iCloud for Windows downloading other people's photos
forums.macrumors.com
forums.macrumors.com
[0]: https://krebsonsecurity.com/2019/03/facebook-stored-hundreds...
https://support.apple.com/en-us/HT202303
https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...
iMessage is end-to-end encrypted, but a key to decrypt messages is stored in iCloud backups.
BTW both Apple and Google have a way of doing end to end encryption of backups with a recovery option in the case of device loss. Apple deliberately chooses not to enable it for iMessage and iCloud photos (it is used for keychain passwords among other things). Credible news reports state that Apple did this at the explicit request of the FBI. https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...
Also note that Apple policies prohibit anyone else from offering cloud backups for iPhones, so you're SOL if you want cloud backups and privacy. Apple's way or the highway.
A minor point of fact (I have posted this Reuters link more than anyone): a careful reading of the article does not specify an explicit request. It is very much implicit in the article. There is no direct reporting on the request itself.
It is obvious that there was an explicit request. The article simply strongly implies it, because Reuters will not report as fact things they can not verify.
The point I was trying to make still stands. The recovery options are a form of key escrow. They require a recovery code. As I'm sure you know, if you lose your device and forget the recovery code, then it's total loss – the HSM will reset after a fixed number of tries. People are plenty capable of doing that, and with a billion devices, some non-trivial number of them do it regularly.
So instead photos are unencrypted and still scanned server-side.
They can basically insert another "end" for the end to end encryption without any of the parties knowing.
You basically should never trust Apple / Google / Microsoft / Amazon / etc to handle your private information... ever. Use audited open-source messaging apps.
If we controlled all the code on our device and we could build the open source app ourselves that would go a long way. Otherwise you still have no choice but to trust your OS provider.
Nonsense. Understanding one’s own threat model is critical to deciding the acceptable amount of trust to place in these companies, but black and white thinking helps no one.
I’d be very glad if you could mention just one court case proving this.
I believe solving this problem is the crux of the next major breakthrough (if it ever comes) in privacy and personal security. I'm not even sure a solution exists, but a lot can happen when smart people put their heads together on a seemingly intractable problem.
Here's the original story: https://9to5google.com/2020/02/03/google-photos-video-strang...
Google is even worse, you can't contact a human. Their app reporting process insisted I create a Google account and report it from within Android's App Store if I expected them to take action. I have better things to do than jump through unnecessary hoops.
This could be very much like the technical cloud-based version of the fictional Tyler Durden splicing dick pics into single frames of 35mm film movies.
Based on what people use phones for these days some sizable percentage of icloud synced photos have to be something you really wouldn't want to get out there to random other icloud users.
Apple is required to hand over data without a search warrant over 30,000 times per year to US authorities.
https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...
> When you turn off iCloud Backup, a new key is generated on your device to protect future messages and isn't stored by Apple.
So it doesn't look like any extra steps are required.
Messages are all backed up twice by default: once from each device.
Turning off iCloud Backup is like migrating off of gmail to keep daddy G from reading your correspondence: it doesn't work when everyone else you correspond with is still being surveilled.
A glitch is just an exploit that just hasn't been sufficiently documented.
https://support.apple.com/guide/icloud-windows/use-icloud-sh...
The important and hard part in crypto is key management, but that's considered too complicated a concept to explain to users.
"Your Privacy Is Our Top Priority Security at the expense of privacy is not what we're committed to. Reolink Cloud collaborates with Amazon Web Services for secure data storage. Also, we use standard AES algorithm for data transmission encryption, use RSA/ECDHE algorithm for secure key exchange, and follow the TLS standards. When you save footage to Cloud or play clips back, your personal information is always kept confidential from beginning to end."
When they tried to encrypt photos end-to-end much of HN (and others) flipped out and raised such a fuss they gave up.
There is no evidence that iCloud was going to implement end-to-end encryption. This was a rumor that was spread by people who defended Apple's plan to implement on-device CSAM scanning.
That must signal some widely-objectionable, obvious implementation error that rubbed common people and engineers the wrong way.
That said, the option should at least be available to those who know the benefits and accept the risks.
We must not forget that most of us over here have affinity with technology to at least some degree.
We might manage just fine, but it's way above our grandparent's heads.
I'm currently using Onedrive (with Office 365) as my main data backup...
https://www.macrumors.com/2021/06/29/icloud-data-stored-on-g...
Assuming these are even from iCloud in the first place, they could have been their version of "stock photos".
Assuming these are from iCloud, could have been the user's previous deleted photos. Could also just be photos on their windows computer. So many options. Going straight for the most unlikely scenario is strange, and seems like people have an agenda.
All I am saying is that this is a very serious security breach if true, and everyone in this thread is taking a forum post at face value. There are a hundred things that could "cause" this, even if true.
The data appears to be improperly handled personal info. There is no evidence suggesting that the photos are from a "used computer" and the photos are directly downloaded via the iCloud for Windows client.
Guess iTunes has been sunset and deprecated by Apple Music - who buys music tracks these days ???.
I must be the only oddball that still curates and listens to his music on a PC (Spotify).
If I upload photos on, say, icloud.com, it'll turn up on my devices days later.
In 2022, that shouldn't be categorised as merely slow when it is basically broken.
This is a well-known issue with thousands and thousands of posts on various forums, with the usual answers of "Have you tried turning it off and on again?".
The photo sync functionality is probably the most broken part of the Apple ecosystem that I've encountered, and this security issue just proves my suspicions.