Apple – Privacy – Government Information Requests
apple.com
apple.com
This is key. The way we engineer software and services can have a major impact on the war against overly invasive government requests. We know that these requests will come; it's our responsibility to design things in a way that protects customers from our legal obligations when confronted with them to the greatest extent possible.
While this certainly serves their own interests, kudos to Apple for baking this type of consideration into the basic iOS design. They should and will be financially rewarded for it.
They control the OS, they DO have access to everything.
An OS is actually much more powerful, it controls everything, it has direct access to memory. If a user can see his photo, the OS can.
You can (and always should) design encryption code without having a single root key. Entirely open sourcing that code should not make any difference to the security of the encrypted data.
How do you know that? Secret court orders are secret. "National security" trumps everything these days.
LavaBit chose to shut down rather to insert a backdoor that was forced on them. I doubt Apple will shut down over that.
And thanks to Snowden we know Apple's products have been backdoored already.
http://www.spiegel.de/international/world/catalog-reveals-ns...
http://www.infoworld.com/article/2609310/hacking/apple--cisc...
Are you saying it's outside of scope for NSA to forcefully install a backdoor or request encryption keys?
How do you explain LavaBit?
How do explain NSA's hardware in data centers?
How do you explain NSA's hardware in cell phone providers centers?
How do you explain NSA's backdoors in Microsoft's products?
And I think an Apple employee is that last person that would leak anything. They work for Apple after all, starting to work there surely takes some abandonment of principle.
In the end, why would anybody feel assured by what someone believes someone else would do?
Edit: Why is imaginenore downvoted so heavily? His concerns seem rather rudimentary.
lets be honest, if they want your data your the weakest link. if you want to be paranoid enough to go the route your thinking its far cheaper for them to take you to a back room and employ a hammer to you.
It's important to note however that the passcode is just 4 digits long by default, and could be bruteforced by Apple in milliseconds if they wanted to. So to say that "Apple cannot bypass your passcode" is misleading, as guessing it is absurdly easy.
http://www.slideshare.net/alexeytroshichev/icloud-keychain-3...
They could order Apple to disclose signing keys so that the government can install spyware themselves. See http://en.wikipedia.org/wiki/Lavabit#Suspension_and_gag_orde... for a case where they have done something similar before.
It would have to be an OS update since applications don't have access to that stuff, even if signed with an apple key.
That said, it'd be kind of unsubtle, and they'd probably get caught.
iOS won't let even the most permissively configured, "unreviewed" app do things that apps aren't supposed to be able to do?
Well, actually it isn't surprising at all.
EDIT: It appears I was wrong, this was only in LA county.
“The passcode is entangled with the device’s UID, so brute-force attempts must be performed on the device under attack. A large iteration count is used to make each attempt slower. The iteration count is calibrated so that one attempt takes approximately 80 milliseconds.”
This is still an argument for using a longer length code, however, since a simple 4-digit number would only take 800 seconds to brute force.
It should be obvious, but I think it should also be stated in a way that makes it a lie if it's later discovered that left some way to access or keep the passcodes.
Has Apple publicly claimed that they will also refuse to push individualized compromising code updates to devices on demand by gov't authorities?
That won't work.
>Has Apple publicly claimed that they will also refuse to push individualized compromising code updates to devices on demand by gov't authorities?
No, and even though I strongly doubt the government would even try to do this and even more strongly doubt Apple would comply, their new tech (apple pay and touch ID use hardware support to even protect against this sort of breach which shows that they are certainly thinking about it). I'm pretty sure Apple won't even have the ability to silently push an OS update (if they did then someone could find out because it would be in the OS and then all hell would break loose) - it would have to be accepted by the target which means there is a reasonably large chance of detection.
Link: http://www.apple.com/ipad/business/docs/iOS_Security_Feb14.p...
"And would require Apple's complicity" - Or perhaps rather Qualcomms's...
Security is always a convenience/security trade-off. iOS is about as good as you can get before inconvenience will turn people to less secure devices.
To me, it seems like this passcode thing is a good way to keep my data safe from thieves but from the govt.? don't think so.
Too bad they (and other phone manufacturers) don't protect phone calls with some kind of end-to-end encryption.
Apple asserts that Facetime and Facetime Audio are end-to-end encrypted. And Google claims Hangouts are encrypted as well.
I don't know whether there are caveats (or how many) to either of those claims. But that's about as much as one could hope for in the current climate. [2]
[1] Particularly upstart computer companies dealing with the telecom oligopoly. Long cozy with governments and law-enforcement, if not an explicit part of government.
[2] It's a serious bummer that FaceTime never developed into the open standard they claimed at introduction. I've been curious about where that fell apart. (Competitor disinterest, patent liability, carrier terms, etc)
All of this is a damn shame because in my experience the competing standards don't have the usability and quality that FaceTime provides.
So they ARE giving data to the government at their request...
BTW, that percentage of say, 100 million customers (which I'm sure Apple has, probably more) is 3850 people, not an insignificant number...
Anyhow, I personally wouldn't trust anyone anyway. Google, MS and Apple are all American corporations, and need to comply with US law, no matter how asinine.
0: https://www.apple.com/privacy/docs/government-information-re...
* "In addition, Apple has never worked with any government agency from any country to create a “back door” in any of our products or services."
If Apple provides an interface to request user-data to law enforcement / NSA, that's not a back door in the product or the service.
* "We have also never allowed any government access to our servers. And we never will."
If they provide user-data after being served with a warrant (possibly through email or to their legal department), their servers were never accessed, yet the data was provided.
It's always interesting to read what is and isn't said. Word games, I swear.
I think that would be reasonable information to share, because it'd educate both law enforcement and the general public about what data is available from their devices.
Plus it'd settle the issue of word games- or at least bring it closer to being settled in my eyes. We can't get a good idea of what is going on with these 10k foot marketing pronouncements.
Page 4 onwards provides a list of information they provide to law enforcement agencies. Probably prudent if you're an apple customer to simply assume all of this information is as good as public.
...
For all devices running iOS 8.0 and later versions, Apple will no longer be performing iOS data extractions as the data sought will be encrypted and Apple will not possess the encryption key.
Interesting. What changed in iOS 8, I wonder?
Yes, that's true. But if you run an email service that's based in Cupertino, what do you do when served with a lawful search warrant or wiretap order? Say "no," and be found in contempt of court and have all your servers carted away by some men in black so they can find the file they're looking for?
There are a few ways around this. One is not to permanently store warrant-worthy user data (Snapchat, Wickr, etc.). Another is end-to-end encryption (original version of Hushmail), though key distribution and UX become problems. A third is to move your servers to Switzerland, though then you get served with process from the Swiss authorities instead of FBIDHSDEAetc.
Apple has taken none of these steps. Assume our hypothetical Cupertino-based email service has not either. What do you do when the Feds show up with a lawful order?
I don't expect them to say no. That's why I don't expect them to imply that they would or suggest that they never have.
It's been "fun" to read Jewel vs. NSA proceedings, press statements, and officials' statements about these issues because of the extent to which they play word games to technically not lie according to specific (re)definition of words.
Even if you are root it's no guarantee, thank you rootkits :/
As with all things security, sometimes it comes down to trust and legal protections.
And, if you keep your headquarters in Cupertino, quite possibly from US authorities as well (see the currently in-progress Microsoft case about access to servers in Ireland).
You could still NSL a backdoor, but if the service is open source at least there's a chance of the code being audited.
Without a trust the only thing that comes close is an in person P2P pairing ceremony.
Key management might work in an enterprise setting with a central authority, but making sure your friend's public key isn't swapped with the government's is pretty hard if you don't trust the cloud provider, telecom, or intermediate infrastructure.
https://www.apple.com/apples-commitment-to-customer-privacy/
In addition the new section launched today includes a page on government information requests, including "National Security Orders from the U.S. government." One sentence summary: they provide data to the government when required to by law.
PRISM itself is a program that is structured as a request/response, and the requests are approved by the FISA court, so it would fit into Apple's language in that section.
The initial report of PRISM implied that the NSA and FBI had direct, unfettered access to providers' "central servers", but that has been since walked back a bit. The points of concern with PRISM are 1) poor oversight from the FISA court, 2) overly broad request criteria resulting in huge datasets collected, and 3) the lack of public oversight due to gag orders.
Really? I haven't been able to follow every report, as the Snowden leaks generated a lot of content over the past year. Can you give a source to where PRISM's central server access has been "walked back a bit"?
http://en.wikipedia.org/wiki/PRISM_%28surveillance_program%2...
The press report that most directly addresses the issue is probably this one:
http://www.cnet.com/news/no-evidence-of-nsas-direct-access-t...
Incidentally the author of that story is doing a startup now, visits HN, and actually has posted in this thread! Username is "declan."
Essentially, it seems there are a number of NSA programs that we can now distinguish from one another.
PRISM uses the FBI and FISA court orders to directly request records from hosted application providers like Google, Yahoo, Apple, etc.
But there are also other programs that claim to be authorized under the FISA law that target network infrastructure companies like Verizon and AT&T, apparently sucking up and storing huge amounts of raw traffic directly from network infrastructure. This would be the famous "secret room" at AT&T network building in California. These could suck up Apple traffic (or anyone else) but Apple would not be aware because it's at the network layer.
Then there is MUSCULAR, in which the NSA helped the British GCHQ hack into the internal networks of Google (without Google's knowledge) to suck data out of the unencrypted connections between Google servers.
Seemingly, they also have some sort of canary in place in case they get secret requests under the patriot act: http://boingboing.net/2013/11/05/apple-hides-a-patriot-act-b...
By omitting the line you are, for most intents and purposes, saying that you received a request. Now, saying you received a request and saying specifically what request you received are different, but I imagine the gag order doesn't make that differentiation.
Gag order is not that you can't say a specific thing, it's that you can't communicate a specific piece of information. The canary is communicating something.
A court order can ask you to lie, so the "I can't lie to my customers" defence probably won't work.
It was removed for the latter half of 2013, and this just-released first half of 2014 report.
Take that as you will.
I consider that a back door.
>We have also never allowed any government access to our servers. And we never will
Makes it clear what he means in the first statement.
I've known Apple to engage in hyperbole to a significant degree, but never -- in nearly 40 years-- to lie publicly.
They haven't denied providing information under warrant. Basically, every US company is going to do that.
But that's on a case by case basis, not wholesale.
I'm very interested to see how the device vs. account data-request ratio maintains/changes with the release and adoption of iOS 8.
It's not unreasonable that American citizens might feel more empowered voting with their dollars than with ballot papers.
Myself, I think they did fairly well, certainly the best of any tech company out there today.
Ok. "We're enabling custom encryption key management. You may now generate and use your own encryption keys. In addition to ensuring the device data is encrypted, nothing in your iCloud account can be recovered if you lose your key because it is all pre-encrypted before being sent to iCloud. Again, if you lose your key, there is no recovery possible. We'll also be opening up a new bug-bounty program specifically for identifying weaknesses and exploits in our baseband, firmware, and OS that could result in the leaking of your encryption keys and personal data. Here at Apple, we take your privacy serious."
Until then I assume it is unsecure.
With the companies in question, it's not hard to vote with your feet and complain. With the government, it's very difficult.
(The same is largely true in the EU, even though it's possibly more pronounced the US.)
When someone voted in by a single state can influence the entire country like that, it makes everyone feel powerless. I'd rather give my money to a company that has my interests in mind throughout the years in exchange for products and services than dump thousands of dollars into someone's campaign like a drunken bet at a Las Vegas casino every couple of years.
I mean when the wikileaks cable dump came out, there was quite a bit of noise about how US government people should not visit the site because it would still constitute a breach of security even though it was in the public domain, and that they could lose their jobs for it. This is no different, really. The material is still classified whether it's spread all over the press or not, so discussing it with uncleared persons such as the public would (IANAL, again) I imagine be a breach of security.
China seems quite determined to block IM systems which do not cooperate with the authorities and permit monitoring of communications. Most recently, both Line and the Korean KakaoTalk were blocked [1].
Skype remains useable in China, presumably because Skype permits efficient monitoring [2].
It seems unlikely that China would tolerate such a prominent opaque communications channel as iMessage in the hands of a significant proportion of their citizens.
Thus, if China refrains from blocking iMessage for a prolonged period of time, wouldn't it be reasonable to assume that China is in fact able to snoop on iMessage?
[1] http://www.ibtimes.com/china-restricts-messaging-apps-confir...
[2] http://www.reuters.com/article/2012/01/31/us-china-dissident...
Nonetheless, Apple's relationship to China is a interesting case:
• On one hand, China is posed to be the largest market for Apple in just a handful of years.
• On the other hand, it's hard to imagine China approving of e.g. un-snoopable instant messaging in the hands of the populace.
Personally, I'm waiting for the other shoe to drop. Now that the police can't go to Apple for your data, we'll start seeing more judges ordering users to unlock their phones to allow them to be searched. I don't think it will be long before such a case reaches SCOTUS, and then we'll see how that works out...
Contempt of court? Fine and then jail him for non-compliance. Seize Lavabit's assets if required. I doubt he would have let it come to that.
But their solution was analogous to "won't give us back that alleged stolen $20 we told you about? We want your whole bank balance."
Aww hell naw.
I guess he made his point, but he screwed over his customers twice in this case. First by dumbing down his crypto to be easier to use and allowing it to be broken as it did by the feds, and second screwing every customer over by not complying and shutting down his service.
Is not that against 5th amendment?
While lower court decisions have gone both ways, according to wikipedia,
in United States v. Doe, the United States Court of Appeals for the
Eleventh Circuit ruled on 24 February 2012 that forcing the decryption of
one's laptop violates the Fifth Amendment [1]
So there is hope.Perhaps a more practical problem is even with a 5 digit pin, it's entirely possible to simply try all combinations. You probably need more than 8 digits before that becomes impossible.
[1] http://en.wikipedia.org/wiki/Key_disclosure_law#United_State...
Given a long time. Don't forget iOS slows your brute-force attempts down substantially. I'd be curious how long a brute-force attack would take given the current behavior of the OS.
I think we are all intelligent enough to know that even if Apple were handing over information, it wouldn't exactly be good for business to admit you've been complicit in handing over personal details to the Government, would it? "Yes, we have been giving away your information, but we promise not to do it any more. Hey, we just released a couple of new iPhones, want to buy one"
Anyone else notice the page is cleverly worded and any mention of security seems to be limited to iOS 8 context? "In iOS 8 your data is secure", "In iOS 8 we can't give law enforcement access to your phone" - maybe I am just overanalysing things here, but I have learned not to be so trusting of companies as big as Apple considering the amount of information that they hold.
You know we're living in a new kind of world when privacy is being used for marketing purposes...
According to [1], there are about 600 million apple users, so this translates to 23,000 customers exposed due to government information requests.
Seems like a large number. Is 600M correct?
[1] http://www.cnet.com/news/apple-to-reach-600-million-users-by...
I can understand the marketing benefits Apple sees in making these disingenuous privacy claims. I'd be willing to call that "just business" except for one thing: Trying to persuade people they have a technological solution will necessarily get in the way of the absolutely vital political project of destroying the political and legal foundations of the surveillance state.
Are these four-digit passcodes being used to derive encryption keys? If so, I'd like to hear where the additional entropy comes from. There's no use encrypting things with a 128-bit key when the effective entropy of the key is really only ~12.3 bits.
I'm sure the engineers at Apple would not have overlooked this; it would be great to hear more about the specifics.
[1] especially if the attacker can download encrypted data and try an infinite number of times (instead of e.g. typing the passcode on the phone or hitting the iCloud servers)
1. PIN
2. Random key in effaceable NAND storage (generated on device reset)
3. Burned in permanent CPU-unique key.
I think OP's linked statement from Apple means that Apple is now also encrypting data stored on the iCloud servers.
http://www.apple.com/ipad/business/docs/iOS_Security_Feb14.p...
From today's announcement (scroll to "iCloud"): Mail and Notes are not stored in encrypted form on iCloud servers. http://www.apple.com/privacy/privacy-built-in/
From December 2013: Mail and Notes are not stored in encrypted form on iCloud servers. http://support.apple.com/kb/HT4865
Surely all IMAP traffic doesn't flow through their servers.
I'd recommend using a longer passcode. If you don't want to use the keyboard, choose a long number for a passcode and you will still get a number-pad when entering it.
Another loophole to be aware of is the "escrow keybag". If you're paired with a laptop, there is a file in /var/db/lockdown that can work in place of the PIN (the device can decrypt the escrow keybag with #2 and #3 above and use the keys therein to decrypt the files it needs). Apple did this to allow backups without unlocking the device.
[Edited because it now seems unclear which Apple policies have changed.]
Apple has clearly stated that its system was not compromised.
The user reset questions were socially engineered meaning it is irrelevant whether or not the data is encrypted. From Apple's perspective the owner of the data is downloading it.
Yep, you're right. My point, perhaps poorly stated, is that if Random Hacker X can figure out the answers to the iCloud reset questions, so can a law enforcement agency. Then they can log into that account. Impersonating someone this way is legal -- or at least has not been ruled to be illegal -- as long as it's done under court supervision under the Wiretap Act or similar legal authority authorizing prospective surveillance.
Possibly related: I disclosed last year that the Feds have demanded that major Internet companies divulge targeted users' stored passwords, and in some cases the algorithm used and the salt: http://www.cnet.com/news/feds-tell-web-firms-to-turn-over-us...
Answers about very famous people. Wikipedia will not tell me your mothers maiden name.
Also, as much as I sympathise with the women whose accounts were breached, actors aren't always the sharpest tools in the shed, and phishing schemes are a common tool for gaining access to other peoples accounts. One of them (I don't remember which) publicly claimed iCloud backup for her iPhone was "too complicated" a while ago. Given that it's as complicated as "turn it on, and make sure it gets plugged into power with Wifi every so often", I don't doubt some of them would fall victim to even a very simple phishing scam.
"On devices running iOS 8, your personal data such as photos,
messages (including attachments), email, contacts, call history,
iTunes content, notes, and reminders is placed under the
protection of your passcode."Also note that today's announcement says Mail and Notes are "encrypted in transit" only. In other words the December 2013 page remains current.
[Edit] - Clearly something is off here. iPhone keeps a copy of the last several hundred emails downloaded from my IMAP server, I would expect an iCloud backup of those emails would be "under the protection of the passcode" (a.k.a encrypted).
That doesn't mean Apple is somehow encrypting the messages stored on my IMAP server. Likewise, it doesn't mean Apple is encrypting customer emails stored on their @iCloud.com (or whatever) email servers....
I'm going to assume there are just some wires crossed here, but I do hope they clean up the document and clarify this.
Well, no shit. If they did that I'd log into my Gmail web interface and see encrypted gobbledygook instead of my emails.
I think companies like apple and google are undertaking PR exercises like this in the hopes of finding that sweet-spot between the sense of crisis (excitement?) that smart phone ownership brings and the banal integration of technology into everyday life. There _are_ government requests, but they do not affect _you_. maybe. So my question: Is government surveillance now officially part of the iPhone experience?
To the extent that a debate exists, apple is engaging and steering that discussion. This is just pure organizational reflex. And it's cynical in some sense, but apple doesn't really have a choice in the matter either. Ultimately it is what the US officials consider to be an acceptable level of visible surveillance, which is a political consideration.
Sometimes I feel it's not unethical to use user's data for marketing, the way facebook and Google tell us; that they don't directly share details with marketers, but they let them target the audience.
Ask your self:
Would Snowden use this phone? Your answer to this question is the same as the answer to the question "Is this phone secure?"
I guess I'll get downvoted for this sense it goes against the Apple circlejerk, but this issue is more important to me than magic internet points.
#1 Mac unit sales
http://www.macworld.com/article/2062821/apple-by-the-numbers...
2010 @ 13662k
2011 @ 16735k
2012 @ 18158k
2013 @ 16341k
Total = 64,896,000
#2 iPhone unit sales
http://www.statista.com/statistics/232790/forecast-of-apple-...
I only take the number from 2013 & 2014 because Apple trend to upgrade fast.
2013 @ 53.6 Million,
2014 @ 63.2 Million,
Total = 116,800,000
Now, quote from "Government Information Requests"
"less than 0.00385% of customers had data disclosed due to government information requests."
Only 699529.6 round to 699529 customers had data disclosed.
I would think at least 50% of the older models are either on-sold or the user hasn't upgraded.
edit: UVB-76 has a good point, there is probably a very high percentage overlap.
Source: http://verizonmath.blogspot.com
http://www.digitalmusicnews.com/permalink/2014/04/24/itunes8....
800 Million,
#4 ipod users
http://www.statista.com/statistics/276307/global-apple-ipod-....
2010 @ 50.31 Million
2011 @ 42.62 Million
2012 @ 35.17 Million
2013 @ 26.38 Million
Total = 154,480,000
#5 Apple Laser Printer user
#6 Apple magic mouse user
#7 Apple Newton user
#8 Apple PowerBook user
#9 Apple MacBook user
#9 Apple Xserve user
Yes I made a mistake, however this is just a word game from Apple overall.
Even if we take the total number of iTunes customers (~800 millions), it comes down to 30,800.
Legally there is a combination of abuse and grey area right now, and it's going to get worse near term.
Those government information requests don't cover how many times an officer at the local or state level has accessed someone's phone either illegally or questionably legally.
This move by Apple can help to blunt that effort by the local police.
If this turns out to be as good of a move as it seems like it is, Apple has acquired my attention in a way they weren't able to previously (I've been an Android user from day one). Plus I like the new larger iPhone 6.
Can someone confirm or deny the following? I think this is the current state of affairs.
A) Apple will unlock PIN-locked devices by government request, but the best they can do is brute-force. This is very slow, as it can only be done using the phone's on-board crypto hardware (which has a unique burned-in crypto key), and the PIN is stretched with PBKDF2. It has been this way for a while. Apple has no "backdoor" on the PIN or any form of cryptographic advantage here that we know of.
B) The new thing mentioned in the OP's link is that things stored on Apple's servers are now encrypted as well, with your iCloud password.
Is this correct?
What do you mean by this? I doubt the passcode is stored in plaintext anywhere, and if I recall correctly, the passcode is convolved with the CPU's burned-in crypto key before storage, so you couldn't recover it from a backup without the corresponding phone.
Your example is a little unique though because you have physical access to both their computer and their phone. In theory you could just brute force their iTunes backup password.
I imagine every vendor selling encryption would make this claim. Otherwise, they would have to say there is a flaw in their implementation or publicly reveal their backdoor.