3 ms·
"However, this feature is neither confidential nor private as Google still has unlimited access to its users' emails, even when they use confidential mode." Ye
by helpPeople 7y ago
"However, this feature is neither confidential nor private as Google still has unlimited access to its users' emails, even when they use confidential mode."
Yes, that's how databases work.
If we use this same logic, is Apple not being private with your data?
- eridius 7y agoApple uses end-to-end encryption for iMessage, which is the only Apple-related confidential communication I can think of (well I have no idea what the guarantees around FaceTime are).
- izacus 7y agoUhm, Apple also holds emails, calendars, contacts and notes on their servers via iCloud.
- ceejayoz 7y agoNotes can be set as secure, which encrypts them with a password Apple doesn't have access to.
- eridius 7y agoBeyond explicitly using secure notes (which are encrypted), I don't recall Apple promising "confidentiality" of those things. I mean, I don't expect Apple to give that data to others, but I also don't assume Apple has no way of accessing that given a court order.
- deleted 7y ago[deleted]
- wysifnwyg 7y ago1. The emails are not end-to-end encrypted. 2. Google retains full access to the email even when you set a self-destruct timer. 3. If you password-protect an email, Google can link your recipient's phone number with their email address. I think those are valid concerns. Don't you?
- TheSoftwareGuy 7y agoMy understanding is that Apple only stores your data in an encrypted form, and does not themselves possess the key used to encrypt that data. I remember it used to be if you forgot your password there was no way to retrieve your iCloud backups because there was no way to decrypt them. My knowledge of this is quite dated though, so I could be wrong.
- izacus 7y agoThat's not true for iCloud at all. It is true for iMessage (although they can push new keys to your devices to decrypt content remotely), but iCloud has no such guarantee. They even give those keys to Chinese government for Chinese citizens: https://www.theverge.com/2018/7/18/17587304/apple-icloud-china-user-data-state-run-telecom-privacy-security https://www.theverge.com/2018/7/18/17587304/apple-icloud-chi...
- partialrecall 7y agoI've not bought into the Apple ecosystem so I'm not totally sure how it works, but when you back up your files to Apple's servers, isn't it encrypted on your device before transmission in such a manner that Apple is unable to decrypt it on their servers? That's been my impression. (There is the matter of Apple's software being closed source and maybe they could push a compromising update that pushes your data to their servers without encrypting it, but that's probably a matter for another discussion.)
- rndgermandude 7y agoAs all the celebrities who got "hacked" and had their nude pictures released on the internet can attest to, this is not the case. The reason for this is convenience: In order to encrypt something you need a key. If you derive the key from e.g. the account password, then some people will promptly forget the password. If you derive it from the device key, then people will lose or break their device. Either way, they will get mad at you when you tell them that yes, you can reset their password/key and restore access to their account, but all their backed up data will stay inaccessible. So Apple allows you to reset a password (e.g. by answering "security questions") and then you have access to some of your data again, which means Apple has to have access somehow to that data. Apple divides the data they store into two categories: encrypted (to which Apple still has access if they want or need to) and end-to-end encrypted (to which they do not have access, so it will be gone if you lose the key): https://support.apple.com/en-us/HT202303 https://support.apple.com/en-us/HT202303 So e.g. your photos and videos and files in general are recoverable by you, Apple, or somebody who got a hold of your password, or managed to reset your password. While e.g. your keychain is "End-To-End" and meant to unrecoverable in the case of a lost key (well, unless your lost key was easily guessable and thus bruteforcable).
- partialrecall 7y agoHow did those celebrities get hacked? It was my impression that they had poor passwords, or got betrayed by a friend to whom they had sent the images. If the Apple services themselves were being compromised, that's news to me. It was also my impression that Apple claims that if you lose or damage your device, your shit is gone forever and they can't get it back (and that independent repair services can get around this by simply fixing the damaged device.)
- drcode 7y agoA "database" is a tool for storing data, which is a concept that completely orthogonal to the question of how a piece of data is encrypted or who is in possession of the decryption keys.
- nixpulvis 7y ago> Yes, that's how databases work. A database is, at its core, just a bunch of bytes structured in some way. There's nothing stopping you from storing an encrypted value in someone else's DB, and as long as you keep your secret private your plaintext is as safe as your encryption scheme.
- zaphod4prez 7y agoThis comment doesnt seem to be in good faith. > Yes, that's how databases work. The article is arguing for end-to-end-encryption, which is perfectly do-able for google. It's not a matter of "how databases work" at all, like literally not even a bit. It's a matter of what features the company has chosen to implement. > If we use this same logic, is Apple not being private with your data? Has Apple launched a "confidential" email mode that does not protect the ostensibly-confidential emails? Google is making privacy claims and not backing them up by actually making them private. But... No, Apple is not being that private with your data! I'd love it if Apple worked to make E2E encryption easier in iCloud mail, and they should do so.