6 ms·
The legal headache Apple faces here (and as a result, the power lever held over them by nation-level interest groups) is the liability of storing user-generated
by homesickgoose 5y ago
The legal headache Apple faces here (and as a result, the power lever held over them by nation-level interest groups) is the liability of storing user-generated content on servers under their control. NOT the photos on your phone, those are YOUR liability.
Their cloud offering is fully E2EE (to the best of everybodies knowledge), so doing it à la Google Drive or OneDrive is not possible. If you can not access the unencrypted content and have/will not backdoord the encryption mechanism, yet are still being forced to implement such a scheme by a legal entity, client side is pretty much your only option.
As a side-note, IMO the company does not have a strong enough moral compass to assign the required man-hours into a project of this magnitude just out of good will. I would assume they are being forced to do so.
- fwn 5y ago> Their cloud offering is fully E2EE (to the best of everybodies knowledge) Do you have a source for that? I was not able to find one. This source, for example, suggests iCloud is not fully encrypted: https://www.reuters.com/article/us-apple-fbi-icloud-exclusive-idUSKBN1ZK1CT https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...
- homesickgoose 5y agohttps://support.apple.com/en-us/HT202303 https://support.apple.com/en-us/HT202303 I stand corrected, the vast majority is not E2EE'd. Now there unfortunately is no information about the at-rest encryption "On server". Going by the iCloud encryption debate in china [1] and the alleged security modules used [2], they probably have the keys to "Photos" iCloud. Which is consistent with the Reuters claim that "backed-up [...] encrypted services remain available to Apple employees and authorities". [1] https://www.nytimes.com/2021/05/17/technology/apple-china-censorship-data.html https://www.nytimes.com/2021/05/17/technology/apple-china-ce... [2] https://cpl.thalesgroup.com/encryption/hardware-security-modules https://cpl.thalesgroup.com/encryption/hardware-security-mod...
- cageface 5y agoiCloud is certainly not fully E2EE.