This must be some "technically correct" weasel words bullcrap, as without at least equivalent access there is no chance Apple would be operating in China.
This must be some "technically correct" weasel words bullcrap, as without at least equivalent access there is no chance Apple would be operating in China.
[1] https://www.reuters.com/article/technology/apple-moves-to-st...
https://en.wikipedia.org/wiki/ICloud#Advanced_Data_Protectio...
> On December 7, 2022, Apple announced Advanced Data Protection for iCloud, an option to enable end-to-end encryption for almost all iCloud data including Backups, Notes, Photos, and more. The only data classes that are ineligible for Advanced Data Protection are Mail, Contacts, and Calendars, in order to preserve the ability to sync third-party clients with IMAP, CardDAV or CalDAV.
https://s3.documentcloud.org/documents/21114562/jan-2021-fbi...
Every company from your device's manufacturer, OS vendor, telecom carrier, app distributors and 3rd party software providers can be compelled to help make that happen.
And then there's always Cellebrite and friends.
It is end-to-end encryption, where each device's key generation is handled by your phone's Secure Enclave.
This article is a decent starting point in terms of what Advanced Data Protection is:
https://support.apple.com/en-us/102651
If you want a deeper dive into the security engineering of iCloud Keychain, the second half of this Blackhat talk by Apple's head of Security Engineering & Architecture (SEAR) is really great:
Synchronizing secrets: https://youtu.be/BLGFriOKz6U?si=cY94TYo28bRj4G7y&t=1357
Yes of course, but it's not so simple to bypass the hardware-enforced protections that exist both device side and server side. As far as I can tell, it seems effort was made to design/architect everything in such a way such that the protections can't be retroactively circumvented even under legal compulsion.
Disclosure: I previously worked for Apple, but not on the design/implementation of any of this stuff and this is all my own opinions, not those of Apple.
Advanced Data Protection is mostly concerned with protecting data from attackers on the server and in transit.
If you're interested in protections when an attacker has physical access to your device, you should read the "Encryption and Data Protection" section of Apple's Platform Security Guide.
Web: https://support.apple.com/guide/security/welcome/web
PDF: https://help.apple.com/pdf/security/en_US/apple-platform-sec...
If they can fish remotely and automatically, accountability goes completely out the window.
The communist party doesn't have "access" to a billion phones: what would they even do with all that garbage. They can ask Wechat what you send your friends, sure, and that's enough to police most crimes.
We don't have the budget or organizational acumen of the NSA.
Apple (and many other organizations) contracts work out for liability reasons, this is not the first instance of it.
Also note the language - specifically a “back door” or “master key”. If you call it something else, literally anything else, the statement holds up.
The feature is not named "back door" or "master key". It's a feature of iMessage with various names such as "zero click".
Also note they have created features before that provides law enforcement access to data at different stages of a pipeline.
All web results for `imessage "zero click"` are about vulnerabilities/exploits. Are you claiming some of these are intentional, or what?
"An Israeli spyware company has reportedly cut access to its clients in Italy following allegations that its product was used to target critics of the Italian government.
"The move comes after WhatsApp alleged last week that spyware made by Paragon Solutions was used to target 90 WhatsApp users in two dozen countries, including journalists and civil society members.
"Italy's government confirmed in a statement on Wednesday that seven mobile phone users in the country had been targeted by spyware on WhatsApp, calling the incident "particularly serious"."
(Not that the article has any evidence supporting the same claim about WhatsApp, either. In fact, the article describes WhatsApp/Meta claiming to have "disrupted" the spying and reporting it to the Italian government.)
Is that even necessary? A gag order means they can't reveal backdoors, and their entire stack is so locked down that discovering them is hard and unlikely.
If there's a gag order, then companies say "we have a gag order". Like Google and Twitter did back in the day when asked. And then immediately started releasing Transparency Report to show how many of the gag orders they receive, so gov't couldn't say "we don't request anything".
Yes it can, thats the whole point.
They can "No comments" all the way, but there's no way to legally forcing a commercial company to lie. The company can lie, of course, but it's their choice, not an order.
https://www.bitsaboutmoney.com/archive/debanking-and-debunki...
Even if no formal regulation to that effect exists for social media companies, intelligence agencies presumably have sufficient leverage to ensure similar access.
I suspect that disabling advanced data protection in the UK was meant to let Apple say it was complying as far as it could while fighting the main order.
A future update was going to ask users themselves to disable it in order to continue backing up their phones to iCloud.