Hacker News new | ask | show | jobs
by codedokode 671 days ago
Apple already has a kind of "backdoor": they store the keys for encrypted cloud backups in their cloud as well. They advertise that cloud data are encrypted but prefer not to mention that they also have a key to decrypt it. Even with the highest level of security [1] your contacts list in Apple Cloud are not encrypted. Why? Probably someone asked for this.

[1] https://support.apple.com/en-us/102651

1 comments

No, it’s because the CardDAV standard was not created with encryption in mind. It’s also why calendar and mail are not encrypted in iCloud.
CSV or PNG weren't created with encryption in mind, but one can easily encrypt them. Apple can always make their own proprietary protocol. This doesn't explain anything. However the version that the govt wants to be able to see who is in person't contact list explains it well.
If Apple did that, people like me would accuse them of EEE.

We don’t trust proprietary stuff because we’ve been burned by it, if there’s an open standard, even a worse one: use it.

If it’s really that bad, we need to improve the standard.

As I understand, this protocol is used between an iPhone and iCloud and it being open or not doesn't change anything because there is no alternative iCloud or iPhone.
You’re mistaken, you don’t only connect to your iCloud from iPhones.

You connect from any compatible client; and the effort that has gone in to the Mail client for iOS means it’s a decent enough mail client for non-iCloud mail accounts too.

Apples closed ecosystem is mostly its developer tooling and iMessage.

CSV and PNG are not server protocols like CardDav, CalDav, and IMAP, they are file formats.