7 ms·
Apple has always been subject to US law, and as such, was always required to provide information that they do have access to. If it's in iCloud, most of it can
by aeontech 5y ago
Apple has always been subject to US law, and as such, was always required to provide information that they do have access to. If it's in iCloud, most of it can be extracted by the law enforcement with court order.
Nothing changed between now and the San Bernardino case. The difference was that FBI wanted Apple to compromise device encryption, which capability does _not_ exist now.
- shockeychap 5y agoSo why hasn't end-to-end encryption been utilized for years with the storage of email and other files, like they do with iMessage content?
- aeontech 5y agoYou can certainly use E2E encryption (ie, S/MIME) for your email, whether it's using Apple Mail or not. I'm not sure what you suggest Apple can do about it if you don't use PGP/GPG on your side though (and yes, you can use S/MIME for email both with iOS and macOS). How Apple CloudKit security works is documented [0] and what Apple can provide to the law enforcement is pretty easily googleable [1], and has been subject to much media coverage over the years. All I was saying is that this is not some recent change. [0]: https://support.apple.com/en-gb/guide/security/sec3cac31735/web https://support.apple.com/en-gb/guide/security/sec3cac31735/... [1]: https://www.apple.com/legal/privacy/law-enforcement-guidelines-us.pdf https://www.apple.com/legal/privacy/law-enforcement-guidelin...
- CRConrad 5y ago> You can certainly use E2E encryption (ie, S/MIME) for your email, whether it's using Apple Mail or not. I'm not sure what you suggest Apple can do about it if you don't use PGP/GPG on your side though (and yes, you can use S/MIME for email both with iOS and macOS). What Apple could do seems fairly obvious: Build it into their mail client and enable it by default, no?
- aeontech 5y ago> Build it into their mail client and enable it by default, no? Support for S/MIME _is_ built into the client. The user has to configure their certificate keypairs, that part is not under the OS’s control (unless I’m missing something)
- CRConrad 5y agoSo, enable it by default and make setting up keys part of the mail client setup?
- kube-system 5y agoThe hardest thing about a service trying to end-to-end encrypt an email, is that any given email service provider only controls one end.
- upofadown 5y agoYou only need regular client side encryption to protect things in the cloud. Just generate a key on the phone and keep it there. Probably the reason they don't do that is that it would make it so that a lost phone would result in the loss of cloud stored data. People store things in the cloud to prevent that sort of loss. Email when encrypted end to end in the traditional ways is safe on the IMAP server but also has a requirement to back up a key off the device to prevent loss of old emails on loss of device.
- wolverine876 5y agoEmail can't be secured for many reasons; use a modern, secure messaging app for that, such as Signal. Regarding encryption in particular: Encrypting email metadata prevents emails from being delivered and processed. Metadata is as valuable as the content of the email. Encrypting emails at rest prevents server-side services from operating, such as webmail.