Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This page says it was last updated a few weeks ago, but the recommendation against iCloud backups seems to have glaring errors and omissions.

> Keys to unlock the phone’s full-disk encryption are also stored in the iCloud backup. This arrangement allows law enforcement to request the backup data from Apple and use the key to unlock the entire phone. It also offers a convenience, where if the user forgets their unlock code, Apple can still recover the device.

This is not true. Even if it were, the advice to activists should in all cases be to enable Advanced Data Protection so that almost everything (except iCloud mail, contacts and calendar) are end-to-end encrypted (including iCloud phone backups). Apple cannot access the data or help in any kind of recovery when Advanced Data Protection is enabled. It is up to the user to set up recovery contacts and recovery key (and keep this safe).



great! here are the github issues for the repo so you can make that change: https://github.com/InfosecForActivistsTeam/infosec-activists...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: