


UK Demand For a Back Door To Apple Data Threatens Americans, Lawmakers Say (msn.com) 94
Members of key congressional oversight committees wrote to the United States' new top intelligence official Thursday to warn that a British order demanding government access to Apple users' encrypted data imperils Americans. From a report: Ron Wyden, a Democrat on the Senate Intelligence Committee, and Andy Biggs, a Republican on the House Judiciary committee, wrote to just-sworn-in National Intelligence Director Tulsi Gabbard and asked her to demand the United Kingdom retract its order.
If the top U.S. ally does not back off, they said, Gabbard should consider limiting the deep intelligence sharing and cooperation on cybersecurity between the countries. The Post first reported the existence of the confidential British order last week. It directs Apple to create a back door into its Advanced Data Protection offering, which allows users to fully encrypt data from iPhones and Mac computers when putting it in Apple's iCloud storage. Apple cannot retrieve such content even when served with a court order, frustrating authorities looking for evidence of terrorism, child abuse and other serious crimes.
The order was issued under the Investigatory Powers Act, which allows the British Home Office to require technical cooperation from companies and forbids those companies from disclosing anything about the demands. It would apply globally, though the U.K. authorities would have to ask Apple for information stored by specific customers.
If the top U.S. ally does not back off, they said, Gabbard should consider limiting the deep intelligence sharing and cooperation on cybersecurity between the countries. The Post first reported the existence of the confidential British order last week. It directs Apple to create a back door into its Advanced Data Protection offering, which allows users to fully encrypt data from iPhones and Mac computers when putting it in Apple's iCloud storage. Apple cannot retrieve such content even when served with a court order, frustrating authorities looking for evidence of terrorism, child abuse and other serious crimes.
The order was issued under the Investigatory Powers Act, which allows the British Home Office to require technical cooperation from companies and forbids those companies from disclosing anything about the demands. It would apply globally, though the U.K. authorities would have to ask Apple for information stored by specific customers.
Apple PR Nightmare (Score:3)
If Apple pulls out of the UK market, that's a significant blow to their financials, but perhaps it would be a smaller blow than losing worldwide confidence in their products.
aww poor wittwe Apple-sucking baby (Score:1, Flamebait)
Did I hurt your feefees by pointing out that Apple is spying on you?
You know Apple is part of PRISM [theguardian.com] right? And that PRISM is part of what makes Five Eyes work? Apple is not just giving your data to the US, it's giving it to multiple countries.
Re: (Score:2)
UK being one of them, so I don't see the point of the UK's government request...
Re: (Score:2)
UK being one of them, so I don't see the point of the UK's government request...
I think it's theater. But an alternative is that they want earlier access to information because they don't trust the US to keep up its end of the commitment to spy on their citizens and provide them with the information.
Re: (Score:3)
Go to a physics conference sometime and see all the MacBooks around. Gee, those physicists are certainly very, very stupid.
Re: (Score:2)
I'll go one further: Intelligence in one field does not translate to any other fields.
I've puzzled over this for a long time. How can some people who seem so intelligent (in one field) be moronic in another.
I think the most egregrious example is how people use Microsoft, Apple, etc, completely trust them to keep them safe, while we now know without doubt they are the ones spying on you. There is literally no pushback. A little bit of hand wringi
Re: Apple PR Nightmare (Score:2)
I love the irony of writing a post in the style of an imbecile that accuses anyone using a particular computer to be a moron.
Bravo! Oh, wait, you were not joking. . .
Re: (Score:1)
an imbecile that accuses anyone using a particular computer to be a moron.
Crapple's marketing is specifically aimed at morons, reframing their idiotic purchase as the actions of a "creative genius". Unsurprisingly this means most Crapple users are morons.
You sound like a Crapple fan. Kudos. You're a marketing sucker. No amount of technology will fix that. Ever.
Own it. No need to get angry about it.
Re: (Score:2)
Oh look, you're doing it again. It's like I pointed out that you had mud on your face and you said, "Oh yeah!?! Well look at this!" Then you proceeded to pick up a giant pile of shit and smear it all over your ugly mug.
You're good for some laughs, if nothing else.
Re: (Score:2)
Oh look, you're doing it again.
Triggered much? Sometimes, it's best to just let go of the shovel...
Re: (Score:2)
And a when it happens to surgeons... a little scary
Re: Apple PR Nightmare (Score:2)
I see you didn't understand what I wrote at all. I was referring to buying the argument.
Cost and Compatability (Score:2)
In fact, I used to have a mac myself but when they failed to update the laptop for ~3 years and the Mac Pro for 10 years and then, the new ones lost the mags
Re: (Score:3)
Re: (Score:2)
Given the way the current system works (public & private keys) adding a backdoor is simply not possible, so they'd have to do a major refactoring of the code to use a different system to comply with the order.
This is just Apple trying to dazzle lawmakers with technobabble. The reality is, Apple already knows how to turn your user password back into your encryption key (otherwise restoring an iCloud backup to a replacement device would not be possible), and simply storing a copy of your password on Apple's servers would be an adequate "backdoor". It'd be a PR nightmare for Apple for sure, but absolutely trivial to implement.
I'm really surprised on a "News for Nerds" site there's so many people repeating the ref
Re: (Score:2)
Cryptographically you can have two master keys, so presumably Apple owns those. But that's data in the cloud, on the phone they might not even have that and if you can't get into the phone then likely Apple can't either - after all they want you to buy a new one anyway. Any criminal would be stupid to put their data in the cloud where Apple, Microsoft, and Amazon can read it just as easily as they read your company's source code.
Re: (Score:2)
If this is thwarted by the invention of a backdoor (or the public disclosure of an existing one), then it won't be long for nefarious actors to use this level of access beyond the scope of UK officials.
That doesn't necessarily follow.
You seem to be assuming that a backdoor has to be some sort of exploitable flaw, but it doesn't need to be that at all. Apple could, for example, add an API that requires cryptographic authentication using a key that only Apple has, or only the UK government has, etc. As long as that API is implemented correctly it would keep out anyone without the necessary key. Public disclosure of the API and even the details of its implementation wouldn't matter as long as the key was
Apple should not be in control of the encryption (Score:2)
Just like when the US was trying to pressure apple into giving up the keys to the kingdom for that terrorists phone. They did a mind job on the american people by somehow keeping people from asking the real question of "why is it possible for them to even give up this information". The owner of the device should be responsible for their own encryption. If you are "trusting" someone else to be in control of your encryption, then you may as well not be encrypted at all. Encryption plugins should be the paradi
Re: (Score:3)
The owner of the device should be responsible for their own encryption.
This should be at least an option. However, typical user is not capable of managing their keys and that means that recovery would not be possible. This in turn will create false perception among non-techies that encryption is dangerous for your data and will undermine the whole system. Either way, UK government wins by undermining user data encryption.
The situation with UK government has only one good solution - Apple tells them to go pound sand and Trump threatens punitive tariffs if they do anything ab
Re: (Score:1)
This in turn will create false perception among non-techies that encryption is dangerous for your data and will undermine the whole system
Isn't it already the perception of DNSSEC among techies?
Re: (Score:2)
Re: (Score:2)
Re: (Score:2)
False perception? It'll point out a real thing: when encryption is done right, nobody can access the data unless they have the key. So it's both a danger and a strength.
There's no reason to not point this out and let people learn from it.
If they think they can do things well, they have a chance at keeping
Re: (Score:2)
Multiple keys. You can put some in escrow. Or split a key into shards, print them out, put all the shards in different safes, 5 out of 8 votes can unlock the data. Having just one "the key" is simplistic, even if it's common.
So I could imagine a system where Apple says "sure, here's all the data, we've decrypted our lock on the data, now you just have to get past the remaining certs if you have those keys." Would be nice to have Apple allow changes to their system so that the user can do their own encrypti
Re: (Score:2)
We've got some industrial users who were (at least in the past) very hesitant about turning on full security. They have a fear that once the switch is flipped that they'll lose access to their own data because it's now encrypted, and there's a compex PKI set of keys and certificates and HSMs and so many other stuff that they don't understand. At the same time they have their own customers demanding that they protect data, as well as government pressure, so I presume they've bowed to the necessity by now.
Re: (Score:2)
Re: (Score:2)
Re: (Score:2)
Manually encryption could be automatic. But then it wouldn't be manual. Ugh.
The problem here is that the average user isn't a crypto expert. And the average user doesn't know how to modify their phone or add their own encryption. This is very similar to how most Linux users didn't bother with GPG (that and because it was obtuse to those unfamiliar with more modern cryptography). But it is perfectly feasable that Apple, or cloud providers, have an API where customers can plug in their own security. The
Re: (Score:2)
Re: (Score:2)
Well, I'm mostly a computer user. The phone is for games on the toilet and making phone calls :-) But yes, if you could add your own trusted apps to the phone to do this. I doubt it would ever happen with Apple, but if there's full source code for Android kernel...
You dont re-encrypt the data in the stream, you encrypt once on your end, then whatever the stream does with it is its own business (if it wastes time doing more encryption then so be it). The "traffic" thus is never plaintext, ever. You sourc
Re: (Score:2)
If we're talking about using a different cloud storage service, the question is moot. They don't seem to be asking DropBox to unlock anything.
Managed decline (Score:5, Insightful)
Re: (Score:1)
Just like Putin plans for all western nations, including the US. In fact, everything you wrote could be applied to the US. Doesn't mean the predictions are true, it's more suggestive that you've either been convinced of Putin's propaganda or you work on behalf of his interests.
Re: (Score:1)
For anyone interested in watching this unfold - UK is what managed decline looks like in practice. Your country gets poorer, your national identity is forgotten, your individual rights are eroded. The next step isn't trans-national cosmopolitan population but sectarian violence and fracturing of your country into multiple smaller states. On the current trajectory there won't be United Kingdom in 10 years, but there will be England, Wales, Scotland, etc. and they all will be much, much poorer and even less influential on the world stage.
Managed decline? Us folks across the pond are asking ya ta hold our beer, bud. We're gonna show ya how to accelerate that decline.
Re: (Score:1)
Some of the regions could be better off as independents. Scotland could get back into the EU, from which it would benefit greatly, for example.
The UK should have broken up long ago. It was only held together by the Empire and former glory, and then later by the EU doing its best to make sure that the regions were not neglected. Now that it's just English politics running everything, conditions for the other countries have deteriorated. There is a slight exception in Northern Ireland, but only because their
Scotland is bankrupt (Score:3, Informative)
Its economy is only afloat because of what the English taxpayer gives it. If it was independent it would need to go to the IMF immediately.
https://www.ft.com/content/ff6... [ft.com]
It would inherit its share of the UK's national debt, denominated in a foreign currency - the pound.
It would not be eligible to join the Euro because its indebtness would be too great.
Re: (Score:3)
If Scotland did become independent then the currency would be a matter of negotiation. Chances are they would continue to use the pound for a while, which would make the rest of the UK somewhat reluctant to see their economy tank. There would probably be a transition period until they could adopt the Euro.
As for how much debt they would inherit, that's another thing to be negotiated. As a part of the EU though their economy would do fine, especially with all that renewable energy they have. Remember that th
Re: (Score:1)
Chances are they would continue to use the pound for a while
OK - so what happens is that the banks stop lending north of the border except with a significantly higher interest because there is a very high chance of de facto devaluation of the currency once it is detached from the rUK pound. So people will keep their money in banks guaranteed by the Bank of England, which will remain the central bank, but no company will invest in Scotland; too much uncertainty.
which would make the rest of the UK somewhat reluctant to see their economy tank.
But only a little bit, and the cost of propping up a bankrupt government will be too much. The Scottish eco
Re: (Score:3)
The currency wouldn't be devalued. It would be sterling until the join the Euro.
Currency 'devaluation' (Score:2, Informative)
The trading deficit means that money would leave the economy rapidly and interest rates would rise. The government would have to cut imports massively, face a severe fiscal and economic crisis, or change currency, and not to the Euro. 'Devalue' might be the wrong word, but the effect would be the same. The breakdown of currency unions is a nasty experience for those caught up the events when it is done in a crisis.
Re: (Score:2)
That all seems extremely unlikely.
Re: (Score:3)
"The UK should have broken up long ago. It was only held together by the Empire and former glory"
I suggest you go learn some history. The United Kingdom came to pass in 1603, long before any British empire, when the SCOTTISH king James I was crowned king of england too. And Wales had been under english rule since the 12th century.
"Now that it's just English politics running everything"
Really? So the devolved governments do nothing and have no powers?
Stick to BS'ing about your own country, not ours which you
Re: (Score:3)
Not so. The kingdoms of Scotland and England were ruled in personal union for a century before the United Kingdom came to pass in 1707 with the Act of Union under Queen Anne. It took almost another century before Ireland became part of the United Kingdom rather than being ruled in personal union.
Re: (Score:2)
Fine, but the act of union simply formalised what had been the de facto situation for the previous 100 years under more or less absolute monarchs until the civil war. After that Cromwell created the - albeit short lived - commonwealth of england and scotland which pretty much demonstrates the point.
Re: (Score:2)
Some of the regions could be better off as independents. Scotland could get back into the EU
Could it though? From a techincal perspective nation forming is hard, and you need recognition as a nation. And there are a few EU countries which have a REALLY STRONG vested interest in making it a truly terrible idea to break away from the country you're currently part of.
If Scotland gets independence and is then utterly fucked over, this puts pressure on the Basque region to not leave, for example and there are ot
Re: (Score:2)
Spain would be fine with it, as long as it happens through legal means. Their issue with their break away wannabe state is that they keep refusing to offer any legal path to that, which has lead to non-legal means being employed.
Unless something incredible happens then I think independence is inevitable, as it's the decline of the UK. We are locked into it pretty tightly now, and it's looking more like it could get worse, rather than better.
Re: (Score:2)
Spain don't generally speaking want the basque region to break away via legal means either.
I think independence is likely too, but I think the feeling that Scotland would be welcomed with open arms by people who don't eat to encourage their own independence movements is dangerously naive.
Re: (Score:2)
What I mean is that Spain won't mind Scotland joining the EU if it is through a legal route, because they can simply deny the Basque region such an opportunity.
It might have a small effect where it convinces a few more people that if they did break away the EU would take them, but realistically with the polling as it is and the long road to a legal vote, it's not a big concern.
They could also do what we should have done and agree to negotiate with the EU before actually leaving, not setting up a deadline or
Re: (Score:2)
Well it's tricky: if enough people want it via legal means it gets politically tricky to ignore self determination. Much easier if you can make people a bit less keen by showing what happens if you leave.
Different circumstances, reasons and treaties, but wow did Brexit dampen enthusiasms for leaving the EU, when people saw what the consequences were. That had not gone unnoticed.
But yes, Scotland world need to negotiate first. The trouble is that could also load to a long to indefinite period of uncertainty.
Re: (Score:2)
And there are a few EU countries which have a REALLY STRONG vested interest in making it a truly terrible idea to break away from the country you're currently part of.
Surely Czechia, Slovakia, Slovenia, and Croatia would all count as fairly recently having broken away from the country they were part of?
Re: (Score:2)
Great job brexit and you're also describing the USA.
Why is this modded up? (Score:3)
The whole of europe is in managed decline pal. Check out the German and French economies at the moment which are in the toilet - the latter currently having a debt of 110% of GDP! As for southern europe , oh dear. The only country in the EU thats doing well is Poland ironically.
Re: (Score:2)
Re: Managed decline (Score:2)
Technically, England, Wales, and Scotland are their own countries already.
Re: (Score:3)
Managed decline is preferable to unmitigated disaster, which is what we're headed for here on the left side of the Atlantic.
Re: (Score:2)
Re: (Score:2)
I never said those were the only two options in the entire set.
I inferred those are the only two options available to us without a political sea change, and we're still a good 23 months from that being a possibility.
Re: Managed decline (Score:3)
Re: (Score:1)
Re: (Score:3)
This doesn't sound like UK, except manybe in the minds of a far right Merka First type. UK still protect rights of individuals, it's national identity is still very strong. You should be far more concerned about the rapid decline in America from the last few weeks as we spiral into unchecked autocracy, it will collapse before the UK does.
Excellent Idea (Score:5, Funny)
I'm all for backdoors into software.
Best regards
Vlad
Typo in the description (Score:3, Insightful)
There, I fixed it for you.
Reasonable chance of success (Score:2)
The action being proposed by the committee members is quite likely to work. The UK government is keen to build bridges with Washington right now, and has worked pretty hard at doing so. They'll be quite responsive to this kind of political pressure.
imperiling Americans is the US Govt's job (Score:3, Insightful)
The real concern is that the American people learn that Apple grants access to the same backdoor built in for the US government.
National Security vs Private Sector Security (Score:2)
National Security vs Private Sector Security
To want one, but not the other is literally insane.
really ? (Score:2)
frustrating authorities looking for evidence of terrorism, child abuse and other serious crimes.
Because we all know that those are absolutely the only issues that they would ever dream of seing as a reason to sift through our personal information.
Also note that "looking for evidence" implies that the targets of these searches don't need to be guilty, only suspected.
I'm all for jailing terrorists and child molesters and throwing away the key. I also like my personal freedom to do innocent and legal things without the government poking around in it.
Reasonable suspicion (Score:2)
'Also note that "looking for evidence" implies that the targets of these searches don't need to be guilty, only suspected.'
That's always the case with any search warrant. Nothing to see here.
Re: (Score:2)
The difference being that you can't script a physical search and scale it up.
If the police would go and search every single house in the country because some genius thought they can interpret the laws that way on their hunt for, say, a pot farm, there would be an uprising. In the digital sphere, that is exactly what we're looking at. Overreach is the norm, not the exception.
Hmm (Score:2)
the Investigatory Powers Act, which ... and forbids those companies from disclosing anything about the demands.
Does this mean that Apple already violated the UK law?
Re: (Score:1)
No, as that is referring to demands (not requests) against a particular third party. Because governments don't want those who hold data to tell the owners of that data that their affairs are being poked into otherwise they'd invoke pesky data protection things like the 4th Amendment, or similar in their country, and we can't have that.
Domestic threat (Score:1, Offtopic)
I'm more scared of a domestic threat from an unelected immigrant. https://www.the-independent.co... [the-independent.com]
Good thing he has "read only" access to my data. https://www.cbsnews.com/news/t... [cbsnews.com]
Re:Domestic threat (Score:5, Insightful)
Honestly, you might as well complain about how people didn't vote for a particular cabinet secretary. It is a spurious complaint that can only be based on an intentional misunderstanding of the democratic process. Utterly silly.
Re: (Score:2)
It's still going to be Biden's fault when Medicare and Medicaid are slashed. https://www.npr.org/2025/02/10... [npr.org]
Re: (Score:2)
An Obama appointee is not going to accurately or fairly portray the motives and agenda of her political opponents. She's just a hack brought in to build straw men.
Re: (Score:2)
There's a reason political campaigns are often very heavy on the "what" and very light on the "how", and it's that voters love to fill in the blanks in a way that works for them, if they even think that far given all the single-viewpoint information bubbles many of them now wrap themselves in rather than have to consider different opinions. A lot of people are going to get behind someone promising to
Re: (Score:2)
Stop looking for an excuse to say that this isn't what Trump won on. Stop listening to the people who say otherwise, they know better but tell you different for malicious reasons.
Holy hells the hypocrisy (Score:3, Interesting)
The United States government whines continuously about needing back doors into all encryption, then bitch when an ally wants the same? Can they even read their own playbook? Or are we so deep into the "gimme everything, you should get nothing" territory now that they no longer have a playbook?
Re: (Score:2)
The United States government whines continuously about needing back doors into all encryption, then bitch when an ally wants the same? Can they even read their own playbook?
The US government is not monolithic. No organization is, but the US government less so than most.
In this case, it's law enforcement agencies -- notably the FBI -- who is always whining about needing backdoors, but it's a Congressman who is complaining that backdoors may endanger Americans. Presumably the Congressman disagrees with the FBI.
America threatens world, says world (Score:2, Insightful)
There's going to be a flood of chickens coming home to roost with Presidents Elon and Trump (Mump? Trusk?) in the coming years.
Obviously this example is only tangentially related to the dastardly duo, but any benefit of the doubt will fall against America for the foreseeable.
I thought this was by US request all along (Score:3)
Cutting off nose to spite face (Score:5, Interesting)
'If the top U.S. ally does not back off, they said, Gabbard should consider limiting the deep intelligence sharing and cooperation on cybersecurity between the countries.'
I thought you liked having a military base in the Chagos islands in the Indian Ocean, as well as various listening posts in the UK. There's a listening centre on the North Sea coast which the UK cut the US off from when there was a previous row; the US backed down.
If a back door exists... (Score:2)
...bad guys will use it
There are only two options, full security or no security
Just give them the encrypted files. (Score:2)
No besties anymore (Score:2)
If the USA were to step over that line how would traditional USA allies respond? With invasion treats feeling more r
Of course the downside is (Score:2)
Re: (Score:2)
OTOH, does that mean we don't have to participate in wars either?
Re: (Score:2)