7 ms·
If you turn on iCloud, it's theater. Android with syncing enabled does much better in real world tests. Notably in hong kong, they were able to crack the iPhon
by codemac 6y ago
If you turn on iCloud, it's theater.
Android with syncing enabled does much better in real world tests. Notably in hong kong, they were able to crack the iPhones, but not the Pixels[0]
I'm pretty sure without iCloud and a long enough password (or fast enough self destruct mode) iPhones could be as secure, but I don't know anyone that uses an iPhone and does not use iCloud in any way.
[0]: https://qz.com/1844937/hong-kongs-mass-arrests-give-police-access-to-phones/ https://qz.com/1844937/hong-kongs-mass-arrests-give-police-a...
- rnikander 6y agoWhat part of iCloud is the problem?
- codemac 6y agoThe part where it backs up all your messages without using a device specific key. The only things end to end encrypted are listed on this page: https://support.apple.com/en-us/HT202303 https://support.apple.com/en-us/HT202303 If you turn on iCloud syncing, basically you're falling back to simple "in transit" and "at rest" encryption. A lot of iPhone cracks involve just attacking your iCloud account, and then reading all of your messages from backups. This is not possible on Pixel which encrypt your device backups with on-device hardware encryption.
- gumby 6y ago> Pixel which encrypt your device backups with on-device hardware encryption. Can you set up a new android phone from an old phone’s backup? If so, how could this work? This is a standard way to set up a new iPhone: “restore” from a backup of your previous phone. Especially handy when your old phone is no longer available (lost/broken)
- glennpratt 6y agoYes, decryption requires the original device's unlock PIN/pattern/password: https://security.googleblog.com/2018/10/google-and-android-have-your-back-by.html?m=1 https://security.googleblog.com/2018/10/google-and-android-h... Not that I fully understand how hard it is to circumvent.
- gumby 6y agoOh, I see. Apple has done that since the original iPhone too, and I believe iPod before it. I thought you meant they used a hardware key.
- codemac 6y agoFor your backups - but once you use iCloud to sync devices in real time, they just use their service keys, and your iCloud credentials are enough to read your iMessage history.
- rnikander 6y agoOkay, so if I understand correctly, the data in those Apple products is not secured, but turning on iCloud on a device does not ruin encryption for other apps that take it seriously. So if I have an app that uses Keychain (end-to-end encrypted) and encrypts it's data properly, it is still secure. Unless Apple is really bad and somehow collects my keys from keychain, or collects keys passed to CryptoKit, etc., straight out of RAM, and sends them to 3-letter agencies ... if I think that's happening, then I will look for new devices.
- codemac 6y agoI'm not sure I understand your keychain point. With iMessage you can message others with just your iCloud credentials if you turn it on, and you have access to full conversation history - without needing any particular device keys.
- angled 6y agoThe agencies are believed to have the iCloud decryption keys.
- smoldesu 6y agoiCloud has always been suspicious: Apple cancelled end-to-end encryption on iCloud after a certain three-letter agency filed a complaint, saying that it would disrupt investigations and have a considerable impact on the law enforcement capabilities of our country. Not to mention, Apple's behavior has been decreasingly auspicious in places like Russia and China, where they've started preinstalling state-sponsored apps and relocating servers to government-controlled provinces, respectively.
- jhugo 6y ago> Apple's behavior has been decreasingly auspicious in places like Russia and China, where they've started preinstalling state-sponsored apps and relocating servers to government-controlled provinces, respectively. This is a legal requirement to operate the service in China. Apple’s choice is between offering iCloud in China or not offering it at all in China, not between offering it with local servers or with out-of-country servers.
- smoldesu 6y agoIt is indeed a legal requirement, and both Google and Microsoft have chosen not to provide services in those areas for this exact reason. Apple is the only major tech company that still operates in China, and has become pretty politically passive in the region. I only bring this up because Apple claims that "privacy is a human right", which I suppose is pretty conditional to what kind of human you are.
- jhugo 6y ago> Apple is the only major tech company that still operates in China This is not even remotely true, even if you define "major tech company" to mean "major US tech company". Both AWS and Azure have actual cloud regions in China (delivered with a local JV partner just like Apple's cloud services are). Even Google operates there in various ways - they have four offices there, they manufacture hardware there, and they sell tons of ads to Chinese companies via their local subsidiaries (for display outside of China obviously).
- 6y ago
- iudqnolq 6y agoThis is true of your primary worry is nation states. If your primary worry is criminals/domestic partners/employers, this isn't the case. You can't give security advice without considering what you're protecting against. Edit: your linked article says nothing about icloud