Second, iCloud E2EE is woefully incomplete. When you iMessage with someone, they have iCloud Backup on by default, and non-E2EE by default, which means that approximately all of your iMessages (including all image and document attachments) will still be readable by Apple and the FBI because they are backed up twice: once from each end of the conversation.
Furthermore, the E2EE for iCloud Photos is not designed to preserve privacy. Even though iCloud Photos now supports E2EE for the content of the photos and videos stored, the file metadata is not E2EE, and the metadata includes the FILENAME and also a unique hash of the unencrypted file content.
Yeah I wasn't sure how they claim iCloud Photos is E2EE, on your side there, but the iMessage thing is obvious, if information is leaving me it's going to someone and becomes that persons information. Not much you can do about that. ¯\_(ツ)_/¯
I did specifically choose not to mention Photos for that reason.
if information is leaving me it's going to someone and becomes that persons information.
This is fine. Not having end-to-end encryption by default is not fine, because default plain text backups effectively removes the end-to-end encryption.
Yeah. I don't think this is done out of malice though, Apple has literally hundreds of millions of customers, not being able to restore access to the majority of these due to lost passwords would risk losing customers which they can't have.
That said I think the benefits of Advanced Data Protection should be more clearly explained to users and the feature should be more prominently presented during onboarding, both new users but also existing users when the feature was rolled out.
Comments
https://sneak.berlin/20231005/apple-operating-system-surveil...
Yeah I wasn't sure how they claim iCloud Photos is E2EE, on your side there, but the iMessage thing is obvious, if information is leaving me it's going to someone and becomes that persons information. Not much you can do about that. ¯\_(ツ)_/¯
I did specifically choose not to mention Photos for that reason.
This is fine. Not having end-to-end encryption by default is not fine, because default plain text backups effectively removes the end-to-end encryption.
Yeah. I don't think this is done out of malice though, Apple has literally hundreds of millions of customers, not being able to restore access to the majority of these due to lost passwords would risk losing customers which they can't have.
That said I think the benefits of Advanced Data Protection should be more clearly explained to users and the feature should be more prominently presented during onboarding, both new users but also existing users when the feature was rolled out.