5 ms·
Since user encrypted iCloud backups would prevent password recovery to access your data I'm more inclined to believe the decision was made out of convenience fo
by viktorcode 6y ago
Since user encrypted iCloud backups would prevent password recovery to access your data I'm more inclined to believe the decision was made out of convenience for the end user.
General public would hate it when the support won't help them recover family photos which are still stored in the cloud. Full encryption is nice to have, but overwhelming majority of users won't get any tangible benefits from that.
- bugfix 6y agoSo why not give users the option to encrypt everything if they want to?
- jaywalk 6y agoBecause of the FBI, obviously.
- gruez 6y agobut then again, who's going to be using it? A sibling comment mentioned that you can still do local backups which are encrypted and don't leave your device. What's the intersection of people who cares about their backup being encrypted, but can't set up itunes sync on their computer?
- dkonofalski 6y agoI would use it because I like the convenience of iCloud backup and not having to ever plug my phone into anything.
- gruez 6y ago>and not having to ever plug my phone into anything. works over wifi too. https://www.switchingtomac.com/tutorials/ios-tutorials/backup-your-ios-device-over-wifi-automatically/ https://www.switchingtomac.com/tutorials/ios-tutorials/backu...
- dkonofalski 6y agoIs that still accurate? You don't use iTunes to sync the phone anymore and I don't think the encrypted backups could be done via WiFi. If that's changed, then that's awesome.
- xurukefi 6y agoI'm convinced that if you give the general public the "encrypt everything option", then too many people will opt in without being aware of the consequences. They will eventually forget their password, loose all their family photos and blame Apple for it. A disclaimer also wouldn't help here. If anything, this should be some hidden developder mode kind of option to make sure that only those opt in who know what they are doing.
- gsich 6y agoThen you make them aware of those consequences. This is solvable.
- amiga-workbench 6y agoUsers don't read, they smash Ok buttons without understanding.
- kgwgk 6y agoMake them sign several clauses on a contract and send back a scanned copy. Really, if they still go through it without understanding what they are doing it will be on them.
- mattnewton 6y agoSigned copies protect you from litigation in court, not loss of brand value in the court of public opinion. Plenty of people bitten by it will just never use a backup product from you again, and every time apple sneezes a flurry of journalists are there to document it.
- UnFleshedOne 6y agoI guess the idea here is to make enabling the option enough of a pain so that only people who need it are going to use it, and button smashers will be spared.
- patrickserrano 6y agoI worked in education and had teachers and administration who were smart people, consistently asking to have their passwords reset. And the only requirement we had was that it needed to be 8 chars long, no special chars or capitalization. (This was a result of students and staff not being able to remember their passwords for more than a day or two) I can't imagine needing a password for them to recover photos and messages.
- MagerValp 6y agoThat's essentially what backing up to your Mac instead of iCloud gets you. The data is encrypted with your key to a device that you control.
- zahrc 6y agoAnd this is also what most people want, most of them don't care about security, privacy and safety. It's convenience and accessibility.
- whoknew1122 6y ago100% this. Working at AWS, I've dealt with (presumably) IT professionals who couldn't understand why we don't backup their KMS keys in case they delete their key and data gets orphaned. This sort of encryption bears a heavy burden on the customer. And the customer often doesn't want to accept that burden.
- jtdev 6y agoBut we shouldn't default to "let's compromise data security and privacy because some customers can't keep track of their keys". That would be like a shoe store only selling velcro shoes because some shoe buyers struggle with tying shoe laces...
- gruez 6y agoBut you can still make local (itunes) backups that are encrypted?
- felipemesquita 6y agoYes. It’s handled by Finder now since new versions of macOS don’t have iTunes, but it’s the same encrypted backup functionality.
- sneak 6y agoDoesn't matter; all of your iMessage conversation partners likely have iCloud Backup enabled (it's on by default) and are providing Apple your plaintext chat history with them.
- r00fus 6y agoFor those who can avoid using iMessage for meaningful discussion, that's why we have Signal/Telegram/etc. Also it takes that extra effort to piece together evidence if you have to search someone else's phone for my data.
- 6y ago
- Beggers1960 6y ago"I'm more inclined to believe the decision was made out of convenience for the end user." Bingo. We have a winner.
- sneak 6y agoReuters says six sources inside Apple said it was the FBI. My sources inside Apple tell me that there was at least a partial implementation for doing e2e backups safely, including a system for using friends/family to certify recovery in the event of password loss (presumably something like secret sharing). The FBI and Apple actively collaborated to prevent this from coming to pass. > One former FBI official who was not involved with these talks told Reuters that Apple was won over by the agency. “It’s because Apple was convinced,” said the source. Your claim directly contradicts the article.
- boomboomsubban 6y agoSix sources confirmed the FBI contacted Apple, they can't fully prove that that contact caused the decision. I'd bet it at least played a role, but the article is not as clear cut as you make it out to be.
- t0mmyb0y 6y agoThis is correct. Apple works with FBI while publicly saying they don't.
- PragmaticPulp 6y ago> including a system for using friends/family to certify recovery in the event of password loss Having friends and family take ownership of partial secret keys is a non-starter. Few people would actually go to the lengths of distributing fractional secrets to their friends and family. Even fewer people would do a good job of not losing them over the years. Outside of techie circles, account recovery is a relatively frequent occurrence. The majority of general public customers would prefer being able to recover their account even if it means a vanishingly small chance that the FBI would be able to access it in the even of an investigation.
- admax88q 6y ago> Few people would actually go to the lengths of distributing fractional secrets to their friends and family. Even fewer people would do a good job of not losing them over the years. I feel like this is all a solvable UX problem. The secrets could be automatically distributed and stored on friends/family devices, could be integrated into iMessage directly. "Choose friends you trust to help you recover data." If N of your M designated friends and family still have access to their phone when you need to recover your backup then you can get access, maybe by presenting a QR code on each device you can scan, or a notification you can interact with after confirming identity via a phone call or something. The secrets wouldn't require any actions to keep intact, they could always be synced into iMessage and included in your own backups. Kind of like you're operating a RAID array across your friends and family, N+X redundancy, so long as no more than X of your group needs recovery at the same time you're good. Kind if an interesting approach actually, would be neat to build this into Matrix as an experiment.
- the_duke 6y agoRelated to this, it seems FB sort of panicked with the recent Signal exodus. The app demanded cloud backups from me 8 times over 2 or 3 days. Presumably so that returning users still have their messages intact.
- randomdude402 6y agoTelegram sent out a message yesterday saying that they have gained 25 million users in the last 72 hours alone, pushing their total user count to 500 million. I suspect Signal took a somewhat smaller number of users from FB than this.
- random5634 6y agoNo kidding. If you run windows deployments the bitlocker key backup to domain / azure / whatever is a must / lifesaver. FAR FAR too many situations where users don't keep their keys. It can be as simple as upgrading the chip on your computer - which happens with AMD machines because they've had a long run of AM4 socket support. Boom, you fTPM is gone now, and user is complaining they've lost their irreplaceable stuff. I've seen this on IT side with backups. They set up an encryption key on the backups (pub / private) 6 years ago. 6 years later, when it comes time to recover under some time pressure, no one has a CLUE where the key is and old staff are long gone. Absolute nightmare. For all the folks saying managing encryption keys at scale is like tying your shoes - 100% false. To manage keys (especially ones where the private key is rarely if ever actually used) takes very very HIGH levels of care. One solution - have encryption keys periodically "fail" so you are forced to prove you know how to recover your key - but no one does that. Same issue used to occur with 2FA apps on phone upgrades before they made it easier to move stuff over to new devices.
- j45 6y agoThe option to enable full zero knowledge encryption should exist for icloud.
- voidmain 6y agoApple has a publicly documented solution for Keychain involving HSMs, which I think makes decent default tradeoffs between recoverability and security. And of course they could, and once did for local backups, offer an opt-in unrecoverable passphrase option. On the face of it they have decided to favor law enforcement over their customers here.