[HN Gopher] NCSC, GCHQ, UK Gov't expunge advice to "use Apple en...
___________________________________________________________________
NCSC, GCHQ, UK Gov't expunge advice to "use Apple encryption"
Author : jjgreen
Score : 159 points
Date : 2025-03-05 19:34 UTC (3 hours ago)
(HTM) web link (alecmuffett.com)
(TXT) w3m dump (alecmuffett.com)
| martinsnow wrote:
| Did the site get hugged to death?
| dizhn wrote:
| works fine for me
| marcellus23 wrote:
| not working for me.
|
| edit: it did load eventually after waiting for a minute or
| two
| bigfatkitten wrote:
| Yes. Here's the substance of the post:
|
| https://archive.is/YZF6r
| martinsnow wrote:
| Thank you
| dang wrote:
| I've made a (shortened) copy of your comment and pinned it to
| the top of the thread. I hope that's ok with you! I just
| thought it's only fair for you to get the karma.
|
| (If not, let me know and I'll undo.)
| bigfatkitten wrote:
| It was fine, but I inadvertently deleted it before I saw
| your comment. I saw it in my comment history and thought I
| double-posted!
| dang wrote:
| Ha! I guess I'll make a new one. Sorry for the
| confusion...
| sarcasticfish wrote:
| Could someone that understands more than a third of what was
| written explain what's going on?
| nickthegreek wrote:
| Uk Govt wanted Apple to give them backdoor keys to all
| accounts. Not even just UK accounts, all accounts. Apple said
| no and said they will remove encryption from iCloud for UK
| users. Apple then sued UK govt to try and get the whole thing
| stopped so that they dont need to remove the encryption from
| UK. But some parts of the govt were telling other parts to use
| some of the encryption features.
| Hizonner wrote:
| One part of the UK government is trying to force Apple to
| introduce back doors in cloud data encryption. The back doors
| are intended for UK government access to user data. This
| undermines the whole feature. Meanwhile, other parts of the UK
| government have been encouraging at-risk people to use the same
| feature, including to hide information from hostile _foreign_
| governments. The UK government as a whole has apparently
| realized that this is embarrassing and taken down the advice.
| dingdingdang wrote:
| Surely Apple's lawyers can use this information in court -
| the fact that the government itself is relying on, and
| recommending, citizens and (presumably) intelligence assets
| to use Apple's encryption technology abroad makes it VERY
| clear that outlawing said technology will systematically
| weaken ALL UK information infrastructure and make it 110%
| easier for foreign powers to exploit and sabotage the UK as
| whole.
|
| edit: removed political quip since, as evidenced by sub-
| comments, it too easily derails from the primary discussion
| point, excuse-moi.
| miohtama wrote:
| Apple is not planning to fight for the UK citizens over
| encryption.
|
| It's a job for the democracy and voters.
| Hizonner wrote:
| Well, the rumor is that Apple has secretly appealed the
| order (which is officially secret) to whatever secret
| tribunal reviews such secret orders to create secret
| features giving secret government investigations access
| to various people's secrets. The Court of the Star
| Chamber, I think it's called.
|
| Which is at least Apple doing something vaguely like
| fighting. But, yeah, UK citizens might want to think hard
| about doing something about the situation themselves. For
| one thing, Apple will probably lose. And the US
| government isn't going to have Apple's back against the
| UK, either.
| jen20 wrote:
| If you think Reform are likely to be in favour of anything
| other than the most authoritarian implantation of whatever
| law enforcement suggests they want, I don't think you've
| been paying attention to who Reform are.
| danparsonson wrote:
| > Do we really need Reform in power for common sense to
| flourish in the UK to any degree?!
|
| No. You've mistaken demagoguery for common sense I'm
| afraid. That's one of their favourite tricks though, so you
| could be forgiven for the mistake.
| HPsquared wrote:
| Notice which side wins out.
| dark-star wrote:
| As I understand it (which might be incorrect), they don't want
| to tell people "use Apple encryption" anymore and e silently
| removed that advice from their websites. Probably due to the
| fact that they didn't get their Backdoor access to user data,
| so now they want people to just now encrypt stuff
| ohgr wrote:
| Wankers! Sorry that's not constructive. But that's what they are.
|
| Especially when government ministers regularly accidentally
| delete everything and get away with it...
| gred wrote:
| Muppets!
|
| (As an American, I love UK slang. It's both familiar and exotic
| at the same time.)
| petecooper wrote:
| >I love UK slang
|
| I recommend checking your preferred book source for Roger's
| Profanisaurus:
|
| https://en.wikipedia.org/wiki/Roger%27s_Profanisaurus
| bigyabai wrote:
| Fights like this only legitimize the EU's DSA to me. UK users
| would not be beholden to Apple for E2EE if their clients had
| legitimate alternatives to the first-party iCloud service. There
| would be no world where Apple could even threaten to disable it.
|
| Break the walled garden down, and all of the sudden it doesn't
| matter what Apple's stance on E2EE is. But Apple wouldn't want
| that, since then you might realize they aren't the sole arbiters
| of online privacy.
| nkellenicki wrote:
| I'm all for the DSA as well, but this argument doesn't hold
| water. Any sufficiently large cloud provider alternative (ie.
| Google, Microsoft, etc) would likely be the target of similar
| government instructions. In fact, I bet they already are - they
| just can't talk about it.
|
| And of course, it's already possible to disable iCloud backups
| and use a smaller provider or host your own alternatives. I
| already do, through Nextcloud, etc. It's not as fully
| integrated of course, but you bet that if it was, then the
| largest alternatives would be targeted all the same.
| petedoyle wrote:
| If Apple were to add new APIs, it might be possible to use
| personal cloud storage (NAS, Decentralized Web Nodes, etc.)
| with the same UX as iCloud with E2EE.
| zimpenfish wrote:
| > it might be possible to use personal cloud storage [...]
| with E2EE
|
| Which would quickly become illegal if UKGOV is set on
| getting access to people's iOS backups / cloud storage /
| etc. Hell, it's already a legal requirement to hand over
| your keys if UKGOV demands them[0].
|
| [0] "Regulation of Investigatory Powers Act 2000 part III
| (RIPA 3) gives the UK power to authorities to compel the
| disclosure of encryption keys or decryption of encrypted
| data by way of a Section 49 Notice." https://wiki.openright
| sgroup.org/wiki/Regulation_of_Investig...
| doublerabbit wrote:
| I would be less pissed with this if the UK actually kept
| the data to the UK.
| timewizard wrote:
| You'd be fine with _domestic surveillance_ as long as
| it's kept within country? The average jurisprudence of a
| UK citizen is mind blowing to me.
| alecmuffett wrote:
| OP here. I am sympathetic, really I am, but the challenge then
| is a diversity of solutions tends to lack really good high
| quality security systems integration, meaning that data leaks
| differently. It's hard to have a high integrity solution which
| is an open standard and implemented equally well by all
| players.
| bigyabai wrote:
| I would rather that Apple invests in solving hard problems.
| Spending that money on legal representation only kicks the
| can down the road.
| alecmuffett wrote:
| One of the hardest problems you can face is getting a
| community of disparate developers to do the right thing at
| scale; sometimes the easiest solution for that is a
| monolithic integrated blob.
| bigyabai wrote:
| I agree, that's why I applaud smart regulation. Apple is
| a disparate business too, you have no way to bring them
| to the table for doing "the right thing" unless there's
| some threat of repercussions.
|
| It's really easy for Apple to back themselves into a
| vulnerable corner with the "ecosystem" mentality drawn
| out to it's logical extremes. I'd argue it's our
| democratic duty to stop businesses from endangering their
| customers like that, but that really depends on how you
| feel about consumer protections.
| easytiger wrote:
| The EU and the EUC are not your friend when it comes to privacy
|
| https://home-affairs.ec.europa.eu/networks/high-level-group-...
| bigyabai wrote:
| Nor is the jurisdiction Apple is headquartered in:
| https://arstechnica.com/tech-policy/2023/12/apple-admits-
| to-...
|
| It feels like a moot point, to me.
| easytiger wrote:
| How is an exploration of broad spectrum legislative attacks
| on all forms of encryption regardless of hosting and
| corporate ownership and data communication moot?
| freehorse wrote:
| > There would be no world where Apple could even threaten to
| disable it.
|
| They did not "threaten to disable it" and apple's stance on
| E2EE is not the issue here, UK's stance is. UK essentially made
| icloud E2EE by demanding apple to make a global backdoor into
| it, and essentially thus forced them to disable it. It is not
| disabled anywhere else in the world.
|
| Essentially the UK (and other states) want somehow to have
| their pie and eat it too, but that's just not possible.
| doublerabbit wrote:
| If UK is already doing this, then what's them from banning
| all new iPhones? Some countries do.
| mikestew wrote:
| _then what 's them from banning all new iPhones?_
|
| The torches and pitchforks that are soon to follow? You
| might get away with that in oppressive "some countries",
| but I just can't imagine it ending well in someplace like
| the UK.
| ziddoap wrote:
| > _UK users would not be beholden to Apple for E2EE if their
| clients had legitimate alternatives to the first-party iCloud
| service._
|
| Any sufficiently popular alternative would be subject to the
| same issue: you can't backdoor encryption without making it
| insecure.
|
| > _There would be no world where Apple could even threaten to
| disable it._
|
| Your framing of this seems to blame Apple, and I don't
| understand why.
| jeroenhd wrote:
| The UK demands a backdoor in the backups, so having an
| alternative backup app isn't the solution here. All the
| alternatives would just get forced into also adding backdoors,
| or everyone working for the companies that provide alternatives
| find themselves unable to ever enter the UK again.
|
| That said, I do wish there were more backup solutions for
| mobile platforms. Android has an API for this, but it's only
| available to software signed with manufacturer keys. LineageOS
| and various other custom ROMs use this to allow Seedvault
| backups, but as a stock Android user I can only pick between
| Google backups and no backups.
|
| On the other hand, these backups do contain material you don't
| necessarily want random apps to have access to. Seeing how
| powerful stalkerware/"parental control" already is on Android,
| I recognise that there are dangers that the general population
| might not realise. Adding additional warnings and messages
| about backups (even when the backups are made using
| manufacturer software) would probably strike a balance, though.
| mig39 wrote:
| Man, you know you're the baddies when you have to have "secret
| courts."
| ndegruchy wrote:
| Didn't realize he was _also_ talking about the US secret
| courts. Sorry.
|
| Uh...[1] yeah. Secret courts are the worst! Those British and
| their secrets!
|
| [1]:
| https://en.wikipedia.org/wiki/United_States_Foreign_Intellig...
| mig39 wrote:
| Like I said, you know you're the baddies when you have to use
| "secret courts."
| abtinf wrote:
| A charge of hypocrisy necessarily implies you agree with the
| principle.
| ndegruchy wrote:
| I don't. I was merely pointing out the hypocrisy, not
| understanding that he meant it as a blanket statement for
| both/all countries with secret courts.
| mig39 wrote:
| I'm not American. But if my country had (or has) secret
| courts, I'd think they were evil too.
| crimsoneer wrote:
| ... this is very silly. Sometimes the government needs to have
| secret stuff, and that needs an oversight body... _and they
| need to see the secret stuff_
| timewizard wrote:
| The oversight body is the legislature. The judiciary has no
| ability to provide oversight. The judiciary cannot act on
| it's own. It cannot conduct investigations. It can only act
| on cases and motions within those cases. The two ideas you've
| presented do not have anything to do with eachother.
| paulddraper wrote:
| Specific details, sure.
|
| Locations of military assets, passcodes, officials' personal
| details, etc.
|
| _But you cannot have a democracy without the people knowing
| what their government is doing._
| ChrisArchitect wrote:
| Related:
|
| _Apple takes UK to court over 'backdoor' order_
|
| https://news.ycombinator.com/item?id=43270079
| rvz wrote:
| Why would you want to live in the UK, especially under this
| government?
|
| Unless you want to enjoy a full surveillance state close to
| China?
|
| Even if you are running away from the US, you should just ignore
| the UK as a destination at this point.
| ajsnigrutin wrote:
| Most people were born there and have nowhere to go.
|
| The problem is, that it's spreading... EU already wants "AI" to
| read our private messages, US and it's patriot act was not much
| better (+ everything within wikileaks), etc.
| bigfatkitten wrote:
| https://archive.is/YZF6r
| cs02rm0 wrote:
| _So the question in my mind is: is the UK Government attempting
| to cover-up its previous advocacy of ADP, by censoring this old
| document?_
|
| In a word, yes.
|
| I'd be fascinated to know who in the hive mind decided to do it
| though; I can't see someone too senior coming up with an http
| redirect as the answer. I guess the scrub order came down the
| chain and an automaton jumped into action.
| mike-the-mikado wrote:
| Perhaps they know that ADP security is broken. That would
| justify both changing the recommendation and asking to read it.
| st3fan wrote:
| Lock Down Mode is for when you think your phone is compromised.
| Not for enhanced encryption or even day to day use.
___________________________________________________________________
(page generated 2025-03-05 23:00 UTC)