UK demands access to Apple users' encrypted data
Discussion
ATG said:
andyb28 said:
Thinking about this more. I don't think Apple have rolled over, instead I think they have done this because of the uneducated impossible requests for back doors.
Yup.I'm not convinced the collective might of Apple cannot come up with more nuanced, elegant approaches (actually scrub that. I can. They'd need someone else to do it first and stick an Apple badge on it
). But that's up to them.130R said:
Apple just removed end-to-end encryption for the UK. So the government have successfully weakened online security / privacy for all UK based users. Great job.
I am trying to compile a list of other juristictions that don't allow ADP.I am thinking China, Russia and North Korea. Maybe one or two places
in the Middle East.
It looks to me like UK is trying to join that list and it's not a good look.
Sadly, I have to pay for this level of stupidity.
130R said:
Apple just removed end-to-end encryption for the UK. So the government have successfully weakened online security / privacy for all UK based users. Great job.
No, they didn't.They removed ADP for new users (existing users later). ADP only applies to a limited set of data categories that the majority of users were not using anyway as it was optional and had to switched on. The "important stuff" is still end-to-end encrypted.
Murph7355 said:
That is not the same with bit heavy encryption (as you know, because you understand it). Sure, they can ask Mr Alleged Criminal for his key and I'm sure they will all cooperate and not one will say "what key", "sorry, my hard disk failed and it was lost" or "the dog licked it".
And police and CPS already have powers to address that.https://www.bbc.co.uk/news/uk-england-11479831
Murph7355 said:
...
Will it materially stop the very worst of the internet. Unlikely. But just because you cannot stop 100%, doesn't mean you should not try to stop 99%, 98%, 90% etc IMO. Remember, not "not understanding", just having a different opinion.
All the weakening of encryption like this achieves is enabling mass surveillance of the general population by anyone with the resources to do it.Will it materially stop the very worst of the internet. Unlikely. But just because you cannot stop 100%, doesn't mean you should not try to stop 99%, 98%, 90% etc IMO. Remember, not "not understanding", just having a different opinion.
Which is both what they want and the price they are willing for us to pay.
Strangely Brown said:
130R said:
Apple just removed end-to-end encryption for the UK. So the government have successfully weakened online security / privacy for all UK based users. Great job.
No, they didn't.They removed ADP for new users (existing users later). ADP only applies to a limited set of data categories that the majority of users were not using anyway as it was optional and had to switched on. The "important stuff" is still end-to-end encrypted.
ADP is end-to-end encryption for iCloud data like backups, photos, notes, etc. With standard data protection that iCloud data is encrypted but the encryption keys are stored by Apple.
dcb said:
I am trying to compile a list of other juristictions that don't allow ADP.
I am thinking China, Russia and North Korea. Maybe one or two places
in the Middle East.
It looks to me like UK is trying to join that list and it's not a good look.
Sadly, I have to pay for this level of stupidity.
Ah the old "we'll be just like North Korea" line of logical reasoning. Always a winner. You'll be all "the world will think we're a laughing stock" next I am thinking China, Russia and North Korea. Maybe one or two places
in the Middle East.
It looks to me like UK is trying to join that list and it's not a good look.
Sadly, I have to pay for this level of stupidity.

Evanivitch said:
Murph7355 said:
That is not the same with bit heavy encryption (as you know, because you understand it). Sure, they can ask Mr Alleged Criminal for his key and I'm sure they will all cooperate and not one will say "what key", "sorry, my hard disk failed and it was lost" or "the dog licked it".
And police and CPS already have powers to address that.https://www.bbc.co.uk/news/uk-england-11479831
I'd still much sooner the authorities were able to go straight to kiddie porn, terror related stuff etc without jumping through hoop after hoop. (Maybe they're wanting to do this as the hoop you link to causes delay which in itself creates issues for people "tidying up"?).
Appreciate you feel that protecting your family photos and life's Word documents etc is more important than that. I don't. We're all different

grumbledoak said:
All the weakening of encryption like this achieves is enabling mass surveillance of the general population by anyone with the resources to do it.
Which is both what they want and the price they are willing for us to pay.
Still shrugging my shoulders. (I used all the tin foil up cooking bacon for breakfast).Which is both what they want and the price they are willing for us to pay.
Fill your boots. Surveil me as much as you want

Murph7355 said:
Evanivitch said:
Murph7355 said:
That is not the same with bit heavy encryption (as you know, because you understand it). Sure, they can ask Mr Alleged Criminal for his key and I'm sure they will all cooperate and not one will say "what key", "sorry, my hard disk failed and it was lost" or "the dog licked it".
And police and CPS already have powers to address that.https://www.bbc.co.uk/news/uk-england-11479831
I'd still much sooner the authorities were able to go straight to kiddie porn, terror related stuff etc without jumping through hoop after hoop. (Maybe they're wanting to do this as the hoop you link to causes delay which in itself creates issues for people "tidying up"?).
Appreciate you feel that protecting your family photos and life's Word documents etc is more important than that. I don't. We're all different

So if you could explain what MOD will require contractors to do in future that would be much appreciated, because right now it looks like the whole defence industry will need MODNET laptops from Monday...
130R said:
Strangely Brown said:
130R said:
Apple just removed end-to-end encryption for the UK. So the government have successfully weakened online security / privacy for all UK based users. Great job.
No, they didn't.They removed ADP for new users (existing users later). ADP only applies to a limited set of data categories that the majority of users were not using anyway as it was optional and had to switched on. The "important stuff" is still end-to-end encrypted.
ADP is end-to-end encryption for iCloud data like backups, photos, notes, etc. With standard data protection that iCloud data is encrypted but the encryption keys are stored by Apple.
king didn't. End-to-end encryption still exists so they did NOT "remove end-to-end encryption for the UK" as you claimed. They have removed end-to-end encryption for some categories of data where it is stored on Apple servers.Messages, Health etc and the important personal stuff is still as it was.
This stuff is important and misinformation helps nobody.
ETA: For the avoidance of doubt...
These iCloud data categories will no longer benefit from end-to-end encryption in the UK:
iCloud Backup
iCloud Drive
Photos
Notes
Reminders
Safari Bookmarks
Siri Shortcuts
Voice Memos
Wallet Passes
Freeform
What is not changing as part of Apple’s decision to pull Advanced Data Protection from the UK is the end-to-end encryption offered for those initial 15 different iCloud data categories. This means that the following iCloud data categories are still protected by end-to-end encryption by default for all users in the UK:
Passwords and Keychain
Health data
Journal data
Home data
Messages in iCloud
Payment information
Apple Card transactions
Maps
QuickType Keyboard learned vocabulary
Safari
Screen Time
Siri information
Wi-Fi passwords
W1 and H1 Bluetooth keys
Memoji
Edited by Strangely Brown on Saturday 22 February 19:39
Murph7355 said:
Still shrugging my shoulders. (I used all the tin foil up cooking bacon for breakfast).
Fill your boots. Surveil me as much as you want
It's not the government surveillance angle that's the direct problem with an engineered in back door in an encryption or other system (though you shouldn't be blasé about such a thing anyway).Fill your boots. Surveil me as much as you want

It's that once said back door exists, it can be used by basically anyone.
Murph7355 said:
Evanivitch said:
Murph7355 said:
That is not the same with bit heavy encryption (as you know, because you understand it). Sure, they can ask Mr Alleged Criminal for his key and I'm sure they will all cooperate and not one will say "what key", "sorry, my hard disk failed and it was lost" or "the dog licked it".
And police and CPS already have powers to address that.https://www.bbc.co.uk/news/uk-england-11479831
I'd still much sooner the authorities were able to go straight to kiddie porn, terror related stuff etc without jumping through hoop after hoop. (Maybe they're wanting to do this as the hoop you link to causes delay which in itself creates issues for people "tidying up"?).
Appreciate you feel that protecting your family photos and life's Word documents etc is more important than that. I don't. We're all different

ATG said:
They won't be able to do any of that because all of that data will still be properly encrypted. It doesn't matter what Apple does. You can encrypt the data BEFORE you send it to Apple. Stopping Apple from providing end to end encryption is a minor inconvenience for anyone who wants to store or communicate data privately. If Apple put a backdoor in their own E2E encryption layer, then it ain't E2E encryption anymore. The service becomes pointless so they're withdrawing it. It is now fractionally more inconvenient to send encrypted data, that's all.
I agree, but it raises the question of what they'll do to the commercial AES256 tool providers.ATG said:
They won't be able to do any of that because all of that data will still be properly encrypted. It doesn't matter what Apple does. You can encrypt the data BEFORE you send it to Apple.
But, assuming you're talking about icloud backups and not manually encrypting data (not sure?) then, doesn't Apple hold the keys - isn't that the point of ADP?Evanivitch said:
ATG said:
They won't be able to do any of that because all of that data will still be properly encrypted. It doesn't matter what Apple does. You can encrypt the data BEFORE you send it to Apple. Stopping Apple from providing end to end encryption is a minor inconvenience for anyone who wants to store or communicate data privately. If Apple put a backdoor in their own E2E encryption layer, then it ain't E2E encryption anymore. The service becomes pointless so they're withdrawing it. It is now fractionally more inconvenient to send encrypted data, that's all.
I agree, but it raises the question of what they'll do to the commercial AES256 tool providers.ATG said:
Evanivitch said:
ATG said:
They won't be able to do any of that because all of that data will still be properly encrypted. It doesn't matter what Apple does. You can encrypt the data BEFORE you send it to Apple. Stopping Apple from providing end to end encryption is a minor inconvenience for anyone who wants to store or communicate data privately. If Apple put a backdoor in their own E2E encryption layer, then it ain't E2E encryption anymore. The service becomes pointless so they're withdrawing it. It is now fractionally more inconvenient to send encrypted data, that's all.
I agree, but it raises the question of what they'll do to the commercial AES256 tool providers.Murph7355 said:
And?
I'd still much sooner the authorities were able to go straight to kiddie porn, terror related stuff etc without jumping through hoop after hoop. (Maybe they're wanting to do this as the hoop you link to causes delay which in itself creates issues for people "tidying up"?).
Appreciate you feel that protecting your family photos and life's Word documents etc is more important than that. I don't. We're all different
Even if we assumed that the CP terrorists can't manage their own E2EE, how will losing authentication and integrity guarantees make it easier for authorities to go after that stuff?I'd still much sooner the authorities were able to go straight to kiddie porn, terror related stuff etc without jumping through hoop after hoop. (Maybe they're wanting to do this as the hoop you link to causes delay which in itself creates issues for people "tidying up"?).
Appreciate you feel that protecting your family photos and life's Word documents etc is more important than that. I don't. We're all different

Gassing Station | Computers, Gadgets & Stuff | Top of Page | What's New | My Stuff

