Alice and Bill have identical Apple devices. Only one gets Apple’s strongest iCloud protection.
472 comments
I am judging by a simple fact, that "please confirm your age" screen is now mandatory during the iPhone setup in all countries, and in some it's behind a KYC. I have a strong opinion that this is insane. And once they let the foot in the door - there is no closing it.
iCloud already protects sensitive categories of data (like Passwords, Health data, Messages in iCloud, etc) with end-to-end encryption by default.
Except that there is a footnote in Apple's security document where they confirm that Messages in iCloud is not end-to-end encrypted if you don't enable ADP and have iCloud Backup enabled (which is probably most users):
Standard data protection: When iCloud Backup is enabled, the keys to your backups are secured in Apple data centers. If you use both iCloud Backup and Messages in iCloud, your backup includes a copy of the Messages in iCloud encryption key to help you recover your data.
https://support.apple.com/en-us/102651
So, there is always a backup of Messages in iCloud accessible to Apple and thus (US?) law enforcement, unless you enable ADP and the people you communicate with also use ADP.
WhatsApp is similar by the way. Unless you enable E2E backups, they end up in iCloud/Google Drive backups and are only encrypted at rest. Of the major messengers, I think only Signal completely opts out of iCloud backups and have their own real E2E-encrypted backups.
Even most technical people I talk to do not know this and don't have ADP enabled.
There are a lot of weak defaults like that.
Apple has moved more things into the bucket of "we do not have the keys for this" over time, but pretending that this isn't a tradeoff for the common customer is disingenuous. That's why ADP exists, so that those who want to make a different tradeoff can do so.
Commenters on HN tend to be technically savvy and tend to want the defaults to be tailored to a technically savvy customer base. That's fine, but that's not a real representation of all of the smartphone users out there, and in this case Apple is directly offering the choice that they usually get knocked for taking away.
One of the few good things about WhatsApp is that Meta can very credibly claim that they can't access the backups (as they're not stored by Meta). Meta holds the encryption key & Google/Apple hold the backups, so at least you now have deal with two entities to get the data.
I don't think without forcing more customers to loose data (e.g. by requiring them keeping an encryption pin/key) it's possible to perform backups in a (much) better way.
Yes, because Apple knows the key, they can yield your cleartext data to law enforcement or whoever they authorise, but that is implied in the trust model, it isn't kept a secret or done dishonestly. A backdoor would is a devious or dishonest mechanism to siphon data, which nothing of the sort is happening here, because the trust model is transparent to the user.
That's a very user-unfriendly place to be. Most users won't understand why their data is gone, become unhappy, and distrust their devices to safely store their data. It's not even about buying more Apple products at that point - it's just literally reinforcing the stigma that "I can't understand tech, it's too complex".
You can't be security-maxxing and user-experience-maxxing at the same time. I do like Apple's approach which at least gives you the option.
They obvioualy never ever resisted anything except its a good PR stunt.
We are quickly heading to a world where governments want us to KYC everything, and we saw with the Revolut breach what happens when very, very bad people gain access to our private data.
The UK is a minor footnote. They can afford to lose it if push came to shove, but for now they're willing to make conciliatory gestures.
Not quite.
The request to confirm age is there, but actually completing it isn't mandatory (though granted, it does leave an 'alert' thingy on your phone settings saying you haven't finished setting it up).
"
Unfortunately this first phrase is not strictly true in the sense that UK customers have their e2ee secrets exposed under common use cases, without requiring a passcode. My copresenter and I published some research at DEF CON 34 this year showing how the e2ee data is particularly vulnerable when ADP is off. Overall, people that do not work with extraction capabilities are currently over-estimating the strength of apple's e2ee and encryption in general. The platform security whitepaper documentation is insufficient on transparency and there are a number of best practices Apple is not following to better meet the e2ee claims they currently advertise.
Maybe Apple should withdraw all encryption support from all UK government accounts? The Prime Minister can use a Huawei or some chunky thing from a military contractor.
Apple should withdraw from the UK until the UK government learns to respect encryption and privacy.
it is?
Especially since big tech is steaming ahead to mandating passkeys that only they are allowed to control/backup. Not long until all governments could intercept your passwords to all services.
I would hope to see Apple pull out of the UK market over this, and certainly to stop selling Apple devices to the UK government and to remove the UK government entities from Apple services.
Could I flash coreboot/libreboot, (mostly) disable IME, get opensource firmware for every peripheral, and get a chain of custody for every part from boule to finished part? perhaps, but this is not realistic for most people.
You're making a long list of assumptions that are not true. Incremental, improved privacy offered by apple over something like Windows is a significant improvement for most people.
Going to court is the pretty good "put up or shut up", idk what else you are expecting here.
Tim's public displays for privacy would be a perfect cover story for a gagged backdoored device.
Not likely the case in 2015 Apple nor probably even now, but perhaps a technique for the future or elsewhere to watch out for.
We don't want it the other way around; companies placed outside the borders doing and selling whatever they want without a care. So we end up in a negotiation.
Apple choose to maliciously comply; subtly revealing the TCN, giving all UK users notices about what their government demanded of them to encourage public outrage, and push on the correct parts of the UK government that has their interest in mind.
They can do both of things. There's no law against leaving a country for not respecting human rights like privacy and encryption.
PS: If you think the British gov is authoritarian.. well, you might not know what the term means and/or anything about the spectrum of governments operating today or in the past.
The British government is certainly not as authoritarian as those in China or Russia, but that doesn’t change the fact that it’s still terrible and restricts people’s rights. For example, you can be detained for as long as they want if you refuse to unlock your encrypted device.
Can Apple afford to lose the UK market? Almost certainly yes -- it's a fairly minor global player. Can the current UK government afford to deal with the massive fallout of banning all Apple products right now? That might be, as Sir Humphrey Appleby would say, a very courageous move.
In other words, Apple could simply state that in order to protect their users they cannot and will not do this, and will withdraw from the market rather than comply. That puts the onus on the UK government to either put up or shut up.
It would be fascinating to see how this would play out. Would "think of the children" and "OMG, terrorists!!" win against, "but I still want my iProducts"?
Read the full thread on Hacker News →
Related stories
- Apple's Two-Tier Encryption in the UKmacanorak.comLobsters · 21 points · 6 days ago
- Practical Decryption exFiltration: Breaking PDF Encryptionpdf-insecurity.orgLobsters · 3 points · almost 7 years ago
- Ars Technica · 0 points · 13 days ago
- Hacker News · 1 points · 9 days ago
- Hacker News · 7 points · 9 days ago
- Hacker News · 126 points · 10 days ago