6 ms·
That Apple operates iCloud in every single country except China, where GCBD (AIPO Cloud (Guizhou) Technology Co. Ltd) operates iCloud, think I makes pretty clea
by capableweb 3y ago
That Apple operates iCloud in every single country except China, where GCBD (AIPO Cloud (Guizhou) Technology Co. Ltd) operates iCloud, think I makes pretty clear what's going on.
- graeme 3y agoThat’s separate from iMessage, which is end to end. Apple used to be able to access iMessages through iCloud backups. They changed their system worldwide, now they can’t. So presumably GCBD also lost access to iMessages in iCloud backups.
- deleted 3y ago[deleted]
- sneak 3y agoApple can still read ~100% of all iMessages in real-time because iCloud Backup (non e2ee by default) serves as a key escrow backdoor in the e2ee of iMessage. It is thus legitimate to state that iMessage is not e2ee as in practice each iMessage is also encrypted to a key held by Apple (in addition to the endpoints). Even if you turn it (e2ee iCloud Backup) on, it's ineffective, as both parties to a conversation must have turned it on for the conversation to be private. Your beliefs are inaccurate.
- deleted 3y ago[deleted]
- throwaway290 3y ago> iCloud Backup (non e2ee by default) I don't see any option to enable e2ee iCloud Backup on iOS 16.6, does this mean your information is outdated and it's all e2ee now?
- vages 3y agoIt’s called “advanced data protection”. You’ll find it hidden deep within the iCloud settings. It’s off by default.
- suumcuique 3y agoWow, thanks for mentioning this. I was also under the impression it was e2ee by default but it was actually disabled for me.
- b112 3y agoInteresting. FYI, I'm not an apple user, but no upset that some are. I wonder. Is this an attempt to market? Make it optional, but tout "we do this!', as if it is? It's not a bad marketing position.
- throwaway290 3y agoMore prosaically it's probably because turning it on means it's easier to lose access to your data if you lose devices/keys. Apple can't help you if they don't have the keys. It's not a bad marketing position.
- Twisell 3y agoActually there is a third option, don't back-up your iMessage to iCloud in the first place. In this configuration you need to transfer your content from device to device using a local backup if you intend to keep your messages. You the have the same level of privacy (if not higher) than with ADP. But with the same drawback, if your recipient does backup to iCloud without ADP then messages can be intercept by apple at rest on your recipient iCloud backup. Incidentally ADP mainly target users that didn't trusted iCloud backup for the lack of e2e encryption at rest.
- Twisell 3y agoYes and to be precise this is the relevant source : https://support.apple.com/en-us/HT202303 https://support.apple.com/en-us/HT202303 The optional iCloud feature called "Advanced Data Protection" is currently an opt-in. It comes with a significant drawback for typical pop and mom users --> If you lost you password and recovery key it's game over you loose everything. So I guess it's sensible to keep this as an opt-in until users are better educated about this drawback. What will be quite significant is wether or not this feature will be available for chinese users. It make sense from a technical POV to block ADP feature in poorly democratic countries that might request it like China and maybe tomorrow the UK. PS : Once a significant % of users activated ADP it could be a good UX improvement to display a warning to mixed ADP status conversation that the conversation is not fully e2e encrypted. However this might be premature right now otherwise early adopters of ADP would be flooded by such warning.
- Retric 3y agoThere’s some confusion here, iMessage is end to end encrypted by default. That in no way protects the information on each users device. If iCloud is enabled, then by default it gets unencrypted copies of these messages from the device unless “advanced data protection” is also enabled which ensures iMessage is encrypted but means losing your password also loses access to these backups. However, disabling iCloud sidesteps this issue and honestly if you want that kind of privacy then disabling iCloud is probably a good idea. So if one users uses ADP and the other user disables iCloud then the conversion is protected.
- pixel_tracing 3y agoIf you scrolled down in the link provided above, it mentions with BOTH Standard and Advanced data protection messages are end to end encrypted, it’s just with advanced data protection the encryption key also ends up being encrypted too, but I’m positive even this has changed recently. You can try looking at logs when you turn on messages in iCloud and see that your messages are encrypted. So lots of confusion in this thread, my advice for Apple would be make it very very clear to users that your data is safe. I mean they are threatening to back out of UK, so it’s against their core principles and also probably very technically expensive to undo they end to end encrypted system.
- graeme 3y agoDon’t know why you’ve been downvoted. You’re correct. I forgot ADP was optin. This is likely why China allows it. Also possible ADP is off as an option in China. Of course this wouldn’t work for the UK system unless the UK demanded the iCloud keys same way as China has.
- cced 3y agoThey don’t want their data leaving their country? Doesn't GermanyAlso have some privacy laws that require data on Germans to stay within Germany? Isn’t this just an extension of that in a way?
- capableweb 3y agoIs China the only country where this applies you mean? Because Apple runs the iCloud servers in every single country, except China.