Hacker News new | past | comments | ask | show | jobs | submit login

Don't they use Google Cloud for ICloud storage?



They use multiple types of cloud storage; the data is encrypted and Google isn’t processing it, just storing it.


A common misconception - parts of iCloud data are encrypted at rest, but a good chunk of it is not. They've indicated they want to get there at various points in the past, but unless I've missed an update it's not there currently.


The files are still encrypted at rest (using convergent encryption) to obscure their contents from the underlying storage service, but Apple holds the keys:

> Each file is broken into chunks and encrypted by iCloud using AES-128 and a key derived from each chunk’s contents that utilizes SHA-256. The keys and the file’s metadata are stored by Apple in the user’s iCloud account. The encrypted chunks of the file are stored, without any user-identifying information, using third-party storage services, such as S3 and Google Cloud Platform.

https://www.apple.com/business/docs/iOS_Security_Guide.pdf (page 56)


>Apple holds the keys

Unless you live in China, in which case Apple and the Chinese government hold the keys.


We don't know this to be the case.

Unless you some evidence to the contrary ?


The Chinese government made Apple hand over control ofiCloud infrastructure in China to a Chinese company. So those encryption keys stored in iCloud are now in the hands of aChinese company subject to Chinese government control.

Not exactly an ideal arrangement, but it was likely that or switch off iCloud in China, or pull out of China completely. Which to be fair Google actually did.


Again. There is no evidence that has been presented to date that indicates that hardware keys were given to the Chinese government.

We suspect it may have happened. But nobody actually knows.


Files encrypted at rest on Apple’s servers represents protection for Apple against external threats, not for the user.

These are security schemes that do not enhance the user’s privacy.

It’s cool that some companies are security conscious enough to do this, but for the user’s privacy remember that ... if it’s not end to end encrypted, it doesn’t matter for privacy, just for security and those two notions are very different ;-)


According to this (https://support.apple.com/en-us/HT202303) everything is encrypted at rest on the server, except for mail.

Everything isn't end-to-end encrypted, is that what you are talking about?


Agreed. It's the main reason why iCloud isn't HIPAA compliant


Using multiple storage providers makes iCloud non-HIPAA compliant? Or did you mean something else?


I believe so but that’s an implementation detail. They could switch to AWS or Azure.


They heavily use AWS, Google Cloud, and Azure.


Not anymore for Azure. Google Cloud replaced Azure for them.

https://www.apple.com/business/docs/iOS_Security_Guide.pdf

Control (Command) + F and there's no mention of Azure anymore.


Looks like they use Google Cloud and AWS. I assume they’ve built their platform in a way that they can easily use many different providers.

https://www.theverge.com/2018/2/26/17053496/apple-google-clo...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: