this post was submitted on 07 Feb 2025
65 points (98.5% liked)

Privacy

727 readers
44 users here now

Protect your privacy in the digital world

Welcome! This is a community for all those who are interested in protecting their privacy.

Rules

~PS: Don't be a smartass and try to game the system, we'll know if you're breaking the rules when we see it!~

  1. Be nice, civil and no bigotry/prejudice.
  2. No tankies/alt-right fascists. The former can be tolerated but the latter are banned.
  3. Stay on topic.
  4. Don't promote proprietary software.
  5. No crypto, blockchain, etc.
  6. No Xitter links. (only allowed when can't fact check any other way, use xcancel)
  7. If you post news exclusive to a country please name it. ~(This isn't a bannable rule, just a recommendation!)~
  8. If in doubt, read rule 1

Related communities:

founded 3 months ago
MODERATORS
top 12 comments
sorted by: hot top controversial new old
[–] [email protected] 35 points 2 days ago (2 children)

I dont know how you say: “This is fucking scary” in British English, but in Canadian English, I’d say it like: “This is fucking scary”.

[–] [email protected] 2 points 2 days ago (1 children)

It's scary in that they don't understand why that's a bad idea, but it's kind of stupid in that Apple probably can't, if Apple implemented E2EE at all correctly.

Assuming that's true, they can demand all they want, but you can't just:

if government_order == true:
  iCloud.unlock()

...assuming they use any of the usual encryption algorithms.

What is interesting is that they've ordered Apple to do it but (maybe) not Google, which has a much larger share of Android users in Europe. Is the UK iOS-heavy?

[–] [email protected] 2 points 1 day ago* (last edited 1 day ago)

Assuming that’s true, they can demand all they want, but you can’t just:

if government_order == true: iCloud.unlock()

…assuming they use any of the usual encryption algorithms.

Proton services are encrypted, but if Andy Yen goes full nazi (which he haven't done yet), he could just send you a javascript on the browser UI / update the apps, with code that extracts your keys and sent it over to their servers.

And they could force the update by refusing you to access your data until you've updated.

[–] [email protected] 28 points 2 days ago (2 children)

If encryption can be backdoored, then it was never encrypted anyway.

[–] [email protected] 7 points 1 day ago* (last edited 1 day ago) (2 children)

I mean, it could be.

Proton services are encrypted, but all that they have to do to "backdoor" it is just sending you a javascript to your browser / update your app with code that would extract your keys and sent it over to them.

The encryption was not "backdoored", they just retroacrively backdoored it.

They could even hold your data hostage until you update the apps.

[–] [email protected] 2 points 1 day ago* (last edited 1 day ago)

This is why FOSS is so important. Then you can at least control the app and know that it's not being updated with malicious code.

[–] [email protected] 5 points 1 day ago

Yes, i talked about this in another comment (off this acc tho) that you can't perfectly trust anything. Not even free software, so you have to cross your fingers and hope they are truly private and secure.

Self hosting is the best private and secure way to store files.

[–] [email protected] 5 points 2 days ago (1 children)

Encoded would be the proper term then.

[–] [email protected] 3 points 2 days ago

Yep. What's the point of trusting "encoded" sensitive content that can be cracked at a whim by the company?

It's times like these where self hosting is a blessing.

[–] [email protected] 11 points 2 days ago (1 children)

For those of you not in the UK, or unfamiliar, its important to understand just how intrusive the gvmt are in terms of privacy and how intrusive they want to be. We are world leaders in gvmt led privacy oppression.

EFF article

[–] [email protected] 0 points 1 day ago

We're not far behind you and firing up a gasoline engine in a runners marathon going the wrong way, too.