Apple reportedly dropped plan for encrypting backups after FBI complained (2020)
theverge.com
theverge.com
Even if you disable backups, whenever you correspond with someone that has backups enabled those messages are still accessible to Apple.
While there maybe encryption in transit of messages, the encryption of messages at test is effectively defeated when the messages are at rest in icloud.
I am curious, is it possible to do an icloud equivalent backup without using icloud? Perhaps with a different backup app, nas, etc?
Ideally it would be nice if you could opt yourself out of having any conversations backed up, but I'm sure to Apple the privacy benefits doesn't outweigh the amount of customer support hours that would be wasted explaining to people why some of their conversations aren't transferring to their new iPhone.
itunes.
ISTR that local backups would contain more than the icloud backups as well - there are some things that won't be backed up into the cloud?
That's more of a problem with who you choose to communicate with and their security practices than a problem with Apple. The same counterparty could also have a weak/non-existent passcode on their phone, or is jailbroken.
Why the disconnect?
I literally never heard of this. There are problems with PGP (eg. no forward secrecy, non-reputability, unencrypted headers) but "your counterparty could be compromised" isn't one of them.
* https://latacora.micro.blog/2019/07/16/the-pgp-problem.html
--
Messages in iCloud also uses end-to-end encryption. If you have iCloud Backup turned on, your backup includes a copy of the key protecting your Messages. This ensures you can recover your Messages if you lose access to iCloud Keychain and your trusted devices. When you turn off iCloud Backup, a new key is generated on your device to protect future messages and isn't stored by Apple.
This seems crazy to me. I understand that the problem of losing your key is a troublesome one, but this seems analogous to storing important information in a safe then taping the key to the safe so you're never in a position where you can't open it.
If the FBI thinks it's a great idea that should be reason number one not to do it, at least when it comes to data security.
It's then a question of if you trust apple to be this "someone". If you don't trust them, then you should probably question if you trust the system at all given most of it cannot be audited.
And also asking this same someone to take care of the safe.
General public would hate it when the support won't help them recover family photos which are still stored in the cloud. Full encryption is nice to have, but overwhelming majority of users won't get any tangible benefits from that.
works over wifi too. https://www.switchingtomac.com/tutorials/ios-tutorials/backu...
If anything, this should be some hidden developder mode kind of option to make sure that only those opt in who know what they are doing.
It’s unfortunate because apple has the cash and panache to take it mainstream, but they probably don’t have any market incentive to do so, at least until someone else figures out the ux that doesn’t cut clueless user fingers off.
But we've conditioned users to accept a million dialog boxes to confirm random choices that are mostly inconsequential CYA.
Don't assume your users are immature just because they use a computer. This assumption is only with computers, I don't know why.
If the easy/simple first idea after giving it zero seconds of thought isn't good enough, the possibility actually exists to give it more than zero seconds of thought and try more than one thing.
It's also possible that the simple warning does work just fine, after it's ubiquitous for a while.
Everything about a computer was baffling originally, and now grandma scans documents to create pdfs and attaches them to emails. She's still grandma, she stil is baffled by many things, but there is a whole pretty big body of good understanding that she DOES have, just like she knows how to operate many other parts of her life.
The irreversable nature of protected data could perfectly well become one of these things that everyone knows.
All it probably requires is simply being a feature of ordinary life for some amount of time.
And maybe a little more standardization around terminology and ui so that people can tell when they are dealing with a secure thing vs an ordinary thing.
I'm pretty convinced the proportion of people who would be likely to expect Apple to be able to recover from a lost password, even though they'd specifically opted out of that, would tend to ~100% of any group of users (not just Apple users).
Many people think "The Internet" is their browser (Oh, mum, [sigh]). Try to explain public key cryptography consequences to them, I dog-dare you. If Betty (Oh, Betty, [deep sigh]) from next door said it was "better" then they'll go for it anyway, and only pay attention to the consequences when it's too late.
The article is a year old, and I think Apple could do some stuff around what they already do (if you forget your password on one device, you can typically reset it using the password from another device, all the while maintaining the cryptography chain). There's some interesting avenues that could be explored there, but until they have a solid-as-they-can-make-it public release-candidate, we won't hear anything about it.
I can't imagine needing a password for them to recover photos and messages.
This sort of encryption bears a heavy burden on the customer. And the customer often doesn't want to accept that burden.
Here it is from their own docs: https://support.signal.org/hc/en-us/articles/360007062012-Ne...
> An iTunes or iCloud backup does not contain any of your message history. Only new messages, not conversation history, will be displayed.
Frustratingly, if you forget the backup password you have to Reset All Settings on the device, no way to change it going forward if you lost the old one. Of course, there should be no way to get to the old backups if you don't have the password, but if you have access to the device (thus, the source of the data to begin with) you should be able to change it without a reset.
That is the problem. It's very frustrating to tell some people that they can't recover their data because they forgot the password
If you can keep a password for a long time then you can do your backups yourself I guess?
To be fair, this also describes Windows users. Most users of any platform are average non-IT people.
A web search shows this surprising stat, for all the user's services:
"78% of people have had to reset their password in the last three months. - HYPR study"
And 57% for work accounts. Wow.
Or to further your shoe store idea. The majority of people know how to tie their shoes. Most shoe stores usually don't keep a lot of stock of shoes larger than a US size 12 men's shoe. My foot happens to be larger. I have a different use case. So I often have to go through a different workflow (e.g. ordering online, having the store custom order my shoes, etc.).
If you want full data security, you need additional technical knowledge and a different workflow. iCloud isn't for you.
They could put a clear warning on the iCloud screen as well. However, there is a large market for the iPhone in non-tech savvy people, especially old people, who may not understand fully what this decision means.
People can, will, do, and did ignore any and all warning messages and then look to support to help them. It does not seem to matter how large, scary, or clear the warnings are. They will be ignored.
So if you're Google or Apple and want to ensure that people's identity documents or tax records or business documents aren't stolen when the laptop or phone is, you make encryption the default. It helps that these devices are easier to sell to businesses. I'm thankful for these choices.
In my professional capacity as an information security practitioner and my personal capacity as a privacy advocate, I find the idea at hand distasteful. Improved security should be available to everyone, not just those with a deep grasp of how to manage cryptographic keys. Gaining any measure of data security should not be reserved solely for us in the technical elite.
There might, perhaps, be a slightly different discussion to be had about making it more common for tools to enable advanced users to manage their own keys. But this should never come at the expense of the common user. We have a profound professional responsibility to be better than that.
Many people assume that that when it says "can't", it actually means "won't", and that they'll be able to beg or browbeat support into helping them.
I can also already see the argument: "but that's not my data, it's in My Documents, it's a document so it shouldn't be encrypted!"
Communicating these things to users is hard because when it comes to computers, the lexicon is often personal. What one user calls My Documents might refer to the My Documents collection in Windows, and another one might mean a random folder they created that they put documents in. It's basically impossible to get everyone on the same lexicon, although it's getting better as young kids grow up with computers.
As someone who very much doesn't use iCloud for exactly this reason, I'd have a lot more sympathy with that argument if Apple didn't push everyone towards iCloud and the accompanying insecurity while simultaneously making it much more difficult than it needs to be to move your data between, onto and off Apple devices in other, more secure ways.
I’ve come to this conclusion. So what are my options since Apple keeps such tight control on everything? Plug in nightly to iTunes or libimobiledevice? Stand up an iTunes server for LAN backups requiring Windows or macOS? What about the 30-40% of nights I’m on the road?
I’m all for ditching iCloud for backups but Apple has made it really inconvenient to do automated backups with anything but iCloud. Libimobiledevice is slowly working towards LAN backups so we’re getting there but then I’m still in need of mDNS reflection to make it happen over WAN.
I’ve made efforts into tying as much of my data to self-hosted solutions as possible but full device backup on your own hardware is still a gaping hole in the iOS ecosystem.
Regular users just care that they don't lose their data. Offer them the option to keep it 100% secure from prying eyes at the risk of losing access to it permanently if they misplace the password, and 99% will tell you to pound sand.
Most people can tie their shoelaces, so may stores don't even bother carrying velcro shoes.
Likewise if the situation was inverted, hardly anyone would sell shoes with shoelaces.
When there's finite resources for businesses the needs of the many overcome the needs of the few
>99% will tell you to pound sand
Or they'll select it anyway because they don't really understand what they're doing notwithstanding big, scary warnings. A lot of tech people want everything to be configurable but that often is just not a good idea.
Bingo. We have a winner.
My sources inside Apple tell me that there was at least a partial implementation for doing e2e backups safely, including a system for using friends/family to certify recovery in the event of password loss (presumably something like secret sharing).
The FBI and Apple actively collaborated to prevent this from coming to pass.
> One former FBI official who was not involved with these talks told Reuters that Apple was won over by the agency. “It’s because Apple was convinced,” said the source.
Your claim directly contradicts the article.
Having friends and family take ownership of partial secret keys is a non-starter. Few people would actually go to the lengths of distributing fractional secrets to their friends and family. Even fewer people would do a good job of not losing them over the years.
Outside of techie circles, account recovery is a relatively frequent occurrence. The majority of general public customers would prefer being able to recover their account even if it means a vanishingly small chance that the FBI would be able to access it in the even of an investigation.
I feel like this is all a solvable UX problem. The secrets could be automatically distributed and stored on friends/family devices, could be integrated into iMessage directly. "Choose friends you trust to help you recover data." If N of your M designated friends and family still have access to their phone when you need to recover your backup then you can get access, maybe by presenting a QR code on each device you can scan, or a notification you can interact with after confirming identity via a phone call or something.
The secrets wouldn't require any actions to keep intact, they could always be synced into iMessage and included in your own backups. Kind of like you're operating a RAID array across your friends and family, N+X redundancy, so long as no more than X of your group needs recovery at the same time you're good.
Kind if an interesting approach actually, would be neat to build this into Matrix as an experiment.
I think the idea was, we already have multisig, where it takes M of N parties to perform a transaction. But that's no good for individuals everyday transactions.
But why can't M of N just be used to perform one special kind of transaction, which is "reset my password"?
And it doesn't have to actually be other people. If you don't have any friends you want to trust, the other M of N parts could all be other things of your own. Other devices, thumb drives, hardware keys, printed qr codes, memorized phrases, etc. Maybe some inconvenient to access but they exist if things get bad enough.
It seems perfectly doable, and the only reason the Apples and Googles of the world aren't doing it, or at least working on it, is because they're choosing not to.
Another comment actually said that Apple were working on this and eve had it largely worked out, and it was actively killed.
There seems to be no fundamental technical or user problem making good user security impossible. Simply too many powerful entities for their different reasons don't want most people to have it.
AMP was my favourite example. You could interpret AMP as Google ensuring a better experience for users, or as Google highjacking the web into a closed ecosystem to squeeze out competitors. HN threads about AMP almost always concluded that it was a terrible overreach by Google, anti-competitive, and bad for everyone. But an article suggesting that Apple maybe put the FBI ahead of users in this instance? Dismissed because OP is "inclined to believe."
I think in part a fair number of HN folks maybe do web dev work, and having google restrict the junk they can dump on users was annoying to them. A fair bit of the anti-trust rhetoric is not coming from consumers or consumer advocates but other businesses - some of which have just horribly seedy business models (the recommendation engine searching sites with all the auto-generated fake reviews complaining of de-prioritizations etc).
The app demanded cloud backups from me 8 times over 2 or 3 days.
Presumably so that returning users still have their messages intact.
I suspect Signal took a somewhat smaller number of users from FB than this.
FAR FAR too many situations where users don't keep their keys. It can be as simple as upgrading the chip on your computer - which happens with AMD machines because they've had a long run of AM4 socket support. Boom, you fTPM is gone now, and user is complaining they've lost their irreplaceable stuff.
I've seen this on IT side with backups. They set up an encryption key on the backups (pub / private) 6 years ago. 6 years later, when it comes time to recover under some time pressure, no one has a CLUE where the key is and old staff are long gone. Absolute nightmare.
For all the folks saying managing encryption keys at scale is like tying your shoes - 100% false. To manage keys (especially ones where the private key is rarely if ever actually used) takes very very HIGH levels of care.
One solution - have encryption keys periodically "fail" so you are forced to prove you know how to recover your key - but no one does that.
Same issue used to occur with 2FA apps on phone upgrades before they made it easier to move stuff over to new devices.
> iCloud backups include nearly all data and settings stored on your device. iCloud backups don't include:
> Data that's already stored in iCloud... iMessages... Health data
Only the more technical "about encryption" page [2] that most users wouldn't seek out contains the full story, providing a list of regular encryption vs. E2EE services and admitting the key issue:
> Messages in iCloud also uses end-to-end encryption. If you have iCloud Backup turned on, your backup includes a copy of the key protecting your Messages. This ensures you can recover your Messages if you lose access to iCloud Keychain and your trusted devices. When you turn off iCloud Backup, a new key is generated on your device to protect future messages and isn't stored by Apple.
The problem is that the first page makes it sound like no iMessage related data is backed up, when the truth is that the messages themselves aren't but a backdoor copy of the encryption key is, and lists it along with other E2EE services like Health data that do not have a key backed up and remain E2EE protected with iCloud backup. A user would have no reason to even seek out the second article to learn that it's not the same.
Concerningly, iCloud Photos are not E2EE at all. It's no more secure/private than Google Photos or any other app.
[1] https://support.apple.com/en-us/HT204136 [2] https://support.apple.com/en-us/HT202303
I mean, is everything iCloud compromised, all the time, everywhere? That kinda flattens Apples privacy claims.
The catch is that if iCloud Backup is enabled, the iOS device will make a copy of its private iMessage key and save it with the backup, rendering your messages accessible to Apple. This doesn't affect Keychain.
Other services such as iCloud Photos are not E2EE and are always readable.
The excuses of it being unwieldy are 100% because its not transparently integrated.
The average customer from the general public understands that they're not going to become the subject of an FBI investigation and they'd gladly take simplified UX and account recovery as a tradeoff.
It's no doubt a reflection of my social circle, but it includes plenty of people that barely know how to turn their computer on. Many of them are asking me what to do to protect their privacy and ability to communicate.
If I were Keybase right now, I'd be starting back up development and cranking out some marketing right about now. That's a huge opportunity.
Then any random client can hit keys.gmail.com (or whatever pseudo standard one wants for finding the key servers) cache public keys and on some TTL check for revocation/etc.
Then the only thing the user would have to know about is whether the from box is "green" indicating that the user was validated, "yellow" indicating an invalidated email, or "red" indicating a problem with the validation. Once the validation is complete via a back/forth exchange the clients then know they can encrypt emails to the destination, thereby turning the from field green on the next email exchange.
Sure people using those services would also be allowing the service to see their private keys, but for phone apps, or desktop applications the key generation portion could be done on the machine and only the public key pushed to the email providers keyserver.
Plenty of other email services (proton mail, symantec) make this very easy for the end user.
This whole "Apple cares about your privacy and encrypts your data" false narrative really needs to finally end.
This is pure speculation, but I wouldn't be surprised if this is why the government has been so lax on antitrust regulation with Big Tech.
Edit: I can't just let this lie. Just because you can't see it doesn't mean it's not true. The sky at night is still blue, there's just not enough light for human eyes to see it. I have plenty of footage from night skies where the sky is still clearly blue. This footage [0] is clearly taken at night while the moon is below horizon then the sky becomes blue again (still at night) when the moon rises. The light reflections in the water as well as still being able to see the stars in a blue sky shows the sky is still blue even at night.
* With the recent investigation into Apple [0] by the DoJ, I don't see this deal continuing for far longer. Unless the investigation is just for show.
[0]: https://www.businessinsider.com/biden-team-continue-scrutini...
The most likely reason we haven’t seen antitrust action is more boring: it’s hard, our politicians are old and don’t even use email, and they’ve been consumed with more pressing matters.