Apple introduces end-to-end encryption for backups
support.apple.com
support.apple.com
1) they just ate every other 3rd party "secure" backup services lunch just like they did to the Hi-Res music industry.
2) details of what they backup securely, besides photos (which is top priority for me): iCloud Drive: Includes Pages, Keynote, and Numbers documents, PDFs, Safari downloads, or any other files manually or automatically saved to iCloud Drive.
3)BUT, perhaps the BIGGEST news here is that Apple is making a backup statement to what they've been saying for years and what they've recently gotten negative attention on: They don't want your data. They're not Goodle/FB/Amazon. They're giving you 2TB+ of space and you can encrypt it to the point that you'll lose your data and they don't care -- they don't want to mine your data, they don't want to know what you store on there, the don't care to scan your pictures with AI 20 different ways, they don't want to monetize it, etc, etc., just pay them money for their service and transactionally they give you only thing that you want in return -- reliable, secure, private service.
seriously, anyone at this point advocating for any other phone/os/service out there besides apple is really going out of their way to swim up river.
I'm advocating for an open and interoperable ecosystem of operating systems, services and applications, which is the only way to ensure sustainable customer freedom. Unfortunately that ecosystem doesn't exist yet so we're stuck with the duopoly of evil-doers (and while Google openly admits it is their business model to monetize you and your data, Apple has been caught with their hands in the cookie jar a bunch of times already and they're just developing a sweet tooth, so...).
Full disclosure: I've been using only iPhones for 12 years and am still using one today.
The news articles in the main view are just top business stories from Apple News. I don't see anything ad like at all, actually.
What's particularly odd is that some articles have no ads at all. Some have the same ad repeated literally 3-5 times in a short 1,000 word article. And the ads are all trash. They seem like those awful chum-boxes you see on web sites. Who in their right mind thought this would be appealing to the typical Apple user? I mean, regardless, I have never intentionally clicked on any ad on the web in 30 years, and I'm not going to start now.
It's sad because it's exposed me to regional newspapers from around the world. I live in California and see articles from newspapers in Idaho, Utah, Connecticut, upstate New York, Dallas, Miami, Chicago, etc. and even from other (mostly English-speaking) countries like Canada, England, Ireland, Isreal, and Australia. They even include some (English-language) stuff from China. I don't normally see news sources that diverse on the web because it takes more effort. But the ads just make it not worth it to continue using.
I hate ads, but for most people paying some bucks a month to make sure their 2nd brain of photos/notes/passwords/texts/etc is totally (and now privately) backed up is a worthwhile insurance policy.
I think the argument that advertising iCloud plan upgrades in settings, where you’ll be pointed to if you run out of backup storage, is very benign as far as ads go. Although I do think that they should have a method to dismiss it(I don’t see this so I’m projecting that they don’t).
Windows even sent a notification questioning my choice to disable location tracking.
Unlike MS - you have to link everything with an ID when first setting up W11, no choice unless you go to extreme workarounds. Constant nagging and manipulation thereafter.
With that said, what platform are you using that has no ads at all? Presumably Linux on the desktop, which I can almost use. But unfortunately I can't use it on mobile, I have too many use cases in the personal and business world that require a 'normie' grade phone.
Advertising does not require that you spy on each individual person.
Google, for instance, used to show you ads based only on your search keywords.
This is still true. You basically never see personalized ads on search, since getting a contextual ad for cruises when searching for programming answers probably isn't going to end up with many clicks. Instead, it's only really 'Google Ads' (AdSense on other websites) and YouTube where personalized ads result in higher CPMs.
(Although Google does indeed use your search history for ad targeting.)
Yes, and it's not the advertising part that is evil. It's the part where they spy on every aspect of your life because doing so makes ad sales more profitable.
I don't think that is necessarily evil, but it certainly is embarrassing for Google since Google used to make fun of competing search engines for that exact behavior back when Google was still the underdog.
Spying on everyone's credit/debit card transaction data, on the other hand, is definitely evil.
> as Google said in a blog post on its new service for marketers, it has partnered with “third parties” that give them access to 70 percent of all credit and debit card purchases
https://adwords.googleblog.com/2017/05/powering-ads-and-anal...
Personalized is "we're showing you ads for local gyms because we noticed that you've been watching a lot of Youtube videos about workout routines". Or whatever.
If a digital panel switched to show me restaurants in San Francisco because they detected that I travel there a lot, that is absolutely personalized.
Similarly, if a maps service shows me restaurants near my destination that have paid for placement, thats not personalized. If they show me fast food restaurants on my route because I got directions to one previously, that is personalized.
It is a moot point because Apple isn't anti-advertising _nor_ anti-personalization. They are pro-privacy. Like Google, they will just move ad determination onto the device.
We don’t know that. We know that they put ads in the App Store, that’s it. I wish they did not, because it made the store even more of an unusable mess, but it really is not even in the same league as Google and Facebooks, systematic surveillance.
> increased pressure to sustained growth from shareholders
This sounds truthy, but is there any evidence of this? Apple is famously the company that tells rent seekers after more ROI above all to fuck off (both Jobs and Cook).
> I'm advocating for an open and interoperable ecosystem of operating systems, services and applications, which is the only way to ensure sustainable customer freedom.
Now that’s a real point, which deserves more than being buried after a paragraph of half-truths (and I almost entirely agree, FWIW).
> It's good to be passionate, but blind devotion is dangerous,
After starting a post like this, it is disappointing that you fell in the trap you warned the OP about. Being contrarian and using mis-informed tropes is not a good way of having a rational discussion. It is not being cool or clever at all.
One of my favorite CEO moments comes from Tim Cook on an earnings call: “If you want me to do things only for ROI reasons, you should get out of this stock,” And then more recently “If you're a short-term trader, do not invest in the Apple stock,”
I understand both, but it’s so odd to hear a CEO tell people “no, we don’t want your money” and I will grant that Apple is luckily not in the position of needing it.
For users to trust them as a guarantor of privacy and rights is naive at best if not outright idiotic. Since they comply with Beijing why would one assume they won't feed your data to Fort Meade and Brussels - who as a sidenote are planning to outlaw end-to-end encryption for major apps: https://www.patrick-breyer.de/en/posts/messaging-and-chat-co...
What Cook is saying is that Apple is in the enviable position of being to make long term plans. Not every decision can immediately be boiled down to an ROI calculation, but that's what short term thinkers want.
For example, how much has Apple invested to develop this E2E system (the tech, support, etc...), and what is the ROI? IMO, over the long term it should have a positive ROI, even if I can't draw a direct link from quarter to quarter right now.
They also put ads in Maps, Stocks, and News, and they "started asking people last year if they wanted to enable personalized ads on these apps."[0]
> This sounds truthy, but is there any evidence of this? Apple is famously the company that tells rent seekers after more ROI above all to fuck off (both Jobs and Cook).
"Inside the ads group, Teresi has talked up expanding the business significantly. It’s generating about $4 billion in revenue annually, and he wants to increase that to the double digits. That means Apple needs to crank up its efforts. "[0]
Plus the advertise iCloud in the Settings app with a red badge, which is just annoying.
[0] https://www.forbes.com/sites/kateoflahertyuk/2022/08/15/appl...
(I don’t use stocks and news isn’t available outside the US, or atleast Singapore/Taiwan.)
https://www.macrumors.com/2022/08/15/apple-could-bring-ads-t...
This doesn't mean they need to do it with targeting/data mining. I swear all the data mining does is show me ads for stuff I just purchased 3 days ago, and that's with google-level surveillance.
If all this additional surveillance, sorry "targeting", is that worthless why should we even consider allowing it?
I am an iPhone user since three years ago but if at some point I get a better deal elsewhere, I'm off.
And with Apple I pay extra for premium, and there is only so many ads[1] one can shove in before the premium feel is gone.
As for the targeted ads, I share your feeling that the targeting is badly over hyped, except you are lucky compared to me:
Ads for products I bought 3 days ago would be wildly relevant compared to most of the ads I can remember from Google. It was almost always scammy-looking dating sites. For a decade. Don't know what I did wrong but it seems there was a fluke with my account. Or they just god more money from scammy-looking dating sites than from anyone else.
Oh, and when it wasn't ads for scammy-looking dating sites it was pay-to-win games, and based on the ads you could be forgiven for thinking they were made by the same folks.
[1]: I'm no hardliner here: contrary to many on HN I actually see value in some ads and think I have sometimes made better purchases/been reminded to do things I wanted to do anyway.
Every time people tell me that AI is great, I remind them that the most frequent ads I see are: 'Goth Muslim hookups' and 'automatic chicken coop door'.
> We don’t know that
"Apple’s VP of advertising platforms Todd Teresi has been asked to bolster annual revenue into 'double digits' from about $4 billion today" (Aug 2022)
https://www.forbes.com/sites/kateoflahertyuk/2022/08/15/appl...
Double digits isn’t a major player. Google and FB are already making nearly 200B ad revenue each. If every Apple app and device showed ads constantly it still wouldn’t come close to the views that fb and web pages get to display ads used by Google and Facebook.
Just to put everything onto the same scale, 4 to "double digits" requires a 2.5X increase. "Double digits to triple digits" would require a further 10X increase.
If Apple is indeed going full adtech and data harvesting, there is nowhere for consumer left to go, no competitor.
And regulators aren't stepping in either - multuple companies were caught illegally selling private customer data and there were no consequences.
But I would agree it is not sufficiently deterrent for a company this size.
They clearly want a slice of that market, and they have the patience needed to wade in.
I can’t begin to imagine how irritated Tim Cooke is by the revenue Google and Facebook make from adverts on iOS and he clearly wants in on it.
Given that both those ad companies make revenue off iOS, it’s not unreasonable to aim for a similar level on the platform.
Wow, thanks for using your psychic powers to tell us what Tim Cook thinks and feels and share that exclusively here on HN!
...Unless you have an actual source for this claim?
The only way for a 2T business to grow is by expanding the Services business significantly, in some market that is already known to be close to half a trillion dollars in revenue.
You really think Apple is trying to make small change with ads in Apple Maps?!
The App Store, and their demand of 30% of all revenue that passes through an iPhone is the most infamous example of digital platforms rent seeking.
Google does not take a cut if you use an alternative app store (which isn't possible on iOS)
A bit of hyperbole there. 30% of revenue from sales of digital goods after the first $1m (15% before).
I’ve probably spent $20k on Amazon using my iPhone this year alone. You don’t think Apple takes 30% of that, do you?
Besides, it’s so funny when people use “rent seeking” as a pejorative. Like, yes, the reason my landlord bought this house for a lot of capital up front was that they believed it would be profitable rent it for much smaller amounts for a long time. What, am I supposed to feel entitled to use the house for free?
A bunch of years ago I made several hundred thousand dollars from the App Store. You know how much I would have made without the app store? Zero. Do you think I begrudge the 30% I paid, any more than I begrudge the rent I pay for this house?
I understand people who dislike the Apple walled garden and want no part of it. I do not understand people who want all of the benefits but expect Apple to provide it for free.
"People" including anybody from Marx to the left, all the way to Friendman and Hayek to the right, including Adam Smith...
Sorry, rent-seeking is milking assets without producing value (or with only minimal investment/maintainance costs). It's the opposite of a functional market.
>Like, yes, the reason my landlord bought this house for a lot of capital up front was that they believed it would be profitable rent it for much smaller amounts for a long time. What, am I supposed to feel entitled to use the house for free?
No, you're supposed to not want an economy where people don't mouch off of standing assets, but actually contribute to making value (and products and progress and stuff).
Rent-seeking 101: "Rent-seeking activities have negative effects on the rest of society. They result in reduced economic efficiency through misallocation of resources, reduced wealth creation, lost government revenue, heightened income inequality, and potential national decline."
Making money off of the App Store is pure rent seeking. It's maintainance and (very infrequent) improvement costs (negliblible compared to its profit) don't make it any less so. Heck, actual rented properties like houses also incur some maintainances costs on the owner.
Not quite - if you go over $1m in revenue you pay 30% on all revenue in the following year.
I honestly believe that if the App Store were to start now, they would feel entitled for a cut of all physical goods transactions that happen.
I don't believe Apple produces 30% of value when someone (hypothetically) signs up for Netflix on an iPhone. Apple's App Store actively hinders value creation when they prevent Netflix from using their existing saved credit cards to re-subscribe a user on an iOS device.
> Do you think I begrudge the 30% I paid, any more than I begrudge the rent I pay for this house?
It sounds like you saw value in something, and you paid for it. A competitive product would be able to stand on it's own and developers (and users) could make a decision on what product they wish to use - I'm sure that a lot of developers would continue to use Apple's payment infrastructure because they find it easier!
There must be a name for this fallacy, where one bases their opinions on speculations about how things would be different today if their already-held opinions had been true long ago. Some kind of retroactive confirmation bias?
> It sounds like you saw value in something, and you paid for it. A competitive product would be able to stand on it's own and developers (and users) could make a decision on what product they wish to use - I'm sure that a lot of developers would continue to use Apple's payment infrastructure because they find it easier!
You're not paying for the payment infrastructure. You're paying for the discoverability and distribution. I cheerfully paid 30% to reach a few hundred thousand users when I could have reached, maybe, tens of users on my own. I find it hilarious when people explain how I was ripped off with exorbitant fees.
And neither did Netflix and they haven’t allowed in app purchases for years and are still doing quite well.
They mean "rent" the econ jargon, not "rent" the thing you pay to your landlord.
See: rent-seeking
https://en.wikipedia.org/wiki/Rent-seeking
It's a bad thing basically by definition.
Unfortunately now you've unlocked the "haven't you heard of platform fees (Google Play) or walled gardens (Nintendo eShop) before?" tangent.
There is no new information here - some people are perfectly happy with Apple's walled garden business model as it is and/or don't think Apple should be forced to change, while some think that Apple should be forced to change it so that customers can have more freedom or developers can collect more money.
And 30% take rate of everything from your app including later subscriptions and services is extremely rent-seeking.
It just doesn’t make sense to their business strategy. Apple is premium, ads are the antithesis of premium. Just doesn’t make business sense.
Also the "necessary costs" argument for the App Store fees falls apart when the unmonetized apps are all free.
I want to make an iOS app. I've already paid Apple the $100 bucks per year or whatever it is, so I've "done my part".
Then, I want to have in-app subscriptions and payments, and I found a great service, XYZ, that does this.
So, on my own time, with my own device I bought (which by the way, in another money-grubbing move, HAS to be another Apple device, even though there are 0 solid technical reasons to force this), I write the app, I put in the integration for XYZ.
Can I publish this to large amounts of iOS devices?
Plus, are we actually comparing general use mobile computing devices to niche and mostly fixed computing devices?
In practice, no, a console is not a general purpose computing machine.
On iOS, by design, you can install almost any kind of application even without jailbreaking it. Which people do, you can have Excel and Maps and IDEs and whatever.
Consoles, by design, do not allow that. It's almost strictly meant for games and media.
And again. I don't care. Both types of walled gardens should be abolished.
But apparently we know that they will never put ads or sell our data pinky swear!
Despite the fact that they have already done so.
Once a brand starts to build large-scale mindshare, there is of course the inevitable brand-wars fanboy faction, but there also pretty reliably seems to emerge an anti-brand faction - this pattern is consistent across NVIDIA, Apple, and many other leading-but-controversial companies. The mere mention of these companies in a positive context gets another faction reliably winding up about how awful they are and how everything they do is actually fake and a lie and intended to rip off customers unlike my favorite brand, etc.
It's essentially another form of parasocial relationship - but it's a negative parasocial relationship instead of a positive one. People gain identity from opposing the brand-signifier rather than supporting it.
The existence of fanboy factions is oft-observed at this point, but I rarely see anyone acknowledging the opposite side - the people who just are reflexively contrarian and negative about anything surrounding a brand, regardless of any counterbalancing concerns or factors. The hateboy, if you will.
And blind hate is just as destructive to nuanced conversation as blind devotion. It's also destructive to actual progress - positive steps need to be acknowledged and encouraged even if you think it's still the overall worse option, and negative steps from a brand you favor need to be acknowledged even if you think they're still the overall better option.
To do otherwise is to oppose actual progress over what amounts to parasocial tribalism - in both directions. The hateboys are just as toxic as the fanboys to reasoned discourse.
I've just been extremely disappointed by their hypocrisy around privacy (which is a subject I'm very passionate about). They've betrayed my trust when they announced the on-device scanning functionality a few years ago; yes, I know they eventually dropped it after massive pushback from everyone that understands its privacy implications but before doing that they treated us "screeching minority" like dirt, I've never seen such condescending behavior from a legitimate company, especially one that I previously respected.
Their massive push in the ad space, combined with other scummy behavior (phone-home on macOS, backdoor access that sidesteps firewalls from 1st party apps, etc.) just paints a bleak future where all the big players (Google, Microsoft and now Apple) treat us like sheep; it's just so frustrating and sad...
Do we though?
And “ads in their products” but not “a major player in the advertising space”
[1] https://www.forbes.com/sites/kateoflahertyuk/2022/08/15/appl...
Or they could sell us a rugged iPhone with a removable battery and SD card slot to extend storage but keep the proprietary OS to keep the music/movie ppl happy plus keep out malware not sent via FISA warrant, but if they did that Tim Cook might jump off the top of the donut apparently, so they keep going the way you describe.
I'm sure 3.5 humans who want that will appreciate that product.
(Same for an sd slot.)
Especially paired with a form factor like the 6s for those who don’t want a phablet.
We aren’t talking about blind devotion, though, are we?
We have a tangible actual important thing. Apple can’t plumb our backup data for their own profit.
You want to be careful not to ignore information just because it doesn’t comport with your preconceived assumptions. At least consider weighing them against your assumptions? I’m never going to be against a cookie-based metaphor, but that doesn’t make it apt.
I ran my own Nextcloud instance for ~3 years, recently moved to Syncthing for simplicity. But that use case is more about making certain pieces of data available to all my devices, not for backups.
Still, I did appreciate the breadth of apps that one could install.
Agree with you there -- the data might be encrypted on Apple's servers but that doesn't mean Apple can't scan your data on your device and report the findings back to the mother ship. They've made it increasingly difficult to know or control what system processes do.
There's a fundimentally different approach to advertising by Apple than say, Google or Facebook. For one thing Apple isn't doing web ads. They've not got an adsense style platform and likely never will.
The ad network they're building is for inside their own apps, and likely eventually for app developers to integrate into their own apps - apps only.
In addition those ads are for items within their existing ecosystem, ie more apps.
In terms of data collection this means they dont need the insane levels of information that Google and Facebook collect. All they need is a rough idea of your interests, which can be gained from the apps you use, and your activity in their own apps. Everyone using an Apple device must know they store your location, so that ones an obvious no brainer.
They dont however need to know your browsing habbits. Would it help target better? Absolutely, but the whole aim of their ad network is to keep you inside apps, not browsing the web. If you're using Chrome, Safari, etc they cant advertise to you as again, its not a web-based ad network.
As data collection goes, the way they're doing it is about as least intrusive as you can get. Theres no following you around the internet going on, which has always been the biggest issue with Google and Facebook.
I'm not saying Apple is a 'saint' in all of this, but its not even close to the level of tracking other companies use.
The money generated there will affect behavior elsewhere. These walled garden profit centers always do - having disproportionate number of resources for the task and with it the ability to ignore the needs of the greater business.
That is no longer the case. There are projects starting to come out which are open source and building on top of AOSP like GrapheneOS, CalyxOS and a few others but those two are solid options at the moment.
I am not sure why GrapheneOS doesn't get mentioned here on HN but it's seriously a wonderful project that includes privacy features not available even on iOS. They are this far ahead of the game when it comes to privacy and security. Highly recommend checking them out.
Probably because with GrapheneOS you have to rely on Android phone vendors which lock down the devices more every year. In my opinion, this is not a sustanable solution in the long term. GNU/Linux phones could be more sustainable.
Ok, come on. What apple’s done here is great, and I personally use an iPhone, but you couldn’t think of a good reason to use anything else? An open-source OS?
I also encourage people to check if their devices are supported by LineageOS when they run past their support period, it can be a good way to keep getting security updates past official support windows.
The forums should list some caveats for the device if they exist, but don't assume just because it shows up on the list that everything will work perfectly out of the box -- double check to see if there are any downsides.
Also, I should bring up that LineageOS comes in two variants: one without Google services and one with Google services. If you want to actually de-Google your phone, check to see that you are not going to run into problems with the apps you use.
Occasionally I see people who don't realize how deep Google services can go on Android, which in some ways gets back to your argument about how "open" Android really is. So it's just good to make sure that your stuff will all work afterwards if you're planning to go down that route.
Sure, if you're so laser-focused on privacy that you want some obscure phone which will do nothing aside from text, call, and send Signal messages, go buy the weirdest one you can find. otherwise you won't be finding anything remotely enjoyable if it's not iOS or a major android flagship. And out of those options, only one respects the user's privacy and security.
* They are more and more into advertising business https://news.ycombinator.com/item?id=32520894
* Their executives admit that they want you and your family locked into their ecosystem (leaked emails).
Sorry, but advocating for them seems like very bad idea. Google was cool, pro-customer company once too. Until they had position to not be anymore. Open standards, without any vendor lock are only reasonable way.
I think you and I have vastly different ideas about what "giving" means.
I get 5GB of iCloud storage, unless I pay them £6.99/month for 2TB. No idea what the rate is over 2TB.
Have I missed a trick to getting this 2TB+?
(I have 7 Apple devices in my possession and have owned a further 2 that I've passed on to my kids; given the premium I paid for those I almost expect that I should get 5GB PER DEVICE, but of course that's fairly unreasonable in reality)
Your reaction is derailment because you grabbed the wheel and steered the topic down a road about you and your expectations of discussion standards.
Part of respectable human interaction includes humorous, short and sharp casual responses on occasion. In this case, the post was replying to someone who called Apple's storage limit "pretty useless"... so we're well and truly in the fun zone of casual conversation. Not sure what you're seeking, the equivalent of a formal meeting with diplomats and official representatives?
You then add on hyperbole to end of your reply that I'm expecting some sort of formal discourse. I'm commenting on the "linux distros", which seems irrelevant. Putting a ;)
Just imagine if more people made these sorts of quips out of the blue and how crap it would make the forum over time?
I wasn't aware linux distros would push the limits of 4TB cloud storage, so for me it was micro-informative. I also wasn't insinuating, I was asking you directly how much formality you want in online tech discussions.
All good. I don't want to drown in cheap karma-harvesting reddit posts either, but I don't see that happening here.
When "snark" is measured like spice in cooking, it adds flavour. I'm not suggesting popping the lid and dumping a jar of snark in the broth!
They do make a family plan for Apple Plus ($30/month) fairly compelling: 2TB per family member, Apple TV both has some good original content as well as serving as a quick index into most other stream services, the Arcade Games are fun enough, Fitness+ is something I use about 90 minutes a week, and Apple Music. That is a lot of “stuff.”
Then there are some things that Apple gives away for free. Their podcast app is free and lets you subscribe to a lot of interesting stuff that I might otherwise subscribe to Spotify for. Handoff saves me about 5 minutes a day. Anyway, I don’t much like the walled garden aspect of Apple, but for value and convenience they must be difficult to compete against.
This is an excellent point as to why you shouldn't even bother trying to develop software for apple machines. If it's anywhere near successful apple will just destroy you, after having taken a 30% cut from your revenue for years.
https://www.macrumors.com/how-to/set-preferred-music-streami...
Also Spotify has access to all of the APIs it needs. It just refuses to use them.
additionally, as far as i can see, those apps all free to download and you can buy their plans outside of the apple ecosystem and thus they get a free ride in the App Store without giving away any cut to apple.
You pretty much have to be on their store to sell something, which means you give them access to your sales and customers. Which is a concept that is absolutely wild in any normal healthy competitive landscape.
Then they'll monitor and if you manage to actually be successful, 3 months later there's an Amazon Basics version of your product.
It's so incredible to me how these practices get no push-back. There used to be a time where in the case of Windows, people were wondering if its fair that they ship it with a calculator program. Now you can just use your massive platform and extend in every possible direction, seize secondary markets, nobody seems to care.
* Amazon uses third-party seller data to copy the site's most popular products, an antitrust report by the House Judiciary Committee alleged on Wednesday.
* Former Amazon sellers told an antitrust subcommittee the company released new products almost identical to their own and "killed" their sales.
* Amazon has denied accusations of this behavior in the past. "We have a policy against using seller-specific data to aid our private-label business," Amazon CEO Jeff Bezos said in July.
https://www.businessinsider.com/amazon-uses-seller-data-copy...
Windows was artificially crippled by the DoJ ruling and not including a PDF reader by default. I, for one, like it when more is built into the OS by default.
How is this different than Walmart doing the same thing with their house brand? Or a sporting goods store, or any other store for that matter?
With everything that has happened with Apple since Job’s death, my trust has been eroded so much that yeah I still use Apple but they are the turd sandwich at the end of the day. I trust Google a percent or two less.
I like that they are doing with this E2E encryption. It protects against hackers better. It doesn’t protect against Apple though… they will still continue to sell the analytics on you. Which is fine if you don’t care.
Maybe images/photos isn't something they want to expand at this moment in time but let's not get ahead of ourselves.
Edit:The ocr and face recognition on the iphone is definitely more advanced than usual, thanks to the custom hardware on device.
Outside tech people I know at least
It's fine that very few people care Apple is very good at attracting customers without it anyway, so it's not the classical situation where we, tech people should feel sorry that non-tech people "just don't get it" and don't use Apple services.
And lastly, if indeed no customers care, then that speaks for even bigger respect toward the individuals working at Apple who pushed for this and made it happen. (But I think Apple believes this will be a good business decision, not altruism.)
Lol I would never advocate for any company I engage with to use apple products. Why? Because they suck.iphoto and iCloud are pieces of trash. Most basic thing like, delete local but keep cloud copy seems to be missing. Can't keep a iPhone synced and do this with iCloud. Lulz worthy sitcho.
Also can't even copy files off device easily. Can't put custom apps on devices easily. The company actively kicks back against things like, freedom of information, following standards, reducing e-waste.
You know some of us make decisions around the companies we support on greater levels than just feature a or b is present in device. Apple are a predatory company that in no way promote a software or hardware ecosystem that is ethical imho and they don't promote one I want to participate in.
I wouldn't touch their shit with a barge pole and ontop of this due to being IT everytime I'm forced to I'm mostly confused by wtf folks think is so great. I legit find the kids toy ux difficult to work with, borderline impossible.
I also like blowing clients away with simple tasks like....copying photos to a usb...browsing files on my phone on a pc. You know the basic stuff like they used to do when they were younger but apple cucked it along the way for zero reason lol.
See https://news.ycombinator.com/item?id=33898890.
> Can't put custom apps on devices easily.
You will, from May, thanks to the EU Digital Markets act.
> [...] simple tasks like....copying photos to a usb...browsing files on my phone on a pc.
You can do this with ifuse: https://github.com/libimobiledevice/ifuse
Downloading some random GitHub app to access a phones storage sure as shit won't be happening on any managed corporate devices I deploy. Or unmanaged devices tbh. That's the kinda shit I leave for quarantined VMs.
Data is still not easily accessible once it's on a iPhone.
Got forced to use a iphone 11 or someshit a few years back as a company issued device. Man it was alright at making phone calls, complete POS for doing any actual work on. Basically found it to be an overpriced paperweight that could take ok photos but was impossible to retrieve photos from. No i dont want a icloud account or any of that bs i just want to plug in to pc and pull files like I've been doing for 25+ years on every other platform ive ever used.
[1] I assume because then it's guaranteed the photos are stored on the phone, not just links to the iCloud versions.
[2] https://support.apple.com/en-gb/guide/image-capture/imgcp100...
Is this fact? Last I read about this the law was passed, but it's still unclear if apple will actually allow this.
I absolutely would love if I could use the latest version of iOS and install apps that are not in the app store. I'm currently using trollstore to do this but that means using older versions of iOS that are vulnerable to exploits.
That's an awfully bold statement! I'm quite happy in the Microsoft ecosystem for OneDrive, etc, and I'm not reading this and jumping to Apple. I'm not sure if most people care about these claims, and the people who are very security aware probably don't believe them.
No they don’t. They sell it to you
Otherwise apple likes to track your moves in the areas they do advertising on as much as everyone else.
They actually systematically scan photos and declare people to the police if IA determines it looks wrong.
With Apple, you’re at risk of losing your business just like with any other company who wants your data. Apple didn’t solve the “An offline account is better than a Cloud account” problem.
Obviously the commenter is talking about the new E2EE plan. No way to scan it then, under they do it on device, which they also walked away from.
Apple was developing this technology, but they dropped their plans.
[0] https://www.theverge.com/2022/12/7/23498588/apple-csam-iclou...
They DO want people's data, and they DO hoard it. If they didn't, they would share the source code with the community.
While it is a closed garden, I'll begrudgingly accept it can be marginally better in some fields than other options, but Apple tries very hard to be a proprietary island in a world that has switched to free software.
https://support.apple.com/en-us/HT212183#:~:text=Can%20I%20l....
We don’t cry over bitmaps vs vector graphics in most contexts, especially that the hardware is trivially limited. It’s probably a bit more nuanced with speakers, but I imagine that they also have very real limits on distinguishable outputs for a given input, even if it is not as trivial to see as in the case of a w*h pixel grid of depth n.
So yes, I think mp3/aac to CD, the change is very noticable. CD to HD (24bit), not so much
It might be possible that with very ($1000+) high end headphones about 5% of people could tell a difference, but even that is questionable. I have done many blind A/B tests with my $500+ headphone setup and no one has ever been able to accurately tell the difference repeatedly. There is absolutely no way that someone would be able to discern the sound difference between 320 and lossless on an AirPod-quality speaker.
I’m not sure about large speakers however. I assume that it’s equally difficult to tell any difference, and I couldn’t when I tested my setup. However, I have listened to some incredible $4000+ speakers before, and at that level I wouldn’t be surprised if differences emerged.
There’s so much snake oil in audio and placebo can effect sonic perception so heavily that it’s nearly impossible to find anything objective. There’s also a lot in the chain - the DAC, the AMP, room acoustics… that will effect the sound, sometimes substantially - let alone the speakers and the actual source.
While microphones obviously exist, you can’t measure sound the same way that you can measure the nits and white point of a monitor - it’s far more intangible.
Cross platform support is always a problem though. And frankly I don't buy the "like they did to the hi-res music industry"-- Spotify is still king here.
Their software is not open source. Before this announcement you had to trust Apple not to look into the files you store in the cloud, now you have to trust that they're actually going to encrypt your files and not save the decryption key. Ultimately you still have to trust Apple. A combination of any open source OS, any cloud provider and Cryptomator or Veracrypt wouldn't require as much trust in one company.
And the problem with all these services that provide some kind of E2EE encryption and still have a way to push application updates (or run something in your browser), is that they just slip a version on your machine that sends the password to the feds/whoever when you type it in.
Apple has very publicly refused to do this for law enforcement and there's no evidence they have or ever will
my comment was that against main stream companies apple leads the way, and it's overall great for a consumer.
do you personally expect every piece of open source software? do you run your own email servers, music servers, photo backups, etc.? If not, you somehow trust those companies -- why?
In particular, reviewing open source code has been repeatedly proven to be way harder of a task, than the proponents of this strategy are painting it to be. If you want an auditable codebase, you pretty much have to throw Linux, Chromium/Firefox, Gnome/KDE all out the window - there's just way too much code.
Auditable code is naturally always preferable to non-auditable, but you need to choose your trade-offs - or at least stop pretending you can read a hundred million lines in your life time.
On top of that - do you know a single non-tech person who knows how to set up a VPS, or knows what Veracrypt is? OTOH I can just show my wife: click here to enable backups.
Let me reframe the problem: What is your threat model? How much effort are you willing to commit to mitigate the dangers?
The crazy thing is that apple hardware beats most other hardware, too, at a high price. Better phones, better tablets, better laptops. More secure, more private OS than the popular consumer alternatives (Windows, Android). Arguably much better OS all around, too (at least IMO -- iOS beats even stock Pixel Android at use-ability, MacOS v Windows is like the Harlem Globetrotters playing the Washington Generals.)
For me, and I assume most others, it's not that we expect to read all the code ourselves. It's that there's a large developer community and security researchers who have access to the code who will collectively read it all. Of course this isn't a guarantee that there are no security flaws, and you still have the pipeline problem of ensuring the binaries you get actually come from the code you think they do. But all else being equal, I think open source provides a significant level of threat mitigation.
Even if you fully trust Apple not to intentionally back door anything, there's far fewer eyeballs on their code. Given that access to source code also has the potential to reveal security holes that may have gone unexploited, there of course a tradeoff here too.
Yeah, about that, I'm as much of an Open Source buff as anyone, but:
> Analysis of the source code history of Bash shows the Shellshock bug was introduced on 5 August <<1989>>, and released in Bash version 1.03 on 1 September 1989.
[...]
> The presence of the bug was announced to the public on <<2014-09-24>>, when Bash updates with the fix were ready for distribution, though it took some time for computers to be updated to close the potential security issue.
Especially older Open Source software tends to have maintainers that haven't adopted modern software development practices so we're back to square one, since most of this older software is foundational technology, like Bash.
I'm not implying inferior quality, I'm implying no correlation.
There was a very strong assumption from back in 1999, that "lots of eyes make all bugs shallow", with a focus especially on security.
In reality, there's no correlation.
You need those eyes to actually be looking at stuff proactively, you want automated scans, you want modern software development practices and CI/CD pipelines, you want those eyes to actually be qualified to look at what they're looking correctly, etc.
Just putting stuff out there and assuming "people will look at its insides" is a bad assumption.
Open Source in my experience is not inherently superior from a security perspective to proprietary software.
The Free Software world has had ample opportunity to produce something as carefully assembled, as smooth, and as capable as iOS, and what we got instead was Android.
I've watched the whole FOSS world happen in my career, and there are places where I cannot IMAGINE choosing a closed source solution, given my druthers. But it's also become super clear to me that the FOSS world isn't interested in producing polished user experiences. Sure, you or I could cobble together a FOSS-only phone-and-syncing stack, I guess, but I don't care to. Most people aren't us; doing so is beyond them.
Suggesting a normal person use something OTHER than iOS at this point is questionable at best.
Sometimes it works with a right BDFL, for some time (like Python). It also works with solo projects, and with projects with large commercial support (like Blender), especially those which don't normally accept your pull requests, except as a proof of concept (SQLite).
But the normal open-source model produces things like Linux, git, ffmpeg, VLC, etc, which are wonderful and have immense power, but are hardly sleek or excessively coherent. And each of them is much, much smaller than macOS or iOS.
The kind of person that uses Apple products/services cares about convenience. The person that uses the third party Android ROMs, in particular, cares more about the freedom.
It's more accurate to frame it as preferring low hassle to high hassle. Or to preferring well-designed tools to haphazard efforts. Or, from the other side, preferring some degree of DIY to turnkey products. (In particular, I think this is a HUGE piece of it; lots of hackers want to build their own toolchain, and then they get to feel noble because they're doing it for "freedom.")
I'm pretty "all in" on the Apple ecosystem. Each step of the way, I thought pretty deeply about my choices, and still ended up with an Apple option. But to characterize this as me caring more about convenience than "freedom" implies that I have somehow given up or endangered MY freedom, which isn't the case.
I'm able to do anything I want to do in this ecosystem. Macs are general purpose machines; I can build from source, and I can run code from any repository I want.
iOS is closed by design, and the result has been a very stable and predictable platform that I do not believe is possible WITHOUT that closed nature. I can't hack code on my phone, but I also don't WANT to. There are lots of appliance devices in my life I don't want to hack, and that I just want to USE.
I will admit, Macs are much better in the software realm, but the hardware has almost no internal upgradeability. There's some, but it's less. That's my point. And yes, many non-Apple computers also have that same problem. My gripe isn't with Apple. It's with companies who don't give maximal freedom with their devices, as I prefer more open systems, personally.
Sure. But this is also true of most modern, lightweight, thin laptops. And I'm pretty sure it's true of any phone worth using.
My experience is that a certain sort of FOSS person prefers theoretical freedom to actual usability.
The main reasons I left are repairability and upgradability; forms of freedom that you simply cannot deny Apple isn't great at, from design all the way up to policy. Privacy was also a reason. It is true that you have to place trust somewhere up the chain when it comes to the way specific software handles your data, but things like where it is stored and how it is encrypted are in your own hands when you DIY.
These things are not theoretical; if I want to use a different Wi-Fi adapter, a new SSD, RAM, a replacement screen, speakers or barrel jack then I can. There are parts available for very reasonable prices as well as the manufacturers' repair manual. It doesn't require solvents or esoteric tools.
Now I use a business notebook with Linux that is worse than the M1 in some respects, but in hindsight I'm willing to give up the battery life and cool runnings for the ability to repair and upgrade (and ports! Ethernet, yay!). Same goes for the phone (I went for a FairPhone).
It isn't as polished, very true. There's some rough edges and it takes a little more work, and yes, sometimes a bit of frustration. But the upside is tangible, it's not some form of feigned nobility.
Honestly, I suspect you just like having to tinker with your stack to get work done. (I mean, I've been there - I use OrgMode.)
Sure, being able to swap out parts is theoretically nice, but you'll do that maybe once in the useful life of a computer -- but I haven't needed or wanted to do either in easily a decade. How often does this really come up? On the other hand, you'll confront that lack of whole-package QA and general polish every time you turn your computer on.
And I'm really curious about anyone's privacy needs if they abandon APPLE for roll-your-own. Yes, it's all in your hands now, but most people don't have the time or inclination to be sure they're doing all the right things, security-wise and privacy-wise, to stay safe. There's a good chance your DIY approach is less secure than iCloud unless you literally do this sort of thing for a living. I mean, this is why I don't run my own mail server anymore (hello, Fastmail!).
So yeah, I think lots of people say "freedom" when they mean "I just want to tinker with my toolchain a lot and occasionally feel superior about it."
I use an HP 830 G5, a high end 13" thin notebook from 2018. It cost me 350 bucks. I sold my M1 for 70% of what I paid, and I can replace this thing for something similar, so it makes financial sense in my case. It's just a platform, I don't really care about the thing itself. It hooks into a thunderbolt dock for a lot of it's life anyway.
>Honestly, I suspect you just like having to tinker with your stack to get work done. (I mean, I've been there - I use OrgMode.)
I run Fedora 37 (35 and 36 upgraded without issue). I'm in the process of building a new house, which requires insane amounts of paperwork and communication as well as document storage and exchange. I need this to be rock solid, running E2EE on a NextCloud VPS in combination with this workstation setup does that for me. It's a little work up front, but it's been smooth sailing ever since setup was done. It just gets out of my way; I don't care about this WM versus that, this display manager, the whole systemd discussion. Everything except the fingerprint scanner just works, no tinkering required.
>Sure, being able to swap out parts is theoretically nice, but you'll do that maybe once in the useful life of a computer -- but I haven't needed or wanted to do either in easily a decade. How often does this really come up?
You can't predict breaking your computer. I managed a pretty large fleet of Macs for a living for about 2 years; build quality is great but they're not infallible. When they do break, you're at the mercy of Apple, and I simply do not have the time to wait for their repairs. With this setup, not only can I upgrade whatever, whenever, but anything that will run Fedora and has a modest amount of local storage can replace it for at least the time being.
Compare that to the situation I was in: Any repairs that I couldn't have DIY'd probably would have cost me at least the total cost of this computer (maybe even twice over) and would have put me out of business for a few days.
>And I'm really curious about anyone's privacy needs if they abandon APPLE for roll-your-own. Yes, it's all in your hands now, but most people don't have the time or inclination to be sure they're doing all the right things, security-wise and privacy-wise, to stay safe.
Sure, but I do. I simply hate surveillance capitalism with a burning passion; I honestly think there is a logical set of steps from that to political division and a worse world to live in. So I don't want any part in it. I must admit that that sounds like philosophical grandstanding, but I promise you it's a sincere belief. It's not so much about privacy from state entities; that's a lost battle in my threat model.
If you're locked into an ecosystem that you cannot easily get out of (and there's a BUNCH of dark patterns Apple applies to try and poke you to stay as well as the obvious loss of software licenses) you're a boiling frog. I see Apple going in a worse direction incentive-wise. Nowadays, I just don't care about where they're going anymore, it's not my problem.
Well, that one's not so bad, but is also mostly a commercially-supported endeavor and has been for a long time.
Now, the Linux desktop is a shitshow, sure. It'll remain that way until they can settle on One Windowing & UI Toolkit to Rule Them All, which looks to be happening never and is definitely in part a consequence of so many very basic parts of the GUI being swappable and having tons of competing options. Though the kernel's attitude toward providing stable driver ABIs (or rather, not doing so) isn't helping.
Some of us prefer Android to iOS :) Having used iOS as well, the one thing I miss in Android is Continuity. Other than that, I find Android gives me a better experience. I'm certainly an outlier in many ways though compared to the average user.
This is not the reason for security patches taking too long to be released to certain phones; Google has a monthly cadence of releasing security patches and zero-days have rarely (I can't remember a case of that happening but maybe it has happened) missed do you have a source for it?
> Oooh, ooh, no that's not my favorite thing, my favorite thing is how each cellular company gets to put their own bloatware on top of the bloatware that each phone manufacturer gets to add to it.
There are unlocked phones available and honestly this problem is mostly a US problem. Rest of the world isn't in the iron fists of their carriers.
> Oh wait, maybe it's patch support ending for new phones 3 years after they were released.
You can vote with your wallet and choose vendors where this is not the case; Google, Samsung and Recently OnePlus offer 5 years of security updates.
Yet and still Microsoft solved this problem years ago. Why can’t Google? Hell my 2006 Mac Mini got years of Windows 7 updates after installing Windows on it.
That's crazy, though. It's not like there isn't a module for that cellular modem, and they don't touch that code for every release.
That's like blocking a Firefox update because the Windows driver for the mouse could be impacted.
In the rest of the world phones are unlocked in terms of being able to use different SIM cards, but mostly the bloatware is still there and can only be disabled (not removed)
You mean the same OS that allows you to build your own open mobile OS as opposed to a closed source locked down OS that permits only 1 app store and 1 payment system?
>Suggesting a normal person use something OTHER than iOS at this point is questionable at best.
It's only questionable if you prefer the prison that is iOS.
I lol'd at "prison that is iOS."
Notably, the only other serious competitor in the space is also not open source. Sure, you can probably carefully construct a phone from only FOSS, with some compromises of course. But this is unfeasible for regular users, who have for all practical purposes only two choices. And those same users are unlikely to go for alternative replacements for built-in functionality just to reduce their exposure. Convenience wins every time.
I thought just a couple of months ago they wanted to scan everyone's phones for illegal content.
No, google has had encrypted android backups for years.
Well for your use case maybe, but I do not find the value of trading privacy for freedom to be a good one, specifically since I can secure my data other ways including not storing it at all on my phone.
My phone is a tool, and I prefer to own and control completely that tool
in financial circles, an immediate thought would also be "is such a person short AAPL?".
Count me in amongst the salmon then.
Note that they still want some data, especially given the recent increase in advertising activity.
Few examples: Still can't keep photos on iCloud and delete thumbs on the phone. A real issue my old iPhone had insufficient space and I had to move to OneDrive. Support for other operating systems is lacklustre. One of the core benefits of cloud is accessing your files anywhere when you need them, not possible unless you're lucky enough to find yourself on a Mac at that moment.
The other really annoying thing is you pay $3/m for 200gb or $10/m for 2tb… there’s no middle ground, I’d like to pay $4 for 500gb or $6 for a tb.
Fanboyism is expected, but this kind of statement is always bizzare to me. I run an aosp build with no Google software. How can a closed, proprietary system which pinky swears they will not do nasty stuff with your phone possibly be better than that?
Where are you seeing this?
This is a little hyperbolic. E2EE backups are fantastic; Apple seriously deserves a ton of praise for this. And iPhones have been getting a ton of security/privacy features that I really love, I am not going to dismiss their contributions to privacy. And while I wish some of their services like the Apple VPN/masked emails were better done, they are still fantastic features that I encourage iPhone users to enable, and that I am thrilled to see rolled out to a mass audience.
Alongside that praise, I am though going to point out that the adblocking on the iPhone is sub-par[0] because mobile Safari lacks Firefox's extension APIs, and I'll point out that their app store model blocks some privacy apps like Newpipe, which forces people into using more invasive alternatives that require stricter privacy controls. I'll point out that it is harder in some ways to get away from the default tracking that happens in Apple's apps than it is to root an Android phone and disable/swap Google services.
Threat model and personal expertise matters here; I like a lot of what iPhone do, but I also dislike a lot of what they do. Personally, I feel more confident in my ability to secure a rooted Android device than I do to secure an iPhone against the majority of privacy attacks I'm worried about. That doesn't mean that iPhones aren't the correct choice for a lot of people. I feel much less confident in a family member's ability to secure an Android phone if I can't give them advice or help them through the process.
And all of this is ignoring that privacy is one aspect of consumer freedom and rights. I think we can praise Apple for what is objectively a great move for privacy without being this over-the-top.
----
[0] Before someone complains, I'm not saying that iPhones don't have adblocking. They do have adblocking and I encourage you to use it, it's great. But that adblocking is objectively not as powerful or comprehensive as it would be to use a tool like Ublock Origin.
I don't think I've ever seen someone make the argument that Gorhill should be trusted less than the advertising industry, that's a new one for me.
People get really offended when I bring this up. I'm not saying that Safari adblocking is useless (you should use an adblocker with Safari, and there are devs doing excellent work to get around Apple's limitations, I have a lot of respect for them), but you are making a tradeoff for that sandboxing/permissions in the form of a less effective adblocker. This isn't just me saying this, if you talk to people writing iOS adblockers, they will tell you the same thing.
If you are so scared of Gorhill that you need to make sure he isn't tracking you, then sure, make that tradeoff. Or more realistically, if there are other privacy features on iOS that you care about more than adblocking, then make that tradeoff. But it's not just silly to pretend that the browsers are equivalent, they aren't.
And it's even sillier to pretend that an Open Source standard in adblocking should be rated higher on someone's threat model than the actual websites that are tracking you when you use a browser.
Once again, it's OK for people to like iOS or to point out that it has some excellent privacy features that make it a good choice for privacy-conscious consumers. And I'll give Apple praise that on iOS, the default browser supports an adblocker at all -- it doesn't require you to install a separate browser to get access to one. But we don't need to get hyperbolic and start arguing that Apple is somehow leading the pack on literally every single privacy issue; they aren't. It's OK to say, "in this specific issue, it isn't possible on iOS to get the same anti-tracking behavior that we could get on Android or on a desktop PC/Mac."
Did you personally vet the open source code? Did you compile it from scratch and install it on your phone or are you trusting it’s the same code?
https://github.com/gorhill/uBlock/wiki/uBlock-Origin-works-b...
This is specifically looking at (pre-manifest-V3) Chrome, so there are some other differences with Safari, but CNAME uncloaking is the most obvious example.
See also some of the previous comments I've made about this in the past (https://news.ycombinator.com/item?id=23622206). A few of these details might have changed (I vaguely think I remember Apple raising the rule limit), but I think the fundamentals are all still true.
> Did you personally vet the open source code? Did you compile it from scratch and install it on your phone or are you trusting it’s the same code?
I have read through parts of uBlock Origin's code, yes, but ultimately I'm trusting the broader Open Source community to say it doesn't have holes in it. And yes, I'm trusting Mozilla's vetting process for its "trusted extension" category. I think that's a reasonable thing for most people to do.
Of course, I could compile the extension myself, but I think to a certain degree that would be security theater.
----
Again, just really surprising to see an argument that boils down to "this Open Source application might potentially spy on me, and that's a greater danger than the websites that I know are actively spying on me right now." If Safari adblocking is good enough for you and your threat models, great. You don't need to justify that by pretending that uBlock Origin is insecure.
I will note, by the by, that Safari's limitations mean that (at least on desktop) the top-rated adblockers like AdGuard have shifted to running as external applications separate from the browser (https://adguard.com/en/welcome.html). This is not a dig at AdGuard, I think the AdGuard devs (as of last time I checked) are doing really great work. But if you're worried about sandboxing, running a desktop app is a lot more invasive than running a browser extension. I don't know if there are ways to do the same circumvention on iOS, so it's possible that AdGuard devs are staying in the browser sandbox there; I'd need to double-check.
Of course, you can use apps like AdGuard as pure extensions in their more limited form (I don't recommend a specific iOS app, but unless something has changed since the last time I checked, AdGuard is a solid choice) -- but you will get a more limited adblocker as a result. The performance might be good enough for you, and that's fine. But it's still correct to say that it will be more limited.
----
I will also add to this just to preempt anyone arguing otherwise that I am not saying that browser extensions shouldn't have better sandboxing. They should, extension sandboxing is awful and it needs to improve. What I am saying is that the specific sandboxing model that Safari uses (and that Chrome is moving towards) for adblocking limits their effectiveness.
What if it's for somebody that wants to play Fortnite on their phone?
... so, they... didn't? Plenty of those services, including Tidal, probably the most prominent one, still exist.
> seriously, anyone at this point advocating for any other phone/os/service out there besides apple is really going out of their way to swim up river.
This is the top comment in this thread right now, and I'm guessing it's because the readers of Hacker News value satire. If Apple's ecosystem is so bewilderingly excellent that nobody in their right mind would choose anything else, why did Apple start offering a bunch of their services, like Apple Music and Apple TV, on other hardware ecosystems?
> they just ate every other 3rd party "secure" backup services lunch just like they did to the Hi-Res music industry.
Except they only control 50% of the smartphone market and 15% of the PC market. So there is still a large market they're not covering
Can I buy something from my local supermarket without them knowing what I bought? Can I create an EC2 instance on AWS without Amazon knowing who created the instance?
I don't like a super powered monopolistic company as much as the next guy and I totally agree that ads situation in App Store is not a straight business but come on.
Some people want to use their computer completely privately and that's totally fine, but when you are using a cloud service, they probably will know how you use it. What they do with that data and how they handle it on the other hand is of importance. The problem with the whole tracking fiasco starts when the provider sells your data or "access", collected using dark patterns for example to others.
Can I buy something from my local supermarket without them knowing what I bought?
That is stupid, yes you can easily if you don't use their fidelity card and eventually that you use cash!That still leaves the purchase data freely available, and if you purchase the same kinds of items regularly you can probably build a profile. The purchase data itself is still valuable and still tracked.
Tell me your secrets! :P
You just have to let two empty spaces in front of a sentence. Not less, not more, just 2.How will they do recommendations if they don’t keep track of what you listen to? How will they do recently played lists?
How will they know if they should send notifications to your phone for your apps if they don’t have a record of what apps you have installed? All notifications are bundled together and sent from their servers to save battery life.
what you're describing is not the norm and those options should always be available, but the effort to value is simply not there to large portions of the mobile users.
iOS still doesn't allow you to sideload without shenanigans (requiring your to not only have a Mac, but also have it resign any custom apps every week is beyond unreasonable). Some people don't care about that, but I do and not being able to do so is 100% a dealbreaker for me.
Not using Apple because you disagree with their decisions does not make one intentionally "going out of their way to swim up river." It just makes one a normal person who doesn't want to use, what it to them, an inferior product.
> the don't care to scan your pictures with AI 20 different ways
This is especially ironic as another post on the HN front-page today is about Apple giving up on their plan to scan iCloud photos for CSAN after months of pushback.
sideloading is a deal breaker for me, so I'd rather stay out of the walled garden on my Android
This is not something to celebrate IMO, Apple keeps doing this and then pushing out the 3rd party options either by pure positioning and bankruptcy or by app store policy.
The result is no choice, no competition, and over time a worse product due to absence of market forces ... beyond the high resistance threshold of getting bad enough for a user to flip the table and exit the entire iOS ecosystem they've invested in - this is the danger of 100% vertical integration.
Did Apple ever implement the ability to run software without first phoning home and asking for permission? The last time I checked they had not followed through on their promise to do so.
https://www.howtogeek.com/701176/does-apple-track-every-mac-...
https://mjtsai.com/blog/2022/06/16/apple-reneged-on-ocsp-pri...
https://security.googleblog.com/2018/10/google-and-android-h...
Google Workspace also apparently supports client-side encryption/decryption.
wouldn't be photos scanned on the iphone? - not sure if it's all local or goes to the mothership
Really? Isn't this the same Apple that told the FBI that they could get access to a suspect's data from their iCloud account. And the same Apple that was part of the US government's PRISM program to sell user data to the NSA? What makes you think people happy with competing services will jump to them blindly?
> They're not Goodle/FB/Amazon.
They are exactly like them. All of them claimed they care about user privacy, before massively collecting the private data of their users and then exploiting it.
> ... reliable, secure, private service ...
Reliable, sure. "Secure" is debatable when the keys are stored on the iDevices that only Apple can access any time. "Private" is laughable when every Apple product now comes with a disclaimer / popup permission informing that they will use your data to enhance personalised ads served to you by their ad platform.
This comment is made every time Apple makes one step forward but it's apparently easy to forget that Apple also took ten steps back.
I'm using LineageOS + MicroG happily and there are other alternatives that don't buy into any of these big corporate monoliths.
I'm not swimming up river but you are carrying water for a multi-trillion dollar behemoth.
Apple is hella late to the game encrypting data and you better bet there's a backdoor to getting that data if an FBI request comes in.
What's the truth though? Are they able to coordinate with law enforcement if needed or not? I find it hard to believe there's no government agency paying attention to iMessage of criminals. Am I mistaken?
If there's anything I learned about any offers made from big tech, I would never trust any of them until proven for long-term usage for half a decade at bare minimum.
3-2-1 strategy is still a proven method for decades and will still be over any cloud services out there, including iCloud's.
Not sure how common is my attitude but I do not give a flying fuck about what Apple does. I keep my own backups (been doing it since the 80s). Today's Apple to me looks like a money company that makes some hardware by accident.
and in general, the less I attached / depend on a single company for anything significant, the better I feel.
Whatever they say and do, they'll eventually revert to that simple logic when it matters.
If you want to unload photos out of your devices with assurance no one's gonna look, buy a NAS and dont connect it to the internet.
I think FB really wants data about your behavior but based on what they’re been doing with chat security I don’t get a sense they want to or need be able to read through peoples chat history to get that.
This kind of thinking is a lot more dangerous than OEMs not giving us better privacy and data protection.
re: point 3 - they really TRIED to scan all your data with your CSAM tool but got too much pushback. They are only doing this now because they are dropping CSAM and trying to garner public favor.
What's stopping them from doing this scanning at acquisition or access by the user? We already see Google running models on your phone for things like Magic Eraser.
All Apple has really announced here is that if you're using Apple Apps and Services then they're the only ones who can mine your data. This pivots nightly into their Ad Services.
Their devices are still sending a bunch of telemetry. They're still in the ads business
Not saying that this recent move is bad, it's good to see. But at the same time, I'd rather manage and encrypt my own files on my own dfs than get trapped in the walled garden
In every country they operate in? Especially those run by dictators, autocrats and wannabe dictators/autocrats?
If not would their next Ad or Speech on humanity, morals, rights, privacy and other virtue signalling include a disclaimer that those are not available in such countries?
I'm baffled that the information security requirement has reduced from zero-trust to trust the shiny hardware maker because 'they say so'.
> anyone at this point advocating for any other phone/os/service out there besides apple is really going out of their way to swim up river.
I'd happily swim (or) drown trying instead of blindly trusting privacy claims of a Child labor exploiting, Union Busting, Virtue Signalling insanely hypocritical ultra-mega corporation.
This does not in any way make me want to switch back from GrapheneOS.
Probably. Android is getting locked down with remote attestation anyways. There's no point to it anymore, might as well choose the better tended walled garden.
If they don't want their user's data then why are they running an ad business?
I genuinely refuse to believe a real human wrote that sentence, there's just no way, right?
Photo checksums can't be e2e encrypted huh? They reported today they abandoned their plans to do CSAM scanning on people's devices[1] and connecting the dots it seems like they wont need to since they can just do it in the cloud.
[1] https://www.wired.com/story/apple-photo-scanning-csam-commun...
I mean, unlike perceptive hashing, cryptographic hashes do not lie.
If that article is correct it doesn't sound like they've abandoned the idea at all, only modified. It's still the same thing essentially, they check your file hashes for "known illegal images or other law enforcement inquiries".
Edit: confirmed that these are regular, real checksums https://support.apple.com/en-us/HT202303
> The raw byte checksums of the file content and the file name
I wonder if this is literal; otherwise they wouldn't achieve any de-dupe if you just rename the file.
The vouchers were encrypted, and could only be decrypted if there were, I believe, 30 independent matches against their CSAM hash table in the cloud. At that point the vouchers could be decrypted and reviewed by a human as a check against false-positives.
It sounds like with a raw byte hash they might be able to match a photo against a list of CSAM hashes, but they wouldn't be able to do the human review of the photo's contents because of E2E.
If the hashes are cryptographic, then this is impossible (given today's technology).
> with the ones in the CSAM hash database
The CSAM hash database isn't public AFAIK.
> I remember someone posting about a year ago a bunch of strange looking images that produced those collisions.
You're probably thinking about their proposed 'perceptive hash', which has since been scrapped.
Who are they sorting it for that this can't happen after decryption?
Is there any proof they actually abandoned this? NeuralHash seems alive and well in iOS 16[1]. Supposedly the rest of the machinery around comparing these hashes to a blind database, encrypting those matches, and sending them to Apple et al. to be reviewed has all been axed. However that's not exactly trivial to verify since Photos is closed source.
[1]: https://support.apple.com/guide/iphone/find-and-delete-dupli...
Therein lies the rub: the payload itself is protected by an encryption scheme where the keys are intentionally being withheld by either party. In the case of Apple's proposed CSAM detection Apple would be withholding the secret in the form of the unblinded database's derivation key. In the case of Advanced Data Protection the user's key lives in the SEP, unknown to Apple.
By design the interior of the "safety vouchers" cannot be inspected, supposedly not even by Apple, unless you are in possession of (a) dozens of matching vouchers and (b) the unblinded database. So on the wire you're just going to see opaque encrypted containers representing a photo destined for iCloud.
Although it was starting on CSAM material, it wasn't clear which other illegal activities Apple would assist governments in tracking. In countries in which [being gay is illegal](https://www.humandignitytrust.org/lgbt-the-law/map-of-crimin...), having Apple employees aid law enforcement by pointing out photographic evidence of unlawful behaviour (for example, a man hugging his husband) would have been a recipe for grotesque human rights abuses.
With photos encrypted, Apple can't be pressured to hire human reviewers to inspect them, and thus cannot be pressured by governments that enforce absurd laws to pass on information on who might be engaging in "unlawful" activities.
[1] https://www.eff.org/deeplinks/2021/08/apples-plan-think-diff...
So I read this as Apple quietly saying "we're not bending to China on privacy". Which is the first step toward probably being banned from providing Apple services in China.
Unfortunately, I think the privacy problems surrounding iCloud Photos remain to an extent.
> Some metadata and usage information stored in iCloud remains under standard data protection, even when Advanced Data Protection is enabled. For example, dates and times when a file or object was modified are used to sort your information, and checksums of file and photo data are used to help Apple de-duplicate and optimize your iCloud and device storage
This checksum is described as:
> The raw byte checksum of the photo or video
This hash can technically be shared by Apple, since they own the key used to encrypt it. And depending on when the hash is computed (post-encryption it's no problem, pre-encryption we have a problem), this could technically be used to find people sharing known undesired images e.g. Tank Man or CSAM.
It's a lot easier to tell vendor X that "in country Y list Z is the one that should be used when looking for CSAM", and then add some known Tank Man derivative hashes to that list and find out directly who to arrest.
There is no way for a user to verify if Apple has actually end-to-end encrypted their backups or not.
This is likely describing content-addressable storage. It is the underpinning of many iCloud services that store user files / blobs. It is also a commonly used pattern in backend services generally.
The presentation about ZFS' native encryption[1] covers many of these sorts of trade-offs necessary to do full-disk encryption at scale.
Personally, I don't think Apple intends to screw you, and they have a good reason, but isn't not trusting your provider the entire point of e2e encryption?
It is one of the first question I asked myself: "with e2e encryption, it means no de-duplication, it will be expensive for Apple". Turns out they still have de-duplication, and therefore weaker privacy.
Anyways, "As we continue to strengthen security protections for all users, Apple is committed to ensuring more data, including this kind of metadata, is end-to-end encrypted when Advanced Data Protection is enabled". It would be interesting to see if they really are committed. For now, I don't blame them, it is already better than most offerings, and it just came out. However, it will be an interesting point to watch for in the future: it is a privacy feature that actually costs Apple money to run, will they do it?
Note: I assume a standard hash like SHA, working at byte level. Not the CSAM scanning thing that can match similar pictures even if the files are not exactly the same.
If someone has all kinds of duplicates, so what? Eventually, they have to pay and up their subscription price for the additional cloud storage. The only way de-duplicating could possibly save money is if two or more people with the same file are both pointed to that same file in a location that is not within their account.
I don't buy this de-duplication argument.
They can remotely wipe apps. They can force-install apps and force updates. It is not too far-fetched to think that they can just remotely copy anything stored on your device to their servers. So, with an adversary that capable, I'm not sure encrypted backups provide a meaningful improvement to security and privacy.
> The third-party doctrine is a United States legal doctrine that holds that people who voluntarily give information to third parties—such as banks, phone companies, internet service providers (ISPs), and e-mail servers—have "no reasonable expectation of privacy" in that information. A lack of privacy protection allows the United States government to obtain information from third parties without a legal warrant and without otherwise complying with the Fourth Amendment prohibition against search and seizure without probable cause and a judicial search warrant.
If you want maximum security use an air gapped computer. But that won't let you send messages on the go.
How is this possible on iPhone/iPads, where using Apple services like the App Store is required to install software?
We cannot say the same for Apple.
If people in China and other privacy-hostile countries can side-load from alternative app stores (like F-droid for Android), the government/Apple doesn't control user access to particular undesireable apps.
There's obviously reverse concerns to this side of the coin but the overall concept has arguably always existed eith jailbreaking (Cydia store, AltStore(?)) and I haven't heard any stories about people becoming massively compromised in the way all the naysayers and Apple would have us believe.
[1] https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=uriserv%...
And Apple already chooses the reverse for you by not allowing apps you may want and by charging at 30% tax for doing so. There is a vast disparity between the behaviors!
Use your own server? Great, it's secure software-wise, but if someone broke into your house, it's all of the sudden the worst liability ever. The next thing you know, your entire identity, your photos, everything is stolen. You have excellent technical security, perhaps the weakest physical security.
So new plan, you use a self-hosted NextCloud instance on a VPS somewhere. That's actually not much smarter than using iCloud - VPSs handle data warrants all the time. They also move your data around as they upgrade hardware, relocate servers, and so forth.
So new plan, you use iCloud E2E encryption. You have to trust that Apple does as they say, and trust that their algorithms are correctly functioning. Maybe you don't want to do that, so new plan:
You use a phone running GrapheneOS, with data stored on a VPS, with your own E2E setup. Great - except you need to trust your software, and all the dependencies it relies on. Are you sure GrapheneOS isn't a CIA plant like ArcaneOS was? Are you sure your VPN isn't a plant, like Crypto AG? And even if the VPN is legitimate, how do you know the NSA doesn't have wiretaps on data going in and out, allowing for greatly reducing the pool of suspects? Are you sure that even if the GrapheneOS developers are legitimate, the CIA hasn't stolen the signing key long ago? Apple's signing key might be buried in an HSM in Apple Park requiring a raid, but with the GrapheneOS developer being publicly known, perhaps a stealth hotel visit would do the trick.
So new plan, you build GrapheneOS yourself, from source code. Except, can you really read it all? Are you sure it is safe? After all, Linux was nearly backdoored with only two inconspicuous lines hidden deep in the kernel (the 2003 incident). So... if you read it all, and verify that it is perfect, can you trust your compiler? Your compiler could have a backdoor (remember the "login" demo?), so you've got to check that too.
At this point, you realize that maybe your code, and compiler, is clean - but it's all written in C, so maybe there are memory overflows that haven't been detected yet, so the CIA could get in that way (kind of like with Pegasus). In which case, you might as well carefully rewrite everything in Rust and Go, just to be sure. But at that point, you realize that your GrapheneOS phone relies on Google's proprietary bootloader, which is always signed by Google and not changeable. Can you trust it?
You can't, and then you realize that the chip could have countless backdoors that no software can fix (say, with Intel ME, or even just a secret register bit), so new plan. You immediately design and build your own CPU, your own GPU, and your own silicon for your own device. Now it's your own chip, with your own software. Surely that's safe.
But then you realize there's no way to verify, even after delidding the chip, to verify that the fabrication plant didn't tweak your design. In which case, you might need your own fabrication plant... but then you realize that there's the risk of insider attacks... and how do you even know those chip-making machines are fully safe? How do you know the CIA didn't come knocking and make a few minor changes to your design, and then gag the factory with a National Security Letter from giving you any whiffs about it?
But even if you managed to get that far, great, you've got a secure device - how do you know that you can securely talk to literally anyone else? Fake HTTPS Certificates from Shady Vendors are a thing (TrustCor?). You've got the most secure device that is terrified to talk to anybody or anything. You might as well start your own Certificate Authority now and have everyone trust you. Except... aren't those people... in the same boat now... as yourself... And also, how do you know the NSA hasn't broken RSA and the entire encryption ecosystem with that supercomputer and mathematicians of theirs? How do you know that we aren't using a whole new DUAL_EC_RBG and that Curve25519 isn't rigged?
The rabbit hole will never end. This doesn't mean that we should just give up - but it does mean we shouldn't be so ready to nitpick the flaws in every step forward, as there will be no perfect solution.
Oh, did I mention your cell service provider always knows where you are, and your identity, at all times, regardless of how secure your device is?
Edit @INeedMoreRAM:
For NextCloud, from a technical perspective it's fantastic, but your data is basically always going to be vulnerable to either a technical breach of Linode, an insider threat within Linode, or a warrant served (either a real warrant, or a fraudulent warrant, which can happen).
You could E2E encrypt it with NextCloud (https://nextcloud.com/endtoend/) which would solve the Linode side of the problem, but there are limitations you need to look into. Also, if a warrant was served (most likely going to be authentic if police physically show up, at least more likely than one they served your data over), you could always have your home raided, recovery keys found, and data accessed that way. Of course, you could destroy the keys and only rely on your memory - but, what a thing to do to your family if you die unexpectedly. Ultimately, there's no perfect silver bullet.
Personally... It's old school, I use encrypted Blu-rays. They take forever to burn, but they come in sizes up to 100GB (and 128GB in rare Japanese versions), they are physically stored in my home offline, and I replace them every 5 years. This is coupled with a NAS. It's not warrant-proof but I'm not doing anything illegal - but it is fake-warrant-resistant and threats-within-tech resistant, and I live in an area where I feel relatively safe (even though this is, certainly, not break-in-proof). Could also use encrypted tape.
Even though I get an A+ on the Nextcloud Security Scan (https://scan.nextcloud.com/), have 2FA, and custom IP blocking set up in my .htaccess file, it's disheartening to know that I'm not as secure as I thought I was.
I removed all my photos/files from iCloud for privacy reasons, and now I feel helpless contemplating how Linode may just hand my data over if served a warrant.
Any other Nextcloud hardening tips besides Fail2ban and reverse proxying you'd recommend? May I ask what your workflow looks like for preserving files throughout time?
E2EE will consume more space.
this doesn't invalidate the rest of your point, but if your data isn't encrypted at rest on your own hardware, that one very particle point? that's your own fault.
Both Nextcloud and GrapheneOS are FOSS which addresses your concern about it being a government trap.
My partner is able to access my Bitwarden account if I were ever to be indisposed.
Sure nothing is perfect, but tell me how this is not a better solution than trusting the closed source ecosystem of the biggest corporation in the world.
I was merely referring to the fact that unless you build the code yourself, there is no certainty that you have that a government has not shipped a custom hacked build to your device and stolen a FOSS signing key. Unlikely? Yes. Possible? Yes. Also, backdoors, as seen in the 2003 Linux incident, can be as hidden as a deliberately missing equals sign in 1 line of code - so, a sneaky government commit with the smallest backdoor could be undetected even if FOSS. I still think it’s better than proprietary - don’t get me wrong - but it’s not invincible which was my main point about how security does not end.
You can, with some inconvenience, use optical diodes to transmit data from a trusted input device to an untrusted network device for transport over tor, and then push the received messages over a second diode to a display device that decrypts the messages, so that even if you receive an exploit/malware, there is no physical connection that allows unencrypted data to be exfiltrated.
BRB, just setting up six new PCs so I can chat with my friend, lol.
Tbh in theory apple aren't allowed to tell you they have done it or otherwise. So their phones have probably been backdoored for a few years now at request of aus gov.
Because apple isn’t in control of apple for data at rest, and that’s the specific risk.
You have to trust control of the device sure, but you cannot trust cloud data - almost at all - between subpoenas from over eager LEOs and break ins from criminal and state hackers
That's not really true if Apple also holds copies of your iCloud decryption keys. If they want to access your data, they already have all the necessary components.
Let me re-phrase, by giving Apple control over the keys, you give control over the data to whoever controls apple - which is non-zero (Eg. LEO), and whoever may gain control (security vuln).
That is literally the thing that this announcement changes.
I see that Hacker News has plummeted below Reddit in the "bothering to check the link" stakes.
> One must understand that E2EE is used when you don't trust your service provider to handle your data. In other words, the adversary in your threat model is the service provider - and in this case, Apple. And what good is that encryption, if Apple obviously can do almost anything with your device?
There's a similar variance of complexities for hacking and law enforcement overreach scenarios.
E2EE isn't a solution for all attack vectors, but it's a significant mitigation in itself.
I trust Apple’s honesty. I don’t trust many attack vectors. Someone could gain access to their data center. E2EE protects that. A gov could legally compel them to provide data. I trust when they say they’ve engineered it in such a way that they can’t currently do it, and that they would publicly cause a scene and legal battle if attempted-as they have before. Accidental data leaks also happen. In all these scenarios I trust Apples intentions but know that nothing is perfect. E2EE adds a lot for me.
These protections aren't there to protect you from "Apple", but Apple staff.
So for example if someone at Apple has been compromised by a foreign state, they can't copy sensitive customer data just willy nilly. They'd have to jump through a lot of hoops that would be prohibitively difficult.
Google had issues like this in the past where some employees were sending data to the Chinese government. E.g.: information about dissidents, political opponents in Taiwan, etc...
This is one of the reasons Google encrypts even internal server-to-server traffic, because the threat is on the inside of the firewall!
Was that reported anywhere?
Technically no. I still have Fortnite on my iPhone, it just can't be opened. Apple can't wipe apps from your phone, but if they're App Store installed (as opposed to Ent MDM/Sideloaded), they can render them inoperable by revoking the certificate attached to the bundle.
Remotely deleting probably just exposes them to all kinds of legal issues, since it would wipe user data too (which you can otherwise possibly still extract, e.g. through the "Files" app).
This is identical to any developer that doesn’t deliver updates or suspends their developer account.
Those which have downloaded Fortnight at least once can still download and use the game on earlier versions of iOS and even with iOS 16 by following certain mitigations.
Contrary to some online posts Apple haven’t done anything unique to the fortnight account.
a) Overreaching law enforcement, which want to take a look at what I'm up to. b) Data breach at Apple exposes all my data c) Errors where my pictures gets in another users photo album, as seen on Google Photos once.
E2EE defends against all 3
The adversary in this threat model isn't the service provider. The adversary is someone attacking the service provider, like a hacker or a government with a warrant, and getting access to Apple's storage of your data.
Now of course it's not impossible for such an adversary to also defeat other systems at Apple and get your data another way, for example by controlling Apple's ability to send over-the-air updates to Apple devices. But I think that is a sufficiently distinct threat that it's not worth dismissing solutions to the first threat. That would be like dismissing the importance of a web server storing passwords salted and hashed, since attackers could just use a totally different attack to bypass the web server's database access control. Another way to illustrate this might be to point out that attackers can physically coerce you to hand over data regardless of any security measures any service provider could possibly make, but that doesn't mean we should dismiss all such security measures.
This is now possible to achieve in AWS, for example.
https://aws.amazon.com/about-aws/whats-new/2022/11/aws-kms-e...
If only such a service existed.
If only …
However, as with all things here, you can just email and discuss with a real person and we'll set you up the way you need to be set up wrt billing and pricing, etc.
Still with all that said:
>I disagree - the service provider should be considered an adversary and their service - and your tooling - should make it possible to obfuscate every single bit of data and metadata that you store there.
If you're using Apple devices at this point then I think they do unavoidably form some part of your core trust foundation. With current hardware Apple is everywhere in the stack right down to the CPU level, heck arguably below that since they have a special license with ARM and can implement their own custom extensions. If you really think they're an adversary to the point of doing custom backdoors explicitly going after you, then the hardware just can't be trusted.
It's not unreasonable though to look at both Apple's incentives and the state of American law at least and see distinctions between Apple being compelled (or hacked) to provide something they have passive access to on their side anyway vs being compelled to engage in non-consensual active work and feature development (or having that slipped in and make it into general deployment) on things that necessarily must go out to end user devices. The former is both bog standard warrant/subpoena territory and not inherently detectable outside of Apple and the government, since it doesn't directly involve the user as a party at all. The latter is very arguably illegal and provokes far more public response, and involves deploying in ways that make it far harder to keep concealed (and open up other avenues of challenge).
remember Lavabit [0]? will Apple choose to shut down rather than to comply [1]? if the government comes with a warrant, it will be with a gag order, and they will be compelled to silently update your phone to extract whatever the govt needs over the course of a few months.
[0] https://en.wikipedia.org/wiki/Lavabit
[1] https://en.wikipedia.org/wiki/Pen_register#Pen_Register_Act
Apple will probably comply, just like I would probably comply rather than go to jail or suffer injury to myself or my loved ones. But I think it's fair to treat that as a distinct threat.
https://en.wikipedia.org/wiki/FBI%E2%80%93Apple_encryption_d...
in this case it could have set a dangerous (and expensive) precedent for them.
that does not mean they will fight any and all requests.
Sure Apple could update your device to send all your photos unencrypted to them. They could also remotely turn on the mic and spy on all of us. They could also add key word detection to iMessage and flag law enforcement if you text out the wrong words.
I think everyone here understands what Apple could do. Which is why it’s a good thing that signs point to Apple not wanting their customer data. And why Apple refusing government orders that they feel violate their customers is unequivocally a good thing (even if they’re doing it for selfish reasons)
that e2e encryption by a third party does not give you privacy from the US government if that third party can remotely control or update your device and is subject to US laws. it is a direct reply to the assertion made in the GP: "The adversary is someone attacking the service provider, like a hacker or a government with a warrant, and getting access to Apple's storage of your data."
There isn't another mainstream product that offers that.
No one (or even the author) has been able to replicate it or find the Apple ID in any other logs calls.
The problem here is we are wholly dependant on Apples goodwill. It is not required in anyway (hence Googles behavior). At any moment Apple can revoke said goodwill and exploit us to our hearts content and we will have no fallback what so ever because we decided to let the market codify our freedoms rather than preventing companies from being ruthless.
While waiting for them to latch you down tight, you could have already been enjoying the most consumer-centric and privacy-conscious mainstream mobile OS since 2007.
Just because Apple is playing nice at the moment, there is no reason not to force them, and all the other players to have a legal requirement of playing nice. I mean, the hog that is fattened for slaughter thinks its life is great, right up until its not.
If it's a benevolent dictatorship, it's undeniably been a good one to me over nearly half my life. If they ever do turn, I can always just leave. But what is and/or was my alternative? The less-benevolent dictatorships of Google or Microsoft? Spending inordinate amounts of time and effort making a hodgepodge of various Linux devices work together (often unsuccessfully)? I'll pass.
The question could be less if Apple should be trusted, and more if phone makers in general should be allowed to be dictators.
Say I make the Avocado Phone:
- my entire shtick is that "you can only run apps we make, and we vet the source code of every one of the few thousand third-party apps we allow on our device. We will pay you $10,000 if you get compromised using our phone"
- Of course, to achieve this, the phone can't be susceptible to "informed" evil maid attacks (as in, say the hotel's cameras capture you entering your passcode and Avocado ID Password) that replace your OS with an identical one preloaded with Malware. This means that, even as a user, you literally can't load any other software onto the bootloader or OS that would touch the operating system.
- it also takes every opportunity to prevent third-party apps from gaining access they don't need, which includes disabling JIT compilation (ruling out third-party browser engines, unless they want to use a slow javascript interpreter).
At what point does my phone turn from a product that services the security-conscious crowd with a completely bulletproof device, into something that people want to be able to preload software onto, because they didn't realize that security comes at a price? Is it when I sell enough? Is selling 10 million a year enough to where my market presence becomes a problem? 100 million a year? Why would people buy it if the government forces it to be 'open' at the cost of invalidating its entire use-case of being a secure device?
First part is, fundamentally these devices are sold. You could eschew the very notion of property and make it a pure rental, but it’s not the point we are now.
The second part is, as you point out, your idea is completely valid until your service becomes life critical, a huge portion of the country’s population relies on it day to day, you killed any competitor that had a significantly different value proposition and it would have catastrophic consequences if you were to screw it up badly. Basically you became part of the infra. Is it 100 million units ? It’s up to your regulators to decide.
In any case, I don’t see how using Apple products is at odds with supporting better privacy laws. If anything, they are perfectly aligned since it demonstrates a $2 trillion alternative to surveillance capitalism.
Chinese customers don't need to wait. Apple flipped sometime in 2017 and gave up all user emails, photos, messages, etc. to the CCP to stay in the market.
People complain about TikTok spying for China, but Apple is one of the biggest CCP spies around. That runs counter to the brand headspace they keep investing in though.
People have this expectation because other companies have done this.
For example, Google employees revolted when dragonfly was leaked, and got the CCP search-spying project killed. It's weird to think that Google cared more about user privacy than profits than Apple does, but that's how weird the branding works here.
Apple was revealed to be a participant in 2013; there is no reason to believe they are not a part of it now.
the fact you believe this is true today is most telling, I do not find them to be "consumer-centric" they have very draconian policies and if your use of the device fits in their narrow band of use cases then it is find, if it does not you are SOL
0: https://play.google.com/store/apps/details?id=com.apple.move...
For instance if you've been on iOS for a few years and bought a healthy amount of music, those are virtually gone after moving to android. You can mitigate that by either
- forever keep paying Apple through an Apple Music subscription
- somewhat extract the tracks and DRM free them (tracks were DRM free when bought from the Mac, but not when bought on iOS last time I tinkered with it). Of course Apple will make as hard as they can to block this route.
Same for movies and books, and for games/apps as well if they don't have a multi OS pricing scheme.
Switching cost is not just time spent to get used to, more often than not it"s a non significant amount of money lost in the process.
Same deal the other way round of course: Google is more diligent on exposing their content on iOS, but there will stil be paid games and apps to be lost in the process.
This has to be satire.
I've enjoyed 15 years of a wonderful and privacy-first device ecosystem. They're evidently making it even better. And you want me to be upset?
What's the equivalent of the FDA but for consumer privacy?
Corporate altruism, apparently
What am I missing? How am I handcuffed to Apple?
There is a Chrome app on iOS. I don't think many people pick their browser based on rendering engine, but rather on actual browser UI and features (like sync).
I'd love to support Gecko on mobile too, as I've moved the vast majority of my desktop usage to it, but Webkit is still fighting the Blink/Chromium hegemony, too, and that's still fighting the good fight.
Not if they treat user freedom as their enemy.
I don't expect you to agree with me. I just want you to know it is a perspective of its own merits. The web has seen what happens when one rendering engine gets enough market share to dominate and that had a decade or more of repercussions, especially in enterprise application development. We're so dangerously close to that happening again. You may think you are fighting the most for freedom of the two of us, but from my perspective you are fighting a proxy battle in the Cold War and I'm much more worried about the Cold War and the freedoms it may lose us in the long run.
I'm much more worried about the Cold War and the freedoms it may lose us in the long run.
I will have to disagree that freedom is advanced by an OS that forbids you from using software that hasn't been approved by a megacorporation.
We're probably all going to keep disagreeing because it is apples and oranges no matter what analogy we try to use. I do think "potential monopoly" is worse than "practical monopsony" (especially when it is a proxy monopsony and people are still free to not buy Apple and thus not buy Apple's rendering engine choice), but you are welcome to continue to disagree. Again, I appreciate why a lot of y'all see the "practical monopsony" as the larger and more immediate threat.
What may sound like "backpedaling" is that I am admitting sympathy for your concern, despite disagreeing with it. I think you've made good points. I don't find anything "contentious" about it. I still disagree with you, and I'm not apologizing for disagreeing with you. I can understand your points just fine, and also still disagree with them. I would like you to consider my point of view, and maybe engage with me on this issue that it is much more complex than a simple "good versus evil". I hope this not to change your mind, but in the hopes of a better overall discussion than just "Apple is evil and doing evil things because Freedoms". The reality is not that simple. I don't blame you for thinking it is, and you are free to continue to do so, just don't yell at me for saying "well I think it's kind of complicated", please.
"It's a free market because I have the choice between two brutal masters!"
Modern human communication, phones, are too important to be held hostage by just two companies, neither of which are acting in consumers best interests.
IMO this is the time that governments should be acting on behalf of the people, and not the corporations with the deepest pockets.
I can’t. I don’t use Apple Photos, and I can’t set Google Photos as the default photo handler, nor default source or destination, nor tell any iOS device to never save photos in Apple’s silo.
> If I don’t like what Apple does with iCloud, I can move to Dropbox.
I can’t either. I wanted to backup my phone elsewhere and there is no option outside of iCloud.
How have you hacked your system and how long will you be able to?
To keep Apple from saving your photos: turn off iCloud Photos, or log out of iCloud.
To back up your iPhone without iCloud: make a local backup on your Mac or PC. You can even encrypt the backup with a password you choose. You can sync these backup files in any way you would like, including via Dropbox.
You can also sell your iPhone and get a different phone if you don't want anything to do with Apple.
> You can also sell your iPhone and get a different phone if you don't want anything to do with Apple.
If you come to that conclusion, it's basically the answer to your "How am I handcuffed to Apple?" question. If you need to give up the system to properly manage your backups, it's pretty much a situation where you're handcuffed or not, with no clear negotiable middle ground option.
Hmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmm
I mean, I really emjoy my current Apple ecosystem, and I do have all the devices, and I like how everything works currently. But, a switch is mainly a matter of movies my files and exporting/importing photos, contacts, and email. It might take a few years to cycle out ALL the devices, but I don't feel like there is a ton of friction in switching my data over.
It is more that everything is working so well together that I don't want to switch right now.
I do stay away from Apple home automation though, for this very reason. I want something open and local that I control since that WOULD be a huge pain to try and swap away from.
Thus the privacy claims are just advertisement, there is no way to verify them.
Apple devices might as well be fully backdoored.
This is about trust. If you don't trust the manufacturer of your hardware (or developers of software), that puts you down a very specific path of what you can happily purchase.
Isn't it fine to install Google Maps, etc, in a separate profile, inside GrapheneOS?
A small number of comments here are not about E2EE backups but rather the security key announcement. If there's a more detailed URL for that part of the story, we can factor it into its own thread.
> • iCloud Drive The raw byte checksums of the file content and the file name
> • Photos The raw byte checksum of the photo or video
When you send your group iMessage of 30 people the same photo, apple is not storing 30 copies of it, but, one.
My understanding of how E2E encrypted iMessage works is that in group chats it does indeed send 30 copies of your messages, individual encrypted for each recipient in the group.
https://support.apple.com/en-gb/guide/security/sec70e68c949/...
> For group conversations, this process is repeated for each recipient and their devices.
Only the attachment encryption key and URL need to be encrypted to each recipient.
If everyone is using the same file on iCloud, then by definition the file must be encrypted with the same E2E encryption key.
That seems ripe for buggy disaster, and is a big loss of privacy. With enough phones, you could decrypt a large percentage of other peoples data.
If there is a "Revolution Plan (WIP)" document shared amongst a few agitators, and someone in power gets their hand on it (and its "checksum" or whatever), then can they figure out _who else_ has it?
As it is, my iPhone unlock PIN is everything that's needed to decrypt the data server-side [1], and I'm not changing to an alphanumeric password on my phone only because of that.
[1] https://support.apple.com/en-us/HT204915 ("You might also be asked to enter the passcode of one of your devices to access any end-to-end encrypted content stored in iCloud.")
At the same time, I log in to new iOS devices with my Apple ID about once per year. I would love to be able to use a high-entropy key in that scenario. (As a point of reference, WhatsApp allows exactly that for encrypted backups!)
If that's still baffling to you, I'm glad I could introduce you to a very different viewpoint :)
To change your phone passcode: https://support.apple.com/guide/iphone/set-a-passcode-iph14a...
That's only the Apple ID/iCloud/account password, which plays only a minor role in end-to-end encryption.
The phone passcode is the (secret which gates, on Apple's HSMs,) your iCloud encryption key!
https://support.apple.com/guide/security/escrow-security-for...
Got "1234" as a passcode on a long-forgotten family iPad or test iPhone? Better go change it to something secure, as that's what stands between an advanced attacker (that can compromise your 2FA), or somebody able to compromise/apply sufficient pressure to Apple, getting into your iCloud end-to-end encrypted data.
https://support.apple.com/guide/security/secure-icloud-keych... (describes how both approaches work)
https://support.apple.com/en-us/HT204915 (documents that two-factor authentication is now effectively mandatory, which makes using recovery keys impossible)
The device PIN is now exclusively used (off-device!) for iCloud end-to-end encryption key recovery: https://support.apple.com/guide/security/escrow-security-for...
Are you sure it's either/or? Have you gone through the process, and are you sure the PIN is required off-device, rather than ? If that's the case, I do agree that it's not good.
Also I don't quite understand the threat model where a stronger authentication to iCloud allows for weaker data encryption. Considering Apple is usually pretty spot on with these things, this would definitely stick out.
according to the article, I don't think this will be possible because you won't even be able to turn on Advanced Data Protection in this scenario.
"You must also update all your Apple devices to a software version that supports this feature."
Just to get the feature enabled you're going to have to go and "touch" all of the devices you're signed into and either update their OS (and also update their passcode if you're smart) or sign out of them.
Mask unlock isn't perfect, wet hands can throw off Touch ID, and once per day I believe they will just reset and as for the passcode anyway. It's also required for software updates and reboots.
I'm not asking for this to become the default, or even an option given in any setup wizard. Just allow me to set up my own end-to-end encryption recovery passphrase and let me remove all of my device passcodes, i.e. allow me to opt out of HSM-mediated key escrow.
Just make your apple ID password high-entropy.
If you trust Apple to never get hacked or hand over your data to any third party, that's perfectly fine, but that is not the scenario that end-to-end encryption is designed to address.
“…Or tap Passcode Options to switch to a four-digit numeric code, a custom numeric code or a custom alphanumeric code.” which is on their support web site[1]
I want to be asked for it if and only if I grant a new device access to my end-to-end encrypted iCloud data.
I don't think this is an absurd demand. WhatsApp supports this security model, for example. Evem Apple used to, before they forced every iCloud keychain user to switch to their HSM-based model!
Apple even had this exact setting in the past! And they still have a similar thing for Mac disk encryption (the default is iCloud escrow, but a local-only recovery passphrase is also an option).
I switched my pin to alphanumeric because I’m not putting it in every time I pickup my phone. I can live with the inconvenience of putting the passcode in every couple of days or so.
I enter the password at most a few times a week after reboots and if someone plays with the phone and gets FaceID to fail too many times. It’s not annoying at all to unlock with the keyboard rarely.
I wish TouchID were an option on latest pro iphones.
I’ve been using an alphanumeric passcode for about 7 years now. I’ve gotten used to it. It’s not too long to be annoying but better than a numerical pin.
Even if you used 4 numbers for an alphanumeric password, it’s still much more secure than a 6 digit pin.
Unfortunately, that's not the case:
If you trust the secure enclave (for the device unlock scenario) or Apple's HSMs (for the key escrow scenario), a 6-digit PIN is just as secure as a 4-character alphanumeric password. In both cases, you get 10 invalid attempts before your data is wiped, and the odds are negligibly small in either case (10/10*6 vs. 10/62*4).
If you don't, i.e. you are concerned your adversary can somehow perform a brute-force attack, you need way more than four alphanumeric characters.
Users shouldn't be forced to use high-entropy local passwords just because a service provider insists on reusing them for a completely different purpose.
That's not quite true. They use a HSM on their datacenters, which only allows a limited amount of guesses. They only allow a limited amount of guesses, before your data is wiped forever[1].
[1] https://blog.cryptographyengineering.com/2021/03/25/whats-in...
There is no technical need at all for the same password to gate both local device unlock and remote end-to-end encryption key escrow.
It's a pure security vs. availability (and realistically genius bar support load) tradeoff, and I even think they nailed it for the vast majority of users! I just wish they'd let advanced users participate in that tradeoff more actively.
I just really wish they'd made PIN-based HSM escrow the default, but optional (with the "off" switch behind several scary-sounding warnings).
Maybe I'm missing something, but how is having a 6-digit password functionally any different than having no password at all?
> Advanced Data Protection for iCloud is available in the US today for members of the Apple Beta Software Program, and will be available to US users by the end of the year. The feature will start rolling out to the rest of the world in early 2023.
It also doesn’t work for Shared Albums, and for other “Shared” features it requires all participants to have ADP enabled.
Is it possible to have an old device connected to Apple ID, Find My enabled and iCloud backups/sync disabled for ADP to work on your newer devices?
Having no backups/sync on the old devices is fine, presumably people who care about encryption have that turned off at the current state of matters anyway.
They already communicate to you when you use a newer iOS feature that won't work on your other device. But you can still use it. Maybe you won't be able to turn back on those features on the older device, or something
I don't feel like updating to a beta to get this feature (especially for the risks associated with it). But I am curious how the migration will work. Will this basically re-encrpt everything locally and then upload it or will what is already there stay unencrypted.
Also does anyone know, how do features like this work for someone with a single apple device? I don't worry about loosing access to anything because if my phone dies I have... several other devices with keys. But what about someone who doesn't?
"Because Apple will not have the keys required to recover your data, you will be guided to set up an alternate recovery method in case you ever lose access to your account."
I would assume a physical sheet of paper containing recovery codes is a suitable alternative recovery method.
Thanks for pointing that out!
Honestly might not be a bad idea to have a backup somewhere else just in case. Like in the event of a fire or something have a backup sitting in a safe.
It does bring up an interesting conversation, what levels do we go to make sure we can recover accounts in situations like this? Store a USB or a paper in a safety deposit box on the other side of the country? I tend to store all of my backups for my other accounts on my iCloud Drive so... loosing access to that would be catastrophic.
However, for most people their messages will still not be end-to-end encrypted because their contacts will mostly not have this optional feature enabled. To be truly effective, this feature would have to ensure that Apple does not strip the end-to-end encryption from your messages when they are sent to other people using iMessage. In my opinion it is still fraudulent to market iMessage as an end-to-end encrypted system until this is fixed.
I think your opinion is mistaken in conflating separate problem spaces/threat models. E2EE deals exclusively with the transit and reading of data between trusted ends, that's the point. It deals with the threat posed by middle observers. What happens to the data after it reaches and gets stored on one end or the other is out of scope. Certainly important, but still has nothing to do with whether something is E2EE. Communications between people necessarily means no one person is fully in charge. The person on the other side could perfectly well have their PIN be "1234", that wouldn't suddenly mean Signal/iMessage/SSH/whatever are no longer E2EE.
This is definitely an unambiguously significant improvement, and it will help more people stay secure more easily while still making use of wireless services (vs backing up with a cable to a system like I have always done and still do with iOS devices). However, while technology is helpful it's not a total substitute for opsec either. And I think it's a mistake to mush together different domains. iMessage going full E2EE was a good all by itself and its own specific thing, even if Apple was wrong to not deploy the same thing everywhere and also wrong (and still wrong!) not to allow 3rd party options for backups. There was nothing fraudulent about saying it was E2EE.
That's transit encryption. The point of E2EE is to prevent anyone, including the service provider from decrypting the communication. Apple making a backup copy of the comms that they can read breaks the E2EE.
The point is to prevent anyone between the ends from reading it, not anyone at all obviously. The ends are trusted by definition. Once the data reaches them, it's decrypted. They can then do whatever they want with that. The job of the E2EE is whatever happens in the middle (both in transit and at rest).
>Apple making a backup copy of the comms
What the heck are you talking about? Apple does not make a backup copy of the comms. Users may choose to use an Apple provided service that right now is not E2EE to make a backup themselves, if they wish. Or they can choose to backup in other ways (remember, Macs can access iMessage too). Those other backups that have nothing to do with Apple also may, or may not, be E2EE.
I wonder how far you would take the separation of functions. If Signal started offering a service to scan your messages and attachments for spam/malware, sending them plaintext from the app to their server to do so, does that break their E2EE? If they recommended the feature, implied that not enabling it was reckless, and didn't explicitly explain the result being Signal servers reading your messages?
This argument makes no sense for two reasons. First, iMessage and iCloud Backup are not simply apps that you can replace with other services as you choose. "For your own protection" against malware or whatever, Apple restrictions prohibit anyone from offering an SMS-integrated messaging app or a cloud backup app in competition with iMessage or iCloud Backup. iMessage and iCloud Backup are not separate; they are part and parcel of the larger piece of software called iOS. Apple can't play dumb and blame users for making insecure choices when Apple is the one limiting them to insecure options.
Second, even if they were separate apps and replaceable, they are made by the same company. The service provider the end-to-end encryption is supposed to protect against is the same one making the non-E2EE backup. If Facebook started making a phone backup app that was "separate" from WhatsApp but made non-E2EE backups of WhatsApp messages to Facebook servers, and it was used by a large fraction of WhatsApp users, and the FBI was sending subpoenas for WhatsApp messages to Facebook and routinely getting decrypted messages back, would you really be defending Facebook for marketing WhatsApp as end-to-end encrypted? If so, I guarantee you would be in an extreme minority.
No, iCloud simply has nothing to do with iMessage E2EE, nor with Signal nor Nextcloud nor anything else.
>but that doesn't matter because it's separate from iMessage
It is indeed.
>so you can still call iMessage end-to-end encrypted separately from iCloud Backup by defining the "end" as before iCloud Backup runs.
Yes, because that is correct, and you are wrong. The "end" is when an authorized end user possessing the keys access the data. That's how it works. What they do with that data afterwards in completely orthogonal. They can print it out, make it into paper airplanes, and throw it off a skyscraper in the middle of a city and it still will have been E2EE. By your argument, there is literally no E2EE in existence on any common hardware in the world, since it's easy to use a PC to backup unencrypted (and indeed at least until relatively recently that was the rule not the exception, and even FDE only rose to general usage within the last decade or so.
>First, iMessage and iCloud Backup are not simply apps that you can replace with other services as you choose
Irrelevant even if you were right, which you are not.
>"For your own protection" against malware or whatever, Apple policies prohibit anyone from offering an SMS app or backup app in competition with iMessage or iCloud Backup.
You seem awfully confused if you think "SMS" has even the slightest security anywhere on anything. As far as messaging apps, Whatsapp utterly dominates iMessage worldwide. Signal is also very popular. There are Matrix apps, etc etc. What an absolutely ludicrous statement. Internet backups not being open to 3rd parties is indeed bad as I've said, but you can backup to a computer same as was always the option well before iCloud Backups even existed. That's what I do. Or simply not backup of course, such as if someone was using a phone in a high security situation and would rather lose history if they phone had to be wiped then have any risk of disclosure.
>iMessage and iCloud Backup are not separate; they are part and parcel of the larger piece of software called iOS. There is no firewall between them.
Wrong. If you want to allege that Apple is secretly backdooring stuff at a much lower level, well why not go straight down to the silicon? And you're going to need quite the evidence for that.
>Second, even if they were separate apps and replaceable, they are made by the same company. The service provider the end-to-end encryption is supposed to protect against is the same one making the non-E2EE backup blah blah
Also all irrelevant.
You've come up with a make believe fantasy head canon version of what "end to end encryption" means that has nothing to do with what it actually means. People like you love to throw around criminal allegations like "fraud" very lightly.
Source: I used to do security
(Alternatively it might be law enforcement => local intelligence agencies => NSA, since the local law enforcement might still need to provide a warrant to ask this from Interpol ?)
Android backups are E2EE but I don't think Google photos is. Photos aren't included in the phone backup, I think. Would welcome correction if that's wrong.
Google Drive and Photos are not E2EE
An anecdote, an activist had a document in their Google Drive. It was not something people high up wanted being distributed. It was deleted not just from their account, but platform wide. Guess how they did that? Its hash.
But let's not pretend this isn't a subtle backdoor that can invalidate the entire "E2E" implementation. I believe that in the US, having the filename and/or hash/checksum is most of what is necessary to trigger the Foregone conclusion doctrine and force the person to lose their 5th amendment protection and be compelled to decrypt their data to be used against themselves.
I'd like if someone with legal knowledge could comment if my understanding is correct.
Then again, they already have everyone's address books and iMessage traffic, so I guess they already have that data for most of the industrialized world. I wonder who else will preserve copies?
It's not inconceivable, but you need to source it.
A. Apple could create a tunnel from your browser to your devices, they could have key exchange via the web after you scan a QR code shown on your web browser with your iPhone, with some sort of "verify these words are the same" scheme.
B. Apple does the typical OTP/2fa scheme where you enter a x-digit code from your device, and in doing so your Device furnishes a key to Apple to be temporarily used to access your files from the web.
But in both of these scenarios, Apple compromising you via malicious javascript is ever-present, so you're right in that you'd be trusting Apple even more to not store your temporary key for too long or at the request of a NSL.
> When Advanced Data Protection is enabled, access to your data via iCloud.com is disabled by default. You have the option to turn on data access on iCloud.com, which allows the web browser that you're using and Apple to have temporary access to data-specific encryption keys provided by your device to decrypt and view your information.Is there a similar URL for the security key stuff? If so, we can factor that out of this thread, which is almost all about E2EE backups.
I can’t help but feel this dovetails with the CSAM-scanning work that Apple canned last year.
I was always under the impression that ultimately they were doing that work because they needed some mitigations for the fact that iPhoto backups meant people were storing CSAM on Apple’s servers. If they were serious about privacy, that would be a big big problem for them —- hard to say no when the government comes knocking with a legitimate warrant, so they needed a solution that would let them preempt that scenario.
This is a much better solution.
If they were serious about E2E, of course everything would be encrypted.
There is no reason why they shouldn't store only hashes of the encrypted data, or, in fact, not store hashes at all, except -
1) data deduplication, which only saves Apple money
2) storing hashes and thus enabling govt and LE intrusion by mass scanning of content through matching hashes
Neither of these options is good for consumer privacy, and I would expect better from a company that is supposedly about privacy.
I would also be interested to know if they are still doing the perceptual hashing, because that would actually still fit in with their language about storing hashes, because AFAIK they didn't specify what kind of hashes they are storing.
Was client side scanning implemented finally? Perhaps E2E paves the way to client side scanning?
For the hardware key, Apple is a bit late though. All other cloud companies have that 2FA.
Maybe they'll try it again after this.
Apple never said that it was scrapped. They did, however say that they intend to do it.
EDIT:
Follow the links from those articles. Apple never killed the plan! This is what Apple actually said:
> Based on feedback from customers, advocacy groups, researchers and others, we have decided to take additional time over the coming months to collect input and make improvements before releasing these critically important child safety features.
That's not killed. That's just delayed. It's also them reiterating their intention to ship these misfeatures. It was, as pointed out, widely misreported.
Apple is very good at writing technically truthful things that say one thing that cause reporters to report a different thing (which is not factual). This becomes an "everybody knows" sort of thing where the narrative that is widely believed/accepted is not what Apple actually said. They exploit poor reading comprehension ability.
"Apple Kills Its Plan to Scan Your Photos for CSAM. Here’s What’s Next"
That's dead enough for me.
No one wanted that, regardless of how the implementation worked.
Interesting, so this is an opt-in (not default secure).
When that percentage is high enough (a few years), I don't see why Apple wouldn't make it opt-out. (Default it to encrypted, you need to specifically disable it if you don't want it).
Why does what % of the user base who's running the support OS versions make any difference?
Maybe I am just misremembering since like you I figured that was the reason they were doing it, no other reason to do something like that if it was all going too sit there unencrypted.
edit: I take this back—"nothing" should be the right answer.
We all like to vilify Microsoft (rightfully so for all the telemetry crap they pull) but imagine if Windows started scanning all your local disks for files matching certain checksums then notifying authorities when matches occur (thumbnails / other metadata uploaded with the reports) like Apple was planning. Sure, it'll be CSAM first. Then, domestic terrorism; then RIAA / MPAA would jump in on the action... and finally, opaque checksum databases from local governments ("wrong think", Winnie the Pooh memes, pictures from protests, etc.) ; if we don't stop it in its infancy we're quickly tumbling down the slippery slope.
They would've only scanned the files that would end up in the cloud anyway.
But people went "omg my files", stuck their fingers in their ears and refused to read the damn spec.
FWIW, I don't use iCloud and never have used it; I don't care if they scan content once uploaded (it's their servers and I'm confident they'll continue scanning content there no matter how "E2EE" it is - see China and key sharing). As long as they keep their scanning on their devices and off of my device it's all good.
This is nonsensical. iCloud Photos is not e2ee and Apple already scans everything serverside. There is no need for redundant clientside scanning of iCloud Photos.
The clientside scanning is only needed in the cases where:
1) iCloud Photos is turned off
or
2) iCloud Photos is e2ee
Apple actively doesn't want to know your shit or analyse it on their servers. That's why they constantly do things on-device even if it's of worse quality than Google's approach of doing everything in the cloud.
It seems to me a little bit suspect that they wanted to do clientside scanning as a prerequisite for e2ee, as if they simply would not be allowed to publish society-wide e2ee privacy software (without government/regulatory retaliation) without such a law enforcement backdoor. This screams of prior restraint and we should be loudly asking our legislators why the fuck the FBI is pressuring Apple about what software they do or do not publish.
https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...
There is a major 1A violation happening here.
Every day the US government takes more steps to erode our civil rights, even against the largest companies in the world. Someone needs to rein them in.
*The definition of terrorism depends on your jurisdiction.
It would be fair if Apple gave a warning about US governments and courts before enabling sync to iCloud, but I guess they don't want users to know about it.
Also this is a closed source system, so we can't know whether Apple can remotely extract encryption keys or not.
Also as I understand, Apple now demands a phone number to sign up for Apple ID, so it means that now all users and their contacts are non-anonymous for Apple.
As of now, there is no backing up your Mac to iCloud. There is iCloud Drive and all the individual services but TimeMachine is local storage only (shared drive or the legacy TimeCapsule).
Does this mean we’re finally getting TM backups to cloud?
I think, on top of all that, it's still an overall "win" for consumers. But don't treat Apple like the white knight it purports to be. Beware the 'nice guys'.
Remember, they say nothing of what happens when they receive the data for the first time. It may be enough that they scan and store this information upon the initial ingestion, then leave you with the keys.
I hope they will support existing Yubi-Keys etc and not force users to get the dedicated Apple hardware key.
I don't think there is one?
The section of the announcement is emphatically about 3rd party security keys support, so the worry about lack of support of YubiKey over some push for some imaginary Apple Dedicated Key didn't make much sense to me.
Also, security key (at least to me) implies a small, keychain sized device. I wouldn't think of calling my Mac Studio a security key. There is no device marketed as such, even though yes, the SEP can and has fulfilled these purposes.
> [Apple] will now allow users to log in to their Apple accounts with hardware-based security keys made by other companies such as Yubico.
"users will have the choice to make use of third-party hardware security keys"
1) They explicitly state that they're going to keep an eye on the hashes of your files, allowing them to nuke anything they don't like from orbit system-wide. They still know what you have in cases where someone else has it and they know the plaintext. They're definitely going to scan what you keep in their cloud. It will start with kiddie porn, but then it'll be that plus terrorist documents (and who decides what that is???), and then illegal music and movies, and then...
2) It's all implemented with closed-source mysteryware. Who the fuck knows what it's doing? You've got to trust their pinky-swear, and you shouldn't. It probably works as it is described until it receives the special wink from Apple's servers, and then it sends along your private keys (possibly using an exploit they put there on purpose). If it's not verifiable (open-source and reproducible builds), it's a pinky swear.
3) This is your reminder that your iMessage isn't actually E2EE, they have a lot of the keys on their own servers.
These are all things they could fix, but don't. And they won't fix them because they don't actually give a damn about your privacy and security. We should all demand open-source, reproducibly-built encryption software.
Now if we could just get banks on board… they’re probably the single biggest glaring hole in non-SMS 2FA. To my knowledge there’s only 2-3 US banks that even support TOTP, let alone hardware keys, which is insane given how important they are.
I’m sure they’ll get pushback for closing this loophole
iCloud off -> no local CSAM scan.
Local CSAM scan with multiple failsafes (+ actual person checking) + E2EE iCloud -> zero need to allow law enforcement access to iCloud servers. This would also mean that Apple cloud've encrypted them in such a way that even they can't access them.
If there's a better URL for the security key announcement, we can factor this topic into its own thread, since it's a minority topic in this one and mostly getting overlooked.
This means that iMessage as a platform is still backdoored, because most people you iMessage with will be escrowing their endpoint iMessage keys to Apple in their effectively unencrypted iCloud Backups.
Apple (and the FBI/DHS/CIA/NSA soup bois without a warrant) will still be able to read everyone's iMessages in real-time.
Everyone wins. Spies keep spying, Apple gets to trot out the e2ee marketing flag.
Meanwhile, there is nothing to indicate that they don't intend to continue the rollout of their clientside photo scanning software that they previously announced.
Apple, the client side scan pushing and ad platform expanding company is now the same company that is releasing strengthened cloud data protection. Deduplication becomes impossible at any sort of scale and for safety Apple even turns off web access to iCloud when E2E cloud protection is turned on for the first time.
Apple has stated it will cache thumbnails using standard protections when sharing files, using "anyone with a link" will expose the unencrypted data to Apple servers. I wonder if CSAM scanning can take place for those files only.
[0]: https://www.washingtonpost.com/technology/2022/12/07/icloud-...
"When receiving this type of content, the photo will be blurred and the child will be warned, presented with helpful resources, and reassured it is okay if they do not want to view this photo. Similar protections are available if a child attempts to send photos that contain nudity. In both cases, children are given the option to message someone they trust for help if they choose.
Messages analyzes image attachments and determines if a photo contains nudity, while maintaining the end-to-end encryption of the messages. The feature is designed so that no indication of the detection of nudity ever leaves the device. Apple does not get access to the messages, and no notifications are sent to the parent or anyone else."
I can't imagine people working on E2EE at Apple would be okay with client side scanning. The reasoning isn't important, it's an easy slippery slope once implemented. I imagine the encryption team has to constantly push for consumer privacy in a climate where privacy is challenged and compromised for ad companies and governments. I would be absolutely shocked if there wasn't a large amount of internal pushback when the old CSAM detection plan was first announced publicly.
--
> The apple policy was likely about coming up with a way to enable encrypted photos on iCloud while still having some privacy preserving form of CSAM detection. Since it was only enabled when iCloud photos was enabled it was better for privacy on net than the status quo (unencrypted iCloud photos that are accessible to apple and scanned anyway).
This should be a default, basic feature of any service today offering storage of personal information. It's not like we haven't had the technology for decades. It's win-win, too: The company can't be held responsible for the contents because they can't read them, and the user gets privacy. Which in America is legally protected from the government. That means that if the company can't peer into the data, there's no point in even wasting their time with a warrant.
If the keys on the device are generated at the user's behest with some input of theirs, it's out of Apple (e2ee vendor)'s hands, logically, logistically, legally, and ethically.
(letting users into their own devices means the ability to access the entire device, examine what their device is doing, and firewall it if wanted)
Just let me use my local Time Machine backup server!
Sadly, I am convinced I'll never see that feature – it would basically remove the need for any iCloud subscription for me and thereby undermine Apple's "service" efforts too much.
A reasonable desire, but clearly niche enough that it's unlikely to come to pass. (Particularly since, given what little I've seen of how Time Machine works, it would likely require some quite significant dev work on Apple's end to enable.)
Yes, to its local storage only, which makes it completely useless to me. (I have more data on my phone than on my computer, and I can't be the only one.)
> TM doesn’t make much sense without the Finder’s interface.
Why? I can even already connect to the same SMB mount that holds my Mac's backup via my iPhone's "Files" app. Just let me backup to that!
Don’t exclude the back-up folder from TM, though.
(Actually it doesn't – I symlinked the backup directory to an external drive, and fortunately ~iTunes~ Finder follows that. But this is something completely unrealistic to ask of an average user, in my opinion.)
On the other hand I appreciate the hackability, and it is your data. If you’re in the EU, maybe you could have made a GDPR request to get the messages in a database.
Ultimately I don’t disagree with this iOS choice because we’re the odd ones; I understand the decision to put the privacy of “regular users” above a niche developer method which could be exploited more than used in a legitimate way.
It feels to me the correct solution in this case is that Tinder’s database should be encrypted on both iOS and Android and they would provide a way to export chats.
I really think this is the wrong attitude and the result of boiling frogs. Having access to data on our devices should be a given. To me it makes me think of the non-touch iPods of yesteryear. Music files were obfuscated on the device by shoving into human-unfriendly folders and filenames. The argument that this was to avoid music piracy is laughable since we originally had DRM'd music for downloads. The database was proprietary and undocumented which meant the only real way to get music on the device was through iTunes. It also meant that unless your ID3 tags were really good and you went through the process to copy all the tracks off and rename them, your music was locked to your device.
Even then, at least you _had_ a way of getting your music back. I'm not going to say E2EE isn't good or that the security protocols put into place for modern OS's isn't important, but imo it's eroding ownership of data and killing third party businesses. Everything has to be done through a web API now, which means your data has to exist in the cloud. This isn't good.
I don’t get your post. You quote a part to disagree with but everything after that agrees with it. I did say you should have access to your data. I did not say you should have DRM, or that your data should exist in the cloud, or that you should have to access it through an API. I also said “feels to me the correct solution in this case is”. In this case where we are discussing personal, private, possibly sensitive conversations. That has nothing to do with downloaded music, purchased or pirated.
> the result of boiling frogs.
That’s a myth¹, but it wouldn’t apply anyway. I don’t agree with Apple’s decision in the case you presented, but I do agree with it in the other instance. It isn’t incongruent to believe you should have access to your data while also believing it should be reasonably protected from snooping bad actors.
¹ From https://en.wikipedia.org/wiki/Boiling_frog: “While some 19th-century experiments suggested that the underlying premise is true if the heating is sufficiently gradual, according to modern biologists the premise is false: changing location is a natural thermoregulation strategy for frogs and other ectotherms, and is necessary for survival in the wild. A frog that is gradually heated will jump out. Furthermore, a frog placed into already boiling water will die immediately, not jump out.”
Here's an overview of how to remove the various layers of encryption (starting from the backup password): https://stackoverflow.com/questions/1498342/how-to-decrypt-a...
And how to do it if you want to access the WhatsApp chat database: https://yasoob.me/posts/extracting-whatsapp-messages-from-io...
Also some Go tools to inspect iOS encrypted backups https://github.com/dunhamsteve/ios
this wouldn't backup the apps, and app private data
for example, if your phone was running myapp 1.0 and 1.1 was out, restoring might cause your phone to download myapp 1.1
Also, I think if you had 20 kindle books in the kindle app on your phone and backed it up, after restoring you would have no books. You would have to redownload them all.
(strangely, I wonder if you have icloud backups, do these kinds of thing count against your storage space?)
> The new encryption system, which will be tested by early users starting Wednesday, will roll out as an option in the U.S. by year’s end, and then worldwide including China in 2023, Mr. Federighi said.
https://www.wsj.com/articles/apple-plans-new-encryption-syst...
Didn’t want to upgrade my perfectly functioning MBP 15 2015 for Shared Photo Library alone. They found out another way to force the upgrade.
During the client-side scanning debacle I noted they'd have to implement server-side scanning anyway, so they might as well abandon client-side scanning. The wording still allows for server-side scanning ("raw byte checksum" is vague enough be a image hash or merely a CRC-32; I strongly suspect it's the former) - and I'm perfectly fine with Apple choosing this. Their server their rules. It's also the better technical choice IMHO.
1) The image fingerprinting they were talking about before is really different from a "raw byte checksum", since it could recognize photos that had been resized or cropped.
2) AFAIK the plan was always to generate the fingerprint on the device, but to check it server-side, possibly as a pre-flight check before sending the actual file. The thing that upset people was the device generating a too-good fingerprint [EDIT: To be fair, people were also concerned Apple would expand the fingerprint-generating-and-uploading to photos that weren't bound for iCloud—the concern would have been pretty silly otherwise, since of course unencrypted photos sent to iCloud are CSAM-scanned, same as everywhere else). Pretty sure they were gonna keep the naughty-list server-side all along. So, if this is the same thing (I doubt it, see #1) then checking the fingerprints(/hashes) server-side isn't a change in plans.
2) The fingerprint check was supposed to be done client-side based on a server supplied list so that Apple would not get the image and image hash unless there was a match (I'm simplifying this, there was a rather complex procedure involved with thresholds and manual review).
My main concern was that normalizing and making possible client-side scanning would lead to other things being scanned. e.g. China adding images of Winnie the Pooh to scan list, and then sending every Chinese suspect to dissident-ville in the sky. The Apple plan here was insufficient: it wanted to rely on multi-country lists, this had both legal and practical problems - e.g. China has sufficient sway with friendly countries to add its choice of images to the list.
> My main concern was that normalizing and making possible client-side scanning would lead to other things being scanned. e.g. China adding images of Winnie the Pooh to scan list, and then sending every Chinese suspect to dissident-ville in the sky.
Right, but that hardly mattered as long as it applied only to iCloud-uploaded files, since those were and are already being scanned so all those scenarios were already in play (well, not now, I suppose, if you enable encryption... maybe. But at the time they announced the scanning, certainly)
There were some practical differences. e.g. Some programs have a permissive default of always marking as 'save to iCloud', and avoiding this can be nonintuitive. Also certain difficulties with deleted images which I am not sure how Apple had wanted to resolve but could lead to unfortunate differences from the other scenario.
More importantly, the moment the client-side capability was there, legal pressure to use it in all cases was bound to come. Normalizing client-side scanning was also bound to legitimize and encourage doing the same on Android, and I can easily think of certain brands which are way less scrupulous than Apple.
All in all, I didn't see the benefit given that server-side scanning was accepted as legitimate and sufficiently effective by just about everyone, but without the risks of client-side scanning.
Oh, absolutely—unless you want to prevent super-easy use for storing CSAM while also having E2E encrypted storage. Which I'm still nearly-certain was their entire reason for wanting to do that in the first place—which isn't to say there can't also be legitimate concerns about such functionality, I just don't think it was some kind of nefarious plot on their part. At this point I expect they're sitting on the feature until or unless there's public outrage over their inability to provide evidence in some kind of CSAM case or investigation—if that doesn't happen, fine, if it does, they'll push it out as soon as that sentiment overwhelms the anti-scanning one.
Possibly so. However, I believe they have two alternatives to client-side scanning:
A) I think their wording still allows uploading a perceptual hash, which would then allow typical server-side scanning without entirely breaking E2E.
B) They could handle this on a case-by-case basis. I'm sure their code-signing privileges can be (ab)used to get around E2E if Apple really wanted to, and they probably can push an 'update' to a single device to do just that.
I always thought the reason they didn't encrypt backups was as a way to remove pressure from security services to weaken the encryption. Better to let the security services go after Google/apple as the backup provider. And have an option to turn off backups for the security paranoid users.
I wonder why they changed stance...
Plus you can't always trust such a huge business 100%. What'll happen when you're locked out of your apple account? Yeah, no backup!
https://9to5mac.com/2022/12/07/apple-advanced-data-protectio...
Did the term fall out of fashion?
The problem is that any of that information is obtainable by a warrant because Apple retains possession of such data. The whole point of this exercise is to eliminate that possibillity.
We are only going to be able to test this feature one week before it’s released?
I would hope a large feature like this would have had a lot more public user testing/refinement behind it than just one RC build release!
https://www.macrumors.com/2022/11/21/icloud-for-windows-corr...
Incidents like these make me wish Apple's software was Linux quality...
Whatever did happen to the on-device CSAM scanning? Is it still coming to iOS?
> First, iCloud users may now take advantage of hardware security keys like YubiKeys. Both NFC keys and plug-in keys are supported.
This is great news! I wonder if this is able to replace Apple's bespoke 2FA system or it's strictly in addition to that.
Edit:
From Apple's announcement:
> Now with Security Keys, users will have the choice to make use of third-party hardware security keys to enhance this protection. This feature is designed for users who, often due to their public profile, face concerted threats to their online accounts, such as celebrities, journalists, and members of government. For users who opt in, Security Keys strengthens Apple’s two-factor authentication by requiring a hardware security key as one of the two factors.
If I read that right, it sounds like it's in addition to Apple's 2FA? I'd love to replace Apple's weird 2FA mechanisms, but this is still nice.
On macOS photoanalysisd phones home even when not using iCloud at all, fwiw. Who knows what it is doing?
Curious what they're going to do to mitigate that repetitional risk now. Possibly they'll just eat it and say, "look, this is what you fuckers wanted, we tried to solve the problem but you said no."
Not thrilled to see what the next showdown between them and e.g. the FBI is gonna look like. I expect it's not gonna look good in the court of public opinion and that might have unfortunate legislative consequences.
[EDIT] Actually, wouldn't be surprised if they wait until the first high-profile case involving their inability to deliver data on someone who probably is a disgusting scumbag, and use that as cover to go ahead with the local-CSAM-scanning-for-iCloud-uploads, once it's 100% clear what'll happen if they don't and the no-scanning crowd isn't the loudest set of voices anymore.
Lawfully nothing is stopping them, but since pretty much all US cloud services scan files it's clear there are some forces making them to do so. I thought that Apple was able to negotiate a compromise where they scan locally and then they are "allowed" to to E2EE.
Interesting that they proceeding with the encryption regardless.
> When a user first turns on Advanced Data Protection, web access to their data at iCloud.com is automatically turned off. This is because iCloud web servers no longer have access to the keys required to decrypt and display the user’s data. The user can choose to turn on web access again, and use the participation of their trusted device to access their encrypted iCloud data on the web.
Then they explain that if you turn it on again, your devices will send your keys to Apple's servers for the duration of the web session. Technically this leaks your keys to Apple forever, but they promise that they keep it for the duration of the session.
> The raw byte checksum of the photo or video
This means they could still technically scan photos, but they'd have to rely on simplistic checksum matching.
* you can have more than one device
* you can have a trusted contact to get you the keys
* you can have recovery codes
- On the other hand - excellent way to deprive many not-so-old Apple devices from such a critical feature by interlocking it with latest OS versions.
- And yeah, Apple, about time.
[1]https://support.apple.com/en-ca/guide/security/sec973254c5f/...
[2] https://smarx.com/posts/2020/09/convergent-encryption-and-wh...
¹ https://mashable.com/article/apple-icloud-plus-plans#:~:text....
Barely, and only after massive backlash. The code was actually pushed to everyones' phones, and Apple's last-minute decision to disclose its existence before turning it on is the only thing that stopped it.
Maybe the "lesson" Apple learned was to not disclose that sort of thing.
Apple abandoned CSAM scanning on phones because people were vociferously against Apple reporting them to the government when an image on the citizen's phone matched something in the government's own "bad images" database. Whether the scanning was on the phone or in the Cloud was largely immaterial to most people. Some of the more hardcore privacy advocates weren't happy with the on-device scanning, but that wasn't really the thing the majority of people didn't like.
What we learned from all that is that Apple can and will push whatever suits their agenda down onto the phones themselves. If the majority of users are acclimated to being tracked and profiled for the purpose of targeted ads, we won't hear the same outrage that we did for CSAM. Especially if Apple decides we simply don't need to be informed about it.
Now, if you opt-in to this, the key will be deleted from the HSM and stored on your devices only. New keys will be used for newly added data, but the old data will be encrypted with the same key (imagine the computational load of suddenly re-encrypting all those files, not to mention that you’d need to temporarily give Apple the new key or re-do it all locally). You will always need your Apple ID password (or a recovery key/“contact”) to decrypt your data now, and Apple won’t have the key to decrypt your data and give to law enforcement, nor will hackers be able to access it if they find a vulnerability in iCloud.
If you trust Apple not to implement a backdoor, you no longer need to trust them in any other regard to keep this data private.
Exit: upon further reading, it seems the encryption key is stored on your device, and you’ll need one of the recovery methods if you lose all your devices. This is much better as it means a weak iCloud password cannot be used to compromise your key.
> For users who opt in, Advanced Data Protection keeps most iCloud data protected even in the case of a data breach in the cloud.
Here, "cloud" is treated generically - as if Apple doesn't have to do with it. I suppose they don't want to spell it out. A more honest, but still easy-to-understand statement would be:
> For users who opt in, Advanced Data Protection keeps most iCloud data protected even in if someone hacks Apple's iCloud servers.
Nice to hold the corporates accountable but I don't find this to be slimy or anything - maybe just me though.
Since Apple was part of the PRISM program, I'm going to assume there is at least one for the 3 letters agency, which mean it's available for Apple, who designed it, as well.
But it does mean that they can mass scan easily the data, and have to target people personnally, which is already a huge improvement, and cover most people threat model.
I wouldn't trust any of these guys for a millisecond.
Suddenly they're not doing that?
Yeah it’s nice you are taking the security seriously so others can’t get in easily, but you (Apple) are still siphoning off my data for profit after I spent an arm and a leg on your equipment…
It just feel like protecting your investment more than my data security.
Why would governments push back, when this hole which has already been used will _always_ be available?
You have evidence that Apple has been pushing silent updates to individual users ?
“ Is it technically possible to do what the government has ordered? Yes, it is certainly possible to create an entirely new operating system to undermine our security features as the government wants. But it’s something we believe is too dangerous to do. The only way to guarantee that such a powerful tool isn’t abused and doesn’t fall into the wrong hands is to never create it.”
Apple: "So it's not technically feasible for us to respond to government warrants for the extraction of this data from devices in their possession running iOS 8."
Also, "create an entirely new operating system" is an intentionally misleading exaggeration on Apple's part, meant to fool customers but not governments. It makes it sound like the amount of work they would have to do is larger than changing one constant about how many retries are allowed and another constant controlling rate liming, build and sign and flash it to the phone, and delete it after.
I think the FAQ and letter both make clear that Apple could comply with the FBI request and their objection was over whether they should be forced to.
If iOS 8 required a user key for updating the system, this would be technically infeasible. It's not technically infeasible as iOS 8 was implemented, so Apple stopped claiming it is, but only after the FBI embarrassed them about that claim.
> their objection was over whether they should be forced to.
Apple's objection had nothing about being forced to do it. They were forced to provide data from devices before iOS 8 and even provided a document about how to ask them to do it. Apple instead made specious claims about how hard it was and how it would affect other customers' privacy.
The concern typically isn't backdoors, it's bugs. I've had plenty of terrible experiences with Enigmail.
I'm not aware of a time when Apple pushed a software update (silently or otherwise) to defeat security for a user (or users). Can you provide a reference?
I don't know what people expect. These moves are good things and everyone is whatabouting situations that there is 0 evidence has ever happened or would ever happen. It's unfalsifiable, impractical, and honestly just annoying.
If government were to compromise end to end encryption in the manner described above, it would either be visible when used to prosecute people, or invisible because it would never be used to prosecute people (but presumably for intelligence purposes). Even if it were used for intelligence purposes through the method above, which I don't think is at all established, it would still be a significant improvement over having data in a form that is actively used to prosecute people.
The snowden revelations were precisely about information gathering for intelligence purposes. The vast majority of intel gathering is not for prosecutionary purposes.
What is absolutely good is that they have e2ee now, and the only way they could even hypothetically open a back door would be one that was completely secret, for the government, which definitionally closes off a whole class of government use of the data, for example in domestic prosecutions of citizens.
This may not be perfect (it’s not open source etc) but it’s a vast improvement over non encrypted data that was openly routinely given to the government.
On some level the US could also pass a law that says every iPhone user will be summarily executed. That’s how sovereignty works. Is it a realistic concern? Probably not.
Apple's ecosystem is, by default, design and necessity, insecure to Apple. Keys stored on an Apple device are insecure.
One can easily make a similar argument for Android/Google, however, a security conscious user could still take control over their device and install a more secure OS.
In any case, selective support for technical proposals based on broader political vibes is not a particularly inspiring stance.
https://www.cnn.com/2022/06/21/europe/grenoble-france-burkin...
Let's not pretend this is the same thing as kidnapping you and taking you to a reeducation camp because of your religion, leaving your kids alone and confused.
No one claimed that they were being “forced” to be part of a religion. What next? Forcing people to eat pork even if it is against their religion to enforce “secularism”?
This was nothing more than discrimination.
In the US, we had to have laws that allowed Black girls to wear their hair the way they wanted and schools were forcing black girls to straighten their hair to fit in.
People who are forced to wear certain clothes by others in their religion are also often forced to have that religion.
Confusing race with religion is even crazier. We should accommodate people who are physically different, but there is no reason to go out of our way to accommodate people with arbitrarily wacky beliefs and even less reason to go out of our way to accommodate oppression by people with arbitrarily wacky beliefs.
Honestly, every religion is “wacky” to an outside observer.
The secularism rule basically says that the government should not make laws to accommodate one religion because then it would have to make laws to accommodate any and all religions, and there is no limit to how wacky a religion can be.
The law was specifically aimed https://apnews.com/article/religion-france-government-and-po...
> The ruling was the first under a controversial law, championed by President Emmanuel Macron, aimed at protecting “republican values” from what his government calls the threat of religious extremism.
The law passed in the country was set up to disallow laws that favored one religion, but ever since the revolution cast aside Christianity for enlightenment ideals, no such laws had been attempted. It is true that this law was made to prevent laws that favor Islam, but it puts it on equal footing with all other religions. Members of The Native American Church cannot get laws passed to give themselves exemptions to use mescaline.
Very recently in history. China is bad now, European nations have been bad in the past… but who knows what the future holds.
Once data is released (keys, databases, plaintext messages, it doesn’t matter) it can’t be made private later.
https://www.secureworld.io/industry-news/new-eu-push-for-enc...
But Android already collects a lot data from the device before encrypting.
Even MacOS is infected with this privacy invading nonsense that I can't opt out of. It has an Apple News app that I can't uninstall, and whenever anybody sends an Apple News link, even in a private tab, it opens the Apple News app, a handler that I can't disable, sending the article I want to read together with my Apple ID to Apple.
https://www.extremetech.com/mobile/340887-apple-sued-for-all....
FTFY.
Please stop spinning that as if Apple were siphoning every single of one's moves everywhere, irrespective of any telemetry setting one has set.
Both the linked piece and the reporter's Twitter thread seem to have taken great care to bury behind clickbait headlines and scary words the fact that this applies only to App Store, Books, Apple TV, and iTunes Store apps, which are all "store" apps (presumably that's where commercial stuff typically happens) that used to outright be webviews (not entirely sure they are 100% native as of today). I don't think anyone would be appalled if a React-based web app would send vast amounts of requests based on user interaction.
So yeah, they should probably not collect as much data as that and probably should have a toggle to nerf such data collection within the store apps (which is not the same as OS/actual app/service telemetry), but the way things keep getting spinned is beyond ridiculous and does not help in improving anything.
For myself I’m quite happy with this as it is a huge improvement over what we had. My only irk is that they called themselves a champion of security and privacy before this..
https://en.m.wikipedia.org/wiki/FBI–Apple_encryption_dispute
Can you show me another company that has done this?
FWIW, Apple does not treat US and Chinese users the same. If you have a Chinese mainland iPhone, you use a completely different iCloud that isn't even run by Apple.
Apple likely conceded early on that China-based iPhones use China-based iCloud, and the Chinese government likely conceded that Apple phones will use the same OS everywhere, with region-based feature blocking being as far as they'll go in customizing the OS. Both have a lot to lose from the other party terminating the relationship.
The laws are different there and the only way that Apple could meet the requirements of the Chinese government without also weakening their product for the rest of the world was to cede control of iCloud there.
The only true secure option is to build the source yourself, sign it with your own keys, and run it. Assuming you can read all the code and make sure its safe, and read all the code on your compiler to make sure that is safe. And you'll still need to trust the Google-signed bootloader code, which totally hasn't had suspicious custom builds released previously (ArcaneOS?)
You can't see how it works, you can't change how it works, and you have to trust that it does as advertised. You must do all this in the knowledge that over the years plenty of proprietary software vendors have outright lied to their customers about exactly this kind of thing, e.g. [0][1].
I'm not aware of Apple ever doing so though, for what that's worth.
This makes perfect business sense - people will want to buy extra storage. Lock-in is deeper.
Isn't that only required if the guy on the otherside needs to decrypt?
perhaps they just mean "end-to-end encryption*" where the * represents the back door that only apple and various three-letter-agencies have access to.
On page 25 of [1], we can see the security auditing done as part of their only official security certification for the iOS was: "The evaluators searched for publicly known vulnerabilities applicable to iOS using the following sources... The search was performed on multiple occasions between... using the following search terms... The valuator's CVE search found no vulnerabilities apart from the ones listed in the developer's security content disclosure statements, all of which have been fixed in subsequent releases on iOS. The validators reviewed the work of the valuation team, and found that sufficient evidence and justification was provided by the valuation team to confirm that the evaluation was conducted in accordance with the requirements of ..." tl;dr The evaluation process is that they do a web search of key words, check that all the publicly disclosed vulnerabilities have been patched, then call it a day.
To put that into perspective, their are certifying against AVA_VAN.1. It is only at AVA_VAN.2 that the evaluator is required to do any independent vulnerability analysis as seen in [5] Page 155 AVA_VAN.2.3E (bold is changes from the previous level). At AVA_VAN.3 you need to evaluate against "Enhanced-Basic" attack potential. It is only at AVA_VAN.4 that you need to evaluate against attackers with a "Moderate" attack potential. At AVA_VAN.5 (the highest level) you need to evaluate against attackers with a "High" attack potential. Apple's only security certification, which in their own words "provide a measure of confidence—that is, security assurance—that the security needs of a system are being satisfied" and are "used by many organizations as a basis for performing security evaluations of IT product" is wholly three levels below "Moderate" and is effectively self-graded.
Until they actually certify against a standard requiring moderate security, it is only prudent to take them at their word and assume that their products are only fit for systems that "do not view threats as serious". If they want their security to be taken more seriously they should prove it against internationally recognized standards assessed by independent third parties rather than issuing unsupported marketing fluff.
[1] https://support.apple.com/guide/certifications/ios-security-...
[2] https://support.apple.com/library/APPLE/APPLECARE_ALLGEOS/CE...
[3] https://www.cisa.gov/uscert/bsi/articles/best-practices/requ... EAL1: Functionally Tested
[4] https://commoncriteriaportal.org/files/ppfiles/pp_md_v3.1.pd... Page 136 Section 5.2.6 AVA_VAN.1
[5] https://www.commoncriteriaportal.org/files/ccfiles/CC2022PAR... Page 154 Section 14.3.3
> what good is that encryption, if Apple obviously can do almost anything with your device?
> They can still simply push a software update that sends the victim's keys to the mothership and/or simply decrypts everything
> This all just seems like pandering while they continue to accept billions from Google in exchange for their user's privacy.
> Couldn’t they simply use an encryption algorithm that has two private keys and they control one?
Apple could say they are going to cease operations tomorrow, close down the company, and people would comment "Yeah but they could always create a new company". I guess for those people nothing is ever enough.
This is a huge step forward (specifically iCloud E2EE) that I'm super excited about and people are busy coming up with threat models that 99% of us have zero use for and pretending as if this doesn't matter. It's disappointing.
What's disappointing is that Apple has zero accountability for any of these services. Nobody would be so critical of iCloud if it wasn't your only sync option on iPhone, but they force everything to go through them. Apple says 'trust us ;)' and gives the user no way to confirm that they're not decrypting your data as soon as it hits their servers.
The argument is the same as it's ever been. Apple took away too much of the user's control; if the iPhone were a more open platform, nobody would be squabbling over our only sync option.
Edit: Background Sync has apparently been available as an API since iOS 13, but that doesn't change Apple's lack of accountability wrt security practices.
If you don't trust Apple, you should also not trust other cloud back up services. Just turn off iCloud
Other synchronisation like Joplin and Zotero happens via WebDAV. My iCloud is basically empty yet I have every file I could ever need on both iOS as well as iPadOS. Some apps I don’t care for sync via iCloud, that’s all so far. I’m not bought into the whole ecosystem (i.e. apps) too much though. If all you use are apps that only support iCloud, that’s a problem indeed.
there is also a free fork of davx5 on Play as OpenSync: https://play.google.com/store/apps/details?id=com.deependhul...
agree that it should be bundled in to the system though....
Apple didn't took away anything. It wasn't there in the first place and never promised.
My vpn is a Wireguard server (and some Tailscale, recently tested mullvad, works great as well), my position is updated to my family via Home Assistant, Bitwarden pops up automatically anywhere I need to enter a password. Podverse is great for podcasts.
Sure, it's a walled garden and I have my annoyances but much less so than I was led to believe before I got my first iPhone last year. I find it easy to swap out default components where I don't like them (like iCloud and Apple podcasts) and use them when they are superior (like the calendar and mail app, I was always trying 3rd party apps on Android).
You’re welcome.
Nextcloud app also exposed itself as file provider in Files.app, so it's possible to use it in place of iCloud Drive for apps that use the appropriate API. (Unfortunately most apps use CloudKit, which sync over iCloud.)
It's just moving the goalposts. If Apple gave you more control then people would demand that the source code for the chips be open source, or that you could stand over the shoulder of the person assembling your iPhone and make sure they don't plug in a USB drive and install some malware. It's a never-ending battle. You're just going to have to start trusting Apple and other companies, or build your own device from raw materials you mine yourself.
Apple couldn't take away what it never gave in the first place. Anyone using an IOS device should have a basic understanding that Apple highly integrates their devices, OSes and services.
My Contacts and calendar can sync with any provider that supports whatever porn standards are behind it.
When I save and load files using the iOS file dialog, it shows every storage provider I have installed - Dropbox, OneDrive, iCloud Drive and I assume Box if I had it.
I sync my photos with Google Photos because they are a magnitude faster and more predictable than Apple's own Photos.
My passwords are in 1Password.
Can't really say I sync much else.
Your startup may be able to weaken or circumvent your controls and no one would know. But is not true of apple.
Yes!
> It's not like these changes solve the problem.
Perhaps because it is impossible to 100% solve the problem?
A lot of people, me included, are just tired of the endless litany of "50% secure is not secure! 75% secure is not secure! 90% secure is not secure! 99% secure is not secure! 99.9% secure is not secure! 99.999% secure is not secure!"
There is no 100%. Hearing the same level of outrage over a 0.001% gap that we heard over a 50% gap is just fatiguing.
Especially in this audience, everyone knows there is no such thing as verifiable perfect security. Asymptotic progress towards that is interesting; decrying the latest improvement as no better than no security at all just feels... IDK, lazy.
"moving the goalposts"?
Since when has closed source unverifiable crypto been a good idea? Since when has it been a good idea to trust a provider that fully controls the encryption algorithm to also be the only possible store for your supposedly encrypted data?
This is no better than Facebook claiming that Whatsapp is now "E2EE" encrypted. It's a useless PR tactic. If you mistrust Facebook, why would you suddenly trust their unverifiable claim that the data is now E2EE? You could have an argument if at least 3rd party clients were allowed, so that you could detect when they silently change the protocol. But not even that.
There's absolutely no _technical_ thing they could do to gain any trust. The goalpost has never been there.
> It's a useless PR tactic.
Maybe because a single whistleblower would bring down the mother of all class action lawsuits?
Hardcore anti-corporate types like to imagine that these companies are evil geniuses, where all 100,000 employees are operating in perfect alignment, with no mistakes or disagreements, and all secrets are kept perfectly.
It just doesn't work like that. Threat model it for a second: how many more phones is Apple going to sell with this? Maybe a 1% increase, to wildly overestimate it? And what would be the financial harm from a single engineer popping on HN and saying "it's all BS, phones send the keys to the cloud, I worked on the system to store them."?
> There's absolutely no _technical_ thing they could do to gain any trust.
Well, that's true. But there's also no non-technical thing they could do. It is literally impossible to prove perfect technical compliance on an ongoing basis using any combination of technical and non-technical means.
That goes for open source too. Evil compilers, etc, can turn perfectly solid source into malicious binaries. The compiler's source can even be perfectly secure.
At some point you have to think about probabilities and motivations, and move away from this "anything not 100% perfect, which BTW is not possible, is 100% useless" world view.
Sure, like that is going to happen. I mean, "Facebook can read your supposedly-encrypted Whatsapp messages" will raise how many eyebrows exactly?
> But there's also no non-technical thing they could do
No, that's untrue. For starters, release the source. Allow me to run my own backup software on their servers. Allow me to transparently run my own encryption before I upload stuff to their servers. And a very long etc.
> anything not 100% perfect, which BTW is not possible, is 100% useless
This is 100% useless not because it is not 100% perfect (it very well could be), but because it is 100% useless by conception. What threat model does this protect against exactly? The scenario where Apple servers get compromised? I'm quite sure this risk does not even enter the mind of the target audience here, and if it did, the hacker could very well push the silent update anyway. The scenario where Apple itself has access to the data? This does absolutely nothing to prevent it. The scenario where someone can social engineer an Apple employee to give your iCloud key to someone else? It was already not possible.
Two big threats: 1) insider attacks like the Saudi Twitter infiltration[0], and 2) Overreach by legitimate government process like subpoena[1].
> release the source
Useless. How do you know it's the exact source running on-device?
> Allow me to run my own backup software on their servers
Useless. How do you know your own backup software isn't compromised via a secret deal with Apple?
> Allow me to transparently run my own encryption before I upload stuff to their servers.
Useless. How do you know the OS isn't grabbing the raw files? How do you know your own encryption isn't compromised? How do you know that Xcode isn't inserting backdoors in the encryption you compiled from source?
> And a very long etc.
All useless. Tell me your perfect solution and I promise I can show it's useless (by your standards).
[0] https://en.wikipedia.org/wiki/Saudi_infiltration_of_Twitter
[1] https://ijunkie.com/your-icloud-data-phenomenal-law-enforcem...
This does not prevent any of these threats, it does not even necessarily make them more difficult whatsoever. "Insiders" will still have access to the source code doing the encryption and communications, and it is just not possible to protect against government overreach that can literally force you to do anything and keep quiet about it, even in otherwise relative sane countries. Search for NSA letter.
I actually don't expect any corporation to be above the government, fwiw, but this is off-topic.
> Useless. How do you know it's the exact source running on-device?
Because you built it yourself?
> Useless. How do you know your own backup software isn't compromised via a secret deal with Apple?
Because it's YOUR OWN backup software?
> Useless. How do you know the OS isn't grabbing the raw files? How do you know your own encryption isn't compromised? How do you know that Xcode isn't inserting backdoors in the encryption you compiled from source?
Because I have the source of the OS and I built it myself? Because I have literally used the same compiler I use for other platforms and not Facebook's? Because I can then actually monitor the actual communications between the device and the mothership? etc. etc.
The point of this entire thing was to show that _there is_ non-technical policies they can do to actually increase the trust level (or at least have a discussion about it -- as you are), but there is very few technical stuff they can do to increase it, and that's because it would miss the entire point. It's not about "trusting trust perfection" or whatever you think you are trying to argue here. You are trying to protect stuff from Alice by trusting Alice without even being capable of verifying it. It just can't academically work. You need to either be able to verify it or at the very minimum separate both roles.
There you go again :)
You literally just said something that used to take a subpoena from any law enforcement now takes an NSA letter. And that an insider attack that used to mean retrieving a backup file now means inserting back doors in source code that go undetected.
And somehow those aren't even more difficult?
> Because I have literally used the same compiler I use for other platforms
https://www.awelm.com/posts/evil-compiler/
It is literally provable that Apple will never be able to satisfy you. For any mitigation they introduce, you can (rightfully) create a hole in that mitigation.
What you're missing is that the same flaws and attacks appear in all of your "it would be better if" solutions. Once you're invoking NSA letters and malicious source code, all bets are off... including for open source.
> It just can't academically work.
Yes, we agree on that. But it also doesn't work if you're protecting stuff from Alice by trusting Bob, who might be secretly an agent of Alice.
I didn't say that. You said "overreaching government".
> It is literally provable that Apple will never be able to satisfy you
Nothing _technical_, that is, which has exactly been my point.
> Once you're invoking NSA letters and malicious source code, all bets are off... including for open source.
That's not true at all. There's an entire world of difference where "oh the software is just hidden from my eyes, communicating constantly and opaquely with the mothership, changeable at any moment by the same mothership, and all of it running in the same hardware also made by the same mothership" versus "I have these separate components that are only communicating through these channels in these clearly specified ways". The first only allows useless technobabble fake solutions, the second system actually allows discussion about trust and is usually the very minimum expectation of any cryptosystem.
> But it also doesn't work if you're protecting stuff from Alice by trusting Bob, who might be secretly an agent of Alice.
I don't see that as necessarily true either. But anyway, I can now choose between multiple providers for encryption, which _finally_ goes towards measurably increasing trust. Remember, despite the accusations, I have never claimed it had to be 100% trusting trust perfect, I am just claiming this one proposal is 100% useless. If you didn't trust Apple backups before and you would now, I'd question your judgement.
Something like hacking into a journalist's phone would require a lot of cooperation between infrastructure, software, and security to actually perform a targeted attack.
Despite Apple's harsh warnings about leaking secrets, people at Apple have already been spilling the beans about Apple's upcoming Ad platform for over a year, and that's just for something as morally grey as ads that they're going to spin as "privacy preserving" anyways. For something that actually goes against <everything> Apple has ever stood for, like targeting a journalist's phone to read their communications or extract data and secret keys from their advanced protection-protected iCloud Backups, at least one of the hundred involved would find a comfy bunker to live in with a phone line leading straight to News Corp or NYT.
Really having a hard time understanding the detailed security implications of your scenario beyond this vague notion you're presenting that a theoretical hacker can use theoretical tools to silently pwn any Apple device collected to the internet at any time.
A malicious actor who can access _already encrypted_ data storage where you cannot even associate files with a given account ID _without_ having already put a backdoor in the corresponding code may be able to actually put such backdoor in the software that is distributed to iPhones? Yes, I believe that.
As for your actual argument, there are always tradeoffs when we implement "good" but not "perfect" encryption solutions. Here, your trust is indeed in Apple to not perform an evil maid attack, but for many of us, we trust that Apple doing this to a regular person (or journalist, or government official) would be absolutely devastating to their entire brand. Even if most people wouldn't care if Apple cooperated with the CIA to perform a coup in $x country via sending out targeted malware to the leader's phone, they still stand to lose hundreds of billions of, if not a trillion, dollars over the following decade in lost iOS product sales, due to them purposefully hacking their own product to steal user data.
But why does Apple want to be the only administrator on your device?
Note: "Apple Kills Its Plan To Scan Your Photos for CSAM"
I find Matthew Green's take more useful than just about anything in this thread - someone who's very critical of Apple but able to articulate why this is overall net good:
https://twitter.com/matthew_d_green/status/16005676040154972...
Edit: on reflection, I don’t agree with this and wrote this too hastily. I’d still prefer 3rd party by default and believe it’s often a better basis for a discussion.
Reporters rarely add much unless they've got several days to do an analysis piece, which there are very few of. And is never the case for breaking news.
HN threads regularly supply oodles of context and counterpoints you don't find in any articles anywhere. Which is one of the big reasons we come here, right?
I still believe that a 3rd party source that at least has a chance of being more objective than a company issued press release is the ideal basis on which to form a discussion.
Governments will eventually pass legislation targeting E2E and CSAM was the one issue where Apple's method would have defanged support for that kind of law. But one good thing about making those plans public is that any proposed legislation will likely land on Apple's method as being a good compromise. Better for Apple to wait until they're forced by governments to do it.
This will go a long way into restoring my trust on Apple. Yet, I can't help but notice that the "we will scan your photos and snitch on you" workflow they published then is still compatible with enhanced iCloud security. Hell, they can always send a command to the photo's app in your phone to upload all your photos straight to FBI's servers. So in this case technology is like 50% of the trust, the other 50% is sheer commitment to customers and that was tainted by that episode.
https://www.washingtonpost.com/technology/2022/12/07/icloud-...
When apple released client-side scanning (which only ever applies to photos uploaded to iCloud Photos) the only thing that changed was now the scanning takes place on your device where you have transparency and ability to see what hashes are checked. The folks paying attention knew what this was - Apple redesigning a workflow to make LE cool with e2e encrypted photos. You read some false outrage articles and are now somehow still upset at a company doing work that is currently in your best interest. Baffling.
I've read all the technical documentation too. However who says that the mechanism is implemented like intended forever? Maybe Apple or (local) law will change and voila: Your device scan report is reported to Apple and authorities because it is anyway already in place on your device.
>The folks paying attention knew what this was - Apple redesigning a workflow to make LE cool with e2e encrypted photos.
They have just canceled this spyware wholesale,[0] ivalidating your entire point. Interesting how Apple fans can come up with a thousand ways to justify being spied on and then call anyone who points it out cluless.
The features were almost certainly related to each other given their timeline, even if one did not end up shipping.
If Apple would just go ahead and say "we've extracted tens of billions of dollars from you indirectly by letting google do the dirty work, but here's some encryption that doesn't make up for what we've done and continue doing" that would be more accurate.
https://support.apple.com/guide/security/advanced-data-prote...
So Apple only encrypts the files but not the metadata? If that's true the encryption is basically worthless because Apple is still able to "see" what files you upload and scan them for CSAM, copyright infringement or videos of 1989 Tiananmen Square.
Generally the biggest threat that end to end encryption (E2EE) addresses is the people that actually run the servers "inserting their own device to eavesdrop". So Apple in this instance. We would normally have to assume that Apple would do this on a request from state level entities as part of the threat model.
Apple has to provide some sort of E2EE identity verification if they want to claim that they are providing E2EE messaging. I note that they have been making such a claim for some time now. After this, all that will remain is the issue of control of the software. We will still have to trust Apple to not subvert the clients in some way. So nothing has substantially changed yet.
From the little we know about the usability of this new feature I note that the warning about new/changed devices is in small grey text. So very easy to overlook. hopefully Apple will provide enough context to allow the user to do something meaningful in response to such a warning.