10 ms·
I hypothesize that this is a coordinated yet simple ruse to rebuild trust in these brands post-Snowden [1][2]. There was similar press coverage regarding the DE
by xnull 12y ago
I hypothesize that this is a coordinated yet simple ruse to rebuild trust in these brands post-Snowden [1][2]. There was similar press coverage regarding the DEA and iCloud encryption that was misreported in a similar way [3]. The Intercept (where Glenn Greenwald is now reporting from) has a story on what data Apple can still easily give away if you do believe they can't decrypt individual machines [4]. But maybe you don't believe it given the report from the ACLU on backdoors built into iPhones that circumvent encryption [5], and the Hope X talk on backdoors security researchers independently discovered [6].
More importantly, Apple's warranty canary was removed which either means they were served by National Security Letter or (if you're optimistic sort of person) that they are no longer committed to notifying consumers in the event that have been, which flies directly in face of all the PR talk of security commitment recently [7]. Plus remember, Apple can push whatever software they want to your personal device. That's how smartphones work.
We are led to two questions:
A) Why wouldn't the same tactics, National Security Letters and ORCHESTRA-type attacks work [8]? Don't we remember from the Snowden leaks that NSA agents infiltrate tech companies and backdoor software at the source when other avenues are closed or gridlocked?
B) Why all of the publicity about about how secure Apple's product are from snooping? Do we really think we can get away from ubiquidous global surveillance that easily?
I'm sorry. Investigative bodies don't publicly announce what technologies they can't track. There is no phone you can buy on the mass market that will keep your data safe with the exception of - perhaps? - the BlackPhone [9].
[1] http://www.businessinsider.com/apple-google-meet-with-obama-2013-8 http://www.businessinsider.com/apple-google-meet-with-obama-...
[2] http://www.huffingtonpost.com/2013/12/17/obama-tech-executives_n_4460967.html http://www.huffingtonpost.com/2013/12/17/obama-tech-executiv...
[3] https://www.schneier.com/blog/archives/2013/04/apples_imessage.html https://www.schneier.com/blog/archives/2013/04/apples_imessa...
[4] https://firstlook.org/theintercept/2014/09/22/apple-data/ https://firstlook.org/theintercept/2014/09/22/apple-data/
[5] https://www.aclu.org/blog/technology-and-liberty-criminal-law-reform-immigrants-rights/new-document-sheds-light https://www.aclu.org/blog/technology-and-liberty-criminal-la...
[6] https://pentest.com/ios_backdoors_attack_points_surveillance_mechanisms.pdf https://pentest.com/ios_backdoors_attack_points_surveillance...
[7] https://gigaom.com/2014/09/18/apples-warrant-canary-disappears-suggesting-new-patriot-act-demands/ https://gigaom.com/2014/09/18/apples-warrant-canary-disappea...
[8] http://mirror.as35701.net/video.fosdem.org//2014/Janson/Sunday/NSA_operation_ORCHESTRA_Annual_Status_Report.webm http://mirror.as35701.net/video.fosdem.org//2014/Janson/Sund...
[9] https://www.blackphone.ch/ https://www.blackphone.ch/
Additional reading:
(1) https://www.schneier.com/blog/archives/2013/06/the_problems_wi_3.html https://www.schneier.com/blog/archives/2013/06/the_problems_...
(2) https://www.schneier.com/blog/archives/2013/10/defending_again_1.html https://www.schneier.com/blog/archives/2013/10/defending_aga...
(3) https://www.schneier.com/blog/archives/2012/08/is_iphone_secur.html https://www.schneier.com/blog/archives/2012/08/is_iphone_sec...
- jn1234 12y agoI believe that the decision to start encrypting data will just make it harder for local law enforcement to attain your data. When they subpoena Apple for your data they will get the encrypted data. The NSA will probably also receive your data encrypted however they probably won't have any problem unencrypting it.
- randomfool 12y agoWhen they subpoena Apple, they will get cloud data which will not be decrypted. The issue is whether they would be able to give Apple a device and say 'decrypt plz'.
- mullingitover 12y agoIf the device is backed up in iCloud, Apple already has the decryption key and will have to provide it if they receive a supoena. The only way you're safe, even in theory, is to only do local encrypted backups.
- jn1234 12y agoThe whole point of the updated system is that they don't have your decryption key. They will still turn over encrypted data, but LE won't be able to decrypt. That might be a leap of faith though.
- seanflyon 12y agoSo you are saying that if you lose your device there is no way to recover your data?
- psykovsky 12y agoNo, he's saying the decryption key will be a simple passcode for an encrypted private key stored on apple's servers, or something even worse than that. Promising, ain't it? ...with the examples we have of the type of passwords people use...