Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

How do you figure that that's what their website indicates? The site you linked says that backups are encrypted in transit and on the server and they specifically say that the encryption is end-to-end so "only you can access your information, and only on devices where you’re signed in to iCloud. No one else, not even Apple, can access end-to-end encrypted information." That's quoted right from the page you posted.


If you carefully read the sentence before your quote, it says, "For certain sensitive information, Apple uses end-to-end encryption." (Emphasis added.) Then scroll down to the "End-to-end encrypted data" section where it lists the data that is actually end-to-end encrypted. iCloud Backups are not listed there.

AFAIK iCloud backups are not end-to-end encrypted. I believe this past February Tim Cook, or someone else at Apple, was indicating that they were working on changing that. (It was coming up because everyone was wishing the San Bernardino shooter's phone had been backing up to iCloud, so they wouldn't need to get in the phone, they could just access the iCloud backups—IIRC.)


That's fine. That would be better, obviously, but backups are still encrypted in transit and on the server. There's no way for someone to download and decrypt those backups without access to a device that's signed in to iCloud and, as has been said repeatedly on here, if someone has physical access to the device, there shouldn't be an expectation of security.


They can decrypt, and provide access to law enforcement (and do under warrant):

https://www.apple.com/legal/privacy/law-enforcement-guidelin...




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: