7 ms·
Note that this doesn’t satisfy the government’s original request, which was for worldwide backdoor access into E2E-encrypted cloud accounts. But I have a more
by ComputerGuru 2y ago
Note that this doesn’t satisfy the government’s original request, which was for worldwide backdoor access into E2E-encrypted cloud accounts.
But I have a more pertinent question: how can you “pull” E2E encryption without data loss? What happens to those that had this enabled?
Edit:
Part of my concern is that you have to keep in mind Apple's defense against backdooring E2E is the (US) doctrine that work cannot be compelled. Any solution Apple develops that enables "disable E2E for this account" makes it harder for them to claim that implementing that would be compelling work (or speech, if you prefer) if that capability already exists.
- madeofpalk 2y agoWhen you disable ADP, your local encryption keys are uploaded to Apple's servers to be read by them. Apple could just lock you out of iCloud until you do this.
- oakesm9 2y agoThat’s exactly the plan. Anyone with this enabled in the UK will need to manually disable it or they’ll get locked out of their iCloud account after a deadline.
- pacifika 2y agoAnd I guess Apple gets fined for not allowing government approved alternatives to these services not long after.
- kbolino 2y agoThe hardware will not allow this, at least not without modifications. The encryption keys are not exportable from the Secure Enclave, not even to Apple's own servers.
- sureIy 2y agoAre you gonna unlock that phone anytime soon? Thanks for opening the enclave, don't mind if I ship these keys back home. No notification needed, Apple has root access.
- kbolino 2y agoAssuming the enclave can receive OTA firmware updates and those updates can completely compromise it, which are not actually proven facts, there's no way to target this to the UK alone without either exempting tourists and creating a black market for loophole phones or else turning all of Britain into a "set foot here and ruin your iPhone forever" zone.
- jkbbwr 2y agoUnless I am making a mistake here, you still can't extract keys of an opened enclave. You can just run operations against those keys.
- Twisell 2y agoThe Apple security paper describe how to disable ADP through a key rotation sequence. This will be a "forced rotation", they just need to decide how to communicate to users and work out what happens to those who don't comply. Lockout until key rotation look like an option as someone said.
- kbolino 2y agoYeah, this seems the most likely thing to happen here. You'll be forced to disable ADP to continue using iCloud in the UK. This still leaves the question of tourists and other visitors, but it at least fits within the parameters of the system without changing its fundamentals.
- biggc 2y agoNaive question: what prevents Apple from pushing a malicious software update that automatically disables ADP to UK users?
- QuiEgo 2y agoBehind the scenes, it'd probably decrypt it locally piece-by-piece with the key in the Secure Enclave, and then reencrypt it with a new key that Apple has a copy of when you disable ADP.
- jl6 2y agoWe are told the encryption keys reside only on your device. But Apple control “your” device so they can just issue an update that causes your device to decrypt data and upload it.
- RenThraysk 2y agoWould just upload the keys
- drexlspivey 2y agoPresumably these keys live in a hardware security module on your phone called “secure enclave” and cannot be extracted
- RenThraysk 2y agoAh yes, good point.
- fsflover 2y agoIs this module auditable though, or is "just trust us", like everything in the Apple world?
- LPisGood 2y agoIt’s auditable in the sense that there is a very high potential for reward (both reputationally and financially) for security researchers to break it.
- fsflover 2y agoThe same reward exists with FLOSS, but it's much easier to audit, making findings more likely. Also, security through obscurity doesn't work.
- theshrike79 2y agoIf someone has a reliable and workable secure enclave hack they can become a multi-millionaire for selling to state actors or become one of the most famous hackers in the world overnight (and possibly get a life changing amount of bounty from Apple) Basically it's not a hack someone just throws on the internet for everyone to use, it's WAY too valuable to burn like that.
- rdtsc 2y ago> how can you “pull” E2E encryption without data loss? What happens to those that had this enabled? They'll keep your data hostage and disable your iCloud account. Clever, huh? So they are not deleting it, just disabling your account. "If you don't like it, make your own hardware and cloud storage company" kind of a thing.
- lynx97 2y agoMore like "If you don't like it, talk to your local politicians", which is, IMO, a totally valid approach.
- rdtsc 2y ago> "If you don't like it, talk to your local politicians", Indeed people only noticed this because Apple tried to do the right thing and now it's somehow also Apple's fault. No good deed goes unpunished, I guess. I think there is a feeling the government power is so overwhelming that they are hoping maybe some trillion dollar corporation would help them out somehow.
- tripdout 2y agoThe iOS screenshot displays a message saying it's no longer available for new users.
- globular-toast 2y ago> But I have a more pertinent question: how can you “pull” E2E encryption without data loss? What happens to those that had this enabled? Well exactly. The UK just showed the whole thing is a joke and that Apple can do this worldwide.
- wrs 2y ago> how can you “pull” E2E encryption without data loss You can’t. The article says if you don’t disable it (which you have to do yourself, they can’t do it for you, because it’s E2E), your iCloud account will be canceled.
- nashashmi 2y agoAt this point, the right thing to do is allow for an alt-service.
- sneak 2y agoApple has an organization-wide mandate for services revenue. Every product must make money on an ongoing basis, every month. That's why you get constantly spammed to subscribe to things on iOS. Apple will never drop this anticompetitive practice of favoring their services until they are legally compelled to.
- jmb99 2y agoHow would an alt service help this situation? You’d just end up with backdoored services advertising E2EE, no? Apple’s move here is definitely the right one, introduce as much friction as possible to hopefully get the user pissed off at their government for writing such stupid laws.
- nashashmi 2y agoAn alt service located in another country could provide e2ee for a fee and not be under UK law.
- mtrovo 2y agoApple is in a really tough position. I don't know if there's any way they could fulfil the original request without it effectively becoming a backdoor. Disabling E2E for the UK market is just kicking the can down the road. Even simply developing a tool to coerce users out of E2E without their explicit consent to comply with local laws could be abused in the future to obtain E2E messages with a warrant on different countries. A very difficult position to be in.
- replete 2y agoOr, this is how they save face with their customers having complied with the request rather than stop trading with the UK.
- MetaWhirledPeas 2y ago> Apple is in a really tough position. You mean Apple is in a unique position to make a statement. No more Apple products in the UK. Mic drop. Exit stage left.
- sureIy 2y agoBut… money
- musictubes 2y agoBut customers. People keep saying they should just not be in that country. It is far better to have the choice of using an iPhone even if particular features are no longer available.
- TeaBrain 2y agoI think Prof Woodward's quote in the article will likely hold true for Apple's response to the original UK government request: "It was naïve of the UK government to think they could tell a US technology company what to do globally"
- kelnos 2y ago> the (US) doctrine that work cannot be compelled Is this actually a thing? Telecoms in the US are compelled to provide wiretap facilities to the US and state and local governments.
- ckcheng 2y ago>> Apple's defense against backdooring E2E is the (US) doctrine that [government can’t] be compelling work (or speech, if you prefer) It’s really not "work” but speech. That’s why telecoms can be compelled to wiretap. But code is speech [2], signing that code is also speech, and speech is constitutionally protected (US). The tension is between the All Writs Act (requiring “third parties’ assistance to execute a prior order of the court”) and the First Amendment. [1] So Apple may be compelled to produce the iCloud drives the data is stored on. But they can’t be made to write and sign code to run locally in your iPhone to decrypt that E2EE data (even though obviously they technologically could). [1]: https://www.eff.org/deeplinks/2015/10/judge-doj-not-all-writs https://www.eff.org/deeplinks/2015/10/judge-doj-not-all-writ... [2]: https://www.eff.org/deeplinks/2015/04/remembering-case-established-code-speech https://www.eff.org/deeplinks/2015/04/remembering-case-estab...
- codedokode 2y agoIt's weird bending of law. Code, especially closed-source code, is not a speech; it's a mechanism and the government may mandate what features a mechanism must have (for example, a safety belt in a car).
- ckcheng 2y ago> Any solution Apple develops that enables "disable E2E for this account" makes it harder for them to claim that implementing that would be compelling work (or speech, if you prefer) I think it’s really speech [0], which is why it’s important to user privacy and security that Apple widely advertises their entire product line and business as valuing privacy. That way, it’s a higher bar for a court to cross, on balance, when weighing whether to compel speech/code (& signing) to break E2EE. After all, if the CEO says privacy is unimportant [1], maybe compelling a code update to break E2EE is no big deal? (“The court is just asking you, Google, to say/code what you already believe”). Whereas if the company says they value privacy, then does the opposite without so much as a fight and then the stock price drops, maybe that’d be securities fraud? [2]. And so maybe that’d be harder to compel. [0]: https://news.ycombinator.com/item?id=43134235 https://news.ycombinator.com/item?id=43134235 [1]: https://www.eff.org/deeplinks/2009/12/google-ceo-eric-schmidt-dismisses-privacy https://www.eff.org/deeplinks/2009/12/google-ceo-eric-schmid... [2]: https://www.bloomberg.com/opinion/articles/2019-06-26/everything-everywhere-is-securities-fraud https://www.bloomberg.com/opinion/articles/2019-06-26/everyt...