5 ms·
malicious compliance. Providing access when ordered by a court is not as secure so we're removing all encryption?
by InsomniacL 2y ago
malicious compliance.
Providing access when ordered by a court is not as secure so we're removing all encryption?
- smidgeon 2y agoEnd-to-end-encryption-except-when-the-UK-government-is-interested doesn't have the same ring to it, liable to damage the brand ....
- nobankai 2y agoFWIW people always put too much trust in E2EE where they didn't control either end. This was a loooong time coming.
- lokar 2y agoIt’s not really end to end in that sense. They don’t get the key, they just store opaque data for you. The only way apple could get your data is to push code to your device to steal the key.
- ferbivore 2y agoI think their point was that you don't control your device. If Apple did push code to your device to steal the key, how would you be able to tell?
- dmix 2y agoPeople aren't going to use your self-hosted E2E tools on a wide scale. We've been down that road. Best to secure the systems people already use.
- rxyz 2y agothe whole point of ADP is that they cannot provide access
- CharlesW 2y agoYes, the parent commenter missed the part where Apple cannot see the encrypted content when ADP is used.
- zikduruqe 2y agoBut Apple could say, you have 45 days to remove it or we will delete it, then you have to resync your data.
- JKCalhoun 2y agoNo! That's not ... the comfy chair is it?
- brookst 2y agoWhy would they? What priorities are better served by that approach?
- zikduruqe 2y agoWhy would they say to all new users, that they cannot have Advanced Data Protection, whereas older customers can? Now you have a certain percentage of users with encrypted data, and a certain percentage of users that do not. The UK government will not like that. And now Apple has shown that it will not take a stand for privacy it might have to do it to comply.
- brookst 2y agoAh, you missed the part where Apple also said existing users will have to turn it off at an unspecified date.
- InsomniacL 2y agoI'm not suggesting Apple should be able to see the content, I'm saying the Police should be able to, when they have a valid court order issued in accordance with the legislation. For example, A 'Personal Recovery Key' could be recorded in a police database. To gain access to 'encrypted' data from Apple, a court order is needed, once they have the encrypted data, they can unencrypt it using the key only they hold. There's lots of ways to skin a cat.
- ziddoap 2y ago>Providing access when ordered by a court is not as secure so we're removing all encryption? Providing a back door for one government reduces the security and privacy of the service worldwide. This decision keeps the security and privacy for the rest of the world. Sucks for the UK that your politicians decided to go this route.
- pjc50 2y ago"If we can't provide this product legally, we're not going to provide it at all" ends up being the only reasonable position in situations like this. At least this way doesn't compromise users in other countries.