What I don’t understand is how they used an unencrypted form of communication for such important topics.
What I don’t understand is how they used an unencrypted form of communication for such important topics.
How do you know they did? For all we know, this was on an internal mail system that encrypted messages everywhere, except when showing their content to humans (https://en.wikipedia.org/wiki/Analog_hole)
Also, FTA: “[This document is from Epic v. Apple (2021).]”
I think that means they would have been forced to disclose this, even if it were encrypted (“we lost the keys” would be a viable defense to that, but would require a really, really good set of arguments supporting the claim that happened before a court order arrived)
?
What would encryption have changed? Apple were compelled to produce these as part of Epic v. Apple.
Seems reckless to keep confidential information like that, but I’m not familiar with the legal obligations large companies have, of course.
Public companies have to keep audit-related communications, but not something like this [1]. It comes more from civil litigation, where the standard of proof is the preponderance of evidence. If I sue you and produce partial records, and you say you deleted everything, that can be used against you.
https://www.wsj.com/articles/wall-street-to-pay-1-8-billion-...
Article is paywalled, but how can it be proved they’re using something like Signal? There must be at least some discussion available to be disclosured on request by law? How do they define if the subject is relevant enough to require a formal exchange between executives?
The world of big public companies is fascinating.
The threat model for signal is not to get you out of your legal obligation to comply with court orders.
Apple chose to keep these emails around because the value of the emails was greater than the risk of keeping them.
I’m sure that some form of side loading will appear soon. My guess is that all the privacy and integration will be held at arms length from the rest of the ecosystem and may just use webkit to access the user data.
The server itself is owned by Apple and is fully trusted to be secure by the exec team using it.