TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Apple dropped plan for encrypting backups after FBI complained (2020)

847 pointsby Crash0v3rid3almost 4 years ago

19 comments

new299almost 4 years ago
Some have speculated that with the introduction of the PSI&#x2F;CSAM system Apple will enable E2EE backups. Given the lack of an explicit statement on Apple&#x27;s part and their history regarding E2EE backups (this article, and other statements). It seems really unlikely to me that Apple will enable E2EE backups.<p>Under E2EE, assuming the device key is randomly generated, if you have one device (as many users do) and you lose that device you would lose all your data. The alternative is the key is derived from your iCloud password, in which case, if you forget your password, you lose all your data.<p>Right now, you can browse your photos online. There&#x27;s been no statement that this is going away. Implementing this functionality with E2EE backups seem highly problematic.<p>These are huge changes to iCloud functionality that Apple would surely announce...<p>There are many open questions. And given that there’s no clear statement from Apple, I’m inclined to believe that they retain the ability to decrypt all data.
评论 #28125197 未加载
评论 #28125068 未加载
评论 #28125098 未加载
评论 #28125247 未加载
评论 #28126537 未加载
评论 #28125193 未加载
评论 #28127118 未加载
评论 #28125354 未加载
评论 #28126135 未加载
评论 #28125672 未加载
评论 #28127432 未加载
评论 #28125829 未加载
评论 #28127354 未加载
评论 #28127850 未加载
评论 #28125272 未加载
评论 #28125649 未加载
评论 #28125341 未加载
nomorepleasealmost 4 years ago
This really is something Tim needs to address before he again stands on stage and give lip service to Privacy with a capital P.<p>We also need hardball journalists to start asking Tim these tough questions instead of fawning over AirPods<p>And we need employees to start demanding this internally
评论 #28125225 未加载
评论 #28125047 未加载
评论 #28125080 未加载
评论 #28125003 未加载
评论 #28125096 未加载
评论 #28128608 未加载
评论 #28125000 未加载
评论 #28126872 未加载
g42gregoryalmost 4 years ago
I was patiently waiting for the M1 16in MacBook Pro to come out. After reading all these revelations, I am now considering not buying the new MacBook Pro and instead, just stick with Linux.
评论 #28125114 未加载
评论 #28125327 未加载
评论 #28125109 未加载
评论 #28125596 未加载
dukeofdoomalmost 4 years ago
These people really hate you and think low enough of you that they feel they have a right to rummage through your personal belongings anytime they wish. America feels like its over. The dream is dead. The supreme court full of weak people that will rubber stamp the rot. People feared AI, and they got laughed at. But its literally AI bots manufacturing consent on twitter and social media to this authoritarian slide.
heavyset_goalmost 4 years ago
In the first half of 2020, Apple gave data on over 31,000 users&#x2F;accounts based on FISA requests National Security Letter requests[1]. Apple provided data to the government&#x27;s requests roughly 9,000 times.<p>About 85% - 92% of the time, according to Apple, they responded to data requests from the government with the data that was requested.<p>I don&#x27;t see why Apple would turn about face and make it impossible to respond to the requests that they choose to respond with data about 85% of the time.<p>[1] <a href="https:&#x2F;&#x2F;www.apple.com&#x2F;legal&#x2F;transparency&#x2F;us.html" rel="nofollow">https:&#x2F;&#x2F;www.apple.com&#x2F;legal&#x2F;transparency&#x2F;us.html</a>
评论 #28125574 未加载
评论 #28127825 未加载
评论 #28131804 未加载
robertwt7almost 4 years ago
I&#x27;m actually curious, are they allowed to encrypt backups if FBI requested them not to? I thought as American company you have to comply with the law as well. Not sure though<p>Edit: damn downvotes, is this reddit? I&#x27;m literally asking because I don&#x27;t know. nothing is controversial here
评论 #28125233 未加载
评论 #28127880 未加载
sandstromalmost 4 years ago
If anyone is curious of what data Apple have on you, you can request it via their website.<p><a href="https:&#x2F;&#x2F;9to5mac.com&#x2F;2018&#x2F;10&#x2F;17&#x2F;request-your-personal-data-from-apple&#x2F;" rel="nofollow">https:&#x2F;&#x2F;9to5mac.com&#x2F;2018&#x2F;10&#x2F;17&#x2F;request-your-personal-data-fr...</a><p>Note that this won&#x27;t include certain categories that are stored unencrypted on Apple servers, for example iCloud backups and other data in iCloud (files, photos, calendars, contacts, etc).<p>I was quite surprised to see that even excluding all the data they (often) have from peoples iCloud accounts, there is still a bunch of stuff they collect.<p>Aside: I really wish Apple would spend more time on end-to-end encryption, for example of iCloud calendar and contact data as well as (obviously) the backups.<p>They should also have developer guides for app developers, on how to build it into apps: common patterns (group E2E patterns, multi-device E2E, open-source data sync servers that apps could use to arbitrarily synchronize E2E encrypted data between devices, etc).
rubatugaalmost 4 years ago
There&#x27;s a way to make fully encrypted backups of your iPhone locally, check out my blog post from my self-hosting series:<p><a href="https:&#x2F;&#x2F;www.naut.ca&#x2F;blog&#x2F;2020&#x2F;03&#x2F;20&#x2F;self-hosting-series-part-4-backup&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.naut.ca&#x2F;blog&#x2F;2020&#x2F;03&#x2F;20&#x2F;self-hosting-series-part...</a><p>This works well on Linux, and iOS 14. You can skip to the section `Compiling idevicebackup2`.
评论 #28127928 未加载
评论 #28127125 未加载
评论 #28125675 未加载
评论 #28125923 未加载
selstaalmost 4 years ago
Don&#x27;t use the cloud if you care about privacy, or encrypt the data yourself before uploading. Has always been the case.
评论 #28125048 未加载
评论 #28125126 未加载
评论 #28125993 未加载
jopsenalmost 4 years ago
&gt; However, a former Apple employee said it was possible the encryption project was dropped for other reasons, such as concern that more customers would find themselves locked out of their data more often.<p>Sounds more plausible to me.<p>Most of Apples customers are normal end-users, I can see how loosing access is worse for them as compared to data being available for a search warrant.<p>I suspect &quot;risk of loosing the key&quot; vs &quot;risk hackers get access to the backup&quot; is really what you want to weight here.
评论 #28127209 未加载
dragonelitealmost 4 years ago
That is why apple could take such a strong stand point when the FBI asked to crack the device itself some years ago.<p>Your device has become nothing more then a portal into their cloud and ecosystem. Where the fbi pretty much has free reign.
LanceHalmost 4 years ago
Every time I see one of these stories I wonder why the government has a seat at the table to decrease our rights. We currently have the right to encrypt backups. Why is the government lobbying to take that away from us? This is a right the government should be protecting for us, instead of stripping away.<p>An enforcement agency should never be advocating against the rights of the people.
评论 #28129165 未加载
apialmost 4 years ago
Local encryption of backups is very easy. I could code a basic implementation in an afternoon that would lack sophisticated security features but would be &quot;correct&quot; and far better than nothing.<p>There&#x27;s software out there to do it, but it tends to be geeks-only FOSS tools or obscure &quot;advanced&quot; settings in backup engines on things like NAS devices. None of those things are mainstream.<p>The fact that a feature like this doesn&#x27;t come built into things like Dropbox is puzzling until you consider that large companies have probably been heavily pressured against mainstreaming this kind of encryption. The absence of encryption as a standard option (even if not the default) in things like remote storage, cloud file sharing, and e-mail tools can really only be explained this way since I know for a fact that some percentage of business users would love it.
birdyroosteralmost 4 years ago
The answer is simple. Disable iCloud&#x2F;iMessage, backup&#x2F;restore your files the old fashioned way, and use Telegram or something for messaging. Don’t even opt into any of the ways they can spy on you.<p>iCloud and iMessage suck anyways, you aren’t really losing anything of value
评论 #28127120 未加载
评论 #28128221 未加载
Threeve303almost 4 years ago
The federal government should quit using private companies to get around the limitations placed on it by the powers enumerated in the constitution.
mrkrameralmost 4 years ago
&quot;Privacy is a fundamental human right. At Apple, it’s also one of our core values. Your devices are important to so many parts of your life. What you share from those experiences, and who you share it with, should be up to you. We design Apple products to protect your privacy and give you control over your information. It’s not always easy. But that’s the kind of innovation we believe in.&quot; [0]<p>So hypocritical.<p>[0] <a href="https:&#x2F;&#x2F;www.apple.com&#x2F;privacy&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.apple.com&#x2F;privacy&#x2F;</a>
liberty-bzmhalmost 4 years ago
それはまったく驚くべきことではありません。
8eyealmost 4 years ago
apple is burning to ashes over this
评论 #28128502 未加载
评论 #28126541 未加载
scopio918almost 4 years ago
Not sure, what&#x27;s the point of sharing a two years old news.
评论 #28125019 未加载
评论 #28125103 未加载