In the Apple world, they basically carefully redefined privacy as "anyones else besides us getting access". They put themselves as a fully trusted party for everything.
You can finally have your entire iCloud account end-to-end encrypted using Advanced Data Protection since earlier this year.
iCloud Backups, iCloud drive, passwords, health data, basically everything except specifically iCloud Mail, Contacts, and Calendar [1] is all inaccessible to Apple when Advanced Data Protection is enabled.
Second, iCloud E2EE is woefully incomplete. When you iMessage with someone, they have iCloud Backup on by default, and non-E2EE by default, which means that approximately all of your iMessages (including all image and document attachments) will still be readable by Apple and the FBI because they are backed up twice: once from each end of the conversation.
Furthermore, the E2EE for iCloud Photos is not designed to preserve privacy. Even though iCloud Photos now supports E2EE for the content of the photos and videos stored, the file metadata is not E2EE, and the metadata includes the FILENAME and also a unique hash of the unencrypted file content.
Yeah I wasn't sure how they claim iCloud Photos is E2EE, on your side there, but the iMessage thing is obvious, if information is leaving me it's going to someone and becomes that persons information. Not much you can do about that. ¯\_(ツ)_/¯
I did specifically choose not to mention Photos for that reason.
if information is leaving me it's going to someone and becomes that persons information.
This is fine. Not having end-to-end encryption by default is not fine, because default plain text backups effectively removes the end-to-end encryption.
Yeah. I don't think this is done out of malice though, Apple has literally hundreds of millions of customers, not being able to restore access to the majority of these due to lost passwords would risk losing customers which they can't have.
That said I think the benefits of Advanced Data Protection should be more clearly explained to users and the feature should be more prominently presented during onboarding, both new users but also existing users when the feature was rolled out.
Same way as I square it with my MacOS/iOS having a separate tick for Apple data collection vs. everyone elses data collection and having their ad targeting and data having different defaults.
They're a corpo of hundreds of thousands, there's no feelings attached to it from their side. They'll do what makes their stock go up or the CEO will be replaced with someone who'll do the needful.
E2EE arrived very very late and is even off by default. Anybody you are messaging to is going to have E2EE off and their backup data sent to the US government for analysis (see PRISM revelations which Apple participated to). Since you can't get iMessage without iCloud (at least to my knowledge) it's one of the most problematic messaging platform out there because of that.
For Find My, since they can even locate switched off phones, that tells you all you need about how it works. I find the whole concept creepy.
I'll give you that E2EE arrived late and is off by default. But:
For Find My, since they can even locate switched off phones
They can't. Find My is actually truly end-to-end encrypted, at least the version used for when a device is off (I'm not 100% sure how encrypted the self-reported version is for powered on iPhones with data).
Copy-pasting my summary about how Find My works from another comment in this post:
The master private key used by the system is generated locally and never leaves your Apple devices in a state that anyone except your devices can read it.
The master key is used to derive an AirTag specific private key which is provisioned to the AirTag and is in turn combined with an increasing counter which generates a third private key that's never stored anywhere. The ID broadcast is the public key of this third key. It changes every 30 minutes or 1 hour, I forget which.
Other devices see this key, use it to encrypt their own location, and upload that encrypted blob along with the public key to Find My, and in order for Apple to even know which account the encrypted blob they can't decrypt belongs to I have to actually request the location of my AirTag by locally deriving the keypair it used for a certain point in time.
This has all been proven through [1] where they read the whitepaper (which I can't for the life of me find now but know exist because I've read it, or at least parts) and implemented OpenHaystack which proves Apple aren't lying about anything because if they did then OpenHaystack wouldn't work.
I'm aware that for airtags, the implementation should not be too bad. I'm talking about iPhone which are much more important.
They can also be tracked close to real time with their gps coordinates so it cannot be passive, the phone has to report somewhere. And it's reporting in the background, there's no indication that its doing it.
Admittedly I have nothing to back this up, but judging by how well designed Find My is in this aspect, I'd be surprised if the implementation for the self-reporting one is that much worse, I suspect the re-did it in iOS 13 when Find My launched.
Was it ever possible to access your iPhones location through iCloud.com? I know Find My Friends was available there, but I don't remember if "Find My iPhone" was.
Comments
In the Apple world, they basically carefully redefined privacy as "anyones else besides us getting access". They put themselves as a fully trusted party for everything.
How do you square that claim with E2EE and the way Find My works?
You can finally have your entire iCloud account end-to-end encrypted using Advanced Data Protection since earlier this year.
iCloud Backups, iCloud drive, passwords, health data, basically everything except specifically iCloud Mail, Contacts, and Calendar [1] is all inaccessible to Apple when Advanced Data Protection is enabled.
1: https://support.apple.com/en-us/HT202303
https://sneak.berlin/20231005/apple-operating-system-surveil...
Yeah I wasn't sure how they claim iCloud Photos is E2EE, on your side there, but the iMessage thing is obvious, if information is leaving me it's going to someone and becomes that persons information. Not much you can do about that. ¯\_(ツ)_/¯
I did specifically choose not to mention Photos for that reason.
This is fine. Not having end-to-end encryption by default is not fine, because default plain text backups effectively removes the end-to-end encryption.
Yeah. I don't think this is done out of malice though, Apple has literally hundreds of millions of customers, not being able to restore access to the majority of these due to lost passwords would risk losing customers which they can't have.
That said I think the benefits of Advanced Data Protection should be more clearly explained to users and the feature should be more prominently presented during onboarding, both new users but also existing users when the feature was rolled out.
Same way as I square it with my MacOS/iOS having a separate tick for Apple data collection vs. everyone elses data collection and having their ad targeting and data having different defaults.
They're a corpo of hundreds of thousands, there's no feelings attached to it from their side. They'll do what makes their stock go up or the CEO will be replaced with someone who'll do the needful.
E2EE arrived very very late and is even off by default. Anybody you are messaging to is going to have E2EE off and their backup data sent to the US government for analysis (see PRISM revelations which Apple participated to). Since you can't get iMessage without iCloud (at least to my knowledge) it's one of the most problematic messaging platform out there because of that.
For Find My, since they can even locate switched off phones, that tells you all you need about how it works. I find the whole concept creepy.
I'll give you that E2EE arrived late and is off by default. But:
They can't. Find My is actually truly end-to-end encrypted, at least the version used for when a device is off (I'm not 100% sure how encrypted the self-reported version is for powered on iPhones with data).
Copy-pasting my summary about how Find My works from another comment in this post:
This has all been proven through [1] where they read the whitepaper (which I can't for the life of me find now but know exist because I've read it, or at least parts) and implemented OpenHaystack which proves Apple aren't lying about anything because if they did then OpenHaystack wouldn't work.
1: https://github.com/seemoo-lab/openhaystack
I'm aware that for airtags, the implementation should not be too bad. I'm talking about iPhone which are much more important.
They can also be tracked close to real time with their gps coordinates so it cannot be passive, the phone has to report somewhere. And it's reporting in the background, there's no indication that its doing it.
Admittedly I have nothing to back this up, but judging by how well designed Find My is in this aspect, I'd be surprised if the implementation for the self-reporting one is that much worse, I suspect the re-did it in iOS 13 when Find My launched.
Was it ever possible to access your iPhones location through iCloud.com? I know Find My Friends was available there, but I don't remember if "Find My iPhone" was.
Not everything is under E2EE and the Find My is probably not the biggest privacy problem of Apple.
Everything except specifically iCloud Mail, Contacts, and Calendar is E2EE when Advanced Data Protection is enabled.
See this for what is and isn't encrypted: https://support.apple.com/en-us/HT202303
Ah, I stand corrected. They do monitor and intercept everything, then.