3 ms·
The gov’t can force them to reveal any user’s data and slap them with a gag order so no one will ever know this happened.
by tempodox 9mo ago
The gov’t can force them to reveal any user’s data and slap them with a gag order so no one will ever know this happened.
- MontyCarloHall 9mo agoAll user data is E2E encrypted, so the government literally cannot force this. This has been the source of numerous disputes [0, 1] that either result in the device itself being cracked [0] (due to weak passwords or vulnerabilities in device-level protection) or governments attempting to ban E2E encryption altogether [1]. [0] https://en.wikipedia.org/wiki/Apple%E2%80%93FBI_encryption_dispute https://en.wikipedia.org/wiki/Apple%E2%80%93FBI_encryption_d... [1] https://en.wikipedia.org/wiki/Crypto_Wars https://en.wikipedia.org/wiki/Crypto_Wars
- greentea23 9mo agoWhat you cited is for data on a device that was turned off. Not daily internet connected usage. No one is saying you have no protection at all with Apple, it is just very limited compared to what it should be by modern security best practices, and much worse than what can be achieved on android and linux.
- nozzlegear 9mo ago> much worse than what can be achieved on android and linux. * Certain types of Android
- mmh0000 9mo agoMaybe E2E, but the data eventually has to be decrypted to read it. Then you learn that every modern CPU has a built-in backdoor, a dedicated processor core, running a closed-source operating system, with direct access to the entire system RAM, and network access. [a][b][c][d]. You can not trust any modern hardware. https://en.wikipedia.org/wiki/Intel_Management_Engine https://en.wikipedia.org/wiki/Intel_Management_Engine https://en.wikipedia.org/wiki/AMD_Platform_Security_Processor https://en.wikipedia.org/wiki/AMD_Platform_Security_Processo... https://en.wikipedia.org/wiki/ARM_architecture_family#Security_extensions https://en.wikipedia.org/wiki/ARM_architecture_family#Securi... https://en.wikipedia.org/wiki/Security_and_privacy_of_iOS https://en.wikipedia.org/wiki/Security_and_privacy_of_iOS
- dmitrygr 9mo agoSome of those things are not like the others. TrustZone is not a dedicated core. It is a mode of the CPU, akin to x86's SMM
- natch 9mo agoE2E encrypted is nothing if key escrow is happening. Why did they change their wording from: Nobody can read your data, not even Apple to: Apple cannot read your data. You know why.
- nozzlegear 9mo agoIf they didn't want you to think key escrow might be possible, why wouldn't they just leave the wording the way it was? Why go through the effort and thereby draw attention to it? The court system doesn't use sovcit rules where playful interpretation of wording can get a trillion dollar corporation out of a lawsuit or whatever.
- ajam1507 9mo agoWhen did they change their wording?
- hbs18 9mo agoIt's a warrant canary, https://en.wikipedia.org/wiki/Warrant_canary https://en.wikipedia.org/wiki/Warrant_canary