6 ms·
It’s a bit of an open secret among big tech that Apple is a huge user of storage on all major clouds. They manage encryption on their hardware and in return get
by adt2bt 5y ago
It’s a bit of an open secret among big tech that Apple is a huge user of storage on all major clouds. They manage encryption on their hardware and in return get cheap storage, higher availability and competition from their suppliers. Highly doubt Google has access to any iCloud data other than an estimate of the immense size of the service.
- simondotau 5y agoCalling it a secret is an exaggeration. It's more like an obscure topic on Wikipedia: it's publicly available to anyone who cared to ask the question.
- Stratoscope 5y agoThat's what "an open secret" means: something that may be thought to be secret but really isn't.
- deleted 5y ago[deleted]
- deleted 5y ago[deleted]
- fulafel 5y ago> Highly doubt Google has access to any iCloud data other than an estimate of the immense size of the service. They do of course have access to the ciphertext and access to traffic patterns, in crypto threat models traffic analysis tells the adversary a wealth of information.
- manigandham 5y agoLike what? What's a practical vulnerability or leak?
- deleted 5y ago[deleted]
- fulafel 5y agoLet's say Eve was working at Google with access to the ciphertext and io traffic, and was a jealous lover to a iPhone user Alice. They could be interested in profiling IM app usage, to know about size profile of content (pictures?) were stored at what times to know about Alice's activity profile when out of sight. They could also be interested in fingerprinting apps used so they could be matched to for example different dating apps. It's not hard to imagine something business or government related in place of this of course. And do this analysis in aggregate and follow many people at once. Apple could and for all we know possibly has implemented countermeasures for many of these cases, eg to make it hard to distinquish users from the mass of ciphertext.
- manigandham 5y agoHow are you going to figure out a specific user's content size (of a specific app or content type) from a sea of encrypted exabytes? What about this is practical?
- fulafel 5y agoI'm just sketching something, I'm not claiming to have developed a vulnerability research result here from my arm chair. But there's a lot of terrain between "it's encrypted so there are no attack" and "you haven't presented a fully developed attack" especially about a system we don't know much about. Anyway, there are many scenarios that come to mind for knowing their IO sizes. Apps probably have IO fingerprints. Or you could send the set of suspected users differently sized files to probe them. Etc.
- manigandham 5y agoBasic batching or partitioning of data before offloading to storage would defeat this analysis, and that’s assuming you can access and query so much data regularly. I asked for practical examples. I don’t need an in-depth report to see that this doesn’t qualify. Most of this crypto stuff is completely impractical risk, especially compared to some phishing emails.
- rapsey 5y ago> traffic analysis tell the adversary a wealth of information. When it comes to communication. iCloud is file storage. Data at rest encryption.
- fulafel 5y agoIO requests are communication.
- rapsey 5y agoThis kind has very little useful information.
- fulafel 5y agoExact byte sizes of files in sets of files in a io pattern, combined with timestamps, with many occurrences (=chances at correlation), are very distinguishing.
- joshuamorton 5y agoYeah, but the design you're assuming isn't the only way to build a storage system, and other approaches are both more secure and more performant!
- p0la 5y agoVery true when each user is accessing its own encrypted data directly. But from what I read here in the comments, Apple is managing encryption on their own HW, which almost surely means that data is read and wrote from Apple’s machines. Such aggregation of read and write calls across users makes access traffic patterns analyses risk fairly minimal...
- pjerem 5y ago« Their own HW » is in fact « their users devices »
- nuker 5y agoNope, its Apple servers. User devices don’t connect directly to Google
- qeternity 5y agoThis is not entirely true. Additionally Apple proxies traffic to GCP but key management still resides on user devices.
- nuker 5y ago> This is not entirely true You mean user devices may connect directly to Google storage? Did you observe it connecting to IPs in Google owned ASNs?
- NorwegianDude 5y agoIf backup is enabled(which I guess it is as things are backed up), then the key is also shared with apple.
- spookthesunset 5y agoWonder if they delegate the keystore to third party cloud services or that is one of those things they store in-house?
- deeter72 5y agoWhy would Google even attempt to spy on those patterns? it serves no purpose and how do you justify employee time spent for such useless things? Not to mention apple proxies all requests through their servers rendering such analysis utterly useless to begin with.
- tgragnato 5y agoOn one occasion the traffic to google cloud is systematically not proxied: every time one sends an attachment in iMessage, the file (or the media) is encrypted on device and sent to gcs-{eu,us,asia}-00002(?).content-storage-upload.googleapis.com, received from gcs-{eu,us,asia}-00002(?).content-storage-download.googleapis.com This should be pretty visible to Google, the rest of the traffic is handled better.
- zaphirplane 5y agoSo the bucket is open to the world to write
- tgragnato 5y agoNo? https://cloud.google.com/storage/docs/access-control https://cloud.google.com/storage/docs/access-control It just means Google may provide access to metadata outside of Apple’s control. Those metadata could be useful to do classification of anomalies on the basis of pattern of life analysis, or similar.
- spookthesunset 5y agoHow do both parties determine the keys used during a conversation? Are they making heavy use of public key cryptography? If so how? When I send a message to you, do I encrypt it using your public key? What about group messages? Does each conversation get its own key pair? Also it’s interesting they decided to directly hit up google cloud… you’d think they would wrap it so at minimum they could tweak the underlying infrastructure without requiring every client to update.
- nuker 5y ago> and access to traffic patterns I would think Apple is smart enough to mix storage blobs, so one blob is not one user. Plus all requests come from Apple datacenters, not user devices.
- tinus_hn 5y agoIf Apple is anywhere near competent the traffic patterns are useless, all Google can see is ‘data stored on that day was accessed on another day’. All traffic flows through Apple servers and Google has no way of even correlating it to a user.
- zepto 5y agoThe traffic patterns they have access to are apple’s backend usage, not users.
- gentleman11 5y agoI wonder if google can read the file names. Implementation dependent