Even if you disable backups, whenever you correspond with someone that has backups enabled those messages are still accessible to Apple.
Even if you disable backups, whenever you correspond with someone that has backups enabled those messages are still accessible to Apple.
--
Messages in iCloud also uses end-to-end encryption. If you have iCloud Backup turned on, your backup includes a copy of the key protecting your Messages. This ensures you can recover your Messages if you lose access to iCloud Keychain and your trusted devices. When you turn off iCloud Backup, a new key is generated on your device to protect future messages and isn't stored by Apple.
This seems crazy to me. I understand that the problem of losing your key is a troublesome one, but this seems analogous to storing important information in a safe then taping the key to the safe so you're never in a position where you can't open it.
If the FBI thinks it's a great idea that should be reason number one not to do it, at least when it comes to data security.
It's then a question of if you trust apple to be this "someone". If you don't trust them, then you should probably question if you trust the system at all given most of it cannot be audited.
And also asking this same someone to take care of the safe.
While there maybe encryption in transit of messages, the encryption of messages at test is effectively defeated when the messages are at rest in icloud.
I am curious, is it possible to do an icloud equivalent backup without using icloud? Perhaps with a different backup app, nas, etc?
Ideally it would be nice if you could opt yourself out of having any conversations backed up, but I'm sure to Apple the privacy benefits doesn't outweigh the amount of customer support hours that would be wasted explaining to people why some of their conversations aren't transferring to their new iPhone.
itunes.
ISTR that local backups would contain more than the icloud backups as well - there are some things that won't be backed up into the cloud?
That's more of a problem with who you choose to communicate with and their security practices than a problem with Apple. The same counterparty could also have a weak/non-existent passcode on their phone, or is jailbroken.
Why the disconnect?
I literally never heard of this. There are problems with PGP (eg. no forward secrecy, non-reputability, unencrypted headers) but "your counterparty could be compromised" isn't one of them.
* https://latacora.micro.blog/2019/07/16/the-pgp-problem.html