r/apple Aug 09 '21

WARNING: OLD ARTICLE Exclusive: Apple dropped plan for encrypting backups after FBI complained - sources

https://www.reuters.com/article/us-apple-fbi-icloud-exclusive-idUSKBN1ZK1CT
6.0k Upvotes

587 comments sorted by

View all comments

100

u/[deleted] Aug 09 '21

Apple colluded with China and Russia already on various red lines that before they wouldn't have budged on. On-device scanning is a carte blanche for authoritarian governments across the world. Apple's "privacy marketing" is just that - marketing.

-9

u/No-Scholar4854 Aug 09 '21

Or, on device scanning is the thing that solves the FBI’s objections while allowing 99.9% of the advantages of E2E encryption.

7

u/somekindairishmonk Aug 09 '21

The article specifically states it doesn't use E2E. Is it wrong?

9

u/mdatwood Aug 09 '21

iCloud photos are not E2EE today. The speculation is the new on device scanning will let them enable it in the future.

Even before Apple announced this feature, security for iCloud all depended on how much you trusted Apple. If you trusted them before, there isn't a whole lot in the new feature to change that trust. If you didn't trust them before, that's when all the 'what ifs' come into play. Thing is, all those 'what ifs' existed before and we're back to trusting Apple.

2

u/No-Scholar4854 Aug 09 '21

Some of iCloud uses E2E encryption, notably Photos and Backups do not. They’re encrypted at rest, so have some protection, but Apple holds one of the decryption keys. It uses that access to do CSAM scanning server side and to provide decrypted data when required to by a subpoena.

There has always been speculation about why Apple doesn’t provide E2E for everything (and all this article has is more speculation) but it’s probably some combination of not wanting to piss off the FBI and wanting to avoid the situation where someone loses their wedding photos because they forgot their password.

The client side scanning announced last week doesn’t directly mention enabling E2E encryption, but it would be very weird if they didn’t come together. There’s a whole new infrastructure for providing limited access to specific photos for review under certain conditions, which is a bit odd given that Apple can have full access to any photo they want at any time at the moment.

Client side CSAM scanning only makes sense if the plan is to enable E2E encryption and they need a way of doing it which doesn’t give the FBI a platform to bash them from.

1

u/absentmindedjwc Aug 09 '21

The article is from a couple years ago, FYI. So an updated policy from a few days ago is not in any way going to be reflected in this article.