‹ BackHN Continuity

Thread

Two-tier encryption in the UK

512 points · 472 comments · ReturnoftheHack

  1. egorfine · · focus · HN ↗
    I genuinely believe that in 2015 Apple had the balls to resist and today they don't.

    I am judging by a simple fact, that "please confirm your age" screen is now mandatory during the iPhone setup in all countries, and in some it's behind a KYC. I have a strong opinion that this is insane. And once they let the foot in the door - there is no closing it.

    1. microtonal · · focus · HN ↗
      Even in 2015 Apple put in backdoors. They have been really good at making people believe things that are not true. E.g. from the linked post:

      iCloud already protects sensitive categories of data (like Passwords, Health data, Messages in iCloud, etc) with end-to-end encryption by default.

      Except that there is a footnote in Apple's security document where they confirm that Messages in iCloud is not end-to-end encrypted if you don't enable ADP and have iCloud Backup enabled (which is probably most users):

      Standard data protection: When iCloud Backup is enabled, the keys to your backups are secured in Apple data centers. If you use both iCloud Backup and Messages in iCloud, your backup includes a copy of the Messages in iCloud encryption key to help you recover your data.

      <a href="https:&#x2F;&#x2F;support.apple.com&#x2F;en-us&#x2F;102651" rel="nofollow">https:&#x2F;&#x2F;support.apple.com&#x2F;en-us&#x2F;102651

      So, there is always a backup of Messages in iCloud accessible to Apple and thus (US?) law enforcement, unless you enable ADP and the people you communicate with also use ADP.

      WhatsApp is similar by the way. Unless you enable E2E backups, they end up in iCloud&#x2F;Google Drive backups and are only encrypted at rest. Of the major messengers, I think only Signal completely opts out of iCloud backups and have their own real E2E-encrypted backups.

      Even most technical people I talk to do not know this and don&#x27;t have ADP enabled.

      There are a lot of weak defaults like that.

      1. commandersaki · · focus · HN ↗
        Please stop with the hyperbole, weak defaults are not backdoors, know the difference. A backdoor is precisely what the UK was commanding, that is a secret way to siphon the cleartext data while purporting E2EE. Messages and other data syncing to iCloud using standard encryption (that is both you and Apple know the key) is simply a different trust model. It has its own set of benefits because there is less technical burden on the user which would usually arise in the event of a disaster and attempting to recover the data.

        Yes, because Apple knows the key, they can yield your cleartext data to law enforcement or whoever they authorise, but that is implied in the trust model, it isn&#x27;t kept a secret or done dishonestly. A backdoor would is a devious or dishonest mechanism to siphon data, which nothing of the sort is happening here, because the trust model is transparent to the user.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.