Please create an account to participate in the Slashdot moderation system

 



Forgot your password?
typodupeerror
×
Security Apple

Apple Advances User Security With Three New Data Protections (apple.com) 22

WankerWeasel writes: Apple today introduced three advanced security features focused on protecting against threats to user data in the cloud, representing the next step in its ongoing effort to provide users with even stronger ways to protect their data. With iMessage Contact Key Verification, users can verify they are communicating only with whom they intend. With Security Keys for Apple ID, users have the choice to require a physical security key to sign in to their Apple ID account. And with Advanced Data Protection for iCloud, which uses end-to-end encryption to provide Apple's highest level of cloud data security, users have the choice to further protect important iCloud data, including iCloud Backup, Photos, Notes, and more.
This discussion has been archived. No new comments can be posted.

Apple Advances User Security With Three New Data Protections

Comments Filter:
  • One reason I started using PayPal back in the day us they had an electronic one time pad. A device that would generate a number. The bank I used for international stuff also had a one time pad.

    This hardware key will open Apple products to a lot of secure environments. My sister has a dongle for her computer.

    But I would like to see a compromise that is less inconvenient. Like maybe the Apple Watch knows you are wearing it, and only you, and that is the only way to log in.

  • by Rosco P. Coltrane ( 209368 ) on Wednesday December 07, 2022 @04:06PM (#63111732)

    Don't put your data in the cloud.

    Don't believe cloud providers' claims on security.
    Assume the cloud providers themselves are a threat.

    • by rtkluttz ( 244325 ) on Wednesday December 07, 2022 @04:58PM (#63111860) Homepage

      Exactly. If you don't control the encryption algorithm independently from the app and encrypt BEFORE the app touches the data, assume the app maker or cloud provider has access to it and can get to your data if they want to. The whole kerfuffle years back when the FBI was trying to get into the iPhone in California from the suspected terrorist, was a master class in misdirecting the public to what they wanted people to focus on. Them: Apple won't give you up. But in reality, the statement should be Apple won't give you up unless they eventually make us with court orders. And beyond that, the REAL question should have been, why is it even POSSIBLE for Apple to give you up? They shouldn't control the encryption and cloud usage should not be forced but yet they somehow redirected everyone and the media from asking those questions.

      • Re: (Score:3, Interesting)

        by uncqual ( 836337 )

        All good advice.

        However it is worth noting that US courts have, in general, concluded that you can be required to give up your "key" - physical or digital - in response to a search warrant just as you can be required to provide the combination to a safe if the search warrant's scope includes the associated location or data. Although if you refuse to do so in the case of physical locks, the search team will probably just drill out or force the lock rather than bother to go to court and have the court toss yo

        • I have nothing to hide to a court. I'd provide the key willingly. I just don't want cloud providers to rip through my data and exploit it.

          Why do you assume people who use encryption are doing something illegal?

          • by uncqual ( 836337 )

            I'm not making the assumption you think I was making.

            However, encryption is sometimes used to conceal criminal activity and the parent mentioned the FBI and the iPhone encryption case.

            Of course in that case those that were most likely to have the encryption key were dead as a result of their criminal activities so the FBI had to figure out other ways (including the attempt to make Apple help them) to decrypt the data.

        • Why isn't this a violation of the constitutional right to be free from cruel and unusual punishment? You have not been convicted of a crime, so why is it constitutional for the government to take away your right to liberty? I also wonder how this isn't a violation of your right to remain silent. You can't punish me simply because I didn't confess to a crime.

          It seems to me the founders, while certainly never considering this possible future state that includes iPhones and encrypted Cloud storage of digital
          • by uncqual ( 836337 )

            Your interpretation of the US Constitution seems to vary from that of the courts. You may think yours is more correct than theirs but they sort of make the rules so that puts you at a disadvantage.

            People don't actually have a "right to remain silent" in all cases. The now infamous "Miranda warning" and its "right to remain silent" clause is a fairly recent invention of the Supreme Court and only applies to those who are in custody and is often misunderstood (thank you Hollywood). Even then it's not absolute

        • by uncqual ( 836337 )

          Addendum:

          As well, a court may well refrain from ordering you to provide the encryption key or the encrypted data if the fact that you could do so would incriminate you (but not because the data itself would -- that's just an object like a knife with blood on it found under your mattress).

          For example, the fact that you demonstrate that you know the password to an encrypted file will tend to incriminate you as the prosecution could use that to tend to disprove your defense (perhaps "suggested" by your lawye

      • "why is it even POSSIBLE for Apple to give you up"

        Because the most common scenario is people who accidentally lost their credentials trying to recover their own account.

  • Google should do the same
  • Bring My Own Key (Score:4, Insightful)

    by registrations_suck ( 1075251 ) on Wednesday December 07, 2022 @04:07PM (#63111740)

    Great. When will I be able to bring my own encryption key, instead of relying on Apple to provide one?

  • So Apple's finally enabled PGP? Great, we need more companies & people to start using it.
  • by iustinp ( 104688 ) on Wednesday December 07, 2022 @09:16PM (#63112372) Homepage
    I see a lot of the comments just downplaying this, but while not perfect, it is a step forward (well, 3 separate steps forward). If you don't trust Apple in the first place, don't use their devices (since the device is the root of trust). But if you _mostly_ trust Apple, then the abilityto encrypt iCloud backups and notes and Photos is a very good thing against bugs in parts of the system and leaks.
    • Except this still seems like theater. If you lose your password... you should not be able to recover ANY data whatsoever. See: tresorit app. It explicitly warns that if you lose your password, you lose your data. In typical encryption, you need an encryption certificate and the password for that certificate. If there's a "forgot password", that means they have the means to decrypt and re encrypt your content
  • protection of personal data is very important, and I can say that the niche for the implementation of this is not sufficiently filled - after all, there is a user request and resources who can help him with this are not enough. If you want to develop an application or launch your own web resource, or you already have it, then you need to use SEO tools and services such as https://ninjareports.com/websi... [ninjareports.com] to analyze the SEO traffic of your competitors and draw up a SEO plan to promote this resource

As you will see, I told them, in no uncertain terms, to see Figure one. -- Dave "First Strike" Pare

Working...