Skip to main content

Privacy

See All Stories

Privacy is a growing concern in today’s world. Follow along with all our coverage related to privacy, security, what Apple and other companies are doing to keep your information safe, and what steps you can take to keep your information private.

ProPublica WhatsApp report acknowledges ‘unintended confusion’ [U]

Site default logo image

Facebook has confirmed to me that all WhatsApp messages are end-to-end encrypted, and that a ProPublica report is based on a misunderstanding. Update: ProPublica has added a ‘clarification’ and amended its story to reflect Facebook’s explanation.

A previous version of this story caused unintended confusion about the extent to which WhatsApp examines its users’ messages and whether it breaks the encryption that keeps the exchanges secret. We’ve altered language in the story to make clear that the company examines only messages from threads that have been reported by users as possibly abusive. It does not break end-to-end encryption.

Expand Expanding Close

UK government backs Apple, and wants to scan encrypted messages for CSAM

Scan encrypted messages for CSAM

The British government has expressed support for Apple’s now-delayed CSAM scanning plans, and says that it wants the ability to scan encrypted messages for CSAM, even where end-to-end encryption is used.

The country is offering to pay anyone who can find a way “to keep children safe in environments such as online messaging platforms with end-to-end encryption” …

Expand Expanding Close

US GDPR-style federal privacy law ‘should replace mess of separate laws’

Site default logo image

Privacy and civil rights activists say that a US GDPR-style federal privacy law should be passed to replace the confusing mass of federal and state laws in place at present. This is an approach also favored by Apple, which wants the simplicity of a single set of privacy requirements across the US.

In the European Union, the General Data Protection Regulation (GDPR) provides the strongest protections ever seen for consumer data, all within a single piece of legislation. The US, in contrast, has no fewer than eight different federal privacy laws, and a mass of current and planned state ones …

Expand Expanding Close

German government admits buying Pegasus spyware, says ‘limited’ to respect privacy laws

German government admits buying Pegasus spyware

The German government has reportedly admitted to buying Pegasus spyware, despite the fact that using some of the functionality would break privacy laws in the country. Privacy is a particularly hot-button issue in the country, given the country’s history.

Sources cited in the report say that the version purchased from NSO had certain features disabled so that its use would be lawful in the country …

Expand Expanding Close

Tim Cook White House visit confirmed; Apple announcement might follow [U]

Site default logo image

Update: Apple did make a security announcement, but only a supply-chain related one.

We learned earlier this week about a potential Tim Cook White House visit to attend a cybersecurity summit hosted by President Biden. Cook’s participation has now been confirmed by a list of attendees shared by an administration official, and could provide an excellent opportunity for Apple’s CEO to drive home the company’s stance on privacy and strong encryption.

A new report today also raises the possibility of a security-related announcement by Apple after the meeting has finished …

Expand Expanding Close

New Pegasus zero-click iPhone attack defeats Apple’s Blastdoor protections

New Pegasus zero-click iPhone attack

A newly discovered NSO Pegasus zero-click iPhone attack against a human rights activist managed to succeed despite Apple’s Blastdoor protections, according to security researchers at Citizen Lab.

It is unclear, however, whether the protections Apple added to iOS 14.7.1 would have succeeded in blocking the attack, as it took place at a time when iOS 14.6 was the latest version available …

Expand Expanding Close

Apple already scans iCloud Mail for CSAM, but not iCloud Photos

Apple scans iCloud Mail for CSAM

Apple has confirmed to me that it already scans iCloud Mail for CSAM, and has been doing so since 2019. It has not, however, been scanning iCloud Photos or iCloud backups.

The clarification followed me querying a rather odd statement by the company’s anti-fraud chief: that Apple was “the greatest platform for distributing child porn.” That immediately raised the question: If the company wasn’t scanning iCloud photos, how could it know this?

Expand Expanding Close

T-Mobile discloses 5.3M more accounts compromised, sensitive data including DOB and address leaked

T-Mobile 3.3Gbps speed 5G SA

In a massive data breach we first learned about earlier this week, T-Mobile is continuing to discover the extent of the damage that’s rising beyond 50 million accounts. In an update today, the uncarrier says it has found an additional 5.3 million current postpaid customer accounts had their name, address, date of birth, or other personal information compromised.

Expand Expanding Close

Apple’s anti-fraud chief said company was ‘the greatest platform for distributing child porn’

Apple's anti-fraud chief child porn statement

Update: A likely explanation for this comment has now emerged.

An explanation for Apple’s controversial decision to begin scanning iPhones for CSAM has been found in a 2020 statement by Apple’s anti-fraud chief.

Eric Friedman stated, in so many words, that “we are the greatest platform for distributing child porn.” The revelation does, however, raise the question: How could Apple have known this if it wasn’t scanning iCloud accounts… ?

Expand Expanding Close

Apple CSAM system tricked, but easy to guard against [U]

Apple CSAM system tricked

Update: Apple mentions a second check on the server, and a specialist computer vision company has outlined one possibility of what this might be – described below under ‘How the second check might work.’

An early version of the Apple CSAM system has effectively been tricked into flagging an innocent image, after a developer reverse-engineered part of it. Apple, however, says that it has additional protections to guard against this happening in real-life use.

The latest development occurred after the NeuralHash algorithm was posted to the open-source developer site GitHub, enabling anyone to experiment with it…

Expand Expanding Close
T-Mobile hack confirmed

T-Mobile hack confirmed, carrier says 47.8M records taken; not just customers

The T-Mobile hack reported earlier this week has now been confirmed by the company. Some of the details differ from claims made by the hacker, but the carrier has admitted that 47.8 million records were taken – and not just from customers. You could be at risk if you have ever even applied for a T-Mobile account, whether or not it was ever opened…

Expand Expanding Close

Corellium will pay for security researchers to check Apple CSAM claims

Site default logo image

Security company Corellium is offering to pay security researchers to check Apple CSAM claims, after concerns were raised about both privacy, and the potential of the system for misuse by repressive governments.

The company says that there are any number of areas in which weaknesses could exist, and they would like independent researchers to look for these…

Expand Expanding Close
Senate bill would require Apple to build a backdoor into iPhones

US Senate bill would legally require Apple to build a backdoor into iPhones

Update: This bill did not get as far as a vote.

This bill was introduced on June 23, 2020, in a previous session of Congress, but it did not receive a vote.

Although this bill was not enacted, its provisions could have become law by being included in another bill. It is common for legislative text to be introduced concurrently in multiple bills (called companion bills), re-introduced in subsequent sessions of Congress in new bills, or added to larger bills (sometimes called omnibus bills).

A bill proposed in the US Senate would effectively make it a legal requirement for Apple to build a backdoor into iPhones. It would make it illegal for Apple and other tech giants to use strong encryption for either devices or cloud services …

Expand Expanding Close

Opinion: The Apple CSAM scanning controversy was entirely predictable

Site default logo image

Update: Within minutes of writing this piece, an interview was posted where Craig Federighi admitted that Apple should have handled things differently.

One thing about the CSAM scanning controversy is now abundantly clear: It took Apple completely by surprise. Which is a surprise.

Ever since the original announcement, Apple has been on a PR blitz to correct misapprehensions, and to try to address the very real privacy and human rights concerns raised by the move …

Expand Expanding Close

Misusing CSAM scanning in US prevented by Fourth Amendment, argues Corellium

Site default logo image

While most of the concerns about governments misusing CSAM scanning to detect things like political opposition have related to foreign governments, some have suggested that it could become an issue in the US, too.

Matt Tait, COO of security company Corellium, and a former analyst at British NSA equivalent GCHQ, says the Fourth Amendment means that this could not happen in the US …

Expand Expanding Close