This is not good: Apple ordered to open encrypted user accounts globally to UK spying. The secret order would give the UK access to encrypted backups belonging to any user — not just Brits.

https://www.theverge.com/news/608145/apple-uk-icloud-encrypted-backups-spying-snoopers-charter

Apple ordered to open encrypted user accounts globally to UK spying

The secret order would give the UK access to encrypted backups belonging to any user — not just Brits.

The Verge

@ayoub well, #Apple is nit just able but willing to implement #Govware #Backdoors for over a decade.

The sheer ability is worrying enough!!!

How Tim Cook Surrendered Apple to the Chinese Government

YouTube
@ayoub
Just a reminder that UK’s Investigatory Powers Act of 2016, also known as the Snoopers’ Charter, was opposed by all #SNP MPs but not by Labour MPs in Westminster. Even back in 2016, before Starmer took them far right, Labour voting aligned with Tory values.
@paulb3017 @ayoub Labour under Blair was quite keen on a lot of this shit.
@paulb3017 @ayoub
That sort of authoritarianism is very Labour. Blair and Blunket will approve.

@ayoub so much for everyone who believes in corporate-guarded encryption.

I prefer it when they are explicit about having all the master keys and backdoors they need, ever, like in this case.

@ayoub Presumably not if you encrypt on client side (e.g. with rclone's crypt option, although I'm not sure how nicely rclone plays with iCloud) and don't tell Apple the private key it wouldn't. Of course, that would mean you'd have to find a separate way to back up the private key.
@only_ohm @ayoub under RIP act I think it's still true that you'll go to prison if you don't hand over the key — or if you lose it…

@ayoub

I wonder what law is being used here? The GDPR should regulate this kind of access to only those 'with a need to know' i.e. no fishing expeditions, only targeted access via a court order based on evidence of illegal activity. Is this fake news?

@russellt @ayoub Investigatory Powers Act, a.k.a. Snoopers' Charter. Not fake. It has been brewing for years.
https://en.m.wikipedia.org/wiki/Investigatory_Powers_Act_2016
Investigatory Powers Act 2016 - Wikipedia

@emilion @russellt @ayoub

Of course. If any entity (e.g. Apple) collects your data, even encrypted, at some stage govts will demand access as a matter of 'national security' - best not to let them collect the data in the first place.

@ayoub

Since when has Apple ‘obeyed’ orders? 👀

@ayoub
The only good cryptography is libre software cyptography.

Privacy in Apple devices is not privacy, it's bullshit. I would rather trust an XOR one-time-pad programmed in Excell by a mentally-disabled 12-year-old over anything purported by engineers in Silicon Valley. This is not a joke, it's a factual statement.

@isacdaavid @ayoub ok, wtf.

Can you not used disabled children as an insult? What the hell.

@ayoub @ajlanes What’s this ssh command on my machine…
@ayoub @ajlanes Fuck ‘em. Just ignore it and make the Government make it public that they are trying to do it!

@ayoub MS, Apple, Bezos, Google. They are all in this #clubofoligarchs
What did you expect? That they would do nothing for their share , their piece of the cake, in this digital warfare?
Just imagine the worst *you* could do taking uninhibitedly advantage of the synergistic control of digital infrastructures.

Really hope being delusional. But my guess it's only the beginning.
Just watch what happens to the (former) superpower USA right now.

@ayoub i doubt apple will comply. they sued the FBI for something similar

@jakeyounglol @ayoub

Back when laws and procedures actually meant something?

@ayoub Go to hell UK. Apple should just turn off iCloud for all of the UK users. FAFO.
@T2R @ayoub *cries in 'jfc I'm so fucking tired already and apple shit makes my long covid brain njust about maybe functional sometimes'*

@ayoub @HarriettMB
“ Apple’s iCloud backups aren’t encrypted by default, but the Advanced Data Protection option was added in 2022, and must be enabled manually. It uses end-to-end encryption so that not even Apple can access encrypted files. In response to the order, Apple is expected to simply stop offering Advanced Data Protection in the UK”

Or just don’t trust any cloud storage…

@ayoub @WilliamNB Politicians should never be entrusted with making policy on tech. They don't understand any of it.

Which makes you wonder what do they understand.

@ayoub I hope they refuse.

BTW, this article says that iCloud backups aren’t encrypted unless ADP is turned on. That’s not correct. They are encrypted, though Apple has a key which can be accessed in case of court order or similar. My source for this assertion is: https://support.apple.com/en-us/102651

iCloud data security overview - Apple Support

iCloud uses strong security methods, employs strict policies to protect your information, and leads the industry in using privacy-preserving security technologies like end-to-end encryption for your data.

Apple Support

@fivetonsflax @ayoub yes you need to turn it on, and critically what most people miss is that messages within the backups aren’t e2e encrypted unless advanced data protection is on.

This js how all those court cases leak messages, because one of the recipients often does not have this enabled (or is using SMS! Or RCS which are not yet encrypted at all on Apple OS’.

@ayoub Rather, the order would give access to any attacker who can find a way into the back door Apple must provide to the UK. We already saw that Chinese hackers penetrated CALEA.
@ayoub @CCC ich glaube das ist was für euch!

@ayoub

F*ck.

Ah well, at least I don’t back up to the cloud. (And yes, I keep an eye on my apps.)

@ayoub With any luck Apple will just stop selling iPhones in the UK... 😀

@ayoub I have a simple program named evdisk that uses the loopback device to mount (and create) a LUKS file system. The LUKS key is GPG encrypted and stored in a directory along with a large file that contains the file system. It is Linux specific so someone would have to port it to other operating systems. I use it to put encrypted backups on a flash drive I keep with my house keys.

You can find the source code on github - https://github.com/BillZaumen/evdisk

GitHub - BillZaumen/evdisk: Utility for managing an encrypted file system mounted using a loopback device

Utility for managing an encrypted file system mounted using a loopback device - BillZaumen/evdisk

GitHub
@ayoub if Apple truly cared about privacy, they’d make replacing functions which rely on their cloud infrastructure with self hosted variants as a first class function.
@ayoub I think what people are missing here is that this is probably being driven by CIA/NSA. Five Eyes end run on spying laws is to have one of the other partners do the snooping on their nationals and provide the data.
@ayoub The exact same thing is happening in France. The Senate has just passed an amendment asking developers to leave a "backdoor" so that investigators can gain "readable" access to encrypted content as part of a bill to combat drug trafficking.