7 ms·
Apple does not allow your iOS iCloud data to be encrypted in a manner where Apple cannot access it. As is alluded to in this article. Privacy advocates and pri
by Darthy 9y ago
Apple does not allow your iOS iCloud data to be encrypted in a manner where Apple cannot access it. As is alluded to in this article.
Privacy advocates and privacy caring IT specialists have repeatedly asked Apple to offer such an option, but so far Apple has decided that regular people would turn such an option on, forget their password, then ask Apple for help and would be unhappy with their brand experience if Apple could not help them out.
If Apple would implement such an option where Apple could not access your data, shenanigans like the ones outlined in the article could not happen. It would also allow people who feel the state will misuse their info use iCloud for the first time.
There could be something good that comes out of this. These bad news could pressure Apple into finally offering an optional iCloud service where only you can see your data.
Answers to likely responses: "just use a different cloud service": on iOS, for cloud backups, there are no alternatives: it's iCloud or nothing.
- danieldk 9y agoAnswers to likely responses: "just use a different cloud service": on iOS, for cloud backups, there are no alternatives: it's iCloud or nothing. Moreover, in the case of Apple this could actually be productive. They have been pushing the privacy angle. Let's not forget that this is the company that pushed out end-to-end encrypted chats to tens (hundreds?) of millions of users before Whatsapp did it. If Apple offered this option, this would be a boon to tens of millions of people, which is far more productive than a few experts moving to relatively obscure alternatives.
- justaman 9y agoApple could utilize their newer devices' capabilities of finger print recognition. If you don't have a device capable of this, you don't get encryption. Sound very Apple™.
- bilbo0s 9y agoGenuinely trying to get an understanding of the pros and cons here, but is there any guarantee that this, or any other, data theft ring used iCloud? I mean, let's say I have an iCloud and it is encrypted in a completely secure fashion such that even Apple cannot access it. Well couldn't this ring have just collected my phone number, Apple ID etc etc from some other Apple database? Maybe I'm misunderstanding the threat here, but it seems to me that this is not going to be fixed by simply encrypting iCloud. Sure, that would be part of a comprehensive response, but the main problem seems to be that these people had access to internal Apple databases. To my mind, "internal" means everything from retail POS data to iTunes. I guess I'm trying to understand why encrypting iCloud would prevent a ring of internal Apple employees from gathering a person's information and selling it? And, to be frank, it's concerning because it's not just Apple. What stops a group of internal employees of any company from gathering a person's information and selling it? What are needed are strong guarantees about data security internal to these companies. My background is in health care technology, so the analogy I would make is HIPAA. But we need HIPAA for everything instead of just for healthcare information. Right now if employees of enterprises outside healthcare access a person's information and they don't sell it, they're just checking on a friend, there is no liability for that. Under HIPAA you're fired at a minimum. That's what we need.
- dagenleg 9y agoJust use different OS then
- danieldk 9y agoLike? On mobile, the only realistic alternative is Android, which is a privacy and security nightmare. On general purpose computers, Linux is better from the perspective of privacy. But for large parts of the general population, Windows is the only realistic alternative. And we know how important privacy is to Microsoft these days :(.
- pawadu 9y ago> Android, which is a privacy and security nightmare Only if your only source of information about Android is WWDC keynotes. But did Phil Schiller tell you about the Korean "malware" that was very quietly purged from App Store last week?
- zuppy 9y agoHow many of the Android devices are using the latest version and what's the option for the rest of them, excluding rooting? There are many advantages of Android, but this is not one of them.
- pawadu 9y ago> How many of the Android devices are using the latest version This comes up every time security discussed. But it is not as black as white as you think: 1. Security patches are separate from OS upgrades [1]. Many vendors incorporate security patches without upgrading the OS. 2. Many core Android components are upgraded via the store. 3. Google scans and remove bad apps from your device no matter Android version [3] -- [1] https://source.android.com/security/bulletin/2017-06-01 https://source.android.com/security/bulletin/2017-06-01 [2] https://www.howtogeek.com/179638/not-getting-android-os-updates-heres-how-google-is-updating-your-device-anyway/ https://www.howtogeek.com/179638/not-getting-android-os-upda... [3] https://support.google.com/accounts/answer/2812853?hl=en https://support.google.com/accounts/answer/2812853?hl=en
- IBM 9y agoGiven the way iCloud security works I'm not sure iCloud was breached at all [1]. Other reports seem to indicate that it was employees at Apple stores and third party resellers who had access to names, phone numbers and Apple IDs [2]. Presumably they would try to phish them later on. [1] https://youtu.be/BLGFriOKz6U?t=32m35s https://youtu.be/BLGFriOKz6U?t=32m35s [2] http://www.foxbusiness.com/features/2017/06/07/chinas-new-cybersecurity-law-tested-by-iphone-information-theft.html http://www.foxbusiness.com/features/2017/06/07/chinas-new-cy...
- eddyg 9y agoIt's almost as if people commenting here haven't even watched Ivan Krstić's Black Hat video...
- sitharus 9y agoGiven that with 2FA enabled Apple can't even reset your password (which has caught the tech press out before https://thenextweb.com/apple/2014/12/08/lost-apple-id-learnt-hard-way-careful-two-factor-authentication/#.tnw_RBRG7wAB https://thenextweb.com/apple/2014/12/08/lost-apple-id-learnt...) I agree that iCloud itself is unlikely the source. It's probably a marketing or support database that contains basic data. Annoying but not a serious breach.
- jasonkostempski 9y ago"Answers to likely responses: "just use a different cloud service": on iOS, for cloud backups, there are no alternatives: it's iCloud or nothing." That makes me unhappy with the brand experience.
- TYPE_FASTER 9y agoThere are other backup backup solutions. You can backup your camera roll to a Synology device in the background: https://www.synology.com/en-us/knowledgebase/Mobile/help/DSphoto/iOS_iPhone https://www.synology.com/en-us/knowledgebase/Mobile/help/DSp...
- JustSomeNobody 9y agoUnfortunately, this still requires location services. I really wish Apple would allow true background photo sync. From your link: To upload photos in the background: iOS apps cannot perform background tasks for more than 3 to 10 minutes. Using geofences to add locations will trigger and resume upload tasks in the background for another 3 to 10 minutes whenever you leave or reenter the defined areas. Tap > Geofence > Create to add geofences.
- TallGuyShort 9y ago>> Privacy advocates and privacy caring IT specialists have repeatedly asked Apple to offer such an option, but so far Apple has decided that regular people would turn such an option on, forget their password, then ask Apple for help and would be unhappy with their brand experience if Apple could not help them out. Were I an iCloud user, I would pay big $$$ for such a feature. But... they do have a point, and anyone who's helped their friends and relatives with IT issues can confirm that.
- Ntrails 9y ago>they do have a point, and anyone who's helped their friends and relatives with IT issues can confirm that. I think it's a pretty common state of affairs when dealing with complaints about Apple's choices. It's not that they're (necessarily) malicious, or that they don't care about security etc. It's prioritising the user experience of an average user over the concerns of a relative minority. I, personally, hope they never stop thinking about their products in that light.
- CaptSpify 9y agoYou are correct, but the problem is that they tout themselves as the goto company for privacy and security. If you are focused on usability over security, maybe don't advertise yourself otherwise.
- strict9 9y agoThere are alternatives, but with more friction and fewer features. My iPhone backups are made to an encrypted disk locally and backed up offsite with Backblaze, also encrypted. Have never used iCloud for the reasons you mention, and haven't missed it.
- matt_wulfeck 9y agoCorrect me if I'm wrong but isn't this the same thing as turning iCloud backups off and doing local encrypted backups instead? It seems like a reasonable choice to me, if you don't want to store in iCloud you can keep it locally with a different encryption model.
- aaomidi 9y agoThe problem is the deep integration between iCloud and Apple devices. Lots of stuff can't be just backed up to a different cloud provider/do locally.
- 0x0 9y agoYes but only iCloud backups can happen automatically and wirelessly every night. For local backups you need to attach the phone to your laptop using your usb cable and click "back up" in iTunes manually every time.
- woobar 9y agoThis is not true. Wi-Fi Sync (that includes iTunes backup) is available since iOS 5[1]. It works automatically if phone is plugged in and computer used for back is online. [1] http://osxdaily.com/2011/10/13/wi-fi-sync-for-iphone-ipad-ios-5/ http://osxdaily.com/2011/10/13/wi-fi-sync-for-iphone-ipad-io...
- 0x0 9y agoI stand corrected, I did not realize this supported automatic backups. It still requires your laptop to be on the same LAN though. It'd be nice if one could host a simple https server somewhere and configure the iOS unit to sync over the internet.
- Kenji 9y agoRoughly half the population has an IQ below 100. Let that sink in for a moment. Do you really think they are able to manage their digital keys such that they never ever lose them in a lifetime? Look, I am all for encrypted storage, it's the only thing I'd use (but I store everything on my own HDDs that are in my physical possession), but I see Apple's point here.
- eridius 9y agoNothing in the article suggests that iCloud data was compromised. It said > users’ names, phone numbers, Apple IDs, and other data Names, phone numbers, and Apple IDs just require access to directory services, doesn't need to touch iCloud at all. It doesn't say what "other data" is, but presumably that's not iCloud either, because it if was iCloud data that would be a much bigger headline and wouldn't have been omitted from the article.