Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Because apple isn’t in control of apple for data at rest

That's not really true if Apple also holds copies of your iCloud decryption keys. If they want to access your data, they already have all the necessary components.



> That's not really true if Apple also holds copies of your iCloud decryption keys.

That is literally the thing that this announcement changes.

I see that Hacker News has plummeted below Reddit in the "bothering to check the link" stakes.


Now we're going in full circle, so I'll just point you to the parent thread:

> One must understand that E2EE is used when you don't trust your service provider to handle your data. In other words, the adversary in your threat model is the service provider - and in this case, Apple. And what good is that encryption, if Apple obviously can do almost anything with your device?


Ironic, since if you follow the thread you'll learn that since Apple still has complete control of your device, it essentially still has access to the keys.


Yea, thats the point.

Let me re-phrase, by giving Apple control over the keys, you give control over the data to whoever controls apple - which is non-zero (Eg. LEO), and whoever may gain control (security vuln).


I don't want Apple to give over the keys. I just want my key to be the only in existence.


Yea… that’s what they’re changing. That is the point. They’re not going to be in control over the keys - which is a good thing to you, it seems.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: