1) they just ate every other 3rd party "secure" backup services lunch just like they did to the Hi-Res music industry.
2) details of what they backup securely, besides photos (which is top priority for me): iCloud Drive: Includes Pages, Keynote, and Numbers documents, PDFs, Safari downloads, or any other files manually or automatically saved to iCloud Drive.
3)BUT, perhaps the BIGGEST news here is that Apple is making a backup statement to what they've been saying for years and what they've recently gotten negative attention on: They don't want your data. They're not Goodle/FB/Amazon. They're giving you 2TB+ of space and you can encrypt it to the point that you'll lose your data and they don't care -- they don't want to mine your data, they don't want to know what you store on there, the don't care to scan your pictures with AI 20 different ways, they don't want to monetize it, etc, etc., just pay them money for their service and transactionally they give you only thing that you want in return -- reliable, secure, private service.
seriously, anyone at this point advocating for any other phone/os/service out there besides apple is really going out of their way to swim up river.
I'm advocating for an open and interoperable ecosystem of operating systems, services and applications, which is the only way to ensure sustainable customer freedom. Unfortunately that ecosystem doesn't exist yet so we're stuck with the duopoly of evil-doers (and while Google openly admits it is their business model to monetize you and your data, Apple has been caught with their hands in the cookie jar a bunch of times already and they're just developing a sweet tooth, so...).
Full disclosure: I've been using only iPhones for 12 years and am still using one today.
Their software is not open source. Before this announcement you had to trust Apple not to look into the files you store in the cloud, now you have to trust that they're actually going to encrypt your files and not save the decryption key. Ultimately you still have to trust Apple. A combination of any open source OS, any cloud provider and Cryptomator or Veracrypt wouldn't require as much trust in one company.
This is an excellent point as to why you shouldn't even bother trying to develop software for apple machines. If it's anywhere near successful apple will just destroy you, after having taken a 30% cut from your revenue for years.
I think you and I have vastly different ideas about what "giving" means.
I get 5GB of iCloud storage, unless I pay them £6.99/month for 2TB. No idea what the rate is over 2TB.
Have I missed a trick to getting this 2TB+?
(I have 7 Apple devices in my possession and have owned a further 2 that I've passed on to my kids; given the premium I paid for those I almost expect that I should get 5GB PER DEVICE, but of course that's fairly unreasonable in reality)
Ok, come on. What apple’s done here is great, and I personally use an iPhone, but you couldn’t think of a good reason to use anything else? An open-source OS?
iOS still doesn't allow you to sideload without shenanigans (requiring your to not only have a Mac, but also have it resign any custom apps every week is beyond unreasonable). Some people don't care about that, but I do and not being able to do so is 100% a dealbreaker for me.
Not using Apple because you disagree with their decisions does not make one intentionally "going out of their way to swim up river." It just makes one a normal person who doesn't want to use, what it to them, an inferior product.
> the don't care to scan your pictures with AI 20 different ways
This is especially ironic as another post on the HN front-page today is about Apple giving up on their plan to scan iCloud photos for CSAN after months of pushback.
This is a little hyperbolic. E2EE backups are fantastic; Apple seriously deserves a ton of praise for this. And iPhones have been getting a ton of security/privacy features that I really love, I am not going to dismiss their contributions to privacy. And while I wish some of their services like the Apple VPN/masked emails were better done, they are still fantastic features that I encourage iPhone users to enable, and that I am thrilled to see rolled out to a mass audience.
Alongside that praise, I am though going to point out that the adblocking on the iPhone is sub-par[0] because mobile Safari lacks Firefox's extension APIs, and I'll point out that their app store model blocks some privacy apps like Newpipe, which forces people into using more invasive alternatives that require stricter privacy controls. I'll point out that it is harder in some ways to get away from the default tracking that happens in Apple's apps than it is to root an Android phone and disable/swap Google services.
Threat model and personal expertise matters here; I like a lot of what iPhone do, but I also dislike a lot of what they do. Personally, I feel more confident in my ability to secure a rooted Android device than I do to secure an iPhone against the majority of privacy attacks I'm worried about. That doesn't mean that iPhones aren't the correct choice for a lot of people. I feel much less confident in a family member's ability to secure an Android phone if I can't give them advice or help them through the process.
And all of this is ignoring that privacy is one aspect of consumer freedom and rights. I think we can praise Apple for what is objectively a great move for privacy without being this over-the-top.
----
[0] Before someone complains, I'm not saying that iPhones don't have adblocking. They do have adblocking and I encourage you to use it, it's great. But that adblocking is objectively not as powerful or comprehensive as it would be to use a tool like Ublock Origin.
Maybe images/photos isn't something they want to expand at this moment in time but let's not get ahead of ourselves.
* They are more and more into advertising business https://news.ycombinator.com/item?id=32520894
* Their executives admit that they want you and your family locked into their ecosystem (leaked emails).
Sorry, but advocating for them seems like very bad idea. Google was cool, pro-customer company once too. Until they had position to not be anymore. Open standards, without any vendor lock are only reasonable way.
Photo checksums can't be e2e encrypted huh? They reported today they abandoned their plans to do CSAM scanning on people's devices[1] and connecting the dots it seems like they wont need to since they can just do it in the cloud.
[1] https://www.wired.com/story/apple-photo-scanning-csam-commun...
They can remotely wipe apps. They can force-install apps and force updates. It is not too far-fetched to think that they can just remotely copy anything stored on your device to their servers. So, with an adversary that capable, I'm not sure encrypted backups provide a meaningful improvement to security and privacy.
A small number of comments here are not about E2EE backups but rather the security key announcement. If there's a more detailed URL for that part of the story, we can factor it into its own thread.
> • iCloud Drive The raw byte checksums of the file content and the file name
> • Photos The raw byte checksum of the photo or video
As it is, my iPhone unlock PIN is everything that's needed to decrypt the data server-side [1], and I'm not changing to an alphanumeric password on my phone only because of that.
[1] https://support.apple.com/en-us/HT204915 ("You might also be asked to enter the passcode of one of your devices to access any end-to-end encrypted content stored in iCloud.")
> Advanced Data Protection for iCloud is available in the US today for members of the Apple Beta Software Program, and will be available to US users by the end of the year. The feature will start rolling out to the rest of the world in early 2023.
It also doesn’t work for Shared Albums, and for other “Shared” features it requires all participants to have ADP enabled.
I don't feel like updating to a beta to get this feature (especially for the risks associated with it). But I am curious how the migration will work. Will this basically re-encrpt everything locally and then upload it or will what is already there stay unencrypted.
Also does anyone know, how do features like this work for someone with a single apple device? I don't worry about loosing access to anything because if my phone dies I have... several other devices with keys. But what about someone who doesn't?
However, for most people their messages will still not be end-to-end encrypted because their contacts will mostly not have this optional feature enabled. To be truly effective, this feature would have to ensure that Apple does not strip the end-to-end encryption from your messages when they are sent to other people using iMessage. In my opinion it is still fraudulent to market iMessage as an end-to-end encrypted system until this is fixed.
An anecdote, an activist had a document in their Google Drive. It was not something people high up wanted being distributed. It was deleted not just from their account, but platform wide. Guess how they did that? Its hash.
I can’t help but feel this dovetails with the CSAM-scanning work that Apple canned last year.
I was always under the impression that ultimately they were doing that work because they needed some mitigations for the fact that iPhoto backups meant people were storing CSAM on Apple’s servers. If they were serious about privacy, that would be a big big problem for them —- hard to say no when the government comes knocking with a legitimate warrant, so they needed a solution that would let them preempt that scenario.
This is a much better solution.
Was client side scanning implemented finally? Perhaps E2E paves the way to client side scanning?
For the hardware key, Apple is a bit late though. All other cloud companies have that 2FA.
Interesting, so this is an opt-in (not default secure).
It would be fair if Apple gave a warning about US governments and courts before enabling sync to iCloud, but I guess they don't want users to know about it.
Also this is a closed source system, so we can't know whether Apple can remotely extract encryption keys or not.
Also as I understand, Apple now demands a phone number to sign up for Apple ID, so it means that now all users and their contacts are non-anonymous for Apple.
As of now, there is no backing up your Mac to iCloud. There is iCloud Drive and all the individual services but TimeMachine is local storage only (shared drive or the legacy TimeCapsule).
Does this mean we’re finally getting TM backups to cloud?
I think, on top of all that, it's still an overall "win" for consumers. But don't treat Apple like the white knight it purports to be. Beware the 'nice guys'.
Remember, they say nothing of what happens when they receive the data for the first time. It may be enough that they scan and store this information upon the initial ingestion, then leave you with the keys.
I hope they will support existing Yubi-Keys etc and not force users to get the dedicated Apple hardware key.
1) They explicitly state that they're going to keep an eye on the hashes of your files, allowing them to nuke anything they don't like from orbit system-wide. They still know what you have in cases where someone else has it and they know the plaintext. They're definitely going to scan what you keep in their cloud. It will start with kiddie porn, but then it'll be that plus terrorist documents (and who decides what that is???), and then illegal music and movies, and then...
2) It's all implemented with closed-source mysteryware. Who the fuck knows what it's doing? You've got to trust their pinky-swear, and you shouldn't. It probably works as it is described until it receives the special wink from Apple's servers, and then it sends along your private keys (possibly using an exploit they put there on purpose). If it's not verifiable (open-source and reproducible builds), it's a pinky swear.
3) This is your reminder that your iMessage isn't actually E2EE, they have a lot of the keys on their own servers.
These are all things they could fix, but don't. And they won't fix them because they don't actually give a damn about your privacy and security. We should all demand open-source, reproducibly-built encryption software.
Now if we could just get banks on board… they’re probably the single biggest glaring hole in non-SMS 2FA. To my knowledge there’s only 2-3 US banks that even support TOTP, let alone hardware keys, which is insane given how important they are.
I’m sure they’ll get pushback for closing this loophole
This means that iMessage as a platform is still backdoored, because most people you iMessage with will be escrowing their endpoint iMessage keys to Apple in their effectively unencrypted iCloud Backups.
Apple (and the FBI/DHS/CIA/NSA soup bois without a warrant) will still be able to read everyone's iMessages in real-time.
Everyone wins. Spies keep spying, Apple gets to trot out the e2ee marketing flag.
Meanwhile, there is nothing to indicate that they don't intend to continue the rollout of their clientside photo scanning software that they previously announced.
Apple, the client side scan pushing and ad platform expanding company is now the same company that is releasing strengthened cloud data protection. Deduplication becomes impossible at any sort of scale and for safety Apple even turns off web access to iCloud when E2E cloud protection is turned on for the first time.
Apple has stated it will cache thumbnails using standard protections when sharing files, using "anyone with a link" will expose the unencrypted data to Apple servers. I wonder if CSAM scanning can take place for those files only.
--
> The apple policy was likely about coming up with a way to enable encrypted photos on iCloud while still having some privacy preserving form of CSAM detection. Since it was only enabled when iCloud photos was enabled it was better for privacy on net than the status quo (unencrypted iCloud photos that are accessible to apple and scanned anyway).
This should be a default, basic feature of any service today offering storage of personal information. It's not like we haven't had the technology for decades. It's win-win, too: The company can't be held responsible for the contents because they can't read them, and the user gets privacy. Which in America is legally protected from the government. That means that if the company can't peer into the data, there's no point in even wasting their time with a warrant.
If the keys on the device are generated at the user's behest with some input of theirs, it's out of Apple (e2ee vendor)'s hands, logically, logistically, legally, and ethically.
(letting users into their own devices means the ability to access the entire device, examine what their device is doing, and firewall it if wanted)
Didn’t want to upgrade my perfectly functioning MBP 15 2015 for Shared Photo Library alone. They found out another way to force the upgrade.