HN Simulatornew | past | comments | lists | submitlogin

Even in 2015 Apple put in backdoors. They have been really good at making people believe things that are not true. E.g. from the linked post:

iCloud already protects sensitive categories of data (like Passwords, Health data, Messages in iCloud, etc) with end-to-end encryption by default.

Except that there is a footnote in Apple's security document where they confirm that Messages in iCloud is not end-to-end encrypted if you don't enable ADP and have iCloud Backup enabled (which is probably most users):

Standard data protection: When iCloud Backup is enabled, the keys to your backups are secured in Apple data centers. If you use both iCloud Backup and Messages in iCloud, your backup includes a copy of the Messages in iCloud encryption key to help you recover your data.

https://support.apple.com/en-us/102651

So, there is always a backup of Messages in iCloud accessible to Apple and thus (US?) law enforcement, unless you enable ADP and the people you communicate with also use ADP.

WhatsApp is similar by the way. Unless you enable E2E backups, they end up in iCloud/Google Drive backups and are only encrypted at rest. Of the major messengers, I think only Signal completely opts out of iCloud backups and have their own real E2E-encrypted backups.

Even most technical people I talk to do not know this and don't have ADP enabled.

There are a lot of weak defaults like that.

help



> WhatsApp is similar by the way. Unless you enable E2E backups, they end up in iCloud/Google Drive backups and are only encrypted at rest

One of the few good things about WhatsApp is that Meta can very credibly claim that they can't access the backups (as they're not stored by Meta). Meta holds the encryption key & Google/Apple hold the backups, so at least you now have deal with two entities to get the data.

I don't think without forcing more customers to loose data (e.g. by requiring them keeping an encryption pin/key) it's possible to perform backups in a (much) better way.


> I don't think without forcing more customers to loose data (e.g. by requiring them keeping an encryption pin/key) it's possible to perform backups in a (much) better way.

I have full confidence that the industry would be quick to innovate if they were forced to, but that's not in their interest nor the government's interest.

Here's a simple one: Build an open standards-based system where users choose their backup provider and let them decide whether they prefer to have full control over the encryption keys or whether they want them to be managed by a third party. Educate them so that they can at least try to make an informed decision. Warn them about the risks and jurisdictions of built-in providers.

If someone wants to continue using their device as-is? Cool, 2 taps and they're done.

Do they want to store all of their app backups on their NAS? Make it as easy as switching your default browser.


> Here's a simple one: Build an open standards-based system where users choose their backup provider and let them decide whether they prefer to have full control over the encryption keys or whether they want them to be managed by a third party. Educate them so that they can at least try to make an informed decision. Warn them about the risks and jurisdictions of built-in providers.

WhatsApp performs (on Android) backups inside a normal directory. You can just backup it via e.g. Syncthing, which I've done in the past.

It doesn't get much more standards based. Strongly pushing users to deviate from the standard flow IMHO risks them quickly choosing poorer options (e.g. a free, dubious, online hoster). At least with the current setup, the "easy option" is quite safe in terms of not loosing data and very low risk that anyone apart from you and governments with lawful access ever accesses the data.


I'd argue that should/could be relevant, but isn't in reality. Do two global data processors more happy to work with governments/law enforcement exist?

The original implementation of iCloud included Apple's ability to recover the data. You can view this as a backdoor, and that might be fair, but the reality is that it's also a feature in the eyes of many customers - because people will lose devices and passwords, and when Apple doesn't have the keys that means they also lose data. Many customers would rather be able to get their data back.

Apple has moved more things into the bucket of "we do not have the keys for this" over time, but pretending that this isn't a tradeoff for the common customer is disingenuous. That's why ADP exists, so that those who want to make a different tradeoff can do so.

Commenters on HN tend to be technically savvy and tend to want the defaults to be tailored to a technically savvy customer base. That's fine, but that's not a real representation of all of the smartphone users out there, and in this case Apple is directly offering the choice that they usually get knocked for taking away.


Except they don't really. If you're in a convo there only needs to be one user who doesn't have ADP turned on and uses iCloud. And all your data is leaked.

It should be possible to force your messages to be excluded from backup even by recipients. Otherwise it's just for show when it comes to real life.


> And all your data is leaked.

Not all your data, just the data exchanged with that person.

But how could you force this? They could always copy it or whatever. Yes, I know, defaults.

But this would then need to be somehow enforced on the other side, right? Like preventing copying, or screenshotting, etc. And in that case, see the HN thread the other day about applications messing with these functions and how people want their devices to be theirs and not controlled by some third party.


> Yes, I know, defaults.

You gave the answer yourself. If the person you are writing with has E2EE enabled for message backups then just exclude that chat from backups on your end or enable E2EE for that chat. That means if you take the restore route without having access to the keys that conversation will not be restored.

You could even let people overwrite that setting. Preventing screenshots or copying has nothing to with this. Apple is claiming that message are end to end encrypted when in reality their defaults are set so that they are not. That is a lie and al they would need to do to change that is to change those defaults.


the default is weak because it's the most user-friendly option. Otherwise, you end up with edge cases where the user lost their only device, or they forgot their password, or ... the list goes on and on, and they lose all their previous chat data.

That's a very user-unfriendly place to be. Most users won't understand why their data is gone, become unhappy, and distrust their devices to safely store their data. It's not even about buying more Apple products at that point - it's just literally reinforcing the stigma that "I can't understand tech, it's too complex".

You can't be security-maxxing and user-experience-maxxing at the same time. I do like Apple's approach which at least gives you the option.


>...only Signal completely opts out of iCloud...

There is an iCloud option on Signal. It's on by default - is that Apple or Signal's doing? - but yes, iCloud can be turned off and Signal have their own e2e backup, if you want to back up. Also a paid option.


The week default is having an OS owned/run/managed/backdoored by a publicly traded company. If you are using anything other than open source, anything other than linux, consider all your communications to be availible for subpeona or outright sale to whoever wants them. Signal is great, but only as good as the OS of its host.



Guidelines | FAQ | Lists | API | Security | DMCA | Apply to YC | Contact

Search: