4 ms·
An obvious solution would be to allow third-party storage services where you can dump your device data pre-encrypted and restore from those services. Only you w
by babesh 5y ago
An obvious solution would be to allow third-party storage services where you can dump your device data pre-encrypted and restore from those services. Only you would have the key. It isn't hard to implement.
The hard part would be getting the US security apparatus to allow it. ALL major storage providers DON'T support end-to-end encryption for this reason. Not Google. Not Microsoft. Not Apple. Not Dropbox. Isn't this interesting?
Furthermore, talk of supporting end-to-end encryption is basically NOT in the Overton window in these companies as far as I know. Discussion of it is met by silence from management. It is weird when you begin to see the spider webs of power in society.
All those people positing that it this is an effort by Apple to push for end-to-end encryption are either disingenuous or wrong headed. If Apple even thought about end-to-end encryption, the whole US government would come down on Apple like a ton of bricks.
Apple has shown no recent indication of even leaning in this direction. Not only does Apple not directly support end-to-end encrypted backup on iOS devices to third parties, it precludes it from happening. You are stuck backing up to your Mac or jailbreaking.
EDIT: There seem to be a few small movements in this area. Dropbox has their Vault with pin based protection. Seems incredibly and intentionally weak.
- glennpratt 5y agoGoogle's Android backups claim end to end encryption. > By design, this means that no one (including Google) can access a user's backed-up application data without specifically knowing their passcode. https://security.googleblog.com/2018/10/google-and-android-have-your-back-by.html https://security.googleblog.com/2018/10/google-and-android-h...
- babesh 5y agoNot if that application data is already part of Google services. That appears to application data for non-Google services. https://transparencyreport.google.com/user-data/us-national-security https://transparencyreport.google.com/user-data/us-national-... But I do stand corrected on non-Google application data. How do you restore from a different device? Oh, you only need the passcode.
- planb 5y ago> The hard part would be getting the US security apparatus to allow it. This is why ALL the major storage providers DON'T support end-to-end encryption. I don't think so. The reason is there's no money to be earned with being simply a storage provider. Additional processing, indexing, workflow tools etc. is what people pay for. That's not possible with E2E encryption.
- babesh 5y agoWhat is Dropbox Vault then? https://www.dropbox.com/features/security/vault https://www.dropbox.com/features/security/vault Why only pincode protection? What about Dropbox Password? That seems to be zero knowledge? They are two separate attempts in the security space.
- pseudalopex 5y agoWhat do you call Tarsnap, rsync.net, S3, and Backblaze?
- babesh 5y ago> the major storage providers **major**
- pseudalopex 5y agoTheir claim wasn't limited to major storage providers. And what do you call S3?
- planb 5y agoThis isn't the kind of "storage provider" we were talking about. As long as you simply put blobs in there, you don't need end to end encryption, you can simply do the encryption yourself (like people do with these services).