Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

How so?

Apple shared all their iCloud user data (messages, pics, docs, etc.) and keys with the Chinese government last year. [1] Apple even updated their TOS forcing Chinese users to agree to it or drop service. [2]

Google got flak for just considering it with Dragonfly, but Apple actually did it.

[1] https://mashable.com/article/china-government-apple-icloud-d...

[2] https://www.reuters.com/article/us-china-apple-icloud-insigh...



> Apple shared all their iCloud user data (messages, pics, docs, etc.) and keys with the Chinese government last year. [1]

They shared all their Chinese users' iCloud data. It's a huge distinction and I feel like you paraphrased it deliberately to try to make Apple appear to have sold out all of their users worldwide. While what they did in China is terrifying in general, it doesn't compromise security for any Apple user outside of China as you very strongly implied it did.

Here's the very first sentence from the link you posted (emphasis mine):

> A state-owned telecommunications company in China now stores the iCloud data for Apple’s China-based users.


Google's Dragonfly was the same thing - sharing "only" Chinese user data.

GPs comparison was privacy between the two companies, and one cares more about selling in China than the privacy of it's users.


You are using one instance - sharing Chinese users' data with the Chinese government - as the sole metric for judging a company's privacy policies. That's just as dishonest as the GP paraphrasing the link they cited to make it appear Apple did something they did not.

I'm not defending Apple WRT their data privacy practices in China; as I said it's terrifying and hopefully not a stepping stone. I was simply calling GP out for deliberately misrepresenting their own citation to make a false equivalence.


Sharing millions of users' personal data with a surveillance state notorious for civil rights violations is not a trivial matter, especially in any discussion involving privacy reputation.

If you think there are privacy issues that are more important than that then list them.


And again you are being dishonest. I never said it was a trivial matter, I said it was terrifying. I was calling out a deliberate attempt to falsely claim Apple was doing to all of its customers what they did to its customers in one country but you are trying to twist it into something completely different by putting words in my mouth. Shame on you.

And now that you've brought this discussion into ad hominem territory, it has lost any relevance to the actual topic at hand. Peace.


First they came for the Chinese, and I did not speak out— Because I was not Chinese.

Edit: Wikipedia link to original poem: https://en.wikipedia.org/wiki/First_they_came_...


More like "First the Chinese government came, and I did not speak out, because they don't care about anyone other than the Chinese."


Challenging your assumptions: 1. Does China only care about Chinese? 2. If the Chinese government was first, who will be second?


The Chinese doesn't even care about the Chinese. Their care about the Communist Party. Everything else comes second.


This allows Apple to continue selling their hardware and software to people living in China (of which there are a lot). This is not a problem with Apple, but a problem with China.


This is constantly being misreported. No. They. Do. Not. Apple's data is kept on the device and so are the keys. If you enable that data to be put on the cloud (it's an opt-in) then they will also store the key, but otherwise they do not.


Yeah... except actually no.

iMeasage, the one be thing that really matters in this case, encrypts it's chats "end to end" but using keys managed centrally by Apple, regardless of your iCloud sync situation, and manages them in a way that can't inspected by users. If a decrypted copy of all your encrypted chats is being sent to a government sink, there is no way for you to know or prevent it.

China cares about being able to intercept and decrypt your communication, they want to be able to identify and punish political threats. That's a service that Apple CAN provide to the Chinese government for all iPhone customers.


I'm always curious how can people get so confident about Apple's security practices, given that none of the parts are open source? Is the trust solely reputation-based?


Boycotting of countries or not is one thing. Once in a country and following the law, Apple's business model is simply more conducive to privacy. Unlike Google, they are not reliant on the collection and analysis of data. On the contrary, like DDG, they use privacy as a differentiator and advantage. The only thing you can trust about companies is their business models.


If you just cherry pick actions and ignore things such as sharing millions of their users' data with a surveillance state, then sure, they seem privacy focused.


There is a huge difference between complying with a state’s requirements and relying on privacy violation for your business model.


Source? iMessage is E2E encrypted so no, Apple did not share that part (or other encrypted data like keychain). They’ve actually gone pretty far in protecting their E2E encryption from adversarial clouds.


Added sources. Apple moved the keys for accessing the data at rest to Chinese servers, which were nationalized by the Chinese government. The Chinese government has access to the users' data at rest and the keys to decrypt it.


I think you are misunderstanding. Apple moved Chinese iClouds to Chinese firms. So yes, Chinese iCloud users in China will be under the full surveillance of the government. Which they always have been. But that has no impact on anyone outside of China.

Dragonfly is a censored search engine, not a user data base.


The Chinese firms were nationalized by the government in July, giving full access. This isn't generic surveillance but complete ownership. First source listed in my original comment.

Dragonfly was complying with China's firewall, because clicking broken links in search results sucks, but it was also linking every search query to the users phone number and sharing with the Chinese government, which is what Google employees revolted over.


This does not affect E2E encrypted data like iMessage. Apple doesn’t have those keys to give.[1]

[1] https://www.apple.com/business/site/docs/iOS_Security_Guide....


But since key management is out of your control or visibility, Apple can just add another key to your account on behalf of the government. They don't have to disclose the existing keys on your device. This gets them the messages going forward but not the ones from the past. So they'd have to do this for all Chinese customers ahead of time, rather than as a response to an inquiry.


Anything's possible if the vendor secretly collaborates with a government to insert vulnerabilities and lies about it. But what we're talking about here is, given the way Apple has publicly declared how the system works[1], what can a government do with full server access.

Apple states "All of the user’s registered devices display an alert message when a new device, phone number, or email address is added." So no, it's not correct to say key management is out of your visibility.

[1] https://www.apple.com/business/site/docs/iOS_Security_Guide....


Your messages are stored on iCloud, right?


Yes but they are now E2E encrypted. Apple rolled out "Messages in iCloud" recently which preserves E2E encryption and excludes messages from regular (not E2E encrypted) iCloud backups.


Only if you enable this feature.


Its enabled by default. iCloud backups are automatically opted in since iOS 9.


Backing up messages to iCloud is not on by default. iPhone will ask you if you want to enable it.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: