12 ms·
Apple – Privacy – Government Information Requests
- declan 12y agoIf you're an iOS user who becomes the target of an investigation by a law enforcement or intelligence agency, remember your data is likely unencrypted in the cloud. So if your device is inaccessible, your email, your location history, your text messages, your phone call history will probably remain accessible. Apple acknowledges, for example, that "iCloud does not encrypt data stored on IMAP mail servers": http://support.apple.com/kb/HT4865 http://support.apple.com/kb/HT4865 [Edited because it now seems unclear which Apple policies have changed.]
- threeseed 12y ago> though the celeb hacking shows the limits of that approach Apple has clearly stated that its system was not compromised. The user reset questions were socially engineered meaning it is irrelevant whether or not the data is encrypted. From Apple's perspective the owner of the data is downloading it.
- declan 12y ago> The user reset questions were socially engineered Yep, you're right. My point, perhaps poorly stated, is that if Random Hacker X can figure out the answers to the iCloud reset questions, so can a law enforcement agency. Then they can log into that account. Impersonating someone this way is legal -- or at least has not been ruled to be illegal -- as long as it's done under court supervision under the Wiretap Act or similar legal authority authorizing prospective surveillance. Possibly related: I disclosed last year that the Feds have demanded that major Internet companies divulge targeted users' stored passwords, and in some cases the algorithm used and the salt: http://www.cnet.com/news/feds-tell-web-firms-to-turn-over-user-account-passwords/ http://www.cnet.com/news/feds-tell-web-firms-to-turn-over-us...
- stephenr 12y ago> if Random Hacker X can figure out the answers to the iCloud reset questions Answers about very famous people. Wikipedia will not tell me your mothers maiden name. Also, as much as I sympathise with the women whose accounts were breached, actors aren't always the sharpest tools in the shed, and phishing schemes are a common tool for gaining access to other peoples accounts. One of them (I don't remember which) publicly claimed iCloud backup for her iPhone was "too complicated" a while ago. Given that it's as complicated as "turn it on, and make sure it gets plugged into power with Wifi every so often", I don't doubt some of them would fall victim to even a very simple phishing scam.
- zaroth 12y agoYou don't have to guess -- they specify exactly what is encrypted in iCloud; "On devices running iOS 8, your personal data such as photos, messages (including attachments), email, contacts, call history, iTunes content, notes, and reminders is placed under the protection of your passcode."
- declan 12y agoBut "iCloud does not encrypt data stored on IMAP mail servers" or Notes http://support.apple.com/kb/HT4865 http://support.apple.com/kb/HT4865
- gfodor 12y agoHow is Apple supposed to encrypt data stored on servers they do not own?
- zaroth 12y ago"Last Modified: Dec 12, 2013".
- declan 12y agoThat December 2013 page is linked to from today's announcement, under "Learn more about iCloud security." See: http://www.apple.com/privacy/privacy-built-in/ http://www.apple.com/privacy/privacy-built-in/ Also note that today's announcement says Mail and Notes are "encrypted in transit" only. In other words the December 2013 page remains current.
- zaroth 12y agoOK. You win 2 internets. And fuck that highly misleading ad copy, Apple. :-( [Edit] - Clearly something is off here. iPhone keeps a copy of the last several hundred emails downloaded from my IMAP server, I would expect an iCloud backup of those emails would be "under the protection of the passcode" (a.k.a encrypted). That doesn't mean Apple is somehow encrypting the messages stored on my IMAP server. Likewise, it doesn't mean Apple is encrypting customer emails stored on their @iCloud.com (or whatever) email servers.... I'm going to assume there are just some wires crossed here, but I do hope they clean up the document and clarify this.
- denom 12y agoIn the end this is not about an information security solution (which is measured by the weakest link). This is about engineering consumer expectations. Privacy and security must be measured in terms of the overall digital-economic ecosystem. Systems at the margins of everyday consumer experience will determine how absolutely secure any computation can be. Consider the baseband processor in each iphone. I think companies like apple and google are undertaking PR exercises like this in the hopes of finding that sweet-spot between the sense of crisis (excitement?) that smart phone ownership brings and the banal integration of technology into everyday life. There _are_ government requests, but they do not affect _you_. maybe. So my question: Is government surveillance now officially part of the iPhone experience? To the extent that a debate exists, apple is engaging and steering that discussion. This is just pure organizational reflex. And it's cynical in some sense, but apple doesn't really have a choice in the matter either. Ultimately it is what the US officials consider to be an acceptable level of visible surveillance, which is a political consideration.
- deleted 12y ago[deleted]
- blueking 12y agoSee the problem here is google and apple and were caught lying over PRISM. So we can't believe anything they say. They are in a unrecoverable position of broken trust. Until I see open source code its just hot air.
- wyager 12y agoEdit: Can someone confirm or deny the following? I think this is the current state of affairs. A) Apple will unlock PIN-locked devices by government request, but the best they can do is brute-force. This is very slow, as it can only be done using the phone's on-board crypto hardware (which has a unique burned-in crypto key), and the PIN is stretched with PBKDF2. It has been this way for a while. Apple has no "backdoor" on the PIN or any form of cryptographic advantage here that we know of. B) The new thing mentioned in the OP's link is that things stored on Apple's servers are now encrypted as well, with your iCloud password. Is this correct?
- z92 12y agoNot surprisingly, that instruction was for the general population. Not the police.
- nathancahill 12y agoIt's actually really easy to recover the passcode from iTunes backups (so probably from iCloud backups too). I've had to do it before to rescue photos off a friend's iPhone. Don't know about >iOS6 though.
- wyager 12y ago>It's actually really easy to recover the passcode from iTunes backups What do you mean by this? I doubt the passcode is stored in plaintext anywhere, and if I recall correctly, the passcode is convolved with the CPU's burned-in crypto key before storage, so you couldn't recover it from a backup without the corresponding phone.
- threeseed 12y agoiTunes backups are encrypted by default. And I can't imagine a typical person deliberately disabling it. Your example is a little unique though because you have physical access to both their computer and their phone. In theory you could just brute force their iTunes backup password.
- 12y ago
- jpmattia 12y ago> less than 0.00385% of customers had data disclosed due to government information requests. According to [1], there are about 600 million apple users, so this translates to 23,000 customers exposed due to government information requests. Seems like a large number. Is 600M correct? [1] http://www.cnet.com/news/apple-to-reach-600-million-users-by-end-of-2013-says-analyst/ http://www.cnet.com/news/apple-to-reach-600-million-users-by...
- nknighthb 12y agoThere are millions of people arrested in the US alone every year. It doesn't seem unbelievable that 23,000 of them had iPhones/iPads that law enforcement wanted data off of.
- alexbecker 12y agoThe "less than" seems pretty superfluous when they're giving that many digits...
- clamprecht 12y agoSo the US is now a country where mainstream companies market it as a competitive advantage that they will try to minimize what they will release to the government. I'm glad companies are doing this, but I'm sad that they even have to.
- zaroth 12y agoThe desire for privacy, and a healthy dose of suspicion for ones government, have both existed for as long as the notion of government itself. Personally, I'm waiting for the other shoe to drop. Now that the police can't go to Apple for your data, we'll start seeing more judges ordering users to unlock their phones to allow them to be searched. I don't think it will be long before such a case reaches SCOTUS, and then we'll see how that works out...
- sarkhan 12y ago> Now that the police can't go to Apple for your data, we'll start seeing more judges ordering users to unlock their phones to allow them to be searched Is not that against 5th amendment?
- clamprecht 12y agoThe US government forced Lavabit to install a back door that didn't exist before (or go out of business, which isn't really an option for Apple). I wonder what is to legally stop the government from forcing Apple to do the same? I guess one answer is that Apple has more resources to fight or lobby.
- res0nat0r 12y agoLavabit wasn't forced to install a backdoor, the guy running it just kept refusing to comply with previous legal requests which were much narrower in scope. Since he didn't comply they took the nuclear option (which he could have easily prevented).
- someone234 12y ago
- mkal_tsr 12y agoYet no comment from them about what being a "provider" under PRISM entails. * "In addition, Apple has never worked with any government agency from any country to create a “back door” in any of our products or services." If Apple provides an interface to request user-data to law enforcement / NSA, that's not a back door in the product or the service. * "We have also never allowed any government access to our servers. And we never will." If they provide user-data after being served with a warrant (possibly through email or to their legal department), their servers were never accessed, yet the data was provided. It's always interesting to read what is and isn't said. Word games, I swear.
- droopyEyelids 12y agoI'd like to see a breakdown of exactly what they can provide with a device request and an account request. I think that would be reasonable information to share, because it'd educate both law enforcement and the general public about what data is available from their devices. Plus it'd settle the issue of word games- or at least bring it closer to being settled in my eyes. We can't get a good idea of what is going on with these 10k foot marketing pronouncements.
- antmldr 12y agohttp://images.apple.com/privacy/docs/legal-process-guidelines-apac.pdf http://images.apple.com/privacy/docs/legal-process-guideline... Page 4 onwards provides a list of information they provide to law enforcement agencies. Probably prudent if you're an apple customer to simply assume all of this information is as good as public.
- joosters 12y agoI. Extracting Data from Passcode Locked iOS Devices ... For all devices running iOS 8.0 and later versions, Apple will no longer be performing iOS data extractions as the data sought will be encrypted and Apple will not possess the encryption key. Interesting. What changed in iOS 8, I wonder?
- 12y ago
- deleted 12y ago[deleted]
- ckuehl 12y agoI'm very skeptical that traditional screen-lock passcodes offer useful protection for the average person. Most people still choose to use 4-digit passcodes for convenience, leaving exhaustive key search [1] well within the reach of even very small attackers. Are these four-digit passcodes being used to derive encryption keys? If so, I'd like to hear where the additional entropy comes from. There's no use encrypting things with a 128-bit key when the effective entropy of the key is really only ~12.3 bits. I'm sure the engineers at Apple would not have overlooked this; it would be great to hear more about the specifics. [1] especially if the attacker can download encrypted data and try an infinite number of times (instead of e.g. typing the passcode on the phone or hitting the iCloud servers)
- wyager 12y agoIIRC, there are three crypto keys involved: 1. PIN 2. Random key in effaceable NAND storage (generated on device reset) 3. Burned in permanent CPU-unique key. I think OP's linked statement from Apple means that Apple is now also encrypting data stored on the iCloud servers. http://www.apple.com/ipad/business/docs/iOS_Security_Feb14.pdf http://www.apple.com/ipad/business/docs/iOS_Security_Feb14.p...
- declan 12y ago>I think OP's linked statement from Apple means that Apple is now also encrypting data stored on the iCloud servers. From today's announcement (scroll to "iCloud"): Mail and Notes are not stored in encrypted form on iCloud servers. http://www.apple.com/privacy/privacy-built-in/ http://www.apple.com/privacy/privacy-built-in/ From December 2013: Mail and Notes are not stored in encrypted form on iCloud servers. http://support.apple.com/kb/HT4865 http://support.apple.com/kb/HT4865
- zobzu 12y ago"Unlike our competitors, Apple cannot bypass your passcode and therefore cannot access this data" Oh really? Privacy is marketing now.
- poopsintub 12y agoThe terrorists have won.
- lmedinas 12y agoIt's one of the strongest marketing moves nowdays. Imagine the amount of "secure" messengers out there in which you only have a "word" from the company saying that it's secure. But they deliver a full closed source service in which there is no way to believe or not. So marketing works.
- josephlord 12y agoThat this has become an area companies are competing in is a good thing. The fact that it was necessary is sad but I don't blame the companies for that. When it is the area for competition it will naturally be the focus for marketing - providing that the marketing matches the reality and isn't misleading that is also a good thing so people can know where the privacy is and choose it.
- fpgeek 12y agoMy fundamental issue with Apple's privacy claims is they are pretending that they have a technological solution to what is, ultimately, a political problem. As the laws in the US (and I imagine some other countries stand), Apple can be compelled provide your data to appropriate governmental authorities, install back doors, not tell you and even lie to you and the world about it. As long as that's true, no assurance from any third-party service provider is worth a damn. I can understand the marketing benefits Apple sees in making these disingenuous privacy claims. I'd be willing to call that "just business" except for one thing: Trying to persuade people they have a technological solution will necessarily get in the way of the absolutely vital political project of destroying the political and legal foundations of the surveillance state.
- justicezyx 12y agoApple is doing what should be done. If everyone is informed enough to understand your point, there is no need of privacy policy, and NSA wont be an issue, and on and on...
- DigitalSea 12y agoThe honest truth about all of this is, even if Apple were handing over information because of back doors, custom database interface applications for the NSA, they wouldn't tell us and would probably be gagged from doing so anyway, have we all forgotten about Lavabit? I hope not. I think we are all intelligent enough to know that even if Apple were handing over information, it wouldn't exactly be good for business to admit you've been complicit in handing over personal details to the Government, would it? "Yes, we have been giving away your information, but we promise not to do it any more. Hey, we just released a couple of new iPhones, want to buy one" Anyone else notice the page is cleverly worded and any mention of security seems to be limited to iOS 8 context? "In iOS 8 your data is secure", "In iOS 8 we can't give law enforcement access to your phone" - maybe I am just overanalysing things here, but I have learned not to be so trusting of companies as big as Apple considering the amount of information that they hold. You know we're living in a new kind of world when privacy is being used for marketing purposes...
- unknownBits 12y agoIt is pretty naive nowadays to store any of your data online while thinking it is secure and no one will, or can touch it. Unless you do some hardcore encryption on your data yourself, which is really hard or even impossible with some data like call-logs, geographic location-data etc..
- blueking 12y agoPR bollocks. Apple does what its told. So does google.
- baby 12y agoIt almost seems like it's a feature of iOS8.
- xkiwi 12y agoFinally those numbers of iPhone activation and mac sold are useful. #1 Mac unit sales http://www.macworld.com/article/2062821/apple-by-the-numbers-mac-not-dead-yet.html http://www.macworld.com/article/2062821/apple-by-the-numbers... 2010 @ 13662k 2011 @ 16735k 2012 @ 18158k 2013 @ 16341k Total = 64,896,000 #2 iPhone unit sales http://www.statista.com/statistics/232790/forecast-of-apple-users-in-the-us/ http://www.statista.com/statistics/232790/forecast-of-apple-... I only take the number from 2013 & 2014 because Apple trend to upgrade fast. 2013 @ 53.6 Million, 2014 @ 63.2 Million, Total = 116,800,000 Now, quote from "Government Information Requests" "less than 0.00385% of customers had data disclosed due to government information requests." Only 699529.6 round to 699529 customers had data disclosed.
- deleted 12y ago[deleted]
- donkeyd 12y agoAbsolute numbers are useless... Pretty much any statistic put into absolute numbers ends up being a stunning number of people.
- chj 12y agoDidn't know that many.
- UVB-76 12y agoThere's probably a big overlap between iPhone and Mac users, but yes, a big number is going to come out the other end.
- cstrat 12y agoThe second hand market for iPhones is quite large in Australia and I imagine its the same elsewhere. Probably not fair to only include those two years iPhone sales. I would think at least 50% of the older models are either on-sold or the user hasn't upgraded. edit: UVB-76 has a good point, there is probably a very high percentage overlap.
- valleyer 12y ago
- deleted 12y ago[deleted]
- downandout 12y ago"On devices running iOS 8, your personal data such as photos, messages (including attachments), email, contacts, call history, iTunes content, notes, and reminders is placed under the protection of your passcode. Unlike our competitors, Apple cannot bypass your passcode and therefore cannot access this data" This is key. The way we engineer software and services can have a major impact on the war against overly invasive government requests. We know that these requests will come; it's our responsibility to design things in a way that protects customers from our legal obligations when confronted with them to the greatest extent possible. While this certainly serves their own interests, kudos to Apple for baking this type of consideration into the basic iOS design. They should and will be financially rewarded for it.
- imaginenore 12y agoAll it takes is one secret court order to force them to leak the key to NSA. They control the OS, they DO have access to everything.
- downandout 12y agoNot if they designed it properly. That's like saying that all makers of encryption software can, if they really want to, access all data encrypted with their software.
- imaginenore 12y agoOf course they can. All you have to do is leak passwords/private keys. An OS is actually much more powerful, it controls everything, it has direct access to memory. If a user can see his photo, the OS can.
- BillinghamJ 12y ago> Not if they designed it properly. You can (and always should) design encryption code without having a single root key. Entirely open sourcing that code should not make any difference to the security of the encrypted data.
- sidcool 12y agoApple has taken a shot against Google and facebook. It has mentioned that unlike its competitors their business model does not depend on selling user data. Which is kind of true, but Google and facebook's business model itself is using user data for marketing. Sometimes I feel it's not unethical to use user's data for marketing, the way facebook and Google tell us; that they don't directly share details with marketers, but they let them target the audience.
- adventured 12y agoI understand this does nothing to stop the NSA from snooping on me. However, the local / state police are a much more imminent threat to your average person with the rise of the police state than the NSA and FBI are. The local police are becoming ever more aggressive when it comes to your privacy and devices like your phone. If this turns out to be as good of a move as it seems like it is, Apple has acquired my attention in a way they weren't able to previously (I've been an Android user from day one). Plus I like the new larger iPhone 6.
- krisgenre 12y agoAndroid phones also have 'Encrypt Phone' feature ( since Gingerbread ) but not on by default.
- crishoj 12y agoHere's an observation, and an idea for testing Apple's claims on iMessage privacy: China seems quite determined to block IM systems which do not cooperate with the authorities and permit monitoring of communications. Most recently, both Line and the Korean KakaoTalk were blocked [1]. Skype remains useable in China, presumably because Skype permits efficient monitoring [2]. It seems unlikely that China would tolerate such a prominent opaque communications channel as iMessage in the hands of a significant proportion of their citizens. Thus, if China refrains from blocking iMessage for a prolonged period of time, wouldn't it be reasonable to assume that China is in fact able to snoop on iMessage? [1] http://www.ibtimes.com/china-restricts-messaging-apps-confirms-blocking-line-kakaotalk-last-month-1651620 http://www.ibtimes.com/china-restricts-messaging-apps-confir... [2] http://www.reuters.com/article/2012/01/31/us-china-dissident-idUSTRE80U0BJ20120131 http://www.reuters.com/article/2012/01/31/us-china-dissident...
- AJ007 12y agoIt is interesting you are the only one who has mentioned China. The other side of the coin is Apple being worried about being locked out of China for not being secure enough. http://www.reuters.com/article/2014/07/11/us-apple-china-idUSKBN0FG0S520140711 http://www.reuters.com/article/2014/07/11/us-apple-china-idU...
- crishoj 12y ago...where by "not being secure enough" means that location data ends up on US servers. I'd be surprised to see the same sort of statement if location data was collected and kept nationally. Nonetheless, Apple's relationship to China is a interesting case: • On one hand, China is posed to be the largest market for Apple in just a handful of years. • On the other hand, it's hard to imagine China approving of e.g. un-snoopable instant messaging in the hands of the populace.
- danford 12y agoExcept it's not open source. If it's not open source then you have no idea what's going on beyond what Apple tells you. Ask your self: Would Snowden use this phone? Your answer to this question is the same as the answer to the question "Is this phone secure?" I guess I'll get downvoted for this sense it goes against the Apple circlejerk, but this issue is more important to me than magic internet points.
- mox1 12y agoNobody sells a 100% open source phone. Everyone uses broadcom, motorola, TI, etc. chips which have propriety firmware. (I'm aware there are a few obscure phones that claim to be 100% open, but not many people use them, not available, etc.)
- stephenr 12y agoThe "its only secure if its open source" argument only really works if you compile the source yourself - otherwise you 're just trusting that the binaries on the devices are in fact compiled from the source that is published, in which case you may as well trust anything they say.
- pikachu_is_cool 12y agoI don't need to read this. Everything on the iPhone is proprietary software. As it has been proven countless times, there is an 100% probability that there are backdoors everywhere on this device. This entire blog post is a lie.
- wes-exp 12y agoAnd software built by volunteers, like OpenSSL, has proven to be so much more secure. It's not like heartbleed left practically the entire internet vulnerable to abuse. Oh wait, yes it did.
- JetSpiegel 12y agoA bug is not a backdoor. Unless you are implying the OpenSSL devs left the bug there on purpose.
- stephenr 12y agoYay for hyperbole!
- BillFranklin 12y ago19250 people have their Apple accounts accessed by #NSA every year.
- dubcanada 12y agoThese threads should come with a tin foil hat requirement. There is so many different views on this. But if you wear a thick enough tin foil hat, it really doesn't matter what anyone says. You will think the gov is spying on you regardless...
- krisgenre 12y agoDoesn't Android phones also have 'Encrypt phone' feature?