How could this even be enforced if Apple pulls out cloud services of the UK ?
It's such a ridiculous request, the British Intelligence agencies must be bored coming up with new ways to make Apple look good.
How could this even be enforced if Apple pulls out cloud services of the UK ?
It's such a ridiculous request, the British Intelligence agencies must be bored coming up with new ways to make Apple look good.
Looking at the market size that might be a decision that Apple is willing to make as it would most likely be a temporary stick. The government can spin it anyway they want, but Apple devices do not work basically at all without the deep integration of their services. A geoblock would effectively mean UK citizens would be left with unusable devices and I can't see the resulting outrage being directed exclusively at Apple.
It'll be interesting to see how this plays out for sure.
Someone else here said something spot on for me, we’re all focusing on how bat sh*t this is because it’s global without even considering how human privacy obligations are just ignored.
Humans have a right to privacy, feels unbelievably pretentious and privileged to even say that. But it’s still true
I wonder if this means that Apple would ultimately take the same approach that they have in China, where the iCloud data and services are entirely localized within China and allows the Chinese government unrestricted access.
china had leverage because of the manufacturing happening over there and the incredible market opportunity, UK doesn't have much.
technically i believe apple could get out of the UK market to provoke a backslash on the government.
If they concede, other government will use the exact same blackmailing technique and one can say it will be the absolute end of their "privacy" marketing campaign they spent so much money into.
I'm still missing how this could be enforced ? To my layman understanding, this reads the same as if China said : "Meta, Tesla, Valve etc has entities in China therefore we get to see all data they store in the EU and the US.
The UK has Zero jurisdiction in Ireland for example where a lot of EU data may be stored.
The insane overreach was the UK wanting data on people not in the UK
Our noble "we can't have American data in the hands of our enemies," their savage "forcing American companies to turn over user data."
in other words, you store much more data on a phone versus a doomscrolling app[*]
*: unless you make videos and publish PII in them :)
I agree that the TikTok demands are pretty similar, though I might quibble over whether they're literally the same, since arrangements like that are the status quo in China but not in the US
Original comment below:
How is "remove foreign control of data on our nation's users" remotely the same as "give us access to foreign users' data"?
They're not even figuratively the same, despite you literally misusing that word
If by "give us access to foreign users' data", you mean TikTok, then ByteDance is only required to sell the US portion of TikTok to American buyers. If you mean iCloud, then Apple is only required to keep Chinese users' data on local servers.
"give us access to foreign users' data" referred to what the UK is asking for, I thought the post i was replying to was equating the UK's request to the US'
As a child of Portuguese revolution, I am aware of plenty of stories, apparently many folks nowadays think those are stories to scare misbehaved kids.
Those who are charged with stopping cyber crime are very must against this. End to End encryption is one of the better protections they can give you against foreign hackers and they want you to use it.
Meanwhile down the hall are people who are charged with investigating crimes someone in the country commits and they are want this. It is a lot easier to prove someone is involved in some crime if a warrant can get their data, but end to end encryption means they can only get random bytes. (of course they don't want warrants either, but that is a different issue not relevant here so they will specify warrants in this debate)
Note that this is not China apologia: they do the same brazen shit locally, but they're an authoritarian regime. I have lower expectations for human rights there.
George C. Parker was a conman in NYC who multiples times sold the ownership of the Brooklyn Bridge to his victims. Among other cons.
The only way to prevent that is not having any local office, no employees, nothing. Sell physical objects only by the means of local 3rd party resellers which will import goods. Same thing for services. Of course they can ban imports and services or go after those 3rd parties. It depends how nasty they want to be.
By banning Apple from doing business in the UK.
The US used a similar strategy decades ago to break Swiss Bank Secrecy laws (either Swiss banks had to give up the info or they were going to be kicked out of the US).
As someone else here said, Apple would 100% call this bluff. And you can be certain the UK won't have the US to put pressure on Apple for them. All the would happen is the UK Apple users would be with an expensive paperweight.
All evidence that I have seen suggests that consumers by and large do not care about this kind of privacy. They do not buy iPhones instead of other phones due to the privacy properties.
Therefore Apple's shareholders could order Apple to stay in the UK market.
And if not, then Apple's customers could be compensated with money and other UK-held assets that the government could confiscate.
You may be right, of course. But if there's one tech company who _might_ say "no", it's Apple.
Counterpoint: Apple in China.
[1] https://www.nasdaq.com/market-activity/stocks/aapl/instituti...
To use poker terminology: I think that if the UK made this bet that Apple would call.
Then they can vote in a board of directors that agrees with them, and have that board fire Tim Cook.
I would hazard to guess that you'll see an exodus of a lot of folks leaving Apple either because (a) they won't follow that order, or (b) in solidarity with those that are fired.
Reminder that privacy is feature that Apple touts (how much you believe them is up to you):
> On January 28, 2021, Apple CEO Tim Cook delivered remarks at Computers, Privacy & Data Protection Conference: Enforcing Rights in a Changing World. The virtual conference — hosted annually in Brussels, Belgium — is one of the foremost international privacy and technology conferences bringing together leaders from academia, government, civil society and the private sector. Learn more about the features and controls Apple provides users to safeguard their privacy at http://www.apple.com/privacy
* https://www.youtube.com/watch?v=OaLxTz1Yw7M
Where does your thinking that they'll suddenly forget about revenue from UK over this come from?
https://www.irishtimes.com/business/technology/uk-spy-base-g...
This is not just a case of the British intelligence services secretly “tapping into” Irish telephonic and internet traffic via land and maritime cables. Rather in most cases they are being provided free (or commercial) access to the information by companies associated with the use, ownership or maintenance of these cables.
Post-Snowden the Irish government retroactively legalised it...
Basically by saying that if they don't comply, they can't do business in the UK.
So it's still a problem. This seems like a looming PR battle.
How so?
Though will Apple blink is still unknown. Just because they can doesn't mean they will.
If Apple really has the guts to stare this one down, then I would expect it's the government who blinks.
It says that by train it is about 90 minutes each way and would cost about the same as the car trip.
Not sure it would be worth it though, unless you are in Northern Ireland. If you are someplace more like London it would be a lot faster to go to the nearest Apple Store in France and a lot cheaper.
In the US.
Imagine Russian Oligarchs on android devices! Polonium will roll, I tell you!
https://en.wikipedia.org/wiki/CLOUD_Act
Note that it the bar is having the ability to access the server, so this law is completely incompatible with most GPDR solutions: It's illegal to store European user data and then refuse to hand it over to US law enforcement, regardless of whether the data is stored in Europe or the request breaks European law.
By the way, this is similar to why for true GDPR compliance, data centers should be operated by EU companies that aren't subsidiaries of US companies, because even if the latter operate data centers located in the EU, they would still be bound to secret orders by the US government.
The Overton window is the range of subjects and arguments politically acceptable to the mainstream population at a given time.[1] It is also known as the window of discourse.
[…]
The political commentator Joshua Treviño has postulated that the six degrees of acceptance of public ideas are roughly:[7]
unthinkable
radical
acceptable
sensible
popular
policy
* https://en.wikipedia.org/wiki/Overton_windowOf course it wouldn’t be very profitable. So unfortunately you really can’t expect a major public company to take a stand like in a case like this.
Not so much because British people love their iPhones to such a extreme degree but because they willing to waste money and resources over something this stupid.
IMHO Apple could bring down the government that tried this if they really wanted to.
This is interesting, I know GDPR does not mandate data localization but I was under the impression that the requirements are a bit more difficult/stringent for transferring data out of the EU region ? While not perfect, it's a bit less 'open door' than it would be if it was hosted in the US.
The US has a law saying "If our spies tell American sysadmins to SSH into a server in the EU and copy data off it, they must do it and they must keep it secret"
You’d have to get a surprising number of people to go along with it.
If you think a SOC2 auditor would spot something like this, in a company the size of Apple or Google - you've probably never been through a SOC2 audit :)
And a heuristic anomaly detection system that generates masses of false alarms, and enough different teams and documents and policies to bury an army of SOC2 auditors. And so many log lines almost anything can get lost in the noise.
The janitors always have keys to everything. Especially when it’s required by law.
This all seems very similar to RIM and the aftermath of the riots in the UK. The backdoors became too obvious for customers to ignore. Did not go well for RIM in the market afterwards.
Is it though? I wonder how much of Apple's revenue is from the UK, probably around 5-6%? Apple isn't exactly as popular in the rest of the world as they are in the US.
Would damaging their privacy reputation globally be more valuable than the UK market? I honestly don't know, but my hunch says no - they are likely to want to keep their reputation and dump the UK market. I think more likely is Apple is going to be able to get the UK to cave in. Apple is extremely competent with PR, and would be able to spin any kind of pull-out or degraded service in the UK as the government's choice and fault, to the ire of UK citizens.
I mean this would be even more stupid than Partygate and the whole Truss debacle put together.
We know they collude with US intelligence serviceUS
Apple has no leg to stand on at all. When the NSA comes to your door and demands access to everything you have you don't get to say no. There is no court you can appeal to, and they'll take whatever they want and order you to keep your mouth shut about it. They'll walk right into your headquarters and data centers, force you to move your employees so they can set up an office for themselves on your property, insert their equipment into your network directly and take everything just like they did with AT&T decades ago (https://en.wikipedia.org/wiki/Room_641A)
Your only options are to comply or shut down (https://en.wikipedia.org/wiki/Lavabit) and I'm not even sure the US government would allow "shut down" as an option in some cases. It seems likely that they'd keep a massive target like Apple running even if the owners of the company wanted to cease operations, but lets be honest, Apple makes a lot of people very very rich so they'd never walk away from that. They'll keep making their money and just try to convince themselves that the US are the "good guys" and so it must be okay.
Obviously, Apple is going to comply with US federal law, given that their headquarters and employees are there, as well as their most profitable market. But when possible, they have shown themselves willing to fight against intrusion.
First, that's notably the FBI and not NSA. As gp says, NSA has greater powers with less legal oversight on national security grounds.
Second, a cynic might argue that Apple put up a noisy, principled fight that one time precisely to create the perception that you have here. It could be the FBI learned data requests to Apple are a dead end!
Or the two came to a mutually beneficial understanding: "don't come in the front door waving a court order for the cameras and we'll see what we can do when our reputation isn't on the line, see? And maybe if we help out, that antitrust investigation isn't necessary after all!"
A proposed law, or bill, like the one in the OP’s article, can be fought against.
Anything else is highly illogical or outright stupid, imagine CIA or NSA having meeting on this decade and a half ago and deciding 'well if they won't give us full access when we asked nicely I guess that's it, we have to respect the law and their wish'. LOL. They don't respect basic human rights at all if you don't hold US passport, and even then the list of cases breaking laws and constitution is endless.
Apple is good with their PR, but why do folks accept their every word literally and not as part of marketing spin to sell more services is beyond me. Rest of the market is not even trying to spin it that way which is actually more respectable behavior.
It’s been publicly used in a bunch of prosecutions at this point.
You're including end-to-end encrypted content in that as well, like from Advanced Data Protection?
> If you choose to enable Advanced Data Protection, the majority of your iCloud data – including iCloud Backup, Photos, Notes and more – is protected using end-to-end encryption. No one else can access your end-to-end encrypted data, not even Apple, and this data remains secure even in the case of a data breach in the cloud.
https://support.apple.com/en-gb/108756
I have no opinion on whether US intel has a backdoor into this e2e encryption or not. It seems like the sort of thing where people non-chalantly state that it must happen, but of course no one ever has actual proof or a source.
Can you give an example then? It would be major hacker news news if supposedly E2EE iCloud data were used in a prosecution.
Being willing to sacrifice everything you have, including your career, your freedom, and potentially your life, just to let the public know the truth is not something you should expect people to do. It's a huge amount of risk and sacrifice while the only reward is knowing that you've done the right thing even though you'll be vilified and punished for it. That's what makes whistleblowers heroes.
Snowden left an example of what kind of lifestyle is possible after leaking, and I doubt snowflakes at FAANG would be down for that. Or how about other examples of leakers that have turned up dead? That's a cheery thought to consider.
So yeah, at this point in time, I do believe there's a lot of people that might not agree, but are not up for the task.
I am actually surprised she survived this and wasnt suicided or sent to Guantanamo for water boarding till heart stops, I guess thats only for those without US passports.
I am not a lawyer, but I think that this would be illegal under EU privacy law.
As far as I can tell, China is asking to keep Chinese data in China and have access to it, but it is not asking to access data of American or European citizen and if it did we would be pissed off.
Frankly, the arrogance is appalling.
I suppose this is _good_ but more competent and well funded groups out of Israel, Israeli military complex, Cyprus don’t need to “ask” for a back door.
Honest question, how Apple is doing it in China? Maybe the exact same scheme will work for UK.