Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The article states that apple removed the feature in the UK. So what are the UK government demanding access to?


Advanced Data Protection, where Apple does not keep a copy of your encryption keys (essentially), was removed in the UK.

The UK seems to now want Apple to decrypt/provide access to encrypted iPhone backups. This is where your device backs itself up in a restorable format to the cloud, including passwords and private data. Since Apple has a way to decrypt non-ADP iCloud data, UK wants it.


Just want to elaborate on this:

If you do not have ADP enabled (which is the case in the UK as of now), device (iPhone) backups are not end to end encrypted and are stored on Apple's systems unencrypted (or encrypted with a key that Apple knows).

If you have ADP enabled then device backups are end to end encrypted; only you have the keys and therefore only you can decrypt the backup.


Frankly if Apple (or any provider for that matter) hold the encryption key then it isn't encrypted.


Frankly most of the services you use work exactly like this, so you must think very few things are encrypted


A locked door with a key in the lock is not really locked. As far as a court order is concerned, if they hold the keys they are available with the "encrypted" data".

Apple already (can and do) provide any and all data they hold, including decrypting data they hold the decryption keys for in response to a court order worldwide.


> A locked door with a key in the lock is not really locked.

A physical key sitting in a lock? Anyone walking by can turn it. Done. That's not what's happening with iCloud data.

Apple's decryption key isn't sitting there for the turning. It's stored in access-controlled systems and requires deliberate action and legal process to use. An employee or passerby can't just stroll by and "turn the key."

If you want the only copy of the key to your digital safety deposit box where you store all your stuff, thankfully there is Advanced Data Protection.

> As far as a court order is concerned

All service providers you use will provide data in response to lawful requests.


It's encrapped.


encrappted


It's not removed in the UK for users who enabled it before the ban. There may be existing users of it that the UK gov are interested in.


Why the down vote?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: