• JoshCodes@programming.dev
    link
    fedilink
    English
    arrow-up
    1
    ·
    16 hours ago

    I’m assuming someone is tired here, and it could well be me, but isn’t that quite literally what I said? People were saying E2EE doesn’t mean the data is secure when it gets there, I was trying to separate the discussion into at rest (secure storage) vs in transit (E2EE) because they’re different applications of encryption. I wasn’t really intending to argue about Apple’s practice’s.

    From reading, it is encrypted at rest, which sounds like an Apple thing to do. Decrypted at rest feels very Google. Apple state on their standard plan they store the keys in their data centres which I think is what others were talking about? They say they can help recover them so they’re accessible in some capacity between the user and Apple.

    On their advanced plan details:

    Advanced Data Protection for iCloud is an optional setting that offers our highest level of cloud data security. If you choose to enable Advanced Data Protection, your trusted devices retain sole access to the encryption keys for the majority of your iCloud data, thereby protecting it using end-to-end encryption. Additional data protected includes iCloud Backup, Photos, Notes, and more