Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. Two-Tier Encryption in the UK – Identical Apple Devices, Different Protection(macanorak.com)
    59comments
  2. Nokia Design Archive (2025)(aalto.fi)
    72comments
  3. Linux support is coming to Snapdragon X2 Series(qualcomm.com)
    212comments
  4. Owners mourn spoiled food after firmware update bricks Samsung smart fridges(arstechnica.com)
    75comments
  5. Ideas on modernizing the open-source desktop(lwn.net)
    294comments
  6. Claude discovers a novel enzyme system with CRISPR-like repeats(anthropic.com)
    724comments
  7. Enjoy Every Sandwich(bradmontague.substack.com)
    2comments
  8. RAM: the forgotten history (2024)(coredump.cx)
    2comments
  9. OpenAI agent hacked Australian government website, PM says(bbc.com)
    114comments
  10. The newest ESP32 can run Linux and it's getting close to a Raspberry Pi(xda-developers.com)
    32comments
  11. Meta takes down a critical video about meta AI Glasses after filming at Meta(reddit.com)
    242comments
  12. ArXiv receives multiyear commitments to support it as an independent nonprofit(arxiv.org)
    30comments
  13. When the Debugger Lies(danielmangum.com)
    10comments
  14. VSCode's SSH Agent Is Bananas (2025)(fly.io)
    166comments
  15. Early rogue AI agent activity and attempts to hack found on urlquery.net(transluce.org)
    160comments
  16. Contrastive Language Models(contrastive-lm.notion.site)
    29comments
  17. The "Windows XP Box" (2003)(mini-itx.com)
    37comments
  18. Virtio-nvgpu: Near-native Nvidia GPU access inside a KVM guest(github.com/nestrilabs)
    54comments
  19. Hackers influence ChatGPT and Gemini to direct users to scam centers(medium.com/arielsimon)
    15comments
  20. Oracle Cites 'Force Majeure' to Shield Itself on Controversial Data Center(bloomberg.com)
    5comments
  21. Fixing the Portobello Police Station Clock(pointinthecloud.com)
    110comments
  22. The Year of Internal Tools(geocod.io)
    8comments
  23. Why 'What's Opera, Doc?' looks like that(animationobsessive.substack.com)
    19comments
  24. Automated optimization of a molecular simulation program(shishir-iyer.medium.com)
    2comments
  25. Mercury 2.5 LLM hits 770 tokens per second(artificialanalysis.ai)
    79comments
  26. Women Who Sold Books Door to Door(jstor.org)
    6comments
  27. Making Tailscale Faster(tailscale.com)
    79comments
  28. Making portable my unportable transputer C compiler(nanochess.org)
    8comments
  29. Meta VR Glasses(meta.com)
    409comments
  30. The mystery animal on an ancient god's head(signoregalilei.com)
    37comments

Two-Tier Encryption in the UK – Identical Apple Devices, Different Protection

137 pointsby 3h agomacanorak.com
59 comments
1h agoHN ↗

Fantastic article, and a real concern for UK Citizens.

1h agoHN ↗

Interesting, the government can demand creating a backdoor and doesn't let anyone tell about it. Basically, outlawing E2EE.

1h agoHN ↗

It's crazy SimpleX is fine being based there. I mean, everything is open, the clients have reproducible builds, but it seems like it may end up being a hassle.

Has the UK started attacking any open source E2EE projects yet?

Apple's control over iOS is the main reason I prefer GrapheneOS so much over it. You get amazing privacy and security without sacrificing control. GrapheneOS has said they won't introduce age verification and a backdoor they obviously won't implement.

1h agoHN ↗

I'm guessing they could, in theory, attack open source projects, but it would not be very effective as those could be infinitely forked. That's the reason why governments will actually support an encourage an oligopoly of proprietary platforms via regulations (e.g. mandatory automated scanning) which only companies can practically comply with.

1h agoHN ↗

There's no way to obtain root access on GrapheneOS without making your own builds (which won't be affected by many of the apps adding support for GrapheneOS, who likely would only whitelist the official signing keys) or keeping the bootloader unlocked in perpetuity (because AFAIK there is currently no way to recalculate verified boot hashes on top of a systemless root like Magisk -- not that I even know if that works on GOS in the first place). Some years back I was actually working on calculating AVB2 hashes from a live system rather than ONLY through the Android build process, until TWRP wiped my phone without consent or confirmation due to an OpenRecoveryScript that I absolutely did not put there and I basically stopped tinkering with Android root due to that. I have an iPhone nowadays.

1h agoHN ↗

Since Epstein is no more, the governments became crazy about going after people's private data, perhaps hoping to find some spice. Like some politicians lost their source.

1h agoHN ↗

If Bill left the UK temporarily would the ability to turn on ADP come back? Or is a device from the UK that’s not able to enroll somehow prevented forever? Not saying that this makes it OK, just curious

1h agoHN ↗

I think country is associated with the iCloud/Apple ID account, not the physical device.

1h agoHN ↗

To an extent. My account is on a different country. Even using a VPN, I was still asked to verify my age to access certain websites. The only explanation I could think of is that iOS abused my consent to them using location data for that.

1h agoHN ↗

Yeah, good point. I wonder what would happen if someone without ADP in the UK changed over the region settings to the United States, switched ADP on, and then switched the region back to the UK. I wonder if anybody's tried this?

1h agoHN ↗

You can switch your Apple ID's region to another country, enable ADP then revert your account's region back to the United Kingdom. You've got to leave Family Sharing first and may also need to adjust/cancel subscriptions - I don't think it's totally straightforward.

1h agoHN ↗

What a crazy answer you've written. In the sense of: it's wild that the procedure is like that.

It's almost as wild as when during the pandemic "lockdown", planes had to take off, burn tonnes of fuel and land empty some minutes later at the same airport, because there's some fucking law about landing spots and how they'd be lost if that bullshit wasn't done.

13m agoHN ↗

Off topic - but I am not sure that is true in the UK/EU - did it happen elsewhere in the world?:

Before the COVID restrictions, airlines were required to use their allotted spots at least 80% of the time.[6] During the pandemic, the European Commission temporarily suspended Europe's airport slot rule for a short period.[citation needed] Due to travel restrictions, many flights were cancelled or had limited capacity, which made it difficult for airlines to fulfill all the requirements for possessing an airport slot. The suspension of the slot rule was reinstated in October 2021. After the slot rule was reinstated, the rule only required European airlines to use 75% of their flight slots for the winter season.

https://en.wikipedia.org/wiki/Ghost_flight_%28commercial_avi...

34m agoHN ↗

I changed countries a few months ago. It took me about two months with all the roadblocks, while I already had government issued proofs from both countries about the change and new address.

51m agoHN ↗

I've not looked into it but I suspect this uses eligibilityd, the same thing that does the location based checks to see if EU users can use 3rd party app stores.

From what I remember it uses a combination of things like your current GPS location, your SIM cards reported country and more to determine what country you're really in to restrict certain features.

So it's not as simple as swapping your location in settings, or even traveling to somewhere in the EU, theres a certain sticky-ness to what your device thinks is your current country.

Edit: bit more info on eligibilityd here https://theapplewiki.com/wiki/Eligibility#eligibilityd

1h agoHN ↗

The Apple-vs-FBI narrative is constructed fiction. Sure, they didn't make a custom firmware to dump the phone's contents, but that's irrelevant. Everything relevant to the investigation on that phone was in the non-E2EE iCloud Backup, which the FBI got from Apple long before, via normal search warrant means. Apple likely either got an FAA702 order (aka PRISM, aka the "backdoor" that Tim Apple says doesn't exist - it allows the USG to access anyone's iCloud data immediately, with no warrant (it's not an encryption backdoor, just an access backdoor)) or a standard search warrant and most probably turned over everything they had in iCloud instantly, just as they do constantly when receiving a search warrant or FAA702 order. (As I mentioned, the FAA702 order fulfillment is likely instantaneous/automated, which amounts to direct access to the storage servers.)

The whole "Apple won't do what the USG wants" story is farce, engineered specifically to protect Apple's brand image. Following the Snowden drop when we all learned that the USG has unfettered realtime access to everything in iCloud without a warrant via FAA702, Apple had a major fucking crisis on its hands, along with a lot of other companies. (If you think the CIA can't read any object in S3, you simply don't understand how the world works. Note also that AWS has built a custom, one-off, airgapped AWS region ON PREM for the CIA. https://aws.amazon.com/federal/us-intelligence-community/ )

Those CEOs all went to DC and sat down with Obama and talked it out. The official cover story was something like "Obama wants help with healthcare.gov".

The top leaders from the world’s biggest technology companies pressed their case for reform of the National Security Agency’s controversial surveillance operations at a meeting with President Obama on Tuesday, resisting attempts by the White House to portray the encounter as a wide-ranging discussion of broader priorities.

https://www.businessinsider.com/tech-ceo-meeting-with-obama-... (includes photo)

It is very likely that this media plan was discussed and agreed upon in those meetings. Otherwise, nobody sane in any government in Europe would ever buy an iPhone (or let their citizens do same), given that the USG can read all their photos and messages and emails and contacts in iCloud instantly and without a warrant.

(China of course requires Apple run the iCloud servers for Chinese users in China via a joint venture with a CCP-operated company, which preserves the same realtime full access to all iCloud/iMessage data in China for the CCP as PRISM does for the USG.)

Don't believe the marketing hype.

Further reading:

https://en.wikipedia.org/wiki/PRISM

The Snowden releases support very plainly the direct realtime access of the US intelligence community to tech company servers without search warrants (just FISA orders).

It is the single most used data source by the US intelligence community.

https://en.wikipedia.org/wiki/File:Prism_slide_5.jpg

Apple began providing such data in October 2012.

https://commons.wikimedia.org/wiki/File:PRISM_Collection_Det...

https://www.cnet.com/tech/tech-industry/new-slides-reveal-gr...

1h agoHN ↗

Heres a favourite of mine. Apple & Google were/still are syphoning off all mobile device push messages to US government. They flat out denied it for years until it got leaked from another source, as soon as it was out in the open they admitted and said they were doing it all along but weren't allowed to tell anybody due to government NDAs.

https://www.reuters.com/technology/cybersecurity/governments...

These aren't conspiracy theories, these types of secret agreements happen all the time.

EDIT: it seems the original poster I was replying to has deleted their post, and so this may not make as much sense in the thread now.

43m agoHN ↗

If it was irrelevant then why did the FBI make such a big deal about it? Are you saying the FBI did that just to make Apple look good? Why would they care about Apple's reputation?

36m agoHN ↗

Well in theory more people use an insecure software, the more FBI can monitor

16m agoHN ↗

It was 1984 when I left in 1998. Not missed.

9m agoHN ↗

Border agents in America can search your phone or laptop without a warrant or sufficient suspicion at the border.

Jeff Gray is a man who regularly gets arrested and/or trespassed from public places for holding up a sign saying "God bless the homeless vets". Seems to happen nearly every time he does it at various locations.

Oh, and flock cameras and ICE aren't exactly a sign that America is this beacon of freedom that it likes to portray.

1h agoHN ↗

Very well written article.

It relays my main concern which is that while current governments may use this in moderation and under judicial oversight, future ones may not. And we should build tools for the future not just for now.

There’s a general regression towards fascist and right wing ideologies in the last few years and I don’t want to be up against a wall one day because someone did something with ignorant best intent.

48m agoHN ↗

There’s a general regression towards fascist and right wing ideologies in the last few years

The “fascist” part (authoritarian/totalitarian tendencies) came long before the resurgence of the right, but most people seem to approve of those methods as long as they target those they dislike, so I won’t be shedding any tears for them when it’s their turn at last.

10m agoHN ↗

Very well written article

It is self-evidently written by AI. You can tell from both tropes such as “To bring this into sharper focus” and the fact that it is entirely without an opinion or argument for most of the piece.

40m agoHN ↗

How many of those 30 are unarguably "bad" posts though? Threats of violence and so forth.

34m agoHN ↗

250 years ago some people made some bad posts about throwing some tea into the harbor. Calling for revolution isn't a bad post.

27m agoHN ↗

Big fucking difference between saying you want to throw some tea into a harbor vs inciting that hotels containing asylum seekers should be burnt down.

17m agoHN ↗

That's charitable to say that nobody was saying anything except for "let's drown that tea".

9m agoHN ↗

Weird that you think it was legal for people to say "kill the king" back then.

23m agoHN ↗

And I'd argue that human dignity shall be inviolable

24m agoHN ↗

The chronically online anti-uk folks like to turn a blind eye to anything that’s justifiable for matter of principal.

It’s why the US has such a problem with gun control and laws.

I could argue everyone should have guns, and it’s just bad people, right?

17m agoHN ↗

Right. Switzerland has 100x guns per capita than UK and 2x less intentional homicides than UK.

7m agoHN ↗

Why are we comparing Switzerland? Do you want to try again with the United States?

Let me give it a go; Switzerland has higher gun homicides than the UK.

18m agoHN ↗

I don't know, but the UK has criminalized expressions of support for Palestine Action.

They're dragging grannies off to prison just for holding up signs, and literally accusing them of supporting terrorism.

15m agoHN ↗

If 27/30 meet the bar for "bad" is that an acceptable level of policing speech? 19/30?

9m agoHN ↗

Considering they arrest people for saying "there are only two genders", I'm fairly certain the bar is incredibly low. I'm not sugar-coating this by the way, saw a Youtube video of this happening a week or so ago on one of those police watch videos. Someone in a pub was having a verbal debate with someone about genders, then a bystander told the police and had them arrested for "hate crime" for saying "there are only two genders".

7m agoHN ↗

I dislike harassing, threats, hate speech and everything wrong that people yell to other people.

But I dislike even more that we decide that the solution to it is to pass laws prohibiting speech, and even more that the ones in charge of passing those laws are very incentivised to prohibiting criticism to themselves or their policies or their ideologies.

31m agoHN ↗

I’d say it is a very low quality article. There is very little detail about what the offending speech actually includes. For example:

The wife of a conservative politician was sentenced to 31 months in prison for what police said was an unacceptable post.

What did she say? The article does not elucidate.

Inciting violence for example is not legal. I believe spaces around abortion clinics are also to be free from demonstrations. US free speech absolutists seem to vehemently disagree until you say something unkind about Charlie Kirk or ICE.

The low point might be quoting Elon Musk. This is true in any context, but in particular here. The scandal is real, but none of it is about people being arrested for non-politically-correct speech.

There’s plenty of otherwise real stuff to poke the UK about.

11m agoHN ↗

UK abortion clinic laws go a lot further than banning demonstrations.

1. Holding up a sign offering help to any women being coerced into an abortion is illegal. 2. Standing silently on the road near one can be illegal. 3. parking a car with a bumper sticker near one can be illegal.

The whole paragraph about Musk and rape gangs is nonsense, of course. The biggest rape gang ever convicted in the UK was entirely white. Musk and his ilk only care about rape when the rapists are not white. On average immigrants are slightly less likely to commit sexual assaults (obviously averaging across many different groups).

What did she say? The article does not elucidate.

She called for hotels housing asylum seekers to be burned. I think she is a nasty racist but I also think the sentence was excessive and I am not convinced it was a serious incitement to violence (and that was not what she was convicted of).

US free speech absolutists seem to vehemently disagree until you say something unkind about Charlie Kirk or ICE.

Not American, and I entirely support the right of anyone to make unkind comments about anyone else. You are right that many people apply different standards to their own side, but right wing Americans are are from alone in that.

28m agoHN ↗

This is a deeply deranged opinion piece. The author ties himself into knots to conflate a tiny number of high profile instances involving social media posts with harassment and other negative behavior involving electronic communication.

19m agoHN ↗

The wife of a conservative politician was sentenced to 31 months in prison for what police said was an unacceptable post.

Pretty sure she called for the murder, by arson, of asylum seekers although the article missed that bit out.

18m agoHN ↗

Everyone should read the case of the IT consultant getting arrested in the UK because he posted a photo of him doing some target shooting during a trip to the US: https://www.lbc.co.uk/article/consultant-arrested-linkedin-s...

Stories like this quickly put to rest the idea that everyone who gets arrested must actually deserve it. The bar for posting content that violates the law is very low.

16m agoHN ↗

they already arrest over 30 people a day for speech that offends the prevailing political orthodoxy.

This is completely false and comes from a commonly misrepresented statistic; '30 arrests a day' is plainly the arrests made under section 127 of the Communications Act 2003 and section 1 of the Malicious Communications Act 1988 which includes things like online stalking and harassment. I hope you're just mistaken and not willfully implying that those issues are merely offensive to the prevailing political orthodoxy.

46m agoHN ↗

Just checked - I’m on the lower tier. FFS

Getting really tired of the UK govs incompetence/maliciousness around digital law making

32m agoHN ↗

This’ll go down well (/s) but if you accept that the State has the right to be able to surveil public communications infrastructure (which it has been doing since paper mail was invented, through: radio, telegraph, telex, telephone, fax, email, and mobile telephony) then it’s not surprising certain commoditised public data handling services might be required to provide government access on demand or be restricted from implementing features that can effectively deny that access.

That angry’s up the blood of libertarians, but ultimately from the point of view of the State it has to be able to do its job of detecting and prosecuting serious crime, and it will redraw privacy lines whenever that is substantially impeded by new technology.

28m agoHN ↗

The quantity and quality of communications that have been externalized and become effectively searchable and retrievable has increased by many orders of magnitude since paper mail was invented. I think even if you agreed that the State might have had that right then (which not everyone would), it would be good to reconsider what that means with the communications and information systems of today.

29m agoHN ↗

I genuinely believe that in 2015 Apple had the balls to resist and today they don't.

I am judging by a simple fact, that "please confirm your age" screen is now mandatory during the iPhone setup in all countries, and in some it's behind a KYC. I have a strong opinion that this is insane. And once they let the foot in the door - there is no closing it.

16m agoHN ↗

They never did. they had the balls to resist against western governments, where it was politically adventagous to do so. They folded to China real quick, because they wanted to make sales. All "icloud storage" in china has been on another storage platform, that follows all the local laws.

9m agoHN ↗

The only thing where they tried to push back very hard was the EU's DMA, beyond that they folded quickly to absolutely everything else.

8m agoHN ↗

A non-trivial reason I bought a fairly closed device (macbook) was that Tim Cook, at least publicly, told the FBI to get bent when asked to create a backdoor. Exactly what I want to see, a fight in court.

I would hope to see Apple pull out of the UK market over this, and certainly to stop selling Apple devices to the UK government and to remove the UK government entities from Apple services.

7m agoHN ↗

Faced with a legal order that would have required it to change the security architecture on which ADP depended, Apple found a third option: stop offering the feature that made this dilemma exist in the first place. It reverted affected UK iCloud data to Standard Data Protection, where Apple does hold the keys and can respond to lawful legal procress (except the baseline categories that stay end-to-end encrypted either way). This satisfied the underlying legal requirement without ever building a ‘backdoor’.

Maybe Apple should withdraw all encryption support from all UK government accounts. The Prime Minister can use a Huawei or some chunky thing from a military contractor.

5m agoHN ↗

Strange and hypothetical thought: could Bill purchase a US or international model of the iPhone with US or international iCloud account capable of ADP to activate ADP? Would this allow somebody living or working in the UK the ability to use ADP?