3 ms·
Apple's approach to privacy also includes being a partner in PRISM, a fact which they chose to vigorously deny as false allegations until it was proven to be tr
by whathaschanged 9y ago
Apple's approach to privacy also includes being a partner in PRISM, a fact which they chose to vigorously deny as false allegations until it was proven to be true.
Every story about Apple and privacy chooses to omit thus huge piece of info.
Why should anybody trust them now? What has changed to make anybody believe they aren't still lying about privacy?
- dclowd9901 9y agoIf their technology is built such that even they themselves cannot peer into the inner workings of your content, what good is their association with PRISM?
- rnhmjoj 9y agoBut it's not. It says "encrypted when sent and, in most cases, when stored on our servers". Even if encrypted at rest that doesn't mean they can't decrypt it. The calls and messages should be end-to-end encrypted but they are in control of the PKI so they could probably eavesdrop if they wanted.
- tptacek 9y agoReread Apple's security papers. Much of what's "encrypted on their servers" is encrypted in ways deliberately designed to make it untenable for Apple to decrypt. For instance, material in iCloud is encrypted with a key derived from your device PIN. So concerned is Apple with maintaining their inability to decrypt, even with a brute-force search on the PIN space, that they've contrived an elaborate quorum scheme of HSMs to manage the key space and count failure attempts. Nobody does this and Apple could have stopped here and rightly claimed the most secure large-scale cloud architecture of any mainstream tech company. But they didn't. They used programmable HSMs to implement the system and were concerned that a serious power bent on coercing Apple would target the HSMs. So, once they get the systems deployed, the admins meet and run the programming keys for the HSM through a "physical one way hash function". On stage at Black Hat, Ivan Krstic claims that hash function to have been a Vitamix blender. Almost always, when companies claim to encrypt things serverside, they're doing something shady. And it is always preferable that secrets be kept on devices and never touch servers. But Apple is taking the problem seriously.
- monkmartinez 9y agoI definitely take your suggestions and prose seriously Mr. Ptacek. Do you use iCloud? How about macOS computers? Do you have an article or blog on what you do for backup/cloud? Thank you for this kind of information. Very grateful to have this stuff at hand.
- userbinator 9y agoHow do you know Apple is telling the truth? One thing we're certain of, however, is that Apple has the signing keys. They also encrypt their firmware and even other apps to hide how they work.
- dclowd9901 9y agoI believe if they weren't telling the truth, _somebody_ would've caught on by now. We have lots of people in sec watching court cases involving police trying to break into iPhones. If somehow a department was able to access a phone without a user complying and no known backdoor was exposed, I'm sure we would've heard of it by now. I hope you're not expecting them to open source the secure enclave.
- tptacek 9y agoPRISM is a system for dispatching FISA 702 directives, which are the documents containing "selectors" (search queries) pursuant to a court-approved FISA 702 certification. It is to search warrants what Stripe is to credit card authorizations. "Not" being a partner in PRISM doesn't mean much; it just means you're legally obligated to handle that paperwork by hand. Like every other company in the country, you're still required to comply with a valid 702 directive.
- whathaschanged 9y agoThat has nothing to do with the questions that I posed. Apple being part of PRISM is what I referred to. Not the nature of the program. The intentional lying about it. Why should anybody trust them? “We have never heard of PRISM. We do not provide any government agency with direct access to our servers, and any government agency requesting customer data must get a court order,” stated Apple spokesperson Steve Dowling. http://www.cheatsheet.com/technology/is-apple-lying-about-its-involvement-in-government-surveillance.html/?a=viewall http://www.cheatsheet.com/technology/is-apple-lying-about-it...
- tptacek 9y agoThis article doesn't say anything at all, other than that all the major tech companies denied the original Greenwald claim that the NSA had direct access to servers (claims that every major outlet who published them have subsequently walked back), and that they had anything to do with "PRISM". Other investigative reporters have worked out what PRISM was. Now we're all pretty sure we know. But that doesn't mean the tech companies at the time had any clue. It is somewhat unlikely that the thing that sent them 702 directives was, to them, referred to as "PRISM". Generally, I find, when PRISM gets introduced into a discussion about Internet privacy, the discussion gets rapidly dumber. I'm not saying that's happening here, but it's a risk. If you're going to talk about it, you should have better sourcing than whatever the hell "The Cheat Sheet" is.