Quote of the day by Apple CEO Tim Cook: 'If you put a key under the mat for the cops, a burglar can find it, too' — a stark warning on threats to undermine privacy
https://www.techradar.com/pro/quote-of-the-day-by-apple-ceo-tim-cook-if-you-put-a-key-under-the-mat-for-the-cops-a-burglar-can-find-it-too-a-stark-warning-on-threats-to-undermine-privacy
990 points · 89 comments · view on lemmy.world
89 Comments
Semi_Hemi_Demigod@lemmy.world · 176 pts · 78d
Why would I leave a key under my mat for the cops in the first place?
DrakeAlbrecht@lemmy.world · 189 pts · 78d
Because the cops convinced the city council to pass a local ordinance mandating that all residents leave a key where the cops can find it.
Semi_Hemi_Demigod@lemmy.world · 36 pts · 78d
Cops can just knock down the door.
DrakeAlbrecht@lemmy.world · 96 pts · 78d
Yeah, they're used to being able to force their way in anywhere, but in the digital space, many people have steel security doors, and the police don't have a battering ram big enough.
themeatbridge@lemmy.world · 59 pts · 78d
Also, kicking down the door leaves evidence and usually require some sort of justification or approval. If they have a key to a backdoor, they don't have to tell anyone they were inside, or ask for permission to use it.
cogitase@lemmy.dbzer0.com · 45 pts · 78d
You wouldn't, but that's what governments are effectively asking be done, lending validity to the analogy.
skvlp@lemmy.wtf · 17 pts · 78d
I mean, it’s not like there’s cases of police committing abuse and misuse, are there…?
Zachariah@lemmy.world · 25 pts · 78d
aeronmelon@lemmy.world · 1 pts · 78d
A rare insight into Tim Cook’s mind.
NSAbot@lemmy.ca · 7 pts · 77d
It’s an analogy to the government asking for backdoors into phones and such
pelespirit@sh.itjust.works · 146 pts · 78d
This Tim Cook?
db2@lemmy.world · 86 pts · 78d
*Tim Apple
Buffalox@lemmy.world · 118 pts · 78d
We have an easy peasy solution to that.
We will just make it illegal for burglars to look under the mat.
And if they do look under the mat, we will also make it illegal fro them to take the key.
Finally we will also make it illegal for burglars to use the key.
See there an absolutely bullet proof solution, so why does the tech industry continue to claim this is a bad idea?
As a politician I simply can't understand why they are so contrary to this idea that will increase safety for everybody!!
/s (just in case)
LovableSidekick@lemmy.world · 18 pts · 78d
Or... you and a friend on another floor put your keys under each other's mats. Then you both always have a way in and the chance of a burglar figuring it out is almost zero.
adespoton@lemmy.ca · 20 pts · 77d
That’s security through obscurity, as well as shared keys.
What happens when the burglar in waiting watches someone grab the key and use it?
Or in the case of phone security, what happens when your address is printed on the key?
A better analogy is fire lock boxes, where apartment complexes have a master key stored in a box out front that can be unlocked with a master key firemen carry.
Unfortunately, that bic pen trick turned out to work on those lock boxes a decade or so ago, meaning all a burglar needed to get into ANY residence in ANY building with a fire lock box was a bic pen. In fact, a burglar could open the box, get the key, duplicate it, put it back in the box, and nobody would even know security had been compromised.
It’s a pretty good analogy for what’s being asked for here.
foo@feddit.uk · 11 pts · 77d
I know it's only a joke, but this comment highlights something that many folk in power seem to forget.
Houses and their doormats are in a single physical location that has an unambiguous legal jurisdiction. In any given country, if you break into a house you are subject to that country's laws.
Not so with the Internet. It's very difficult to legislate for something like this because other countries' laws can just ignore you, and you have no power over those countries and their laws. So, making things physically secure is far more effective than legislation, especially when it comes to the Internet.
Buffalox@lemmy.world · 14 pts · 77d
It's not only a joke, it's an analogy to show how stupid the claims of politicians are, that they want to have a backdoor for law enforcement.
Of course the analogy isn't perfect for the reasons you describe, and those reasons makes it actually worse.
SharkAttak@kbin.melroy.org · 10 pts · 78d
Granted, it's a work in progress; after all the commandment that says "You shall not steal" hasn't fully stopped burgling or thieving, but I'm sure it will happen soon.
Today@lemmy.world · 7 pts · 78d
They just haven't shown it to enough school kids yet. That will fix it!
tomiant@piefed.social · 1 pts · 76d
/s /s
anon_8675309@lemmy.world · 48 pts · 77d
Yeah but we saw how quickly you bowed and kissed the ring of king Trump.
That shit erodes trust.
tourist@lemmy.world · 46 pts · 78d
Talk is cheap
Keep pretending that the NSA doesn't already have a million backdoors in your proprietary garbage, Tim.
kaidenshi@lemmy.world · 10 pts · 78d
Considering they are sending all of your iOS activity back to themselves without encryption, to track you for ad serving, yep.
https://www.osnews.com/story/145322/apple-adds-keylogger-to-ios-app-store-for-targeted-advertising-tied-to-your-account-and-unencrypted/
Snowcano@startrek.website · 22 pts · 78d
So where’s the actual story with the ’provided screenshots’? This article is just some rando saying things.
kaidenshi@lemmy.world · 1 pts · 77d
Clicking links is difficult, I get it. Here, I did that for you:
https://xcancel.com/mysk_co/status/2064401062224879888
Snowcano@startrek.website · 1 pts · 77d
Cool thanks. This doesn’t appear in the original article you provided and when I searched the only result for the topic was that article.
kaidenshi@lemmy.world · 1 pts · 76d
It does you just have to click through to the source cited by Thom. Click the link halfway down the OSnews article, “Michael Tsai, quoting Mysk”, then in the resulting article click the link that says “Mysk”. That takes you to the Xitter post by Mysk with the screenshot and description (I ran it through Xcancel so as not to endure Xitter’s shitty site).
Snowcano@startrek.website · 1 pts · 76d
Ahhh I did click that but was viewing on my phone and it loaded to halfway through the comments and I thought it had just dumped me in a forum discussion. 🤦♂️
kaidenshi@lemmy.world · 2 pts · 76d
Oh weird, it didn’t do that to me before but trying it again now it does the same thing to me. Apologies for the snark.
ennof@feddit.org · 12 pts · 77d
This article is based on... a random twitter post that it does not even link to? I'd like to see concrete data supporting this claim.
Whole article be like: source: trust me bro
pelespirit@sh.itjust.works · 1 pts · 77d
It sounds like you trust Apple. I don't
From 2022: Apple sued for tracking users' activity even when turned off in settings The iPhone maker knows a lot about what a user does on their phone.
https://mashable.com/article/apple-data-privacy-collection-lawsuit
From 2026: Apple plans to change its Hide My Email privacy feature that could make it less effective
https://techcrunch.com/2026/06/16/apple-plans-to-change-its-hide-my-email-privacy-feature-that-could-make-it-less-effective/
From 2026: Siri AI may be privacy-first, but the new 'personal-context understanding' features really creep me out
https://tech.yahoo.com/ai/apple-intelligence/articles/siri-ai-may-privacy-first-051500606.html
adespoton@lemmy.ca · 4 pts · 77d
I don’t trust Apple, but I also don’t blanket distrust them. Of those three articles you posted, the only one that gives me pause is the one from 2022 where Apple was sending App Store navigation data back home. I have NEVER trusted the App Store. It has been intentionally hard to use, using dark patterns, and tracking usage ever since iPhone OS 2. Unfortunately for the researchers, it has also been very clear about this; it’s essentially a website that can only be accessed with their custom client.
Up until recently, I’ve mostly trusted Apple because their business goals align with my personal goals; breaking that trust would only harm them without providing any benefit. Recently however, the services arm of the company has gone more aggressively into advertising; I don’t trust ANYTHING from Apple that’s linked to advertising, which now includes not only the App Store, iCloud, Books, News, Stocks, Fitness, Podcasts, Apple Music and Apple TV, but also Apple Maps.
kobra@lemmy.zip · 35 pts · 78d
I think it's important to note that quote was from 2015.
Imgonnatrythis@sh.itjust.works · 21 pts · 77d
So this was before he just made gurgling noises with Trump's ball sack in his mouth like he does now.
hakase@lemmy.zip · 34 pts · 78d
Especially when the cops ARE the burglars in the first place.
some_guy@lemmy.sdf.org · 32 pts · 77d
Politicians who don't understand technology (and some that do) will continue advocating for a break in encryption "so they can catch the bad guys."
No, you fuck. Either it's protected or it's not. I've just been listening to the latest podcast from 404 Media (you should check them out; print and audio). One of their primary stories is about cops accessing Flock cameras to stalk their ex-partners. AUTHORITY NEEDS LIMITS.
Cops Keep Getting Arrested for Using Flock to Stalk People
lightsblinken@lemmy.world · 3 pts · 77d
yup, and one persons freedom fighter is another person enemy and all that.
some_guy@lemmy.sdf.org · 1 pts · 71d
One fascist boot-licker downvoted me. Hey fascist, no one here likes you.
Snapz@lemmy.world · 30 pts · 77d
Also Tim cook quote, "you're so great Mr. Trump, we had an army man, nake you a special trophy just for you. The base is literally a gold bar that I'm illegally giving you. Isn't that fun, you're so great trump. Thank you trump. I love you trump. It's such a joy to socialize with you trump"
Sightly paraphrased
nonentity@sh.itjust.works · 23 pts · 77d
If Apple were truly serious about an individual’s security and privacy, they’d facilitate self hosted online services as peers to the versions they provide on their platforms.
They can be best in class at what they do, but exclusively locking everyone into their ecosystem obliterates any meaningful good will.
ZeroGravitas@lemmy.dbzer0.com · 23 pts · 78d
Why are you drawing your curtains? You must have something to hide. All your neighbours live in glass houses, why do you insist on this strange idea of privacy? Open up, if you're not guilty there's nothing to be afraid of.
Only guilty people draw the curtains.
wpb@lemmy.world · 4 pts · 77d
Oh an btw I decide what guilty means. Open up your curtains.
LightDelaBlue@jlai.lu · 20 pts · 77d
but YOU are the one GIVING the key to cops tim.
Cocodapuf@lemmy.world · 25 pts · 77d
I think you're missing the point. Apple has famously resisted implemented back doors for the authorities.
He's warning against leaving that metaphorical key under the mat.
LightDelaBlue@jlai.lu · 18 pts · 77d
resisted? the era they pretend to do it is gone.
placebo@lemmy.zip · 4 pts · 77d
CultLeader4Hire@lemmy.world · 3 pts · 76d
It’s stupid but it’s not back door access to you phone
LightDelaBlue@jlai.lu · 0 pts · 76d
trus me bro moment.
asdfasdfasdf@lemmy.world · 9 pts · 77d
LOL
https://www.reuters.com/article/technology/apple-moves-to-store-icloud-keys-in-china-raising-human-rights-fears-idUSKCN1G805Z/
anon_8675309@lemmy.world · 3 pts · 77d
That we know of
DarkFuture@lemmy.world · 19 pts · 77d
You mean Time Apple, the man that was renamed by a pedophile and then gave that pedophile a golden gift to appease him?
Doomsider@lemmy.world · 13 pts · 77d
Stop acting like giving gold bars to a paedophile is bribery. It was obviously a payment for child prostitution.
mecen@lemmy.ca · 17 pts · 77d
Doesn't apple backdoor UK users anyway?
unglueclass23@programming.dev · 9 pts · 77d
I don't think they went through with it.
I remember reading a related article reclaimthenet
floofloof@lemmy.ca · 13 pts · 78d
If you're Canadian, please sign this petition against Bill C-22:
https://www.ourcommons.ca/petitions/en/Petition/Details?Petition=e-7416
ArchEngel@lemmy.ca · 5 pts · 78d
Already signed, took very little time.
tigermountain@lemmy.world · 12 pts · 77d
Especially when the cops are the burglars.
UnderpantsWeevil@lemmy.world · 3 pts · 77d
40% of Cops
NGC2346@sh.itjust.works · 8 pts · 77d
Its also aimed at Bill C-22 in Canada that the liberals are trying to speedrun into a law.
ILikeTraaaains@lemmy.world · 6 pts · 77d
I don’t put a key under the mat, even less for the cops.
poopkins@lemmy.world · 21 pts · 77d
Tim Cook wasn't addressing you personally. It's an analogy.
UnderpantsWeevil@lemmy.world · 1 pts · 77d
The analogy presumes you want cops to have free access to your home
ThrowawayPermanente@sh.itjust.works · 2 pts · 76d
If you don't want the cops to have access to your home that means you have supporting to hide which means that can get a search warrant
KiwiTB@lemmy.world · 5 pts · 78d
Also, we paid some bribes to a fascist so....
lyralycan@sh.itjust.works · 4 pts · 78d
A burglar doesn't intend to fuck up your whole life and/or extinguish it. I prefer the burglar over the cop.
cyberpunk007@lemmy.ca · 3 pts · 77d
American?
lyralycan@sh.itjust.works · 1 pts · 75d
English and vocal against the state's mistakes
LovableSidekick@lemmy.world · 3 pts · 78d
"But," he continued, "If you put an obsolete anthrax-infected key under your mat, that's one burglar we don't have to worry about."
betanumerus@lemmy.ca · 3 pts · 77d
NotMyOldRedditName@lemmy.world · 2 pts · 78d
Nevermind a disgruntled employee just sharing it.
wykopopo@lemmy.world · 2 pts · 77d
If you put the key under the bed, the Esptenos will diddle you and declare you a national security threat.
artyom@piefed.social · 1 pts · 78d
Will* find it.
melsaskca@lemmy.ca · 1 pts · 77d
That's why apple is so cutting edge. Wait, maybe they are just experts in the obvious?
explodicle@sh.itjust.works · 9 pts · 77d
To be fair, their main competition is Microsoft.
UnderpantsWeevil@lemmy.world · 6 pts · 77d
angry Linux noises
TheDuke@europe.pub · 1 pts · 77d
I do not trust apple a single second, that they do not have their own backdoors in their OS. I can't prove it, but I bet they scan their customers just as much as google does. They just say they don't to justify their horrendous prices AND milk them for marketing purposes. Double-wammy.
S4m_S3p1l@infosec.pub · 15 pts · 77d
You are not "giving the key to the cops" with Apple, I am so sick of seeing this bullshit misinformation online regarding user privacy. iCloud storage now provides the ability for users to store their encryption keys on their own devices locally, see 'Advanced Data Protection'. On top of that, even Apple doesn't have the ability to access user encrypted cloud data, because no one besides possibly state level agencies, has the capability to crack AES-256 encryption; hence why it is the industry standard. There was even the famous San Bernadino Legal Case case where Apple flat out denied the FBI a backdoor into a known terrorist's phone because of the wide-scale security risks it would've introduced into their devices. In the end they had to buy a backdoor exploit from an Australian Cyber firm.
Has Apple been notorious for traditionally overspending on advertising, packaging, and hype campaigns to justify higher prices? Absolutely, but in ~2020 Apple realised this wasn't sustainable (at least for their phones) and made a significant pivot towards more affordable iphones. They first test ran this in 2018 when they launched the iPhone XR for $749 alongside the $999 iPhone XS. Then in 2020 they made the actual pivot with the release of the iPhone SE (2nd Gen) for just $399, placing flagship processing power in an older chasis. Then in 2022 they decided to make the same pivot with their Laptops, and for the first time in modern history, Apple intentionally cultivated a tiered budget laptop strategy.. Then you have the release of the Macbook Neo as recently as last year, and now Apple is starting to make budget competitive laptop models.
Anyways I sincerely apologise for these massive walls of text, I promise I am not an Apple shill, I have just been extremely passionate about computing hardware and cybersecurity ever since I began my unboxing video and Edward Snowden interview phase as a kid, so I have been following the evolution of the 2010s hardware and digital landscape era for the entirety of my childhood and adolescence; at a certain point, you get sick and tired of seeing people outright lie and spread misinformation that ends up causing people to make terrible misinformed decisions. What I hate more than anything however, is specifically those who end up demotivating people from exercising proper cyber hygiene (because of doomer propaganda), and making terrible product decisions (especially when it comes to Apple) because of historical misalignments with today's current technology trends (see the .com bubble burst, death of netscape + internet explorer, death of widespread user forums and the corporatisation of the internet, the end of Google's public perception of innocence, and the rise of ML and AI integration).
If you're to take anything away from this rant it should be the awareness that the technological landscape is evolving so fast that you can never be certain you're making an informed decision, without first verifying the validity of whatever beliefs are informing your choice. Something easy you can do, is get into the habit of always asking yourself "Are these beliefs based on current or past facts?"- this line of reasoning has never once failed me my entire life, and I should know considering I've been browsing the web for as long as I've known how to read.
wylinka@szmer.info · 2 pts · 76d
Can anyone break even AES-128 without years of supercomputer time?
S4m_S3p1l@infosec.pub · 1 pts · 75d
To give it to you straight: it would take roughly 1.2 unvigintillion years (that’s a 1 followed by 51 zeros) for the fastest supercomputer on Earth to brute-force AES-256 encryption. In other words, AES-256 is practically unbreakable by modern computing standards. Even if you hijacked every computer on the planet, the sun would literally burn out and the entire universe would experience heat death long before you even made a dent. The above commenter apparently has "foundational level knowledge" of computer systems, yet thinks they can put backdoors into their own products.
Just to give you an idea of how this actually functions in their products; Apple comprehensively bakes encryption into both the hardware and software levels of iPhones and iPads by default, making it one of the most secure consumer operating systems available. Every modern Apple device features a dedicated coprocessor called the Secure Enclave which leverages a Built-in Crypto Engine, to ensure that that all data stored on the device's flash storage is encrypted at the hardware level using an AES-256. On top of that, they utilise UIDs (Unique Device Keys) which are physically fused into the device's silicon, during manufacturing. Neither Apple nor the iOS software itself can read this key directly. These are basically just base keys that encrypt the entire file system (including the OS itself). Because the encryption is tied to the specific hardware, they are not even capable of engineering their own backdoors into their systems, without completely breaking the entire underlying security architecture, which underpins all their devices.
Zeon@lemmy.world · 0 pts · 74d
You're completely disregarding the fact that they could possibly implement a malicious firmware update/supply-chain attack. Saying Apple is not capable of hacking their own systems is such a ridicoulously unbelievable statement.
Zeon@lemmy.world · 1 pts · 77d
Do you really trust these proprietary systems to do what they say they're doing? Sure, the key may be stored locally, but an OS backdoor or compromise could still exfiltrate it, giving users a false sense of security.
S4m_S3p1l@infosec.pub · -1 pts · 76d
It's not about me trusting these proprietary systems, it's about me trusting mathematics, and basing my decisions off historical facts. Apple can't just "magic" backdoors into their devices, and since a significant part of their business model has been in pioneering widespread commercial data privacy, it would literally go against their entire business interests. OS backdoors do compromise devices, which is why Apple pays > $1M for bug bounty hunters who find them first.
The problem with you, is that you have no foundational knowledge of how digital devices work, and that's understandable given how widespread these technologies have become. But trust me when I say, cybersecurity isn't a multi-billion dollar industry for no reason, individuals and large corporations pay a shit ton of money to guarantee they aren't shooting in the dark with their systems security & privacy. If you wanna learn more about this stuff, I highly recommend watching Edward Snowden's video interviews where he talks extensively about what he found in the leaks he made about the NSA, because he's able to detail a lot about what intelligence agencies can and can't do when it comes to this stuff.
Keep in mind though, that encryption has been a fundamental game changer which makes it impossible for the CIA even to create a giant search engine that indexes everyone's data, that was only possible back then because everything was sent in plain text with practically zero wifi security. Now wifi security has become a cybersecurity speciality in and of itself.
Zeon@lemmy.world · 2 pts · 76d
Saying Apple "can't" put a backdoor into their own devices is an absolute claim, they're the ones who control the software, so it's possible in principle. Business incentives and bug bounties reduce the risks sure, but they don't eliminate the pressure or legal mechanisms major governments can apply. Snowden’s documents showed that governments have methods to compel or exploit access, and implementation flaws or covert agreements can defeat cryptography in practice.
I do have a solid foundation in how these systems work. You should read the GNU Manifesto and learn about Free Software, it explains why blind confidence in a completely proprietary stack is to remain untrusted. No one should ever be this certain a proprietary system will always respect users rights.
S4m_S3p1l@infosec.pub · -2 pts · 75d
You are actually retarded if you think you think you know anything about technology after making a ridiculous claim like that. Apple is not putting backdoors in their own systems, show me one shred of evidence. It's obvious that you are going to AI, putting in your argument, and then paraphrasing whatever random answer you get lmfao. Get outta here.
Zeon@lemmy.world · -1 pts · 75d
Oh, so we're going straight to insults because your ego got hurt? That's cute.
Now explain to me this, how could I possibly show you one shred of evidence if their systems are proprietary? Oh right, I can't because they don't provide the source code to nearly any of their software.
See how this works?
Zeon@lemmy.world · 0 pts · 72d
Lol, I'm pretty sure I found your Dread account too, weren't that hard to find 😂
S4m_S3p1l@infosec.pub · 1 pts · 54d
Dread?? How old do you think I am 😂 Tbf I did give the impression I'm old, but I didn't realise I came off as being ancient lmao.
trolololol@lemmy.world · 0 pts · 77d
Why would you want a cop in your house?
ATAB
All Tim Apples are Bastards
1984@lemmy.today · -6 pts · 77d
What privacy? It's not even a discussion anymore, it's gone. No point even talking about privacy. It really is gone.
jve@lemmy.world · 1 pts · 77d
Literally 1984.