egorfine
3 days ago
I genuinely believe that in 2015 Apple had the balls to resist and today they don't.
I am judging by a simple fact, that "please confirm your age" screen is now mandatory during the iPhone setup in all countries, and in some it's behind a KYC. I have a strong opinion that this is insane. And once they let the foot in the door - there is no closing it.
microtonal
2 days ago
Even in 2015 Apple put in backdoors. They have been really good at making people believe things that are not true. E.g. from the linked post:
iCloud already protects sensitive categories of data (like Passwords, Health data, Messages in iCloud, etc) with end-to-end encryption by default.
Except that there is a footnote in Apple's security document where they confirm that Messages in iCloud is not end-to-end encrypted if you don't enable ADP and have iCloud Backup enabled (which is probably most users):
Standard data protection: When iCloud Backup is enabled, the keys to your backups are secured in Apple data centers. If you use both iCloud Backup and Messages in iCloud, your backup includes a copy of the Messages in iCloud encryption key to help you recover your data.
https://support.apple.com/en-us/102651
So, there is always a backup of Messages in iCloud accessible to Apple and thus (US?) law enforcement, unless you enable ADP and the people you communicate with also use ADP.
WhatsApp is similar by the way. Unless you enable E2E backups, they end up in iCloud/Google Drive backups and are only encrypted at rest. Of the major messengers, I think only Signal completely opts out of iCloud backups and have their own real E2E-encrypted backups.
Even most technical people I talk to do not know this and don't have ADP enabled.
There are a lot of weak defaults like that.
kyralis
2 days ago
The original implementation of iCloud included Apple's ability to recover the data. You can view this as a backdoor, and that might be fair, but the reality is that it's also a feature in the eyes of many customers - because people will lose devices and passwords, and when Apple doesn't have the keys that means they also lose data. Many customers would rather be able to get their data back.
Apple has moved more things into the bucket of "we do not have the keys for this" over time, but pretending that this isn't a tradeoff for the common customer is disingenuous. That's why ADP exists, so that those who want to make a different tradeoff can do so.
Commenters on HN tend to be technically savvy and tend to want the defaults to be tailored to a technically savvy customer base. That's fine, but that's not a real representation of all of the smartphone users out there, and in this case Apple is directly offering the choice that they usually get knocked for taking away.
wolvoleo
2 days ago
Except they don't really. If you're in a convo there only needs to be one user who doesn't have ADP turned on and uses iCloud. And all your data is leaked.
It should be possible to force your messages to be excluded from backup even by recipients. Otherwise it's just for show when it comes to real life.
vladvasiliu
2 days ago
> And all your data is leaked.
Not all your data, just the data exchanged with that person.
But how could you force this? They could always copy it or whatever. Yes, I know, defaults.
But this would then need to be somehow enforced on the other side, right? Like preventing copying, or screenshotting, etc. And in that case, see the HN thread the other day about applications messing with these functions and how people want their devices to be theirs and not controlled by some third party.
basilikum
2 days ago
> Yes, I know, defaults.
You gave the answer yourself. If the person you are writing with has E2EE enabled for message backups then just exclude that chat from backups on your end or enable E2EE for that chat. That means if you take the restore route without having access to the keys that conversation will not be restored.
You could even let people overwrite that setting. Preventing screenshots or copying has nothing to with this. Apple is claiming that message are end to end encrypted when in reality their defaults are set so that they are not. That is a lie and al they would need to do to change that is to change those defaults.
danhor
2 days ago
> WhatsApp is similar by the way. Unless you enable E2E backups, they end up in iCloud/Google Drive backups and are only encrypted at rest
One of the few good things about WhatsApp is that Meta can very credibly claim that they can't access the backups (as they're not stored by Meta). Meta holds the encryption key & Google/Apple hold the backups, so at least you now have deal with two entities to get the data.
I don't think without forcing more customers to loose data (e.g. by requiring them keeping an encryption pin/key) it's possible to perform backups in a (much) better way.
dns_snek
2 days ago
> I don't think without forcing more customers to loose data (e.g. by requiring them keeping an encryption pin/key) it's possible to perform backups in a (much) better way.
I have full confidence that the industry would be quick to innovate if they were forced to, but that's not in their interest nor the government's interest.
Here's a simple one: Build an open standards-based system where users choose their backup provider and let them decide whether they prefer to have full control over the encryption keys or whether they want them to be managed by a third party. Educate them so that they can at least try to make an informed decision. Warn them about the risks and jurisdictions of built-in providers.
If someone wants to continue using their device as-is? Cool, 2 taps and they're done.
Do they want to store all of their app backups on their NAS? Make it as easy as switching your default browser.
danhor
2 days ago
> Here's a simple one: Build an open standards-based system where users choose their backup provider and let them decide whether they prefer to have full control over the encryption keys or whether they want them to be managed by a third party. Educate them so that they can at least try to make an informed decision. Warn them about the risks and jurisdictions of built-in providers.
WhatsApp performs (on Android) backups inside a normal directory. You can just backup it via e.g. Syncthing, which I've done in the past.
It doesn't get much more standards based. Strongly pushing users to deviate from the standard flow IMHO risks them quickly choosing poorer options (e.g. a free, dubious, online hoster). At least with the current setup, the "easy option" is quite safe in terms of not loosing data and very low risk that anyone apart from you and governments with lawful access ever accesses the data.
tweetle_beetle
2 days ago
I'd argue that should/could be relevant, but isn't in reality. Do two global data processors more happy to work with governments/law enforcement exist?
ipython
2 days ago
the default is weak because it's the most user-friendly option. Otherwise, you end up with edge cases where the user lost their only device, or they forgot their password, or ... the list goes on and on, and they lose all their previous chat data.
That's a very user-unfriendly place to be. Most users won't understand why their data is gone, become unhappy, and distrust their devices to safely store their data. It's not even about buying more Apple products at that point - it's just literally reinforcing the stigma that "I can't understand tech, it's too complex".
You can't be security-maxxing and user-experience-maxxing at the same time. I do like Apple's approach which at least gives you the option.
IndySun
2 days ago
>...only Signal completely opts out of iCloud...
There is an iCloud option on Signal. It's on by default - is that Apple or Signal's doing? - but yes, iCloud can be turned off and Signal have their own e2e backup, if you want to back up. Also a paid option.
sandworm101
2 days ago
The week default is having an OS owned/run/managed/backdoored by a publicly traded company. If you are using anything other than open source, anything other than linux, consider all your communications to be availible for subpeona or outright sale to whoever wants them. Signal is great, but only as good as the OS of its host.
user
2 days ago
briffle
3 days ago
They never did. they had the balls to resist against western governments, where it was politically adventagous to do so. They folded to China real quick, because they wanted to make sales. All "icloud storage" in china has been on another storage platform, that follows all the local laws.
egorfine
3 days ago
Folding before China in China is not the same as folding before totalitarian western demands.
throwawayffffas
3 days ago
Why? They only disabled ADP in the UK, how is it different?
unified101
3 days ago
It isn't.
Matl
2 days ago
Except for where Western governments pearl clutch about freedom and how free and open they are unlike big, bad China and all that.
armada651
2 days ago
Don't fall into the trap of putting our governments on the same level as China, despite the tremendous flaws and the very dangerous backsliding we still enjoy many freedoms that their citizens do not have.
The CCP would like nothing more than everyone living in a democracy saying they're just as oppressed as those living in China. Then their own citizens might abandon such foolish notions as human rights.
We should point out the hypocrisy of our governments but not by using that hypocrisy to minimize China's human rights abuses.
Matl
2 days ago
Multiple things can be true at the same time, there's more repression in China still than in the West at the moment, yes. At the same time it's all rather vague. There's more state control there and more corporate control here. So naturally there's more state repression there. There's also things that China does better than we do. It's not as clear cut as it should be.
If you look at the treatment of pro-Palestine movements in the West, Flock cameras, Palantir contracts, age verification mandates, encryption 'front door' requests, clamping down on whistleblowers etc. then it seems to me that we're heading where China is pretty fast and that the West definitely wants to be where China is, just without the high speed trains.
What I am dismayed by in discussions like this is how simplistic they are i.e. China bad, West good so don't compare.
The collective West just assisted a genocide of an occupied population of people, so when is it going to be 'as bad'? My guess is never because people here want to feel superior over China without actually doing anything for it.
I wouldn't be surprised if you tried to come up with all sorts of excuses why the West is not responsible for Israeli actions in Gaza, it's not a genocide etc. without pausing for a second to realize the Chinese also have plenty to say about what you object to them doing not being authoritarian.
lyu07282
2 days ago
I think state control is felt fundamentally differently in practice if this state control actually serves the people unlike in the west where it serves exclusively capital interests.
> What I am dismayed by in discussions like this is how simplistic they are
Once you really notice the anti-china framing literally everywhere in media, it is really hard for it all not to become meaningless propaganda. It's itself no different from state control just because it's private media because that private controls the state. We aren't allowed a clear eyed view of china, only a carefully curated antagonistic one. But they aren't our enemies at all, it's absurd how obvious that is, the west is the aggressor, not china.
parineum
2 days ago
The state is capital in China. Oppression in China serves Capital and the State because they are the same entity.
Matl
2 days ago
> they are the same entity
I am not aware of a country where that's not true to some extent. But I can't see i.e. [1] happening in the West.
1 - https://www.reuters.com/legal/transactional/china-tax-crackd...
lyu07282
2 days ago
In the west capital in the hands of unaccountable individuals acting in their own interests and the state acting in the interests of those with private capital. Capital in the hands of the chinese state is different because it serves the interests of everyone collectively. Including things the west describes as oppression, but that is a matter of perspective, it's things like this why you are conditioned to hate china:
https://en.wikipedia.org/wiki/Houses_are_for_living,_not_for...
parineum
a day ago
> Capital in the hands of the chinese state is different because it serves the interests of everyone collectively
Even the Uyghurs?
pocksuppet
2 days ago
Remember that North Koreans genuinely believe they are living in the most free country on earth.
philipallstar
2 days ago
> Western governments pearl clutch about freedom and how free and open they are
That's not how to use "pearl clutch". And the UK doesn't do that, and it isn't very free or open, except in the deranged mind of Kier Starmer[0]. Classic liberalism in the UK has long given way to regulation of speech, proud conformity, state dependency, and all the other things that are hallmarks of people who treat the state as a surrogate parent.
[0] https://uk.news.yahoo.com/starmer-defends-uk-commitment-free...
ImJamal
2 days ago
It is not like their HQ is in China. They chose to enter the Chinese market.
sneak
2 days ago
Every iPhone sold everywhere is manufactured in China. They make 34,000 iOS devices every hour, 24/7. That’s not possible anywhere else.
Apple is, from a purely practical standpoint, more a Chinese operation than an American one.
ImJamal
2 days ago
They could manufacture them in China, but not sell the phones there?
sneak
2 days ago
China is their second biggest market, I believe.
Additionally, the humans who make all of the iPhones and iPads are Chinese people, subject to Chinese law. Apple has to do exactly what the CCP wants, at least for now. They are desperately trying to ramp up phone production in India, but there is huge expertise at Foxconn that isn’t in India as yet.
ImJamal
2 days ago
If Apple did not sell iPhones to Chinese consumers the Chinese government wouldn't make Apple provide a different icloud. They made that choice, not by manufacturing in China, but by selling there.
realusername
3 days ago
The only thing where they tried to push back very hard was the EU's DMA, beyond that they folded quickly to absolutely everything else.
PorciiVorbesc
3 days ago
They pushed back on the DMA because that affects the monetisation opportunities of their walled garden ecosystem.
Any other invasive privacy/encryption interventions from the government only affects their users, not their money, so they cave without issues.
indoordin0saur
2 days ago
Wait... you mean this was all just a marketing and PR ploy?
SXX
3 days ago
Apple routinely removes VPNs and other apps from App Store in Russia even though they supposedly left the market in 2022.
They obvioualy never ever resisted anything except its a good PR stunt.
Zenul_Abidin
3 days ago
Apple doesn't KYC in Russia though
We are quickly heading to a world where governments want us to KYC everything, and we saw with the Revolut breach what happens when very, very bad people gain access to our private data.
SXX
2 days ago
Whole point is that Apple routinely execute government orders from the most repressive regime on earth after North Korea. And from bloodiest one in last two decades.
Even though they have zero presence in a country.
hn_submit
2 days ago
Apple is surely resisting, but there's a limit to how far they're willing to go. They won't risk losing the entire EU market, for example. Or the Chinese market.
The UK is a minor footnote. They can afford to lose it if push came to shove, but for now they're willing to make conciliatory gestures.
GJim
3 days ago
> "please confirm your age" screen is now mandatory during the iPhone setup in all countries
Not quite.
The request to confirm age is there, but actually completing it isn't mandatory (though granted, it does leave an 'alert' thingy on your phone settings saying you haven't finished setting it up).
EmbarrassedHelp
2 days ago
It locks down devices like ransomware, permanently restricting functionality of web browsers, messaging apps, and other apps until the user submits to age verification. Its mandatory if you want your device to function normally without restrictions.
egorfine
3 days ago
There is no "skip" button available.
throwawayffffas
3 days ago
[flagged]
user
3 days ago
MisterMunchkin
2 days ago
I never had to confirm my age because my account is old enough to prove I must be old enough
egorfine
2 days ago
Same here. Problem is, I never gave Apple permission to infer about my age. It's none of anyone's business. So when iPhone rebooted after upgrade and told me "you are old enough, I know it" I was simultaneously relieved that I won't be required to pass KYC (never an option) and furious that this shit ever came about.
benatkin
2 days ago
I doubt that with the speed of thought dramatically increasing due to AI, that the door will stay closed just because it's being closed now. That decision will be revisited.
someonebaggy
3 days ago
Is it required to KYC in those countries?
I'm generally okay with "how old are you?" without KYC and changeable later. It just allows apps and websites to display age-appropriate content.
egorfine
3 days ago
> I'm generally okay with "how old are you?"
It's a foot in the door. Once this question exists, the next logical one is "prove it".
ajsnigrutin
3 days ago
Same with digital IDs (for example the EU one), where you'll have to install it to provide a "zero knowledge" proof today, and since you already have everything in your phone, it'll be easy to implement the "real name" policy when registering/commenting/etc.
someonebaggy
3 days ago
I'm not aware of any EU project to make a smartphone literally mandatory (instead of just convenient). If they do, I'll buy a separate smartphone just to hold my ID.
ajsnigrutin
2 days ago
mitxela
2 days ago
But you don't have to use that? They still issue ID cards
ajsnigrutin
2 days ago
How will you insert your physical ID card into your computer to prove pornhub you're old enough to jerk off to porn? Or buy a dildo on amazon? Or order booze online? Or in some countries, even just order a set of kitchen knives from ikea?
mitxela
2 days ago
They already have card readers you use to scan your id on bank websites if that's what you mean
ajsnigrutin
14 hours ago
Yes, physical readers exist, how will inserting my ID card into a reader tell reddit that i'm an adult and that i can jerk off to gonewild there?
The EU digital id, ncluding the age verification part is (unless they fixed it already) limited to hardware attested, non-rooted, not-unlocked androids and apples for now. If you want to jerk off to porn, you're basically mandated to buy an american device (well, you will be, unless they fix it).
someonebaggy
3 days ago
Ok but my phone already asks me for my name, isn't that bad too?
fc417fc802
2 days ago
If you leave it blank or otherwise don't answer does it restrict your functionality?
But anyway it's not really the same thing until and unless governments start making motions to collect a legal name. And even then it still provides some general utility to the user which providing an age doesn't (unless you're setting up the device for a child ofc).
egorfine
3 days ago
Does it require you to prove your legal name?
throwawayffffas
3 days ago
Isn't that the next logical step according to your logic?
user
3 days ago
nkrisc
2 days ago
It asks for a name.
someonebaggy
2 days ago
And an age
nkrisc
2 days ago
Steam thinks I’m 126 years old.
simulator5g
2 days ago
Yes.
shuwix
2 days ago
[dead]