It’s already been proven that not only can Apple decrypt some of your data, they are more than willing to hand it over. They are a willing tool in the government’s quest to oppress society.
nope, neither of your sources says they can decrypt your content. in particular, from your first:
Data transmitted to Google and Apple includes metadata “detailing which app received a notification and when, as well as the phone and associated Apple or Google account to which that notification was intended to be delivered,” Wyden wrote. Sometimes data shared may include “unencrypted content, which could range from backend directives for the app to the actual text displayed to a user in an app notification,” Wyden warned.
note that iCloud Calendar, Contacts and Mail can’t be e2e encrypted, for fundamental reasons (notifications, discovery, SMTP.) but you don’t have to use those.
They have root access on your phone and it doesn’t function without constantly connecting to apple severs for every little thing. If Apple wants access to your data, they’re gonna get access.
I know you mean the best, but an iPhone isn’t any better privacy-wise than an Android is. Regardless of their public stance, these giant monoliths have proven time and time again there’s no respect for an individual’s privacy. If they get caught lying/breaking the law, the fine is merely the cost of doing business.
It would be better to focus on universal ways someone could keep themselves safe. Drop WhatsApp/SMS for Signal, drop Chromium based browsers, use uBlock, a VPN, etc. Arguing over phones is just infighting and not worth the energy.
I disagree on dropping Chromium-based browsers. drop Chrome/Edge/etc. certainly, but Firefox is kept alive by a skeleton crew at this point, and almost certainly has more vulnerabilities than Chromium browsers. the sandboxing and process isolation, the defense in depth, it just isn’t there.
I use Vanadium, which has all telemetry disabled, JIT off by default, and blocks ads.
I will never understand why anyone trusts a corporation who has proven time and again to spy on their own users and report back to the government, even before Trump was on the scene. I guess Cypher was right, ignorance is bliss.
I don’t trust corporations. I trust math, and code, and systems design. I trust AES-256, even though the NSA picked it, because 20 years of cryptography research has revealed nothing close to a break. I trust SELinux, even though NSA invented it, because hundreds of kernel devs from around the world have audited it and touch that code regularly. I trust even proprietary systems which have been extensively independently audited and reverse engineered by security researchers, though I do trust them less.
It’s already been proven that not only can Apple decrypt some of your data, they are more than willing to hand it over. They are a willing tool in the government’s quest to oppress society.
https://arstechnica.com/tech-policy/2023/12/apple-admits-to-secretly-giving-governments-push-notification-data/
https://appleinsider.com/articles/22/02/25/surveillance-firm-says-apple-is-phenomenal-for-law-enforcement
nope, neither of your sources says they can decrypt your content. in particular, from your first:
as for your second, that’s for unencrypted iCloud backups. you have to turn Advanced Data Protection on: https://www.macworld.com/article/2606947/icloud-encryption-how-secure-is-your-data.html
note that iCloud Calendar, Contacts and Mail can’t be e2e encrypted, for fundamental reasons (notifications, discovery, SMTP.) but you don’t have to use those.
They have root access on your phone and it doesn’t function without constantly connecting to apple severs for every little thing. If Apple wants access to your data, they’re gonna get access.
I know you mean the best, but an iPhone isn’t any better privacy-wise than an Android is. Regardless of their public stance, these giant monoliths have proven time and time again there’s no respect for an individual’s privacy. If they get caught lying/breaking the law, the fine is merely the cost of doing business.
It would be better to focus on universal ways someone could keep themselves safe. Drop WhatsApp/SMS for Signal, drop Chromium based browsers, use uBlock, a VPN, etc. Arguing over phones is just infighting and not worth the energy.
I disagree on dropping Chromium-based browsers. drop Chrome/Edge/etc. certainly, but Firefox is kept alive by a skeleton crew at this point, and almost certainly has more vulnerabilities than Chromium browsers. the sandboxing and process isolation, the defense in depth, it just isn’t there.
I use Vanadium, which has all telemetry disabled, JIT off by default, and blocks ads.
I will never understand why anyone trusts a corporation who has proven time and again to spy on their own users and report back to the government, even before Trump was on the scene. I guess Cypher was right, ignorance is bliss.
I don’t trust corporations. I trust math, and code, and systems design. I trust AES-256, even though the NSA picked it, because 20 years of cryptography research has revealed nothing close to a break. I trust SELinux, even though NSA invented it, because hundreds of kernel devs from around the world have audited it and touch that code regularly. I trust even proprietary systems which have been extensively independently audited and reverse engineered by security researchers, though I do trust them less.