12 ms·
Apple reportedly dropped plan for encrypting backups after FBI complained (2020)
- mtgx 6y agoTo make things worse they tie iMessage backups to all iCloud backups, so the so-called "end-to-end encryption" of iMessage is essentially a completely irrelevant/broken feature for 95% of iPhone users. And that's without mentioning that Apple also has the ability to add its own key invisibly without users knowing about it to allow interception (WhatsApp does this, too, now).
- humps 6y ago(Jan 2020)
- viktorcode 6y agoSince user encrypted iCloud backups would prevent password recovery to access your data I'm more inclined to believe the decision was made out of convenience for the end user. General public would hate it when the support won't help them recover family photos which are still stored in the cloud. Full encryption is nice to have, but overwhelming majority of users won't get any tangible benefits from that.
- bugfix 6y agoSo why not give users the option to encrypt everything if they want to?
- jaywalk 6y agoBecause of the FBI, obviously.
- gruez 6y agobut then again, who's going to be using it? A sibling comment mentioned that you can still do local backups which are encrypted and don't leave your device. What's the intersection of people who cares about their backup being encrypted, but can't set up itunes sync on their computer?
- dkonofalski 6y agoI would use it because I like the convenience of iCloud backup and not having to ever plug my phone into anything.
- gruez 6y ago>and not having to ever plug my phone into anything. works over wifi too. https://www.switchingtomac.com/tutorials/ios-tutorials/backup-your-ios-device-over-wifi-automatically/ https://www.switchingtomac.com/tutorials/ios-tutorials/backu...
- dkonofalski 6y agoIs that still accurate? You don't use iTunes to sync the phone anymore and I don't think the encrypted backups could be done via WiFi. If that's changed, then that's awesome.
- xurukefi 6y agoI'm convinced that if you give the general public the "encrypt everything option", then too many people will opt in without being aware of the consequences. They will eventually forget their password, loose all their family photos and blame Apple for it. A disclaimer also wouldn't help here. If anything, this should be some hidden developder mode kind of option to make sure that only those opt in who know what they are doing.
- gsich 6y agoThen you make them aware of those consequences. This is solvable.
- amiga-workbench 6y agoUsers don't read, they smash Ok buttons without understanding.
- kgwgk 6y agoMake them sign several clauses on a contract and send back a scanned copy. Really, if they still go through it without understanding what they are doing it will be on them.
- mattnewton 6y agoSigned copies protect you from litigation in court, not loss of brand value in the court of public opinion. Plenty of people bitten by it will just never use a backup product from you again, and every time apple sneezes a flurry of journalists are there to document it.
- UnFleshedOne 6y agoI guess the idea here is to make enabling the option enough of a pain so that only people who need it are going to use it, and button smashers will be spared.
- patrickserrano 6y agoI worked in education and had teachers and administration who were smart people, consistently asking to have their passwords reset. And the only requirement we had was that it needed to be 8 chars long, no special chars or capitalization. (This was a result of students and staff not being able to remember their passwords for more than a day or two) I can't imagine needing a password for them to recover photos and messages.
- MagerValp 6y agoThat's essentially what backing up to your Mac instead of iCloud gets you. The data is encrypted with your key to a device that you control.
- zahrc 6y agoAnd this is also what most people want, most of them don't care about security, privacy and safety. It's convenience and accessibility.
- whoknew1122 6y ago100% this. Working at AWS, I've dealt with (presumably) IT professionals who couldn't understand why we don't backup their KMS keys in case they delete their key and data gets orphaned. This sort of encryption bears a heavy burden on the customer. And the customer often doesn't want to accept that burden.
- jtdev 6y agoBut we shouldn't default to "let's compromise data security and privacy because some customers can't keep track of their keys". That would be like a shoe store only selling velcro shoes because some shoe buyers struggle with tying shoe laces...
- gruez 6y agoBut you can still make local (itunes) backups that are encrypted?
- felipemesquita 6y agoYes. It’s handled by Finder now since new versions of macOS don’t have iTunes, but it’s the same encrypted backup functionality.
- sneak 6y agoDoesn't matter; all of your iMessage conversation partners likely have iCloud Backup enabled (it's on by default) and are providing Apple your plaintext chat history with them.
- r00fus 6y agoFor those who can avoid using iMessage for meaningful discussion, that's why we have Signal/Telegram/etc. Also it takes that extra effort to piece together evidence if you have to search someone else's phone for my data.
- 6y ago
- Beggers1960 6y ago"I'm more inclined to believe the decision was made out of convenience for the end user." Bingo. We have a winner.
- sneak 6y agoReuters says six sources inside Apple said it was the FBI. My sources inside Apple tell me that there was at least a partial implementation for doing e2e backups safely, including a system for using friends/family to certify recovery in the event of password loss (presumably something like secret sharing). The FBI and Apple actively collaborated to prevent this from coming to pass. > One former FBI official who was not involved with these talks told Reuters that Apple was won over by the agency. “It’s because Apple was convinced,” said the source. Your claim directly contradicts the article.
- boomboomsubban 6y agoSix sources confirmed the FBI contacted Apple, they can't fully prove that that contact caused the decision. I'd bet it at least played a role, but the article is not as clear cut as you make it out to be.
- t0mmyb0y 6y agoThis is correct. Apple works with FBI while publicly saying they don't.
- PragmaticPulp 6y ago> including a system for using friends/family to certify recovery in the event of password loss Having friends and family take ownership of partial secret keys is a non-starter. Few people would actually go to the lengths of distributing fractional secrets to their friends and family. Even fewer people would do a good job of not losing them over the years. Outside of techie circles, account recovery is a relatively frequent occurrence. The majority of general public customers would prefer being able to recover their account even if it means a vanishingly small chance that the FBI would be able to access it in the even of an investigation.
- admax88q 6y ago> Few people would actually go to the lengths of distributing fractional secrets to their friends and family. Even fewer people would do a good job of not losing them over the years. I feel like this is all a solvable UX problem. The secrets could be automatically distributed and stored on friends/family devices, could be integrated into iMessage directly. "Choose friends you trust to help you recover data." If N of your M designated friends and family still have access to their phone when you need to recover your backup then you can get access, maybe by presenting a QR code on each device you can scan, or a notification you can interact with after confirming identity via a phone call or something. The secrets wouldn't require any actions to keep intact, they could always be synced into iMessage and included in your own backups. Kind of like you're operating a RAID array across your friends and family, N+X redundancy, so long as no more than X of your group needs recovery at the same time you're good. Kind if an interesting approach actually, would be neat to build this into Matrix as an experiment.
- the_duke 6y agoRelated to this, it seems FB sort of panicked with the recent Signal exodus. The app demanded cloud backups from me 8 times over 2 or 3 days. Presumably so that returning users still have their messages intact.
- randomdude402 6y agoTelegram sent out a message yesterday saying that they have gained 25 million users in the last 72 hours alone, pushing their total user count to 500 million. I suspect Signal took a somewhat smaller number of users from FB than this.
- random5634 6y agoNo kidding. If you run windows deployments the bitlocker key backup to domain / azure / whatever is a must / lifesaver. FAR FAR too many situations where users don't keep their keys. It can be as simple as upgrading the chip on your computer - which happens with AMD machines because they've had a long run of AM4 socket support. Boom, you fTPM is gone now, and user is complaining they've lost their irreplaceable stuff. I've seen this on IT side with backups. They set up an encryption key on the backups (pub / private) 6 years ago. 6 years later, when it comes time to recover under some time pressure, no one has a CLUE where the key is and old staff are long gone. Absolute nightmare. For all the folks saying managing encryption keys at scale is like tying your shoes - 100% false. To manage keys (especially ones where the private key is rarely if ever actually used) takes very very HIGH levels of care. One solution - have encryption keys periodically "fail" so you are forced to prove you know how to recover your key - but no one does that. Same issue used to occur with 2FA apps on phone upgrades before they made it easier to move stuff over to new devices.
- j45 6y agoThe option to enable full zero knowledge encryption should exist for icloud.
- voidmain 6y agoApple has a publicly documented solution for Keychain involving HSMs, which I think makes decent default tradeoffs between recoverability and security. And of course they could, and once did for local backups, offer an opt-in unrecoverable passphrase option. On the face of it they have decided to favor law enforcement over their customers here.
- zimpenfish 6y agoTitle is missing "reportedly" before "scrapped".
- samename 6y agoI had to remove a word because title was too long. Maybe removing “fully” would’ve been better
- jaywalk 6y agoIt's far from ideal, but I can live with it since I can still backup my phone locally and have those backups be encrypted.
- vulcan01 6y agoTheory: Apple has a deal with the government to not properly encrypt iCloud backups in exchange for the government not regulating them through antitrust. This is pure speculation, but I wouldn't be surprised if this is why the government has been so lax on antitrust regulation with Big Tech.
- dannyw 6y agoThe FBI and DoJ working together isn’t hard to imagine.
- dylan604 6y agoWell, also, the sky is blue. The FBI is part of the DoJ, so by definition they are working together. The Attorney General is the FBI Director's boss. https://www.justice.gov/agencies/chart https://www.justice.gov/agencies/chart
- soperj 6y agothis phrase always bothered me. Technically the sky isn't blue. That becomes quite clear every single night.
- dylan604 6y agoOkay, then "s/sky is blue/water is wet/g" or "s/sky is blue/fire is hot/g" Edit: I can't just let this lie. Just because you can't see it doesn't mean it's not true. The sky at night is still blue, there's just not enough light for human eyes to see it. I have plenty of footage from night skies where the sky is still clearly blue. This footage [0] is clearly taken at night while the moon is below horizon then the sky becomes blue again (still at night) when the moon rises. The light reflections in the water as well as still being able to see the stars in a blue sky shows the sky is still blue even at night. [0] https://vimeo.com/241600503 https://vimeo.com/241600503
- boomboomsubban 6y ago
- luxuryballs 6y agoThis is why I use local only backups but there’s been a number of times where iCloud backups will mysteriously re-enable and I have to go delete the backup and disable. Not a fan of that!
- dylan604 6y agoI'm in tech, and I don't trust the cloud. I use the cloud at employer's behest, but I don't put my personal anything in the cloud that I don't have to. No, I do not have anything to hide. It's more of I have seen too many instances of services getting shut down, or deciding they don't want to offer that service, or just plain going out of business to trust anything to a 3rd party. That's before even deciding if they are able to maintain security and privacy.
- StillBored 6y agoI'm convinced this is also why after 20+ years of knowing how to have a id authenticated/encrypted email system based on public keys its not been made the default in pretty much any of the mainstream email systems. The excuses of it being unwieldy are 100% because its not transparently integrated.
- PragmaticPulp 6y agoI suspect such a system would be popular among the tech crowd, but you're greatly overestimating the general public's desire to deal with any of this complexity. The average customer from the general public understands that they're not going to become the subject of an FBI investigation and they'd gladly take simplified UX and account recovery as a tradeoff.
- freedomben 6y agoI would have agreed with this a few weeks ago, but given recent events you would be shocked at how many people are swarming into things like Signal. The average person is realizing that they don't get to choose what opinions are allowed and what are not allowed. It's no doubt a reflection of my social circle, but it includes plenty of people that barely know how to turn their computer on. Many of them are asking me what to do to protect their privacy and ability to communicate. If I were Keybase right now, I'd be starting back up development and cranking out some marketing right about now. That's a huge opportunity.
- StillBored 6y agoMy point is that it doesn't have to be visibly complex. gmail or outlook could automatically generate and store a public key for every single account transparently then just append signatures to the bottom of emails while providing the public key directory for their users. Then any random client can hit keys.gmail.com (or whatever pseudo standard one wants for finding the key servers) cache public keys and on some TTL check for revocation/etc. Then the only thing the user would have to know about is whether the from box is "green" indicating that the user was validated, "yellow" indicating an invalidated email, or "red" indicating a problem with the validation. Once the validation is complete via a back/forth exchange the clients then know they can encrypt emails to the destination, thereby turning the from field green on the next email exchange. Sure people using those services would also be allowing the service to see their private keys, but for phone apps, or desktop applications the key generation portion could be done on the machine and only the public key pushed to the email providers keyserver. Plenty of other email services (proton mail, symantec) make this very easy for the end user.
- sneak 6y agoI've been posting that Reuters link repeatedly to HN (in context) for the last year or so; hopefully this is common enough knowledge now that I can stop. This whole "Apple cares about your privacy and encrypts your data" false narrative really needs to finally end.
- chopin24 6y ago(2020)
- modeless 6y agoIt's also important to realize that the backup includes your encrypted iMessage messages, and the key required to decrypt them. Meaning that if you have backups enabled, all the "end-to-end" encryption in iMessage is defeated. Apple and by extension the FBI can read your messages. This is documented by Apple here: https://support.apple.com/en-us/HT202303 https://support.apple.com/en-us/HT202303 Even if you disable backups, whenever you correspond with someone that has backups enabled those messages are still accessible to Apple.
- lights0123 6y ago(if you have Messages in iCloud enabled, but you don't loose much by turning it off)
- modeless 6y agoIf you turn off Messages in iCloud then your messages are included in the regular iCloud backup. This is documented here: https://support.apple.com/guide/icloud/messages-mm0de0d4528d/icloud https://support.apple.com/guide/icloud/messages-mm0de0d4528d...
- whatever1 6y agoAnd this is something not clear at all in the advertising campaigns of Apple.
- gruez 6y agoI don't see how this is an issue. Let's say google proudly advertises that chrome is backdoor free. But at the same time they provide a remote desktop solution (aka backdoor) that users can optionally enable. Is this an issue?
- zingermc 6y agoIf the messages are encrypted at rest on your phone, it seems reasonable to expect the same of backups on the server.
- morpheuskafka 6y agoIt looks like the main "about backups" page [1] on Apple Support misleads about this issue: > iCloud backups include nearly all data and settings stored on your device. iCloud backups don't include: > Data that's already stored in iCloud... iMessages... Health data Only the more technical "about encryption" page [2] that most users wouldn't seek out contains the full story, providing a list of regular encryption vs. E2EE services and admitting the key issue: > Messages in iCloud also uses end-to-end encryption. If you have iCloud Backup turned on, your backup includes a copy of the key protecting your Messages. This ensures you can recover your Messages if you lose access to iCloud Keychain and your trusted devices. When you turn off iCloud Backup, a new key is generated on your device to protect future messages and isn't stored by Apple. The problem is that the first page makes it sound like no iMessage related data is backed up, when the truth is that the messages themselves aren't but a backdoor copy of the encryption key is, and lists it along with other E2EE services like Health data that do not have a key backed up and remain E2EE protected with iCloud backup. A user would have no reason to even seek out the second article to learn that it's not the same. Concerningly, iCloud Photos are not E2EE at all. It's no more secure/private than Google Photos or any other app. [1] https://support.apple.com/en-us/HT204136 https://support.apple.com/en-us/HT204136 [2] https://support.apple.com/en-us/HT202303 https://support.apple.com/en-us/HT202303
- deleted 6y ago[deleted]
- IndySun 6y agoSo, obvious question, how then does iCloud keychain (still) work? I mean, is everything iCloud compromised, all the time, everywhere? That kinda flattens Apples privacy claims.
- deleted 6y ago[deleted]
- morpheuskafka 6y agoEverything listed in the second article, including iMessage in iCloud is end-to-end encrypted: AirPods pairing keys, Safari tabs/history, learned keyboard vocabulary, Home app, Health app, Apple Card transactions (not sure what the point of this is as obviously the bank, card network, many others have detailed records), Maps favorites, Memoji, Siri data, Screen Time data, and Wi-Fi passwords, and yes, iCloud Keychain. The catch is that if iCloud Backup is enabled, the iOS device will make a copy of its private iMessage key and save it with the backup, rendering your messages accessible to Apple. This doesn't affect Keychain. Other services such as iCloud Photos are not E2EE and are always readable.
- soperj 6y agoThis is the company that you all trust with your privacy. Good grief.
- stepanhruda 6y agoI’m hoping they simply deferred this for a few years so they don’t anger feds too much at once.
- ur-whale 6y agoIt's increasingly clear that Apple is not in their user's camp.
- esotericsean 6y agoI know a lot of it is marketing, but they're certainly trying much more than competitors.
- modeless 6y agoGoogle has enabled end to end encryption of Android backups.
- random5634 6y agoGood lord - this is a HN only comment. Go ahead and use your phone from china with built in spyware! Or almost all android phones - never updated. Or use whatsup or facebook messenger instead of imessage. It's increasingly clear that HN commentators pushing towards Apple's competitors don't care about privacy at all.
- modeless 6y agoiPhones in China back up to a version of iCloud owned by a Chinese company that presumably shares its data with the government.
- random5634 6y agoExactly. And Chinese made phones shipped overseas (ie India) ALSO often backup to china or have links that way.
- iknowstuff 6y agoAll the apologists worrying about users losing their keys are forgetting that even Google has enabled opt-in end to end encryption on Android: https://www.androidcentral.com/how-googles-backup-encryption-works-good-bad-and-ugly https://www.androidcentral.com/how-googles-backup-encryption...
- Simulacra 6y agoAre they not encrypted when you backup to the computer?