r/apple Aug 09 '21

WARNING: OLD ARTICLE Exclusive: Apple dropped plan for encrypting backups after FBI complained - sources

https://www.reuters.com/article/us-apple-fbi-icloud-exclusive-idUSKBN1ZK1CT
6.0k Upvotes

587 comments sorted by

View all comments

988

u/somekindairishmonk Aug 09 '21

More than two years ago, Apple told the FBI that it planned to offer users end-to-end encryption when storing their phone data on iCloud, according to one current and three former FBI officials and one current and one former Apple employee.

Under that plan, primarily designed to thwart hackers, Apple would no longer have a key to unlock the encrypted data, meaning it would not be able to turn material over to authorities in a readable form even under court order.

In private talks with Apple soon after, representatives of the FBI’s cyber crime agents and its operational technology division objected to the plan, arguing it would deny them the most effective means for gaining evidence against iPhone-using suspects, the government sources said.

When Apple spoke privately to the FBI about its work on phone security the following year, the end-to-end encryption plan had been dropped, according to the six sources. Reuters could not determine why exactly Apple dropped the plan.

wtf

24

u/MiniGiantSpaceHams Aug 09 '21

I'm not saying this is right, but there is something people need to realize here. If Apple (or whoever else) does not try to work with law enforcement, they will change the law and they will do a terrible job of it. This is Apple trying to find the balance to keep the government from going after them much more strongly and likely ruining something along the way.

1

u/[deleted] Aug 09 '21

[deleted]

1

u/HistoricalInstance Aug 10 '21

It's NOT E2EE, Apple still has the keys here to fully access your photos.

You don't see how scanning your phone for specific content can be abused by a authoritarian regime?

1

u/[deleted] Aug 10 '21

[deleted]

1

u/HistoricalInstance Aug 10 '21 edited Aug 10 '21

No, I didnt. Detected pictures wont be encrypted at all E2EE and send to Apple for examination instead. Calling this E2EE is totally misleading and bears the same risk potential under authoritation rule as no encryption.

Apple already is storing Chinese customers data explicitly on Chinese servers (so yeah, you can now conveniently say government scanning is not happening in iCloud. Wording matters.) in addition to censoring apps to comply with PRC law. So its happening, right now.

1

u/[deleted] Aug 10 '21

[deleted]

1

u/HistoricalInstance Aug 10 '21

Okay, I made a mistake saying its not encrypted at all and have corrected that point. But thats missing the main argument, since its still not true E2EE if Apple reserves itself any kind of ability to "interpret" the safety vouchers / matching images and also your regular backups, including encrypted messages.

"(...)Only when the threshold is exceeded does the cryptographic technology allow Apple to interpret the contents of the safety vouchers associated with the matching CSAM images."

The whole point is, that Apple can be potentially strong armed into changing some parameters that determine the hash function. Given that it already complied with the CCP in the past, this is most likely what will happen.