This sort of encryption bears a heavy burden on the customer. And the customer often doesn't want to accept that burden.
This sort of encryption bears a heavy burden on the customer. And the customer often doesn't want to accept that burden.
Here it is from their own docs: https://support.signal.org/hc/en-us/articles/360007062012-Ne...
> An iTunes or iCloud backup does not contain any of your message history. Only new messages, not conversation history, will be displayed.
Frustratingly, if you forget the backup password you have to Reset All Settings on the device, no way to change it going forward if you lost the old one. Of course, there should be no way to get to the old backups if you don't have the password, but if you have access to the device (thus, the source of the data to begin with) you should be able to change it without a reset.
That is the problem. It's very frustrating to tell some people that they can't recover their data because they forgot the password
If you can keep a password for a long time then you can do your backups yourself I guess?
To be fair, this also describes Windows users. Most users of any platform are average non-IT people.
A web search shows this surprising stat, for all the user's services:
"78% of people have had to reset their password in the last three months. - HYPR study"
And 57% for work accounts. Wow.
Or to further your shoe store idea. The majority of people know how to tie their shoes. Most shoe stores usually don't keep a lot of stock of shoes larger than a US size 12 men's shoe. My foot happens to be larger. I have a different use case. So I often have to go through a different workflow (e.g. ordering online, having the store custom order my shoes, etc.).
If you want full data security, you need additional technical knowledge and a different workflow. iCloud isn't for you.
They could put a clear warning on the iCloud screen as well. However, there is a large market for the iPhone in non-tech savvy people, especially old people, who may not understand fully what this decision means.
People can, will, do, and did ignore any and all warning messages and then look to support to help them. It does not seem to matter how large, scary, or clear the warnings are. They will be ignored.
So if you're Google or Apple and want to ensure that people's identity documents or tax records or business documents aren't stolen when the laptop or phone is, you make encryption the default. It helps that these devices are easier to sell to businesses. I'm thankful for these choices.
In my professional capacity as an information security practitioner and my personal capacity as a privacy advocate, I find the idea at hand distasteful. Improved security should be available to everyone, not just those with a deep grasp of how to manage cryptographic keys. Gaining any measure of data security should not be reserved solely for us in the technical elite.
There might, perhaps, be a slightly different discussion to be had about making it more common for tools to enable advanced users to manage their own keys. But this should never come at the expense of the common user. We have a profound professional responsibility to be better than that.
Many people assume that that when it says "can't", it actually means "won't", and that they'll be able to beg or browbeat support into helping them.
I can also already see the argument: "but that's not my data, it's in My Documents, it's a document so it shouldn't be encrypted!"
Communicating these things to users is hard because when it comes to computers, the lexicon is often personal. What one user calls My Documents might refer to the My Documents collection in Windows, and another one might mean a random folder they created that they put documents in. It's basically impossible to get everyone on the same lexicon, although it's getting better as young kids grow up with computers.
As someone who very much doesn't use iCloud for exactly this reason, I'd have a lot more sympathy with that argument if Apple didn't push everyone towards iCloud and the accompanying insecurity while simultaneously making it much more difficult than it needs to be to move your data between, onto and off Apple devices in other, more secure ways.
I’ve come to this conclusion. So what are my options since Apple keeps such tight control on everything? Plug in nightly to iTunes or libimobiledevice? Stand up an iTunes server for LAN backups requiring Windows or macOS? What about the 30-40% of nights I’m on the road?
I’m all for ditching iCloud for backups but Apple has made it really inconvenient to do automated backups with anything but iCloud. Libimobiledevice is slowly working towards LAN backups so we’re getting there but then I’m still in need of mDNS reflection to make it happen over WAN.
I’ve made efforts into tying as much of my data to self-hosted solutions as possible but full device backup on your own hardware is still a gaping hole in the iOS ecosystem.
Regular users just care that they don't lose their data. Offer them the option to keep it 100% secure from prying eyes at the risk of losing access to it permanently if they misplace the password, and 99% will tell you to pound sand.
Most people can tie their shoelaces, so may stores don't even bother carrying velcro shoes.
Likewise if the situation was inverted, hardly anyone would sell shoes with shoelaces.
When there's finite resources for businesses the needs of the many overcome the needs of the few
>99% will tell you to pound sand
Or they'll select it anyway because they don't really understand what they're doing notwithstanding big, scary warnings. A lot of tech people want everything to be configurable but that often is just not a good idea.