9 ms·
But we shouldn't default to "let's compromise data security and privacy because some customers can't keep track of their keys". That would be like a shoe store
by jtdev 6y ago
But we shouldn't default to "let's compromise data security and privacy because some customers can't keep track of their keys". That would be like a shoe store only selling velcro shoes because some shoe buyers struggle with tying shoe laces...
- gruez 6y agoBut you can still make local (itunes) backups that are encrypted?
- felipemesquita 6y agoYes. It’s handled by Finder now since new versions of macOS don’t have iTunes, but it’s the same encrypted backup functionality.
- sneak 6y agoDoesn't matter; all of your iMessage conversation partners likely have iCloud Backup enabled (it's on by default) and are providing Apple your plaintext chat history with them.
- r00fus 6y agoFor those who can avoid using iMessage for meaningful discussion, that's why we have Signal/Telegram/etc. Also it takes that extra effort to piece together evidence if you have to search someone else's phone for my data.
- daxelrod 6y agoWouldn't the data stores of these apps be included in iCloud backups too?
- r00fus 6y agohttps://www.reddit.com/r/signal/comments/6qcxx7/is_signal_data_readable_when_phone_data_is/ https://www.reddit.com/r/signal/comments/6qcxx7/is_signal_da...
- daxelrod 6y agoThank you! I didn’t actually realize it was possible for apps to exclude their data from backup. Here it is from their own docs: https://support.signal.org/hc/en-us/articles/360007062012-New-Number-or-New-Phone https://support.signal.org/hc/en-us/articles/360007062012-Ne... > An iTunes or iCloud backup does not contain any of your message history. Only new messages, not conversation history, will be displayed.
- deleted 6y ago[deleted]
- morpheuskafka 6y agoYes, and the encryption on those really isn't that important as it can be protected by full-disk encryption (ex FileVault) on your hard disk, or throwing the backup in an encrypted container (zip, dmg, whatever) manually. The local iTunes encryption does have to be enabled for call data, health data, WiFi passwords, and browsing history to be included. Frustratingly, if you forget the backup password you have to Reset All Settings on the device, no way to change it going forward if you lost the old one. Of course, there should be no way to get to the old backups if you don't have the password, but if you have access to the device (thus, the source of the data to begin with) you should be able to change it without a reset.
- raverbashing 6y ago"Some customers" do you think the majority of Apple users (not picking on them, they're your average non-IT person) knows about a password they set last year maybe? That is the problem. It's very frustrating to tell some people that they can't recover their data because they forgot the password If you can keep a password for a long time then you can do your backups yourself I guess?
- rootusrootus 6y ago> Apple users (not picking on them, they're your average non-IT person) To be fair, this also describes Windows users. Most users of any platform are average non-IT people.
- Tempest1981 6y agoWhat % of users need to reset their password (for a given service) each year? I was guessing 5%. A web search shows this surprising stat, for all the user's services: "78% of people have had to reset their password in the last three months. - HYPR study" And 57% for work accounts. Wow.
- whoknew1122 6y agoHow should we handle the majority of customers that aren't technically savvy and are just looking to upload pictures of granny? Or to further your shoe store idea. The majority of people know how to tie their shoes. Most shoe stores usually don't keep a lot of stock of shoes larger than a US size 12 men's shoe. My foot happens to be larger. I have a different use case. So I often have to go through a different workflow (e.g. ordering online, having the store custom order my shoes, etc.). If you want full data security, you need additional technical knowledge and a different workflow. iCloud isn't for you.
- 34679 6y agoMake encryption optional, and explicitly state the associated risk of a lost key.
- vulcan01 6y agoThis is actually a good idea. Apple does this on macOS with File Vault: "WARNING: You will need your login password or a recovery key to access your data. ... If you forget both your password and recovery key, the data will be lost." They could put a clear warning on the iCloud screen as well. However, there is a large market for the iPhone in non-tech savvy people, especially old people, who may not understand fully what this decision means.
- ghaff 6y agoAs I recall, that's how Mozy did it for online backups way back when. (I think it was encrypted in any case but they handled the key management by default.) They let you handle your own key if you wanted to but gave a stern warning if you elected to do that.
- Kalium 6y agoIf memory serves, Apple did precisely this with FileVault for a very long time. Google did the same thing with encryption on phones. It was all quite thoroughly optional and all the warnings were thoroughly clear. People can, will, do, and did ignore any and all warning messages and then look to support to help them. It does not seem to matter how large, scary, or clear the warnings are. They will be ignored. So if you're Google or Apple and want to ensure that people's identity documents or tax records or business documents aren't stolen when the laptop or phone is, you make encryption the default. It helps that these devices are easier to sell to businesses. I'm thankful for these choices. In my professional capacity as an information security practitioner and my personal capacity as a privacy advocate, I find the idea at hand distasteful. Improved security should be available to everyone, not just those with a deep grasp of how to manage cryptographic keys. Gaining any measure of data security should not be reserved solely for us in the technical elite. There might, perhaps, be a slightly different discussion to be had about making it more common for tools to enable advanced users to manage their own keys. But this should never come at the expense of the common user. We have a profound professional responsibility to be better than that.
- daemoon 6y agoAnd we are not: Computer backups still exist, if you would like to do local backups. Privacy, most of the time, means less conveniency but it's still possible.
- rootusrootus 6y agoThe problem with this analogy is that it is likely that something like 99% of shoe buyers can tie their own laces just fine, practically in their sleep. That ratio would be inverted when you consider how many users can successfully keep track of their own encryption keys. Regular users just care that they don't lose their data. Offer them the option to keep it 100% secure from prying eyes at the risk of losing access to it permanently if they misplace the password, and 99% will tell you to pound sand.
- BoorishBears 6y agoIf anything their analogy shows why that is in fact the default. Most people can tie their shoelaces, so may stores don't even bother carrying velcro shoes. Likewise if the situation was inverted, hardly anyone would sell shoes with shoelaces. When there's finite resources for businesses the needs of the many overcome the needs of the few
- ghaff 6y agoAnd consider some of the scenarios where an iCloud backup is needed which include some sort of fire, flood, etc. So now they need to be sure that their key is stored somewhere safely online where they can get at it. >99% will tell you to pound sand Or they'll select it anyway because they don't really understand what they're doing notwithstanding big, scary warnings. A lot of tech people want everything to be configurable but that often is just not a good idea.
- rusticpenn 6y agoWe do not need a fire engine to put our candles out. The solution must match the problem.