8 ms·
Here's the BBC report on the matter: https://www.bbc.co.uk/news/articles/c20g288yldko https://www.bbc.co.uk/news/articles/c20g288yldko It applies to content st
by kitd 2y ago
Here's the BBC report on the matter: https://www.bbc.co.uk/news/articles/c20g288yldko https://www.bbc.co.uk/news/articles/c20g288yldko
It applies to content stored using ADP, Apple's E2EE tech. A backdoor into that would mean applying a backdoor into iOS on the phone itself, which is a much larger attack surface than anything centralised.
All of which highlights the clownish nature of these regulations. They are so easy for bad actors to circumvent (eg using their own E2EE), resulting in the ridiculous situation where the innocent get their data stolen and the very people you're targeting being completely unaffected.
- swores 2y agoI'm entirely against what the UK government wants, however I would say: Although you're right that tech people would still be able to choose secure encrypted options, the fact is that the majority of criminals by pure numbers are not very sophisticated - so while this sort of backdoor obviously wouldn't be a guarantee that every criminal conversation could be snooped on, it would work on the 90-99% (I'd guess towards 99) who aren't both cautious enough to try to be secure and tech savvy enough to make the right choices. (But it's still a terrible idea, both for the sake of general privacy principles, and for the risk that current or future governments or personnel will abuse the access, and for the risk that criminals outside government will be able to take advantage of the same backdoor.)
- sejje 2y agoFor three whole minutes until everyone knows it's totally compromised and stops doing that
- swores 2y agoSMS is already known to be insecure and easily snooped on with a warrant, and has been used by police around the world in many cases, yet a surprisingly high number of criminals still use it.
- eapressoandcats 2y agoRealistically most criminals probably don’t even turn on ADP, so it will probably move the needle not at all.
- adim86 2y agoThe idea that criminals are not sophisticated is a weak excuse for this system. Once the government starts mining data from iPhones, criminals will quickly adapt while every law-abiding citizen gets caught in the crossfire. It opens the door for abuse: officials could easily spy on their partners, dig up dirt on rivals, or target those they dislike without breaking any laws. Meanwhile, cybercriminals will have an easy target since every phone comes with this built-in vulnerability. This system is likely to snag small-time offenders, not the real masterminds behind organized crime. This isn’t a smart solution for crime. It just sacrifices our privacy for a few token arrests.
- nottorp 2y agoCriminals don't need to be all sophisticated anyway. They just need to know how to reach one of the sophisticated criminals and pay them to extract whatever they need. Incidentally, as a non US and non UKer, my data with the major tech firms has no protection anyway. Welcome to the club, US citizens :)
- zombiwoof 2y agoVery weak considering we have a criminal in the White House
- watwut 2y agoHe is not sophisticated and did not needed to be sophisticated to be in the White House. And untouchable by the law.
- trinsic2 2y agoThere are already replies with sound arguments against the ideology that 90 of criminals arnt that sophisticated. Secondly, I will also point out that criminals in general watch whats happening to other criminals. If people start going to jail because there mobile communications are being targeted, others will catch on and stop using mobile tech altogether for criminal activities.. People copy what works successfully, you don't need to be smart to do that. So yeah this argument is complete bullshit.
- KennyBlanken 2y agoThe majority of criminals have no idea that their their iMessage encryption keys and iMessages are synced into the cloud and available to law enforcement with a warrant. No need to break devices security, no need for back doors.
- fakedang 2y agoMost GSW victims are killed by one or two bullets, not hundreds of them. You don't need a "vast majority" of criminals to break down a system and exfiltrate data when just a single, possibly state-backed, criminal operation can break your system down and do the job.
- wonderwonder 2y agoThis is a government that believes in thought crimes. They will likely arrest people for having illegal memes on their phones or for texting messages to friends of which the government does not approve. If there was prequal to 1984, it would look something like this.
- hnlmorg 2y agoI really don’t like the UK governments stance on cyber security / counter-terrorism / et al either. In fact, as a UK citizen I’ve actively campaigned against a great many of their policies. However this “thought police” and “arrested for posting memes” comment that often gets pointed on here is itself a nonsense meme. What actually happened was people were arrested for instigating riots. This is no different to what happened in the US regarding the Capital Hill riots — people who helped organise it online were arrested too. The UK has a long history of shitty policies invented to “protect people” but we need to be clear on what’s actually fact and what’s fiction. Otherwise you end up wasting energy protesting against things that are imaginary.
- gruez 2y ago>However this “thought police” and “arrested for posting memes” comment that often gets pointed on here is itself a nonsense meme. >What actually happened was people were arrested for instigating riots. This is no different to what happened in the US regarding the Capital Hill riots — people who helped organise it online were arrested too. According to: https://news.sky.com/story/jordan-parlour-facebook-user-jailed-for-riot-related-social-media-posts-13193894 https://news.sky.com/story/jordan-parlour-facebook-user-jail... One of the "instigators" was sent to prison for tweeting "every man and his dog should smash [the] f** out of Britannia hotel (in Leeds)". While I agree such tweet might be illegal under US law (it plausibly meets the "imminent lawless action" standard), it's a stretch to equate that to "organise [the Capital Hill riots] online" (whatever that means). A tweet by a nobody who got 6 likes isn't "organising". It's shitposting.
- hnlmorg 2y agoDid you actually read that article. In there it even stated there was a pattern of behaviour and that his comments on Facebook had been shared with thousands and directly resulted criminal damage. Not only that, that his comments were intended to cause criminal damage and result in physical attacks against immigrants. What you’ve done is selectively quoted a small subset of portions from that article to misrepresent the full trial. Which is exactly why I had to write my comment defending the UK government earlier. Believe me, I really don’t want to defend the government. The UK government get a lot wrong when it comes to legislation regarding technology. In fact they get nearly everything wrong and I’ve frequently had to have words my MPs about it (not that that’s done any good). But they categorically do not lock people up just for shitposting. At best that’s just an exaggeration. At worst it’s an out right misrepresentation of the facts.
- ljm 2y agoSince it seems to be illegal to even reveal if one of these requests was received, it's also worrying that, by extension, it would be illegal to declare a data breach once the backdoor was inevitably exploited by another bad actor. So, how would anybody know that a foreign government was spying on them? Nothing would stop them installing Pegasus on your phone and exfiltrating even your 'secure' data. The stupid thing is that these laws always find a way to say that people in government are exempt from the provisions, and everybody except them is allowed to be spied on, but they are obviously going to be the first people to be targeted. Not some randomer hoarding CSAM.
- fujinghg 2y agoThis is exactly the problem. The logical outcome is so bad that the only risk mitigation is to not use their services at all.