Hacker News new | past | comments | ask | show | jobs | submit login

If the state is after you, even low-level state actors, all it takes is a court order or subpoena to compel any of the parties involved with your phone or data to hand over your data or start collecting it.

If your threat model includes any level of the US government, and that includes women seeking abortions in states where it is illegal, you cannot rely on US-based company's tech to protect you from the law.




There are state actors other than the US Government, along with plenty of non-state actors who are willing to use illegal techniques on occasion, and this does increase people's protection against those actors.

If you're in a developing country and you engage in activism against some questionable project by the state owned mining company, you're probably not going to get the full force of the NSA directed against you. But your country's domestic intelligence agency may be interested, and they probably only have off the shelf spyware to work with.


Pretty sure most things are stored encrypted/delivered encrypted only to be decrypted and rendered on your phone. Meaning Apple/your provider have nothing to give up for the hypothetical US government demand.


To add to the other comment, Apple installed on-device scanning to iOS as far back as version 14.3 (https://pocketnow.com/neuralhash-code-found-in-ios-14-3-appl...). They claim they won't activate it without a court or government order, but these are becoming easier and easier to obtain. Under the Patriot Act, virtually anyone's electronic devices may be searched for any reason. In effect this means that Apple has access to all information on all iOS devices, and the government may access any of these at will.


This is incorrect, iCloud backups are deliberately unencrypted.

https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...

I haven't heard of any changes to this to-date.


Sure, they’re not E2EE, but stuff like iMessages are E2EE (assuming iCloud backups are turned off so the keys aren’t included in the backup).


“iCloud Data Recovery Service If you forget your password or device passcode, iCloud Data Recovery Service can help you decrypt your data so you can regain access to your photos, notes, documents, device backups, and more. Data types that are protected by end-to-end encryption—such as your Keychain, Messages, Screen Time, and Health data—are not accessible via iCloud Data Recovery Service. Your device passcodes, which only you know, are required to decrypt and access them. Only you can access this information, and only on devices where you're signed in to iCloud.”

https://support.apple.com/en-us/HT202303

That seems pretty clear to me, but maybe it’s misleading?




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: