Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Sure, different devices can be used they share the same key as stated in the document.

But it’s still not clear how that key is derived. It’s not clear, as implemented that Apple do not hold a master key to decrypt all data (as they do currently).

In fact, if the key is randomly generated, if you have one device (as many users do) and you lose that device. Do you lose all your data? Even if you have your iCloud password?

It doesn’t make sense. It would be a massive change to how iCloud currently operates and is used. And I find this extremely unlikely.

Right now, you can browse your photos online. That functionality is going away?

There are seemingly many open questions. But given that there’s no clear statement from Apple, I’m inclined to believe that they retain the ability to decrypt all data.



Most likely you can’t browse your photos online anymore, unless they add some kind of method to export keys from the device(s). I speculate that it is possible to lose all of your data if you lose all of your devices. There might be option to create local backup from device keys, so it would not be the dead end.


Given the lack of an explicit announcement this seems very unlikely.

I don’t think Apple are stupid, it would have been a clear PR win if they said “we’re adding E2EE”.

Given no explicit statement, and how drastically it changes the nature of their service, I don’t think your speculation is justified.


The problem is, that this was not supposed to be released properly yet. Missleading leak caused them to hurry. About E2EE it is not speculation because it is literally on their papers what I linked?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: