unlock an iCloud backup in that situation?
Perhaps a pro-privacy compromise would be for Apple to offer the feature but have it turned off by default, which means 99.99% of users won't ever change that.
That means that Apple can also now perform an offline brute-force attack against your file vault password.
This makes even your offline devices less secure.
If you forget a local iTunes backup password, there is no way to fix it.
a) Is this just tactical move? Apple might choose to delay it's plans In effort to avoid confronting the current administration and wait for more reasonable one.
b) Is this permanent change of strategy? Giving up.
1) There is no way Apple would be allowed to sell iPhones in China, without China government having access to anything. So, I assume that Apple users in China have e2e encrypted exactly nothing.
2) I have a strong suspicion that those 'enter your Apple ID password because your account needs it' message really means 'a government has requested your data and even though it's encrypted, we will nag you about entering a password, and if you give it, you're a free game'.
I don't blame Apple for this, I'm sure they're doing what they can, but when a government says 'give us this data', they can't not comply and stay in business. And a whole point of a company is staying in the business.
Vote responsibly - companies can't protect us from a government we have put into power.
Apple internal is complete detached from the commercials you see. It's about sales, not teaching users.
I wonder what Apple is liable for in light of this.
But the FBI can see everything so thats okay.
Pecunia non olet ("money doesn't smell") is the motto of any commodity market for thousands of years. You might not like who you're buying from, but the POINT is fungibility: to completely remove all distinguishing characteristics, allow interchangeability, separate the value of the good from the value of the producer or seller.
Early stage markets (usually aided by capitalism) on the other hand allows for disequilibrium, competition, and differentiation. At worst is how you get commodities repackaged as "artisanal bottled water" and "bone broth", and the like. But it would be the way to differentiate ethical oil (is there any?) from unethical. Also has been pretty successful at labelling GMO / non-GMO food. So, yeah, there are many cases where you do have meaningful choice.
Well, that's the problem with politics as well, and the reason that modern democracy is a sham (compared to ancient Athenian direct democracy [1]).
[1] obviously for those it included at the time. After all, modern democracy didn't include slaves, women, and even poor white folks (the extension of voting rights to non-property-owning white men happened in 1828, and it was hampered in the South until the early 20th century) until well into the 20th century.
Again, that's not how that works at all. I can name hundreds of items that I've purchased in the past year where there aren't meaningful competitors. I can name dozens of contracts I've entered into where management changed after the contract was signed (sometimes years afterward). Of course then I'm screwed because I'm still stuck in that contract.
Someone else does not exist. That is like saying you voted for Comcast.
For me it's a vote for less tracking, or at least less invasion. It's not saying it's perfect or even close. There's a ton of things I'd change on iOS if I could.
So yeah, I 'vote' Apple because the alternative is a dumb feature phone.
They do. Including an independent third-party security audit.
> it leaks is so many other unpleasant ways
I recall Android security used to lag behind Apple at the device level, but I'm not sure that's still true with current hardware and OS. Could you educate us on the current state of Android data leaks?
For me, my device should have full-disk encryption, sandboxed apps and fine-grained control over app permissions. Both iPhone and Android have that.
Intentionally leaving iCloud insecure in the absence of legal compulsion is a sneaky evasion of all the much-ballyhooed device-level security.
Maybe if you develop for it but then again why did you choose Apple's platform?
Plus, to vote "away" from a company/product, other products should exist that are better, and not just in this single aspect (encryption of backups), but in other aspects that count for your usage.
Its at most 1 bit information, often even less, since it could be a huge number of reasons for each person to vote one way or another, or maybe not vote at all or just random.
You can boycott a company your whole life, and nobody not even the company will care.
What choice is there beyond Apple or Google in terms of smartphones? And I mean actual, ergonomic, everyday convenient choice -- my mother will firmly refuse me if I said "I'll buy you a phone but will have to tinker a full weekend to make it half-privacy-aware". And even if she was on board, she'll just yell at me if she can't do a basic task (this is a controversial topic around here but heavily modded and supposedly Google-less Android is absolutely not as useful as a Pixel or vendor-modded Android).
So...
Google is an ad company. There's nothing they won't do to get to your data. And of course, being a huge company, they will lie about it at Congress hearings, lobby against punishments, make PR campaigns to mislead the general public, cover up their work with China until they are caught, etc. They already did all of these, many times.
Apple is seemingly a good citizen but do we really know what they do behind closed doors? As an Apple user I am still a realist and I know the answer to this question is a firm "No".
We seriously have no adequate choice. I like my iPhone; I don't play games on it (well, a few brain-teasers and a bunch more serious like chess but you get the idea), and I read a lot of stuff on it: work- and hobby-related. Social media gets almost zero attention from me. So smartphones can be very useful if you don't get hooked on BS.
And so I ask you again -- what actual choice do we have? How can we really vote in a way that will make a difference?
We (that is, tech users) have a choice, if we choose it. The ones who don't are the people who can't take that option (ie, your mother). You've stated as much.
What is your choice today, as someone technically inclined?
Well - you mentioned modded Android; but there are several other options, if you don't mind fiddling with things.
More than a few phone operating systems are out there, many open source.
For hardware, probably among the best right now is the Pine64 phone (it's currently in a strange "high-beta" state - you can order one, and it will supposedly be close to what will eventually be sold, but it isn't completely considered a "commercial product").
Alternatively, you could build a phone using a Raspberry Pi (or a similar board, like a Beaglebone or something), or an Arduino (you'll be very limited in what you can do using a standard Arduino - basically make/take calls, store some contacts, maybe SMS).
Note that most phone modules out there are 2/3G - but you can find 4G/LTE modules, fairly cheap if you know what you're looking for.
Your "phone" won't look pretty, but you probably know that. It will likely be fragile at times, and the software quality will depend on what you can find and what you can code yourself. Cloud storage, games, etc - will all be mostly up to you to implement in some manner.
A lot of work, certainly - but that's the only real option, as you can never be absolutely certain, if you're not in control of at least the OS and software.
But for everyone else? Yeah - they don't have any choice, unless they are willing to step up their knowledge (and most aren't, nor should they have to).
Apple is also an ad company.
Apple's advertising business is currently $2 billion, growing rapidly, on track to $11 billion by 2025.
Apple is a hardware company that sells ads.
The "free market" can't fix things if there are no choices to choose from. Sometimes politics has to fix this instead.
Unclear on what exactly?
How much damage is done through encryption alone?
Part of the FBI's responsibility of investigation is to surface this concern to companies that have the power to make that world a reality, and it appears Apple has agreed with them on the risks.
And same goes for every other government. Why should the government can do whatever they want secretly?
The guiding principle the US government operates on in this context is "When a man assumes a public trust he should consider himself a public property" (Thomas Jefferson). There are plenty of ways the fed falls short of the goal, but the goal is set.
... and I don't think anyone's talking about "handing over the keys for all citizen data being open to said government." But we are talking about avoiding having common practice for private citizen information stored in servers owned by a third-party private corporation becoming "It's stored in such a way that nobody, not even the third-party private corporation, can ever access the data without a key the private citizen can throw away." There are some good cost-benefit discussions to be had about whether that should be a thing commonly offered (even if an individual can build it themselves).
To give a concrete example, imagine if Epstein's data on the human trafficking he conducted were impossibly ciphered now in an iCloud backup he made. Does that benefit society? And more practically (regardless of larger ideal morality questions), is it a good PR look for Apple if their tech made it easy for him to do and when the fed comes knocking on Apple's door to retrieve from Apple's servers a dead man's documents that could bring justice for sex-trafficked children, Apple's response was "Sorry; we don't have enough computing power to help you?"
Unless you mean Apple should be actively trying to siphon off private data via their OS and hardware and index it for the feds?
I would then say Apple’s “trusted computing base” isn’t so trusted.
I believe people have been saying that to me for thirty years now, but I'm younger than my peers. ;)
In the context of cloud services specifically, I think that's even less true than in the OS space. Half the benefit of clouds is someone else is maintaining the infrastructure, the backups, the ubiquitous connectivity, etc. None of those are trivial to handle as a solo project, and attempts to make them easier compete with free (as in time).
Even if our phones were 100% trustworthy, they are triangulated by cell towers thousands of times per day. Location tracking can only be avoided by:
1: Not owning a phone.
2: Powering off your device and keeping in a Faraday cage while not using.
Tempting to own a cute little purse that blocks phone signals, but do I really need a cell-phone on my body, 24/7?
If I evaluate the overall pros & cons of my cellphone, it has been overwhelmingly negative. I've had a phone since August 2014, when I went to college. Before that, I would text with my parents' phones.
Here are the top negative things that have happened due to using a phone:
1. Miscommunication, isolation, social anxiety due to social media and texting. Talking in person is so much better. And what about the hours and hours of snapchatting, so pointless and sad looking back.
2. False sense of security, thinking you can know what's going on, help people, intervene when necessary (friend sexual assault stuff at parties). What about when their phone dies? It made me wish we had landlines, or that I had been there. If I didn't have a cell phone, I don't think I would've left the party. I would've stayed and kept watch.
3. Poor posture, lack of sleep, constant exposure to blue light (who knows if the light is really bad), etc.
4. Missed connections by having my head in my phone all the time in public.
5. The US government has a total map of my life since August 2014, even though I have sent thousands of encrypted messages and hundreds of encrypted phone calls.
6. Less time available each day. I have spent typically 1-3 hours per day on my phone since I got one, about 1,980 days ago. This amounts to probably 4,000 to 6,000 hours, or about 170 to 250 days. In other words, about 1/8th of my life since 2014 has been dedicated to bullshit technology.
Here are some positives:
1. I have lots of photos that would otherwise have required a camera. But I have dozens of film cameras and a few digital ones, and there's no reason to shoot photos on such a tiny format. Good luck printing cell-photos beyond 5x7 or even 8x10.
2. I occasionally talk to family. This could be accomplished with a landline.
Maybe I've missed some things, and maybe I'm being pessimistic, but the reality is that I've lost lots of sleep and experienced more problems with interpersonal relationships as a result of having a phone. It's likely that not owning a phone would expose me to a new class of problems, but I've decided to get rid of my phone.
I'm in the process of switching accounts and removing 2FA, so I don't need cell service. Once I get there, I'm planning to write a little blog post about it. After having a baby, it's become clear that a phone is sucking my life away, and I need to be present with my family. Hope to have this all dealt with in the next week or two.
1. Having Google/Apple Maps has helped me find new restaurants and kept me from ever getting lost in foreign cities,
2. Tinder and other dating apps have enabled me to date people that I would never have met in my day-to-day life,
3. Lyft and Uber have come in handy more times than I can count,
and the list goes on. My use-case is different than yours, I’m sure, but there is a reason that smartphones are ubiquitous: we as a society have roughly evaluated the cost-benefit analysis of owning one and tend to side with the ‘benefit’.
No company cares about anything. A company is not a person.
Apple, because of its privacy-marketing, is incentivized to be the privacy player in the market. But only so far as consumers keep them honest about it.
They got away with this loophole because it stayed under the radar; if it gets enough attention and enough customers show that it matters to them, it could change.
On the other hand, it's possible that because we have a smartphones duopoly, Apple only needs to maintain a position where people will say "well at least it's not as bad as Google". I'm upset about this personally, but I'm not ditching my iPhone. Of course, this does cement my decision to never pay for iCloud, for what that's worth (much less, but not nothing).
Agreed, and I am likely going away from Android and into iOS for my next phone. It's still a setting you can change so it's not forced into their cloud thankfully.
I wish Microsoft hadn't backed out. A Surface Phone would be kind of cool. I guess too much stigma about Microsoft has held them back from being competitive. I think they shoulda waited for their Microsoft Store to grow much more organically, then release the Windows Mobile phones.
The other issue is Google's agreements.
A Surface-branded Android phone wouldn't be out of the question, but my gut tells me it would die a quiet death from thin margins and differentiators that aren't big enough for people to get excited.
This. I had some Windows Phones besides my iPhones, because I liked very much what they were doing. Windows Phone 7, despite being technically weak (it was based on Windows CE), had an awesome UI. Nokia had some really affordable phones that were really well-built for the price and Windows Phone was getting traction. Quite a few friends/colleagues bought a Windows Phone, because it was the hip thing after the iPhone. The development story was also great, they used .NET and XAML (IIRC), which also made it possible to demo applications on web pages through Silverlight.
Then they screwed over all the early adopters by completely deprecating Windows Phone 7, doing one final release (7.8). None of the Windows Phone 7 devices were upgraded to Windows Phone 8. Most of the traction they had up till that point was lost and they were basically starting over with Windows Phone 8. Windows Phone 7 was already late to the market, the hard WP8 cut set them back even more years. And then it was simply too late.
There were technical reasons for WP7 -> WP8 (such as moving to the NT kernel, adding multi-processing support). But the hard cut was a catastrophical mistake. Either they should have started with the NT kernel in the first release or they should have had a gradual migration route from WP7 to WP8.
There was this spark of energy around Zune, and then Kin (https://en.wikipedia.org/wiki/Microsoft_Kin), and then Windows Phone that was just completely orthogonal to the stagnant money-printing strategy that Microsoft followed before Nadella. It was this little glimpse of an Apple-like spirit somewhere deep in the behemoth. It was exciting. But it was always treated as a side thing instead of being placed front-and-center. It's now been diffused into Microsoft's various consumer products, most obviously the Surface, but Windows Phone was already dead by the time things started to change.
Aside: despite all the jokes about it, the Zune (2nd gen and forward) was awesome. It was a little late to the game - it really nailed the traditional mp3/video player right when the iPod touch had just come out - but I think it may've been the peak of that category. Everything from the UX to the hardware buttons was so meticulously considered, the screen was much bigger than an iPod Video, it had momentum scrolling that worked really well despite lacking a touch screen, etc. It did not at all feel like a Microsoft product of the time. It was even one of the first services to offer all-you-can-download, subscription-based music. And you could download songs over WiFi.
I would love to see how Windows Phone would’ve matured.
To this day I still think about that little touch/d-pad, and wish something similar had caught on with more devices...
- Doesn't have the hard directional buttons underneath
- Isn't really helpful because you aren't scrolling through hundreds of items like you do in a music library
They botched subsequent pushes on it because the bootstrapping problem around apps had grown too deep.
I don't really think that is necessarily accurate. Lots of smaller developers would be more than happy to have a green field for app development if another player were willing to put the effort into assuring the device isn't a POS, and is priced reasonably. Some of the larger apps (netflix for example) already have a dozen diffrent versions because they support not only ios/android but a pile of similar devices (TV's/etc) and likely don't have a problem with another platform if it has a future and has the prereqs (widevine or similar DRM for example).It's that chicken-and-egg problem where people don't want to use it because it doesn't have the apps they need, and developers don't want to make apps for it because it doesn't have enough users. Microsoft tried to throw money at the problem to middling success. But I think it was too little too late.
I would guess that they aren't the only ones. Do you think LG/Sony/Samsung/roku/apple tv/firestic/etc all got the netflix app ported for free? Maybe. Plex probably isn't getting paid, and they do it too..
But MS was a special case, it seems to me that every time I looked at CE/Mobile/etc they were tossing existing app compatibility aside for the latest and greatest toolkit that went with some not particularly good set of phones.
Their (forward) app compatibility was actually very good. I wrote a WP7 Silverlight app in 2011 that still works on the last release of Windows Mobile 10.
It was just monopoly abusing its walled garden and being anticompetitive, nothing else. Not that Microsoft would behave any differently, if the positions were switched.
It could run chromium based Edge right away logically.
It's supposed to come out later this year.
There's definitely a differentiator, at least. Apparently they've forgotten what happened to the many previous attempts at dual-screen phones and tablets.
It's coming.
https://www.theverge.com/2019/10/3/20895268/microsoft-surfac...
This is not accessible for average Joe, but I'm pretty certain the majority of readers here can use the tools to load an alternative ROM. That you can enable and use F-droid just fine. And are knowledgeable enough to know what apps to avoid.
eg GrapheneOS currently only supports Pixel 2, 3 and 3a:
They've announced that they'll release a Surface phone this year. But it'll run Android.
[0] https://www.theatlantic.com/politics/archive/2015/02/if-corp...
Also, privacy != security. iOS is absolutely in a better position on privacy, even after this new development.
Last Android phone I have bought was Galaxy S8+, just a few months after the release. Had to wait about half a year (if not more) for the next major Android update after it had already dropped for Pixel devices.
You're splitting hairs over the definition of 'cares'. I think we all understand what that word means in this context.
No, we don't, and that's exactly the point.
We tend to anthropomorphize companies. "Good Guy Google" has become "Evil Google". "Micro$oft" has become "Altruistic, OSS Microsoft". Apple has become "Defender Of Privacy". But all of these are illusions created by marketing departments; there is no real sentiment behind any of them that can be used to predict future behavior. And it takes constant vigilance to remind yourself that those narratives are empty.
If it is useful to model such organizations as non-person agents, then while they of course would not “care”, in the sense of emotions, about things, it would be coherent to say that such an organization e.g. “has protecting privacy as a goal”.
Err, I guess I’m eliding the distinction between “being useful to model as an agent” and “being an agent”, which may be a mistake. I suppose what I should say is “if it is useful to model as an agent, it is useful to treat as coherent the claim that it has goals of e.g. privacy stuff.” .
With all of the carefully crafted marketing aimed at bypassing the forebrain and making people feel as though corporations care, it doesn't hurt to keep the fact that they don't at the forefront of the conversation.
It's a common misconception that corporations are amoral incentive-driven machines impervious to ethics, morals or mission.
Corporations are run by leaders.
Many leaders choose to pursue unethical and immoral activities to maximize profit. They justify their actions by saying "it's just business", or "we have a fiduciary duty to the stockholders to maximize earnings per share by whatever means necessary".
Other leaders realize that an ethical purpose can often deliver outsized profits over the long term. Leaders with a moral mission make decisions that sometimes sacrifice short-term profits with the intent to build an organization and a brand for long term.
Not really, those leaders are pretty quick to hide behind the corporate veil when it's convenient for dodging questions of moral (or even legal) responsibility.
The whole point of corporate legal structure is to create an entity that is _separate_ from the humans that occupy offices. That entity is not a person.
I also largely agree that the Apple meme of privacy being trotted out lately doesn't quite jive with this news, but at the same time surely there are people who care about it at Apple, and maybe as a whole they even prioritize it more than others.
But I also don't know how much I really disagree with the FBI's position. In general I have seen this kind of access to be used in the right situations (IE collecting communications of criminals). I understand this can be a slippery slope, but should we trade that for leaving clear evidence against criminals unturned in the name of "privacy"?
From the information I have, the majority of Apple employees do care about values such as privacy and ethical business practices, as well as product quality and usability, but those values can sometimes be undermined by executive decisions based on business and monetary motives.
the (current) supreme court doesn't agree, and their opinion carries a tad more weight. corporations are basically super-persons in the eyes of the court, since corporations intrinsically funnel the resources of its many consituents, unlike individuals.
instead, any entity exerting outsized power, like corporations, should be held to higher standards of duty and transparency. that's an inherent value embedded in the US constitution that is absolutely being trampled over by power-seekers (commercial, political, or otherwise).
that we also rationalize the actions of a corporation (to understand them) doesn't necessarily imply complicity. lacking more evenly distributed power, we should want apple to be pitted against google, the fbi, and the chinese government to funnel apple towards a privacy-oriented stance that it might not otherwise have.
incidentally, (many) americans vehemently support 2nd amendment rights as a way to have some semblance of power in an otherwise overwhelming power structure.
It's entirely possible to do immoral things for the sake of profit while still being prudent about your company's future.
As for sacrificing profits to a moral end: private companies may do this occasionally. Not often, but sometimes. But the CEO of a publicly-traded company expressly does not have the option of sacrificing profits for any higher purpose, unless that directive comes from his shareholders. And in today's world, the shareholders of most major companies are of such a large number and have so many layers of detachment between themselves and the actual company (I don't even know what companies Betterment has me invested in; they can change every day) that the only common goal they can agree on is almost always profits.
An interesting exception to the norm is Facebook: despite being publicly-traded, Zuckerberg maintains both a majority holding and the position of CEO, and is therefore free to go on his crusade of "connecting the world", mostly ignoring what the other shareholders might want.
This is not true AFAICT. In practice it might be.
baords are largely controlled by the various (professional) shareholders, and most, if not all, of them explicity seek profits above all else. that's one way markets get dominated by profit-seeking companies.
the other common argument is that in capital-oriented markets, not-primarily-profit-seeking corporations are at a competitive disadvantage over time, as the extra profits of greedy corporations can push them faster/further along the technology adoption/innovation curve (or economies of scale/scope).
so it's hard for such companies to survive. i don't think in practice that this is a dominant factor in competitive markets, but it's an argument often made (in business schools, for example).
Shortly before being dragged off the stage by the stockholders. Careers have been ruined over not over-performing enough, let alone leading multi-million dollar enterprises off into the desert.
Personification is a useful concept. Companies do have some mechanisms that lead to consistently different decisions compared to other companies in similar situation.
You're like the thousandth person objecting to the concept of HN, with always the same air of revelatory smartitude. But it's not contrarian insider knowledge. It's simply the inability/unwillingness to understand basic symbolic speech.
No, it's because they can't effectively leverage your data to sell you stuff, they don't need it.
Thus follows the privacy marketing.
If Apple did find your data useful, they wouldn't be able to leverage that marketing angle.
Companies are made up of people, who care about people, and also, corporate objectives are not evil, generally. Working with the FBI might raise your eyebrow, but it may not for others, and it's an ambiguous question to most.
In the end, the balance of power has not fundamentally shifted. Most people have little to worry about, some criminals may have more to worry about. Of course the problem arises when innocents are needlessly entangled - hopefully this can be minimised. It's not like the FBI has instant and easy access to your phone, thankfully.
If there is a more secure alternative available then I’ll go with that. Also iCloud backup is now turned off, no need to enable the surveillance state.
Turn off iCloud and do local encrypted backups to your PC or Mac.
This works over your wifi network (if you prefer wireless charging at home) or via a cable connection.
1: https://www.macworld.com/article/3269361/apple-discontinues-...
Or are you suggesting that an average Linux user who wants to back up their iPhone needs to buy and install Windows in a VM, and then is further expected to tinker with ingress/egress network rules to make sure no data is being sent over to Microsoft? I'd say that's a tall order.
If you only use that VM for backing up your iPhone, there are no useful telemetry signals for them to collect in the first place.
Haha, good one. Who cares?
It also does put a shelf life on the underlying software in a way that even crazy old computer software like for an IBM 700 series doesn't have.
It's a command line suite for Mac, Linux, and Windows that interfaces with your iPhone through it's native protocols, including for encrypted local backups.
I’ve also had instanced where the latest version of that library supposedly works, but it’s dependent on another library that hasn’t hit Debian mainline yet. So I’ve had to wait months just to get a version that works even though it was released much earlier.
It’s not a perfect solution by any means.
Of course then you have a local backup on a hard drive which is itself subject to seizure and I believe even encrypted backups can be cracked.
I suppose I could mount a network drive / nfs share at the location iTunes believes is local ...
https://reincubate.com/support/how-to/change-itunes-backup-l...
I fixed the problem for now. I have some older devices I don’t care about the backups for any longer.
>How to move your iPhone or iPad backups to an external hard drive
https://www.imore.com/how-move-your-iphone-or-ipad-backups-e...
If anything, they're more prone to being cracked, since an attacker can load the backup onto a very fast system and run custom software which can run many permutations of keys against the backup to try to unlock it. With actual hardware, they're limited by having to manually enter the key in most cases plus any hardware or OS features which would notice that the user has entered too many incorrect passwords and lock down the device further.
On the other hand, if the computer that your backup has been backed up to is itself reasonably locked down, that might be an acceptable trade-off; they can't try to crack a backup they can't access in the first place.
I'm saying that my phone becomes the synced copy. The cloud is the canonical version (backed up separately elsewhere) and my phone becomes a device I can lose or break and not worry about anything so I don't need to back it up. As soon as I create any content on my phone I upload it to the cloud.
Take my phone from my hand at any moment and as long as I've had signal in the last few minutes I've lost nothing.
What do you think is special about a phone backup compared to a backup of anything else?
I said don't have the primary store of your content to be on your phone and don't backup your phone.
The reason for this is that if you lose your phone, everything is lost since you last backed up.
Instead, store have the primary store of your content to be in the cloud and backup your cloud.
The reason for this is that if you lose your phone, it's irrelevant, just get a new phone and re-install your cloud apps. Now you don't need to worry about backing up your phone ever.
The only failure mode is if your phone has not had a signal to upload new content to the cloud in the last few minutes. Well guess what you probably also haven't backed up your phone in that time either if that's what you were doing.
See?
I've tried getting my family to use it (mainly because they didn't want to pay for iCloud storage), before giving up and just paying their storage for them.
I mean... yes? How else would they do it? Data transfer is power-intensive, and encryption is also power-intensive. Imagine having only 10% battery on your laptop while you're working at a coffee shop or something and suddenly it drops to 5% because it's started a backup.
Sure, the majority of the time it'd probably work out fine, but Apple's UX philosophy is to simply remove undesirable states from the equation by sufficiently limiting users' options. This is exactly the kind of behavior I would expect from this feature.
(to clarify, my desktop PC is always turned on and connected to the network, so most of the other complaints in this thread about it not working with low battery laptops or whatever don’t apply in my scenario. Even in my ideal-case scenario it still barely works)
The agencies have proven time and time again that they're pretty terrible at keeping secrets (see: all the leaks, data breaches, TSA master keys, etc). As long as they have a back door, it's inevitable that it'll happen -- it's effectively a ticking time bomb.
When I send a message over Signal, I can trust that it'll be kept private, barring some truly extraordinary incident. With Apple, it's kept accessible by design (storing the encryption key with the encrypted backup? really?).
It's not about the government accessing my messages, because I really don't care all that much, it's that I don't trust them to keep secrets. If the government has access to something of yours you must assume it'll eventually be made public... whether or not you're okay with that is up to you.
I mean, I'm not up to anything illegal, and I don't actually care about people seeing my stuff, BUT... the concept as a whole of "government should have access to everything all the time, regardless of reasoning" does not sit well with me.
The point is, if someone from the law is interested in you, or suspects you of some grander illegal thing, a lot of us do illegal things that might just be a little less grand, and a lot of us have the digital equivalent of a broken taillight.
> Instead of protecting all of iCloud with end-to-end encryption, Apple has shifted to focus on protecting some of the most sensitive user information, such as saved passwords and health data.
> But backed-up contact information and texts from iMessage, WhatsApp and other encrypted services remain available to Apple employees and authorities.
Way to confuse laypeople with promises of security and data privacy. If Apple had concerns about users losing the key, why not implement it similar to two factor authentication on Apple IDs where Apple also provides the recovery codes (and additionally disallow any other mechanism of recovery)?