For the most part this it’s true, although it’s possible to do it securely. Security cam footage stored in iCloud is end to end encrypted. Apple can’t access it.
Yes. 100%. End to end encrypted means the decryption key is at the other end. Where Apple is.
If it were ACTUALLY secure you would have BOTH the encryption AND decryption keys and Apple would only have a useless, unreadable, encrypted binary blob.
So, it does say that not even Apple can read your data, but it also says it’s protected by “end to end encryption”, which if Apple can’t read your data, is absolutely nonsense usage of the term.
“End to end encryption” means encrypting the data at one end, and decrypting it at the other end. That’s literally the NAME. If they’re not doing that, the term is completely nonsense to use. They might as well say they have fat-free encryption. What they’re really doing is storing an encrypted file that you hold both keys for. And IF that’s what they’re doing, that’s actually fantastic - far better than end-to-end encryption because only you can decrypt it. But they’re not inspiring confidence by COMPLETELY misusing a term that has nothing to do with what they’re doing.
The other point is, if those keys… if you have to manually copy those keys over between all of your devices? Great. You’re actually protected. If, however, you just connect to your Apple account and now you can get your files out of iCloud? That means that Apple DOES have your decryption keys SOMEWHERE, because otherwise they couldn’t send them to your other devices, which means, sorry, whatever they’re promising, they DO have the ability to look at your files if they’re motivated enough.
It has to be decrypted for you to use it stupid… Ffs they literally call it out in the line “No one else can access your end-to-end encrypted data, not even Apple, and this data remains secure even in the case of a data breach in the cloud.”. To apple end to end encryption is keeping the data entirely encrypted up until it hits your device where you use it… I could go on about how you misunderstand the tech but you’re better off just actually looking into how they implement it because they account for your concerns.
The fact that there are multiple seprate recovery options to regain access to your account and with it access to those encrypted backups is all the clue you need to know those keys are not stored only on your device.
Apple has access to those keys - whether they want to directly admit it or not.
“With Advanced Data Protection turned on, Apple doesn’t have the encryption keys needed to help you recover your end-to-end encrypted data.” it’s literally on the page. If they have them, prove it, and launch yourself the most profitable lawsuit against apple possible. Otherwise you’re just bring a grumpy fool.
Two things here. I’m not saying these are necessarily true, but they can be true.
-Apple could be lying.
-Apple could change their corporate policy on providing backdoor access for governments.
In the end, you are trusting a profit-seeking corporation to protect your data and conduct themselves in an ethical and honest way. They also had their phones built in factories where people threw themselves from the rooftop to escape the inhumane conditions. Just saying…
They literally say to store your Recovery keys in a safe place or you could get locked out of your account.
If you don’t know your account password and have lost or otherwise don’t have a trusted device, you need your recovery key to regain access to your Apple Account. If you can’t provide your recovery key, you’ll be locked out of your account permanently.
Print a copy of your recovery key or write it down. Keep your key in a safe place, and consider storing a copy in more than one place. You can also give a copy of your recovery key to a trusted family member.
Don’t store your recovery key in your Apple Passwords app, iCloud Photos, Notes, or iCloud Drive. If you lose access to your Apple Account, you won’t be able to open these apps to find it.
There are no ways to recover your account if you have ADP on. Stop making stuff up. You need to have your key written down and stored somewhere safe, otherwise you are SOL and locked out forever.
It’s literally in the link in the comment this was replying to:
Recovery methods
With Advanced Data Protection turned on, Apple doesn’t have the encryption keys needed to help you recover your end-to-end encrypted data. [I do not believe this] If you ever lose access to your account, you’ll need to use one of your account recovery methods — your device passcode or password, your recovery contact, or recovery key — to recover your iCloud data.
Your device passcode or password is the passcode on your iPhone or iPad, or the login password on your Mac that you set to protect your device and enable two-factor authentication. It’s also used to reset your Apple Account password and to recover your end-to-end encrypted data if you lose access to your account.
A recovery contact is a trusted friend or family member who can use their Apple device to help you regain access to your account and data. They won’t have any access to your account, only the ability to give you a code to help you recover your account. Learn more about recovery contacts.
A recovery key is a secret 28-character code that you can use, along with a trusted phone number and an Apple device, to recover your account and data. Learn more about recovery keys.
How would a ‘trusted contact’ recover keys that are supposedly only stored on your devices, when you yourself have lost those devices; unless Apple has stored those keys elsewhere.
There’s also no telling what they’ve done with your ‘recovery key’. Just because they refuse to help you, doesn’t mean they have no access; they just won’t share that access with you, as it would blatantly expose their illusion.
There’s no way in hell I’m trusting a massive US corporation with securing my data without backdoor access. You have no way of managing encryption/recovery keys on an Apple device or seeing where/how they’ve been stored; you’ve just got to trust they handle it well for you.
I do not trust Apple; or any large profit driven corporation, particularly one that sucks up to the American government (especially THIS American Government). Not in todays age of dystopian surveillance.
I think they’re trying to say that while apple encrypts in transit (upload + download is sftp or some other secure transfer method that can’t be eavesdropped on), they don’t encrypt at rest, meaning the data is written in decrypted format to disk. Which is a data security no-no for mine and most enterprises out there. They’re alleging that if someone got into an apple server, they’d be able to read your data and anyone elses.
Now that might not be true but I don’t see apple saying otherwise anywhere obvious. It’s not true. I’m pretty sure Google do this though. They retain a level of access to train their ai models and other deep learning algorithms on what you write in docs or the photos you upload.
I’m assuming someone is tired here, and it could well be me, but isn’t that quite literally what I said? People were saying E2EE doesn’t mean the data is secure when it gets there, I was trying to separate the discussion into at rest (secure storage) vs in transit (E2EE) because they’re different applications of encryption. I wasn’t really intending to argue about Apple’s practice’s.
From reading, it is encrypted at rest, which sounds like an Apple thing to do. Decrypted at rest feels very Google. Apple state on their standard plan they store the keys in their data centres which I think is what others were talking about? They say they can help recover them so they’re accessible in some capacity between the user and Apple.
On their advanced plan details:
Advanced Data Protection for iCloud is an optional setting that offers our highest level of cloud data security. If you choose to enable Advanced Data Protection, your trusted devices retain sole access to the encryption keys for the majority of your iCloud data, thereby protecting it using end-to-end encryption. Additional data protected includes iCloud Backup, Photos, Notes, and more
E2E in the context of data stored at rest conceptually just means that “current you” is sending data to “future you” where the two ends are “current you” and “future you.”
Always question and audit the implementation of any E2E claim by a vendor, but the term itself refers to how only those with authorized access can decrypt, and that the service provider itself need not be authorized.
If anyone can prove that this implementation has security vulnerabilities (such as Apple being able to view your footage), you are in for a huge payday.
Idk why you’re being down voted. With ADP enabled and using icloud secure cameras the data is encrypted by keys stored only on your local devices, Apple has no access to these keys and there are no recovery options through apple. If you lose all of your devices and your recovery code and your login information, the data is gone. This has been validated by independent third parties. It’s also worth noting that apple still to this day hosts the only corporate “fuck you, we’re encrypting it” public memo I’ve ever seen at https://www.apple.com/customer-letter/ .
Apparently and fr. I’m by no means an apple stan but let’s give them shit for things they’re actually guilty of instead of gaslighting ourselves with new bs.
Yeah, I remember several years ago they got a terrorists iphone and Bush tried to pressure Apple to give them access to the phone; Apple refused to cooperate. Good on them.
Just because you repeat marketing “talking points”, doesn’t make it a “fact”.
Simping for one of the most profitable, closed source, authoritarian friendly, anti competitive, ring kissing pedophile president company is definitely a choice.
The push notification issue applied to all push notifications including any os that delivered them (Google, Microsoft, etc) which is a valid concern we can discuss, family recovery is not possible with ADP enabled jfc learn to read, and I never stated they were the most privacy oriented company in the world. Hate all you like boo but their implementation of E2E is vetted and legit as any, and idk how any of this is simping because I don’t fucking like apple. I’m just not going to subscribe to blind stupid baseless hate that does not follow any factual reality.
No, but it’s generally a good indication. If Apple says they can’t access it, and outline the cryptographic methods used to make sure they can’t access it, and it’s been verified by third parties that if you loose the keys (access to your Apple account) then you loose the data, then I’d probably say it’s pretty good evidence that Apple isn’t lying about their implementation.
If it records to the cloud, it’s not your footage. It can and will be acquired/distributed against your will.
For the most part this it’s true, although it’s possible to do it securely. Security cam footage stored in iCloud is end to end encrypted. Apple can’t access it.
I wouldn’t bet on that.
E2E doesn’t matter if you don’t control the other end.
Yes. 100%. End to end encrypted means the decryption key is at the other end. Where Apple is.
If it were ACTUALLY secure you would have BOTH the encryption AND decryption keys and Apple would only have a useless, unreadable, encrypted binary blob.
They literally give you the keys. See Advanced Data Protection
So, it does say that not even Apple can read your data, but it also says it’s protected by “end to end encryption”, which if Apple can’t read your data, is absolutely nonsense usage of the term.
“End to end encryption” means encrypting the data at one end, and decrypting it at the other end. That’s literally the NAME. If they’re not doing that, the term is completely nonsense to use. They might as well say they have fat-free encryption. What they’re really doing is storing an encrypted file that you hold both keys for. And IF that’s what they’re doing, that’s actually fantastic - far better than end-to-end encryption because only you can decrypt it. But they’re not inspiring confidence by COMPLETELY misusing a term that has nothing to do with what they’re doing.
The other point is, if those keys… if you have to manually copy those keys over between all of your devices? Great. You’re actually protected. If, however, you just connect to your Apple account and now you can get your files out of iCloud? That means that Apple DOES have your decryption keys SOMEWHERE, because otherwise they couldn’t send them to your other devices, which means, sorry, whatever they’re promising, they DO have the ability to look at your files if they’re motivated enough.
End to end means the ends you use it at, ot the server you’re imagining it ending up on.
In this case the “ends” are your devices.
It has to be decrypted for you to use it stupid… Ffs they literally call it out in the line “No one else can access your end-to-end encrypted data, not even Apple, and this data remains secure even in the case of a data breach in the cloud.”. To apple end to end encryption is keeping the data entirely encrypted up until it hits your device where you use it… I could go on about how you misunderstand the tech but you’re better off just actually looking into how they implement it because they account for your concerns.
The fact that there are multiple seprate recovery options to regain access to your account and with it access to those encrypted backups is all the clue you need to know those keys are not stored only on your device.
Apple has access to those keys - whether they want to directly admit it or not.
“With Advanced Data Protection turned on, Apple doesn’t have the encryption keys needed to help you recover your end-to-end encrypted data.” it’s literally on the page. If they have them, prove it, and launch yourself the most profitable lawsuit against apple possible. Otherwise you’re just bring a grumpy fool.
Two things here. I’m not saying these are necessarily true, but they can be true.
-Apple could be lying.
-Apple could change their corporate policy on providing backdoor access for governments.
In the end, you are trusting a profit-seeking corporation to protect your data and conduct themselves in an ethical and honest way. They also had their phones built in factories where people threw themselves from the rooftop to escape the inhumane conditions. Just saying…
They literally say to store your Recovery keys in a safe place or you could get locked out of your account.
Set up a recovery key for your Apple Account
They do not.
There are no ways to recover your account if you have ADP on. Stop making stuff up. You need to have your key written down and stored somewhere safe, otherwise you are SOL and locked out forever.
It’s literally in the link in the comment this was replying to:
How would a ‘trusted contact’ recover keys that are supposedly only stored on your devices, when you yourself have lost those devices; unless Apple has stored those keys elsewhere.
There’s also no telling what they’ve done with your ‘recovery key’. Just because they refuse to help you, doesn’t mean they have no access; they just won’t share that access with you, as it would blatantly expose their illusion.
There’s no way in hell I’m trusting a massive US corporation with securing my data without backdoor access. You have no way of managing encryption/recovery keys on an Apple device or seeing where/how they’ve been stored; you’ve just got to trust they handle it well for you.
I do not trust Apple; or any large profit driven corporation, particularly one that sucks up to the American government (especially THIS American Government). Not in todays age of dystopian surveillance.
Ding ding ding!!!
The test of E2E encryption is “who manages the keys?” If the answer isn’t me, it isn’t E2E encrypted.
The user manages the keys per https://lemmy.world/comment/25340338
I think they’re trying to say that while apple encrypts in transit (upload + download is sftp or some other secure transfer method that can’t be eavesdropped on), they don’t encrypt at rest, meaning the data is written in decrypted format to disk. Which is a data security no-no for mine and most enterprises out there. They’re alleging that if someone got into an apple server, they’d be able to read your data and anyone elses.
Now that might not be true but I don’t see apple saying otherwise anywhere obvious.It’s not true. I’m pretty sure Google do this though. They retain a level of access to train their ai models and other deep learning algorithms on what you write in docs or the photos you upload.Thats not how it works at all. The traffic is encrypted locally on the device before it even gets sent to Apple.
I’m assuming someone is tired here, and it could well be me, but isn’t that quite literally what I said? People were saying E2EE doesn’t mean the data is secure when it gets there, I was trying to separate the discussion into at rest (secure storage) vs in transit (E2EE) because they’re different applications of encryption. I wasn’t really intending to argue about Apple’s practice’s.
From reading, it is encrypted at rest, which sounds like an Apple thing to do. Decrypted at rest feels very Google. Apple state on their standard plan they store the keys in their data centres which I think is what others were talking about? They say they can help recover them so they’re accessible in some capacity between the user and Apple.
On their advanced plan details:
E2E in the context of data stored at rest conceptually just means that “current you” is sending data to “future you” where the two ends are “current you” and “future you.”
Always question and audit the implementation of any E2E claim by a vendor, but the term itself refers to how only those with authorized access can decrypt, and that the service provider itself need not be authorized.
You don’t have to bet on it. Just look it up.
Trolls never do the legwork.
Not sure if I’m the troll, or the other guy, but just in case I’ll add this.
https://support.apple.com/en-lb/guide/security-pdf/sec525461d19/web
If anyone can prove that this implementation has security vulnerabilities (such as Apple being able to view your footage), you are in for a huge payday.
Nope! The only question that needs to be asked is: who manages the encryption keys?
If the answer isn’t you, it isn’t E2E encrypted.
The answer is you lol it’s end to end encrypted. You couldn’t do one google search before making some dumb assumptions?
Do you actually know anything about Apes E2EE or ADP?
You do control the keys. They’re generated solely on your device locally.
Idk why you’re being down voted. With ADP enabled and using icloud secure cameras the data is encrypted by keys stored only on your local devices, Apple has no access to these keys and there are no recovery options through apple. If you lose all of your devices and your recovery code and your login information, the data is gone. This has been validated by independent third parties. It’s also worth noting that apple still to this day hosts the only corporate “fuck you, we’re encrypting it” public memo I’ve ever seen at https://www.apple.com/customer-letter/ .
I’m being downvoted because I dare say something positive about Apple. People don’t like that here.
Apparently and fr. I’m by no means an apple stan but let’s give them shit for things they’re actually guilty of instead of gaslighting ourselves with new bs.
Pretty much. There’s plenty to bitch out apple for. I don’t see why people can’t just stick to the facts.
Yeah, I remember several years ago they got a terrorists iphone and Bush tried to pressure Apple to give them access to the phone; Apple refused to cooperate. Good on them.
https://lemmy.world/comment/25339959
ah, yes!
Sure, let’s stick to facts like Apple is the most privacy oriented company in the world and regularly gives a “fuck you” to the government.
Apple admits to secretly giving governments push notification data - Ars Technica
Apple account data is irrecoverable.
How to request access to a deceased family member’s Apple Account
Just because you repeat marketing “talking points”, doesn’t make it a “fact”.
Simping for one of the most profitable, closed source, authoritarian friendly, anti competitive, ring kissing pedophile president company is definitely a choice.
The push notification issue applied to all push notifications including any os that delivered them (Google, Microsoft, etc) which is a valid concern we can discuss, family recovery is not possible with ADP enabled jfc learn to read, and I never stated they were the most privacy oriented company in the world. Hate all you like boo but their implementation of E2E is vetted and legit as any, and idk how any of this is simping because I don’t fucking like apple. I’m just not going to subscribe to blind stupid baseless hate that does not follow any factual reality.
Jellyfin! Android! Lanepslitting!
These are all things that, if you go against, will bring out the angry nerds.
Oh, you sweet summer child
I’d love to see some evidence that I’m wrong. No one else has been able to provide any.
Absence of evidence is not evidence of absence
No, but it’s generally a good indication. If Apple says they can’t access it, and outline the cryptographic methods used to make sure they can’t access it, and it’s been verified by third parties that if you loose the keys (access to your Apple account) then you loose the data, then I’d probably say it’s pretty good evidence that Apple isn’t lying about their implementation.