I genuinely believe that in 2015 Apple had the balls to resist and today they don't.
I am judging by a simple fact, that "please confirm your age" screen is now mandatory during the iPhone setup in all countries, and in some it's behind a KYC. I have a strong opinion that this is insane. And once they let the foot in the door - there is no closing it.
Even in 2015 Apple put in backdoors. They have been really good at making people believe things that are not true. E.g. from the linked post:
iCloud already protects sensitive categories of data (like Passwords, Health data, Messages in iCloud, etc) with end-to-end encryption by default.
Except that there is a footnote in Apple's security document where they confirm that Messages in iCloud is not end-to-end encrypted if you don't enable ADP and have iCloud Backup enabled (which is probably most users):
Standard data protection: When iCloud Backup is enabled, the keys to your backups are secured in Apple data centers. If you use both iCloud Backup and Messages in iCloud, your backup includes a copy of the Messages in iCloud encryption key to help you recover your data.
So, there is always a backup of Messages in iCloud accessible to Apple and thus (US?) law enforcement, unless you enable ADP and the people you communicate with also use ADP.
WhatsApp is similar by the way. Unless you enable E2E backups, they end up in iCloud/Google Drive backups and are only encrypted at rest. Of the major messengers, I think only Signal completely opts out of iCloud backups and have their own real E2E-encrypted backups.
Even most technical people I talk to do not know this and don't have ADP enabled.
> WhatsApp is similar by the way. Unless you enable E2E backups, they end up in iCloud/Google Drive backups and are only encrypted at rest
One of the few good things about WhatsApp is that Meta can very credibly claim that they can't access the backups (as they're not stored by Meta). Meta holds the encryption key & Google/Apple hold the backups, so at least you now have deal with two entities to get the data.
I don't think without forcing more customers to loose data (e.g. by requiring them keeping an encryption pin/key) it's possible to perform backups in a (much) better way.
I'd argue that should/could be relevant, but isn't in reality. Do two global data processors more happy to work with governments/law enforcement exist?
> I don't think without forcing more customers to loose data (e.g. by requiring them keeping an encryption pin/key) it's possible to perform backups in a (much) better way.
I have full confidence that the industry would be quick to innovate if they were forced to, but that's not in their interest nor the government's interest.
Here's a simple one: Build an open standards-based system where users choose their backup provider and let them decide whether they prefer to have full control over the encryption keys or whether they want them to be managed by a third party. Educate them so that they can at least try to make an informed decision. Warn them about the risks and jurisdictions of built-in providers.
If someone wants to continue using their device as-is? Cool, 2 taps and they're done.
Do they want to store all of their app backups on their NAS? Make it as easy as switching your default browser.
> Here's a simple one: Build an open standards-based system where users choose their backup provider and let them decide whether they prefer to have full control over the encryption keys or whether they want them to be managed by a third party. Educate them so that they can at least try to make an informed decision. Warn them about the risks and jurisdictions of built-in providers.
WhatsApp performs (on Android) backups inside a normal directory. You can just backup it via e.g. Syncthing, which I've done in the past.
It doesn't get much more standards based. Strongly pushing users to deviate from the standard flow IMHO risks them quickly choosing poorer options (e.g. a free, dubious, online hoster). At least with the current setup, the "easy option" is quite safe in terms of not loosing data and very low risk that anyone apart from you and governments with lawful access ever accesses the data.
I see, I wasn't familiar with the way WhatsApp does this. I was talking more broadly about iOS/Android app data backups in general.
> At least with the current setup, the "easy option" is quite safe in terms of not loosing data and very low risk that anyone apart from you and governments with lawful access ever accesses the data.
The backups would still be encrypted and you could even have Apple/Google hold onto the key (if you wanted to), but if the data was stored elsewhere then neither party could access it unilaterally.
egorfine · · focus · HN ↗
I am judging by a simple fact, that "please confirm your age" screen is now mandatory during the iPhone setup in all countries, and in some it's behind a KYC. I have a strong opinion that this is insane. And once they let the foot in the door - there is no closing it.
microtonal · · focus · HN ↗
iCloud already protects sensitive categories of data (like Passwords, Health data, Messages in iCloud, etc) with end-to-end encryption by default.
Except that there is a footnote in Apple's security document where they confirm that Messages in iCloud is not end-to-end encrypted if you don't enable ADP and have iCloud Backup enabled (which is probably most users):
Standard data protection: When iCloud Backup is enabled, the keys to your backups are secured in Apple data centers. If you use both iCloud Backup and Messages in iCloud, your backup includes a copy of the Messages in iCloud encryption key to help you recover your data.
<a href="https://support.apple.com/en-us/102651" rel="nofollow">https://support.apple.com/en-us/102651
So, there is always a backup of Messages in iCloud accessible to Apple and thus (US?) law enforcement, unless you enable ADP and the people you communicate with also use ADP.
WhatsApp is similar by the way. Unless you enable E2E backups, they end up in iCloud/Google Drive backups and are only encrypted at rest. Of the major messengers, I think only Signal completely opts out of iCloud backups and have their own real E2E-encrypted backups.
Even most technical people I talk to do not know this and don't have ADP enabled.
There are a lot of weak defaults like that.
danhor · · focus · HN ↗
One of the few good things about WhatsApp is that Meta can very credibly claim that they can't access the backups (as they're not stored by Meta). Meta holds the encryption key & Google/Apple hold the backups, so at least you now have deal with two entities to get the data.
I don't think without forcing more customers to loose data (e.g. by requiring them keeping an encryption pin/key) it's possible to perform backups in a (much) better way.
tweetle_beetle · · focus · HN ↗
dns_snek · · focus · HN ↗
I have full confidence that the industry would be quick to innovate if they were forced to, but that's not in their interest nor the government's interest.
Here's a simple one: Build an open standards-based system where users choose their backup provider and let them decide whether they prefer to have full control over the encryption keys or whether they want them to be managed by a third party. Educate them so that they can at least try to make an informed decision. Warn them about the risks and jurisdictions of built-in providers.
If someone wants to continue using their device as-is? Cool, 2 taps and they're done.
Do they want to store all of their app backups on their NAS? Make it as easy as switching your default browser.
danhor · · focus · HN ↗
WhatsApp performs (on Android) backups inside a normal directory. You can just backup it via e.g. Syncthing, which I've done in the past.
It doesn't get much more standards based. Strongly pushing users to deviate from the standard flow IMHO risks them quickly choosing poorer options (e.g. a free, dubious, online hoster). At least with the current setup, the "easy option" is quite safe in terms of not loosing data and very low risk that anyone apart from you and governments with lawful access ever accesses the data.
dns_snek · · focus · HN ↗
> At least with the current setup, the "easy option" is quite safe in terms of not loosing data and very low risk that anyone apart from you and governments with lawful access ever accesses the data.
The backups would still be encrypted and you could even have Apple/Google hold onto the key (if you wanted to), but if the data was stored elsewhere then neither party could access it unilaterally.