Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I thought that stuff was all encrypted, and Apple couldn't see it?


It is encrypted (except email) but Apple has the keys for the stuff I listed: https://support.apple.com/en-gb/HT202303

Also, in China Apple handed over iCloud operations to a government owned company, including the keys.


I don’t see Apple having access to keys there. Could you point it out? CTRL+F for “key” came up with 7 results but nothing to suggest Apple holds them and can decrypt. Apologies.


There's a section about half way down that lists all end-to-end encrypted data (keychain, health, payment data, ...).

By implication, all other data is not end-to-end encrypted. That includes iCloud drive, photos, calendar, contacts and mail.


Also one big deal is how Apple handles key distribution. They absolutely could MitM that connection to get access to the user's keychain and the UI doesn't really give the user any feasible way to detect that Apple has added their own key instead of just the key for your other device that Apple doesn't control. It's "end to end encrypted" but if you just handwave away key distribution and leave that up to Apple, what's the point other than a marketing gimmick?


Are we reading the same support article? https://support.apple.com/en-gb/HT202303

Specifically listed as encrypted in transit and on server:

- iCloud Drive

- Photos

- Calendar

- Contacts

Only mail is not according to this support article.

Edit: I see the omission now. These things are not listed under the end-to-end section.


Yes, exactly, so that data is encrypted on the server using a key that is in Apple's possession.


It _is_ encrypted, Apple cannot see it. The parent comment is mistaken


I'm afraid you are mistaken: https://support.apple.com/en-gb/HT202303


Reading that article, the confusion is easy to explain and looks intentional.

It reads "For certain sensitive information, Apple uses end-to-end encryption. This means that only you can access your information" and then immediate shows a giant table of data that is NOT end-to-end encrypted, but not labelled as such -- it's only inferrable by its omissions from the next section of the document.


I agree. It doesn't look like Apple was particularly keen on letting people know that they can actually read most data that people consider private.


>Apple cannot see it.

How can you be sure? End to end encryption is not a guarantee when you're inputting your key into a closed source client to store and retrieve the data.


Especially given that key distribution is totally up to Apple and the end user has no practical way to verify that the key for "My iMac" is really the same key that's actually used by your iMac.


Yea, it's interesting how many comments are flat out wrong

or can't seem to differentiate between what Google does now ...vs what might happen with Apple in the future.


If you think that I am flat out wrong then please provide evidence. In this particular case it is you and Dig1t who are flat out wrong if you claim that Apple cannot see the iCloud data I specifically listed.

Also, I didn't say anything about what Apple might or might not do in the future. I made a distinction between worries about ad targeting and security issues that come with storing data in the cloud without end-to-end encryption.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: