Apple dropped plan for encrypting backups after FBI complained (2020)
reuters.com
reuters.com
Under E2EE, assuming the device key is randomly generated, if you have one device (as many users do) and you lose that device you would lose all your data. The alternative is the key is derived from your iCloud password, in which case, if you forget your password, you lose all your data.
Right now, you can browse your photos online. There's been no statement that this is going away. Implementing this functionality with E2EE backups seem highly problematic.
These are huge changes to iCloud functionality that Apple would surely announce...
There are many open questions. And given that there’s no clear statement from Apple, I’m inclined to believe that they retain the ability to decrypt all data.
Google has done this for Android backups. Apple has actually done it too, but only for Keychain passwords and a couple of other things. So Apple actually already has an implementation of the right solution and intentionally prevents you from using it to secure your backups, reportedly because they failed to stand up to the FBI. Which is strange given their public stance in the San Bernardino case.
In the absence of an explicit announcement regarding these changes in functionality it seems unlikely to me.
If this client side photo scanning thing is part of an ongoing plan to eventually enable end-to-end encryption of iCloud, then Apple made a huge blunder. They should have waited until end to end encryption was ready first so that they could announce it simultaneously.
I don’t know how much I believe that, though.
Also, a big concern that people have is what the Chinese government will want to be censored. Researchers in the US can investigate that without fear.
This is all a good point.
Purely coincidentally, the imminent next release of iOS adds new account recovery options: https://9to5mac.com/2021/08/06/how-to-use-icloud-data-recove...
> The service requires Apple to maintain access to your data to help you recover it. For your privacy, Apple can’t access or help you recover your end-to-end encrypted information, such as Keychain, Screen Time, and Health data.
Seems to suggest that there is no change to end-to-end encryption on iCloud.
> If you create a recovery key and can't access your devices, Apple won't be able to help you regain access to your account or your data.
That sounds like E2EE backups, but its impossible to know if that is truly the case until they provide more details.
The scariest thing about this update to me is that it makes one's iCloud account incompatible (permanently?) with iOS and Mac devices that are not on iOS 15 or Monterey.
They could also make this opt in (add another escrow key slot by default, but allow you to promise that you've written down a recovery key and then destroy the escrow key slot).
Online browsing would use the iCloud password to decrypt the images client side. Thumbnails could be generated client side and stored alongside the images under the same key.
You can make this pretty transparent.
I don't know how this is with iPhones (I don't own one), but with Android these events are almost 100% correlated for many people. That's because you never get prompted for your Google account password on your phone. If you don't use the same Google account on your phone as on your desktop, or don't really use your Google account on the desktop that much to begin with (both apply to me and plenty of others I'm sure) then you might never need to know your password. I've seen people not even realise that they have a Google account, despite using one every day on their phone. Is there anything significantly different with Apple accounts?
In case it seems unlikely that someone would not use their phone account on their desktop, remember that plenty of young people today don't even have a non-phone device.
Comment 1: The problem with adding end-to-end encryption is that password reset is no longer possible (or it's possible but your data is lost)
Comment 2: You can come up with an end-to-end encryption scheme where you can reset your password and keep your data so long as you still have your phone (or when you lose your phone so long as you remember your password)
Comment 3 (mine): But if you lose your phone you often don't have your password any more, so that doesn't really help
By "Is there anything significantly different with Apple accounts?" I really meant does it often ask you to retype your password or otherwise force you to remember it.
This is so true. 1Password silently changed their UX on iPhone app 4 years (?) ago and the primary password was not required between app-quit. I had tweaked my password after using it every minute one weekend installing a new system. When I finally needed the master password, the new password was not accepted. Evidently I misremembered the tweak. That experience still burns me. Not forgotten, not forgiven.
iPhone requires iCloud for purchases, but I use touch password and bypass this. I never need to use iCloud password.
It periodically asks you for your password. If you get it right, it will wait longer before re-asking. If you get it wrong first time, it'll ask again more frequently (and let you pick a new one IIRC). Works pretty well against forgetful humans.
This is the risk most non-tech Apple users aren't willing or even expecting to take. No way Apple would enable this, even as opt-in, because many would misconfigure it, lose their data and blame Apple that failed them.
And good luck explaining they need to buy another iPhone and guard the two instead of one to be truly secure.
Seems like a 1A battle they don't want to fight, because the actual retaliation for the 1A exercise would come in the form of regulation or antitrust that is unrelated to the publication of the objectionable software.
Sad state of affairs in the USA.
A user provided key, not derived from the password.
Chrome uses (used?) this for History encryption, etc.
Apple (or whomever) could sell a "backup box": a simple embedded device with RAID 1 (mirroring) storage and the usual data/charging port(s). First time you plug an iphone into it you are asked to verify using the connected device to store backups.
The user then uses the "backup box" as their regular home charger. Backups happen automatically while charging. The user doesn't worry about keys; attack surface is limited to physically local risks (no network!). People already understand how to protect a physical device: lock in in a safe, move it to a safer location, etc. Instead of trying to solve the security problem for the user, give the user tool they can understand that allow them to protect themselves.
The hard part would be getting the US security apparatus to allow it. ALL major storage providers DON'T support end-to-end encryption for this reason. Not Google. Not Microsoft. Not Apple. Not Dropbox. Isn't this interesting?
Furthermore, talk of supporting end-to-end encryption is basically NOT in the Overton window in these companies as far as I know. Discussion of it is met by silence from management. It is weird when you begin to see the spider webs of power in society.
All those people positing that it this is an effort by Apple to push for end-to-end encryption are either disingenuous or wrong headed. If Apple even thought about end-to-end encryption, the whole US government would come down on Apple like a ton of bricks.
Apple has shown no recent indication of even leaning in this direction. Not only does Apple not directly support end-to-end encrypted backup on iOS devices to third parties, it precludes it from happening. You are stuck backing up to your Mac or jailbreaking.
EDIT: There seem to be a few small movements in this area. Dropbox has their Vault with pin based protection. Seems incredibly and intentionally weak.
> By design, this means that no one (including Google) can access a user's backed-up application data without specifically knowing their passcode.
https://security.googleblog.com/2018/10/google-and-android-h...
https://transparencyreport.google.com/user-data/us-national-...
But I do stand corrected on non-Google application data.
How do you restore from a different device? Oh, you only need the passcode.
I don't think so. The reason is there's no money to be earned with being simply a storage provider. Additional processing, indexing, workflow tools etc. is what people pay for. That's not possible with E2E encryption.
https://www.dropbox.com/features/security/vault
Why only pincode protection?
What about Dropbox Password? That seems to be zero knowledge?
They are two separate attempts in the security space.
For me it seems that latest changes do not change anything, FBI will still object with the same reasons as in the past, because they will have a legal obtained warrant and they need the user backups/phone content. I do not see Apple fighting this in courts especially now when they also have a big fight vs Epic and a fight vs right to repair.
Apple already gives up data on tens of thousands of users and accounts each year in response on requests from governments. Apple keeps statistics about those data requests here[1].
For reference, Apple gave data on over 31,000 users/accounts based on FISA requests and National Security Letter requests in the first half of 2020 alone[1].
During that same period, Apple provided data to the government's requests (non-FISA or NSL) about 9,000 times, and responded to requests for data with the data about ~85% of the time, and 92% in cases of "emergencies"[1].
On the other hand: Apple loves giving people reasons to have more Apple devices
And even if they did, how would we verify that the code they instruct our hardware to run does e2ee correctly, without bugs or backdoors? Apple doesn't seem to be in the habit of opening much of their code or (on mobile) allowing users to install unapproved builds. Unless that changed, I would be skeptical, just as I am of all "e2ee" software that cannot be independently audited by anyone at any time.
I spent 2 months going through the signal code base checking it and now I need to audit the production code on their servers as well as the binaries they have compiled. Any tips?
Also, it's a collaborative effort. If you build your binaries from the same sources that other people use, then you can split up the work, and you all benefit from anyone's discoveries.
Obviously, we don't have perfect verification of the code we run. People can overlook things. Compilers can be subverted. Operating systems can be pwned. Malicious hardware can undermine all of our efforts. But let's not let perfect be the enemy of good, and let's not fool ourselves into thinking that faith in a corporation is a substitute for transparency.
No more problematic than WhatsApp offering WhatsApp web (web.whatsapp.com) or Signal offering its desktop client while being fully end-to-end encrypted and routing communications through the phone.
I played a bit with crypto in a web browser using Rust and WebAssembly, and it works perfectly fine.
Apple has given that excuse before, but they could just provide the option with a serious warning, or make you jump through a couple of hoops first.
Apple is known for not bifurcating user experiences by giving users many options to choose from, but they are also known for their stance on privacy. I don't see why they wouldn't allow for this, maybe at first to trial it on the few that want it before deciding to roll it iCloud-wide.
If I were Apple, from a legal standpoint, I'd prefer not to have the ability to decrypt my users' data. Only in that light does it make sense to introduce the PSI/CSAM system on Apple devices, so you can claim you don't host such content, even if you allow users E2EE backups.
I don't want that on my phone because I'm not a criminal.
luckily, I haven't used an iPhone as my main phone in years.
I agree with this analysis
Like you've said, Apple haven't announced anything, and I don't see what the business case is from their perspective when most people don't know or care what that means (but surely will care if they lock themselves out of their data forever).
We also need hardball journalists to start asking Tim these tough questions instead of fawning over AirPods
And we need employees to start demanding this internally
"Apple's earnings for Greater China in Q2 2021 were up 87.5% from this time last year, to $17.7 billion. During its latest earnings call, Apple has announced dramatically increased revenues from Greater China for the three months ending March, 2021."
China has cracked down hard on domestic Internet companies over the past few weeks (deliberately crushing their tech stock market to rein in these companies and enforce governmental data surveillance/control). They're not going to leave Apple out.
Apple literally cannot lose that market. Its market cap would be halved. Saying they're going after child abuse in the US using a new algorithm is the perfect cover for gradual entry into enabling mass surveillance for China. No one can argue with the child abuse use case, but there will be plenty of consternation when this is used to scan for messages critical of Xi and the boys.
I don't really see how anybody could expect something different, specially here.
I still don't see the why though. It seems obvious to me that nothing is to be expected from corporations, other than a hopefully nice product at a reasonable price. Anything other than that sounds like wishful thinking to my ears, but I might be philosophically wrong.
Any good deeds a company happens to do, is for publicity and helping sales.
As pointed out this feature isn't even being launched in China.
But sorry to derail your narrative: China are the bad guys and all bad things are because of china.
Source?
As stated in the article Apple have said it is US only and will be switched on country by country… so surely if this was “BeCAusE ChIna!!!” It’d be switched on there first right?
[0] https://9to5mac.com/2021/08/09/apple-csam-faq/?_gl=1*l17q2t*....
> so surely if this was “BeCAusE ChIna!!!” It’d be switched on there first right?
Is all of your comments on here arguments?
Even if it was launched globally it didn’t at all invalidate my point. They would ban the entire App in question, not back door it. See Facebook/Twitter as a well known example.
Literally no one is saying this. You're getting incredibly sensitive over a regime that just thwarted investigation into a pandemic that has killed more than 1 million people and making irrational arguments to defend it.
"hey would ban the entire App in question, not back door it. See Facebook/Twitter as a well known example."
Ban *which* app?? The iPhone is not an "app" LOL. It's a hardware device with both software and hardware privacy constraints antithetical to the Chinese government's desire for pervasive surveillance.
Apple is gradually shedding its hardcore privacy stance to retain its fastest growing market. It's not difficult to see if you take off your "ANYTHING BAD ABOUT CHINA IS RACIST!!" goggles.
> China are evil, and that is the reason These pure US companies do bad things
China (the gov) is evil.
> is the reason These pure US companies do bad things
The companies are not pure. China certain does things to coerce them them to do bad things that wouldn't otherwise do. Some things are very bad. Some things aren't bad inherently, but are very unlike apple. Examples:
[1] Hong Kong app removal
[2] iCloud CN being run by another company.
> They would ban the entire App in question, not back door it
China already does this, except it's a phone not an app. They already monitor in-flight data [3], so likely not a huge concern for them, but considering the monitoring they do, why wouldn't this be a nice perk for them. Personally, i doubt that china required apple to do this since they already get what they want. I'm sure they'll love to (ab)use this though. I'm confident that a government somewhere wants this (new UK/EU anti-e2ee laws?).
China can't ban the iPhone, apple actually has that much political power. They are a huge poster child of chinese manufacturing power. Every time a senator asks tim cook to move manufacturing stateside and he says that only china is capable, it pumps china up.
[1] https://www.nytimes.com/2019/10/09/technology/apple-hong-kon...
[2] https://support.apple.com/en-us/HT208351
[3] https://citizenlab.ca/2019/07/cant-picture-this-2-an-analysi...
Then we agree. That is exactly what I said.
Re Chinese gov is evil - ra ra ra.
No they aren’t. Well no more than any other country. They just see the world and their place in it differently to you. But they haven’t invaded anyone since Ghengis Khan … yet they’ve been invaded by most of their neighbours and most of the American and European powers. In that context their view and action looks tempered, not evil.
You’re so right. For instance, the Chinese government sees that nothing of importance happened in Tiananman square in 1989 while the rest of the world sees a massacre.
Seems as though you’re the one feeding on a heap of freshmen-year college cultural equality propaganda.
Really? Chinese citizens don't use their iPhone cameras to store photos locally? They only use WeChat to take pictures and store them? Gee, you should tell Apple AND Tencent this! It would dramatically shift their product development path.
Where did Apple Messages come into play? What does that have to do with locally stored photos?
"This feature isn't even being launched in China" -- yup. Apple has definitely never launched a feature first in the US then rolled it out worldwide.
"But sorry to derail your narrative: China are the bad guys and all bad things are because of china."
Who said that? Seems more like you've got a bias to apologize for the regime than anyone else has a bias to impugn it.
That’s why I mentioned Messages… because that’d be the alternative.
Literally the OP said: “it’s China that is causing Apple to do this”… so in answer to your question: the OP.
Not apologising for the Chinese government. Do you call Biden administration a regime?
None of that makes sense. Why would using the system only to target child abuse in the US make people change their mind about using it against political dissidents?
If you go for a thing directly you show your hand and get a lot of backlash.
Case in point: the British NHS (because we can see it happening in real time).
Add the capability to do something for a good reason (NHS spending should be more efficient; we need approved suppliers // do it for the children) in order to make the further move of what you really want without much resistance (privatise parts of the NHS; eventually much of the NHS // back door every terrorist, dissident, detractor)
In this context, it is exactly how politics work, and you have described shifting the Overton window or even floating the Trial balloon.
re: NHS. The case you are making doesn't fit your reasoning. As for privatisation in general, the current government is following a very basic rulebook:
1. Sabotage/kneecap an institution/ 2. Offer a solution involving cronies/ 3. Achievement Unlocked
1. For example, some Tory MP's (the elite that make the decisions for the plebs) don't need to rely on NHS for healthcare exclusively, hence they have a callous attitude towards it. They deploy all manner of subterfuge, replete with claps, lies and smiles, to starve out a public service funded by taxpayers.
2. The ultimate goal; offer a solution to the problem you manufactured (1) and share the spoils amongst yourselves, by awarding/rewarding and looking after each other's interests.
3. Self-explanatory.
Scenario 1: Apple announces Orwellian system to thwart child abuse in the United States.
Scenario 2: Apple announces Orwellian system to thwart Chinese dissidence.
Which one sounds more palatable to you? To the world?
Apple *has* to take an orthogonal approach to giving China the surveillance capacity it desires. It can't openly enable a regime that just covered up and obfuscated investigation into perhaps the greatest human tragedy of our generation.
Apple wouldn't unlock a single iPhone for the FBI in a terrorism investigation... but it will deploy mass on-device privacy invasion for people who aren't even suspects to thwart child abuse?
Ask yourself: What changed?
If you believe Apple suddenly shifted their privacy stance on a whim, and isn't being subtly pressured by the Chinese government to develop new means of device access and control, I don't know what to tell you...
Your claim is that somehow scenario one makes scenario two suddenly palatable. Like people will say "oh, they ran an allegedly limited surveillance program for the US, so who cares if they run an unlimited one for China?"
>Apple wouldn't unlock a single iPhone for the FBI in a terrorism investigation..
Apple willingly offered to help unlock that iPhone. They're methods were blocked due to police mishandling of the device, and they were unwilling to pay to develop a backdoor for their own product.
>If you believe Apple suddenly shifted their privacy stance on a whim, and isn't being subtly pressured by the Chinese government to develop new means of device access and control,
This thread is about the FBI getting Apple to continue allowing easier access to devices. You brought up the example of the FBI trying to force Apple to allow them to access their devices. And the most recent event is Apple's surveillance of American devices. Yet somehow, you think the only possible reason Apple may be changing their stance is China.
2. Apple has always been less pro-privacy than you claim.
3. Everything mentioned here involves the US wanting more access. You claim that is proof of Chinese influence, rather than the obvious US influence.
I'm not seeing a multitude of spelling or grammar mistakes either, though I will admit that one sentence was poorly constructed. And I see a wrong "they're" I blaim on auto complete, though still my fault.
I see what you did there. Touché.
China could also ban manufacturing there. That would suck for AAPL too.
Cui bono?
Why does Tim Cook need to address this? To benefit Apple shareholders? To assuage the doubts of Apple customers who bought the false claims that Apple has made regarding their respect for users privacy?
Truth be told I don't think that Tim Cook as CEO of one of the richest and most powerful organizations in history needs to do anything because Apple has their customers by the balls. What are the few Apple users who even care about this issue going to do? Switch to Microsoft? Linux? Hah!
Face it, Apple users have made their bed and now they have to lie in it. People have been warning them for years about the Faustian bargain that they were making and how it was corrosive to society to entrench an entity like Apple and now here we are.
What false claim have they made?
Seems like this is still true. CSAM checking only happens when you choose to upload your photos to iCloud Photo Library.
You get downvoted around here if you make remarks critical of Apple users.
Well said. They now finally realise that Apple Inc. was never their friends in the first place, like I have always said.
They cleverly used privacy as a marketing trick to lure them to buying into their ecosystem and to cover their suspicious acts under the reason of 'protecting the user's privacy'.
Given there are lots of Apple users buying M1 Macs, it is more likely that they would need to back up / restore from iCloud as they already do this on their iPhones.
So yes, they are so entrenched and locked in the Apple ecosystem, they won't move and will stay there for good, no matter how many times Apple screws them over. They are not your friends and only on the side of profit.
If anything, this is the only thing which can actually get Apple to reverse their moves. Similar to what happened to Google.
It is an extraordinary claim that requires extraordinary commitment and action. To me, at least, that means privacy without compromise - and for everyone. ("Fundamental human rights" apply to all of us, right?)
Privacy with a bunch of disclaimers attached to it indicating all of the conditions under which your privacy will be abridged is not privacy. And it's certainly not the behaviour of a company that treats privacy as a "fundamental human right".
Apple needs to get a grip when it comes to dealing with and living up to this self-stated core value. I think that given the waves created by this CSAM on-device hash checking announcement and the questions many have about how to square this with their privacy talk, Apple's executives should say something and they should be unequivocal in what they say.
What's more important? Your right to "privacy" (which you can still invoke by simply not using iCloud) or their right to a normal life?
And yes, their CSAM detection has lots of false-positives, but it will evolve. It will be doubleplusgood.
[1] https://www.cdc.gov/violenceprevention/childsexualabuse/fast...
My right to privacy of course because the other option is a strawman. What you are doing is the typical slippery slope of selling out something for everyone because of a small minority of criminals.
"Should criminal Mr. X be allowed to do Bad-Thing-At-Level-10 to Small-Amount or should we do Bad-Thing-At-Level-1 to Everyone?" None of these are correct. Both are or should be illegal.
Did you look into this? Because those who know how this system work says that not only will Apple's system not work it is also clearly illegal:
https://www.hackerfactor.com/blog/index.php?/archives/929-On...
This is getting rolled out in the US, with one of (if not the) biggest populations of innocent people being put in prison in the western world. Where mass-surveillance is, well, massive. If this hasn't specifically been made to be abused as a backdoor it will quickly any way.
Americans must use every legal and constitutional tool in their arsenal to fight abuse and protect their children. The numbers make clear that the old rules no longer work.
And it's "clearly illegal" because of... what? Because his (unnamed) attorney claims it's a felony? What if a different attorney claims it's perfectly legal?
It's just a CSAM detector for content you upload to iCloud. We're willing to shut down schools and shops to save lives but if there's a theoretical .000001% chance that some rando might look at my beach photos, it's suddenly mass-surveillance backdoor China stuff? Come on. We live in a society.
https://www.cdc.gov/violenceprevention/childsexualabuse/fast...
You're trying to play to people's emotions by emphasizing the perceived gravity and prevalence of the problem of sex abuse in general, and then trying to use that emotional momentum to argue for something largely unrelated.
They could start by regulating guns. That would prevent the death, injury, and traumatisation of many children[1]. As a bonus, it would do the same for adults[2].
Or they could deal with the “urgent and preventable crisis” of having 1 in 6 children living in poverty[3].
People in these discussions aren’t against protecting children. Rather, they’re questioning the ulterior motives behind specific policies. If governments and companies could be trusted to keep their promises and not overreach, no one would be batting an eye at the recent Apple announcement. But historically, the inverse has been true: they’re pretty much guaranteed to try to abuse the system.
[1]: https://en.wikipedia.org/wiki/List_of_school_shootings_in_th...
[2]: https://en.wikipedia.org/wiki/List_of_mass_shootings_in_the_...
[3]: https://www.childrensdefense.org/policy/resources/soac-2020-...
Please take my reply in full. The third paragraph addresses your larger point—consider it in isolation and the argument stands. The first two are there to provide context—they cover the notion that many in power only care to “protect the children” when that slogan helps them reach their own goals.
Your posts were downvoted to grey; there’s nothing to “derail”. I’m pointing out to you that the larger discussion isn’t about CSAM, but about the very real possibility that CSAM is being used as an excuse for a stepping stone to a system which will be abused for unrelated matters.
If abuse happens at all, you've already lost. Detecting pictures isn't gonna undo anything that happened in them.
If anyone has experience with developing for iOS/MacOS on hackintosh, please let me know your experience.
If you plan to use it for work then buy a Mac. It’s a tool for a job.
There might be other build services for different languages.
How would going to a hackintosh and loading on the Apple software you are skeptical of help you?
With a Hackintosh, ask yourself if you really value your time. Couple hundred bucks for an M1 Mini feels very cheap in comparison.
You can run Linux as a host, macOS as a guest[1] under QEMU, buy a second GPU that is supported by Apple (e.g., Sapphire Radeon RX 580 Pulse 4GB) and pass that GPU in its entirety to the guest macOS. The same for one of the USB controllers on your motherboard. Effectively, you get native macOS performance under Linux. A bonus: you can use the iptables firewall with the FORWARD ruleset to control guest macOS network access. The overall setup process is involving, but nothing that an intermediate Linux user would not be able to handle. Please note that it might be actually illegal (?) in some (?) countries to run macOS software on non-Apple hardware.
But unfortunately, there is nothing out there that "just works". And how can anything exist if Apple has the size of a small nation.
I'm 99.999% percent positive there's nothing to worry about, but imagenet did have CSAM in it, so you can't be too careful. Really excited to build my own expansion cards. There's really affordable full SMD assembly these days from places like easyeda.
It runs well if you have the time, patience and expertise. There's no fundamental technical barriers. It's purely a matter of enough development resources being committed to the project. I think Apples recent moves would motivate more developers to work on it.
About 85% - 92% of the time, according to Apple, they responded to data requests from the government with the data that was requested.
I don't see why Apple would turn about face and make it impossible to respond to the requests that they choose to respond with data about 85% of the time.
Court orders are part of basic auditing of a service. Seeing what they have to hand over on request (they will hand over everything) tells you exactly what information they have.
Neither FISA/702 orders or NSLs are warrants though, and they do not require probable cause.
I didn't say they were. Apple specifies both FISA requests and NSL requests in their reports, and doesn't combine the two.
FISA can spy on Americans, and does spy on Americans[1]. Not only that, PRISM and other domestic surveillance programs are based on the Protect America Act of 2007 and the FISA Amendments Act of 2008[2].
[1] https://www.brennancenter.org/our-work/analysis-opinion/how-...
[2] https://en.wikipedia.org/wiki/PRISM_(surveillance_program)
I'm not sure how I feel about it, and I don't have a better alternative, but this sounds a lot less alarming than you make it seem. Do you know a better alternative?
Edit: damn downvotes, is this reddit? I'm literally asking because I don't know. nothing is controversial here
Source: I work in fintech
So that has nothing to do with the mechanism of securing data and everything to do with the finance organization compliance with the laws.
"Fintech" is a fancy word for a company doing financial applications, not a copout on financial regulations by using the "tech" word as an excuse.
There are a bunch of standards requiring encryption at rest and encryption in transit of PII and other data in finance. That does not mean that authorized users do not have access to it.
Apple knows which way the wind blows. If they piss off the USG spies, there are lots of "unrelated" ways to make them hurt, including but not limited to additional regulation or antitrust enforcement against their anticompetitive moneymaker App Store.
What this means is that if you are big enough, the 1A doesn't actually apply to you and you can't publish any legal software you like, because the FBI/IC/military will cause you to suffer even though you haven't broken the law.
https://9to5mac.com/2018/10/17/request-your-personal-data-fr...
Note that this won't include certain categories that are stored unencrypted on Apple servers, for example iCloud backups and other data in iCloud (files, photos, calendars, contacts, etc).
I was quite surprised to see that even excluding all the data they (often) have from peoples iCloud accounts, there is still a bunch of stuff they collect.
Aside: I really wish Apple would spend more time on end-to-end encryption, for example of iCloud calendar and contact data as well as (obviously) the backups.
They should also have developer guides for app developers, on how to build it into apps: common patterns (group E2E patterns, multi-device E2E, open-source data sync servers that apps could use to arbitrarily synchronize E2E encrypted data between devices, etc).
https://www.naut.ca/blog/2020/03/20/self-hosting-series-part...
This works well on Linux, and iOS 14. You can skip to the section `Compiling idevicebackup2`.
usbmuxd is responsible for wifi sync. However, it appears there is usbmuxd2 which is compatible with Linux and support wifi sync. I think you may be in luck! If you figure it out, please let me know.
Local backups won't get you privacy when the other end of the chat is still doing cloud backups.
It's sort of like moving email providers and continuing to send and receive email from people with gmail addresses. Google is still reading all of your mail and attachments, just out of your friends' gmail boxes.
Additionally, if the iPhone scans your local data for verboten files, anything you receive or have available to send via Signal would still get picked up and reported on.
In fact, given that Apple do not E2E encrypt backups and already implement CSAM functionality by scanning data in iCloud [1] it's not clear what the purpose of the new PSI/CSAM system is. Which leads many to speculate that it's only purpose is as a prelude to scanning all offline content.
[1] https://nakedsecurity.sophos.com/2020/01/09/apples-scanning-...
It was never going to stop at iCloud uploads.
Sounds more plausible to me.
Most of Apples customers are normal end-users, I can see how loosing access is worse for them as compared to data being available for a search warrant.
I suspect "risk of loosing the key" vs "risk hackers get access to the backup" is really what you want to weight here.
This was a massive PR hit for Apple that continues to this day.
My guess is that they saw encrypted backups as a solution to the leak problem, but the FBI has long used iOS backups as a back door into increasingly difficult and expensive to crack iPhones. Phone analysis is the #1 most common investigative tool for federal (and now, all) law enforcement, so turning off a major tool likely required intervention at the highest levels of government.
Big brother does not like losing their spying abilities.
Your device has become nothing more then a portal into their cloud and ecosystem. Where the fbi pretty much has free reign.
An enforcement agency should never be advocating against the rights of the people.
They expect to have rights that you don't have. They expect to violate your rights in ways the inverse would be a crime.
There are always those who feel themselves above the common person, and appoint themselves decisionmaker unilaterally.
This eventually happens in every country. There have been attempts to limit the scope and scale of spying, but so far nobody has ever been able to contain it. The US intelligence agencies now have utter control over the legislature and judiciary thanks to mass surveillance. There is no way to roll it back now. It's even illegal to talk about it in public, as Wyden and Snowden (and Clapper) have so fully illustrated.
There's software out there to do it, but it tends to be geeks-only FOSS tools or obscure "advanced" settings in backup engines on things like NAS devices. None of those things are mainstream.
The fact that a feature like this doesn't come built into things like Dropbox is puzzling until you consider that large companies have probably been heavily pressured against mainstreaming this kind of encryption. The absence of encryption as a standard option (even if not the default) in things like remote storage, cloud file sharing, and e-mail tools can really only be explained this way since I know for a fact that some percentage of business users would love it.
iCloud and iMessage suck anyways, you aren’t really losing anything of value
I'm actually curious how telegram and signal deal with this, I haven't researched that yet.
End to end doesn't work if the endpoint is compromised, and apple has that baked in as a "feature".
https://medium.com/@elcomsoft/forensic-guide-to-imessage-wha...
Signal; -Legal requests: Signal does not keep communication histories its servers. Since there is nothing to request, Signal conversations cannot be obtained with legal requests. -Vendor cloud: Signal does not keep conversations on its servers. Cloud acquisition is not possible. -Local backups: Signal does not store conversations in local (iTunes) backups. -iCloud backups: Same as above. Signal does not store conversation histories in iCloud backups. -iCloud Drive: No stand-alone backups in iCloud Drive. -File system: Signal database is encrypted. The encryption key is stored in the keychain with the highest protection class. Extracting and decrypting the keychain (e.g. with Elcomsoft iOS Forensic Toolkit) is required in order to decrypt the Signal database.
Telegram; -Legal requests: Telegram keeps a comprehensive history of the user’s regular (non-secret) chats on its servers. Regular and group chats can be obtained with a legal request depending on jurisdiction. Secret chats are never stored and cannot be obtained with a legal request. Telegram is notable for ignoring legal requests in some jurisdictions, which had led the service banned in several countries. -Vendor cloud: As mentioned above, Telegram keeps the history on its own servers. By authenticating as a user, one can retrieve those communications (except secret chats) from Telegram servers. -Local backups: Telegram does not store conversations in local backups. Instead, conversation histories are synchronized using Telegram’s own cloud service. -iCloud backups: Same as above. Telegram does not store conversation histories in iCloud backups. -iCloud Drive: There are no stand-alone backups in iCloud Drive. -File system: Telegram does not feature any additional protection to the working database. Once a file system image is captured from the iPhone, extracting and analyzing Telegram conversations including secret chats and attachments is trivial.
And they can start showing ads on your springboard, but they don't because its not in their self interest. Certainly if Apple did this, it would be the end of iPhone dominance.
So hypocritical.
> On-Topic: Anything that good hackers would find interesting. That includes more than hacking and startups. If you had to reduce it to a sentence, the answer might be: anything that gratifies one's intellectual curiosity
Because someone found it interesting and curious with the state of things.