Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. Nokia Design Archive (2025)(aalto.fi)
    56comments
  2. Two-Tier Encryption in the UK – Identical Apple Devices, Different Protection(macanorak.com)
    15comments
  3. Linux support is coming to Snapdragon X2 Series(qualcomm.com)
    204comments
  4. Claude discovers a novel enzyme system with CRISPR-like repeats(anthropic.com)
    714comments
  5. Ideas on modernizing the open-source desktop(lwn.net)
    255comments
  6. Meta takes down a critical video about meta AI Glasses after filming at Meta(reddit.com)
    175comments
  7. RAM: the forgotten history (2024)(coredump.cx)
    discuss
  8. When the Debugger Lies(danielmangum.com)
    1comments
  9. The newest ESP32 can run Linux and it's getting close to a Raspberry Pi(xda-developers.com)
    14comments
  10. 'That's so AI ' What gen Alpha's biggest insult tells us(theguardian.com)
    14comments
  11. ArXiv receives multiyear commitments to support it as an independent nonprofit(arxiv.org)
    30comments
  12. OpenAI agent hacked Australian government website, PM says(bbc.com)
    87comments
  13. VSCode's SSH Agent Is Bananas (2025)(fly.io)
    161comments
  14. Contrastive Language Models(contrastive-lm.notion.site)
    25comments
  15. The "Windows XP Box" (2003)(mini-itx.com)
    34comments
  16. Do Food Trucks Need a Commissary Kitchen? Yes – Here's Why That's a Good Thing(thefoodcorridor.com)
    2comments
  17. Virtio-nvgpu: Near-native Nvidia GPU access inside a KVM guest(github.com/nestrilabs)
    51comments
  18. Early rogue AI agent activity and attempts to hack found on urlquery.net(transluce.org)
    150comments
  19. Fixing the Portobello Police Station Clock(pointinthecloud.com)
    106comments
  20. Hackers influence ChatGPT and Gemini to direct users to scam centers(medium.com/arielsimon)
    7comments
  21. Why 'What's Opera, Doc?' looks like that(animationobsessive.substack.com)
    18comments
  22. Mercury 2.5 LLM hits 770 tokens per second(artificialanalysis.ai)
    74comments
  23. Making portable my unportable transputer C compiler(nanochess.org)
    6comments
  24. Meta VR Glasses(meta.com)
    394comments
  25. Women Who Sold Books Door to Door(jstor.org)
    4comments
  26. Making Tailscale Faster(tailscale.com)
    72comments
  27. Automated optimization of a molecular simulation program(shishir-iyer.medium.com)
    2comments
  28. The Year of Internal Tools(geocod.io)
    5comments
  29. The mystery animal on an ancient god's head(signoregalilei.com)
    36comments
  30. A brief history of Windows scroll bar shortcuts(devblogs.microsoft.com/oldnewthing)
    100comments

Two-Tier Encryption in the UK – Identical Apple Devices, Different Protection

65 pointsby 2h agomacanorak.com
15 comments
51m agoHN ↗

Fantastic article, and a real concern for UK Citizens.

50m agoHN ↗

Interesting, the government can demand creating a backdoor and doesn't let anyone tell about it. Basically, outlawing E2EE.

44m agoHN ↗

It's crazy SimpleX is fine being based there. I mean, everything is open, the clients have reproducible builds, but it seems like it may end up being a hassle.

Has the UK started attacking any open source E2EE projects yet?

Apple's control over iOS is the main reason I prefer GrapheneOS so much over it. You get amazing privacy and security without sacrificing control. GrapheneOS has said they won't introduce age verification and a backdoor they obviously won't implement.

5m agoHN ↗

I'm guessing they could, in theory, attack open source projects, but it would not be very effective as those could be infinitely forked. That's the reason why governments will actually support an encourage an oligopoly of proprietary platforms via regulations (e.g. mandatory automated scanning) which only companies can practically comply with.

43m agoHN ↗

Since Epstein is no more, the governments became crazy about going after people's private data, perhaps hoping to find some spice. Like some politicians lost their source.

42m agoHN ↗

If Bill left the UK temporarily would the ability to turn on ADP come back? Or is a device from the UK that’s not able to enroll somehow prevented forever? Not saying that this makes it OK, just curious

40m agoHN ↗

I think country is associated with the iCloud/Apple ID account, not the physical device.

18m agoHN ↗

To an extent. My account is on a different country. Even using a VPN, I was still asked to verify my age to access certain websites. The only explanation I could think of is that iOS abused my consent to them using location data for that.

37m agoHN ↗

Yeah, good point. I wonder what would happen if someone without ADP in the UK changed over the region settings to the United States, switched ADP on, and then switched the region back to the UK. I wonder if anybody's tried this?

28m agoHN ↗

You can switch your Apple ID's region to another country, enable ADP then revert your account's region back to the United Kingdom. You've got to leave Family Sharing first and may also need to adjust/cancel subscriptions - I don't think it's totally straightforward.

22m agoHN ↗

What a crazy answer you've written. In the sense of: it's wild that the procedure is like that.

It's almost as wild as when during the pandemic "lockdown", planes had to take off, burn tonnes of fuel and land empty some minutes later at the same airport, because there's some fucking law about landing spots and how they'd be lost if that bullshit wasn't done.

40m agoHN ↗

The Apple-vs-FBI narrative is constructed fiction. Sure, they didn't make a custom firmware to dump the phone's contents, but that's irrelevant. Everything relevant to the investigation on that phone was in the non-E2EE iCloud Backup, which the FBI got from Apple long before, via normal search warrant means. Apple likely either got an FAA702 order (aka PRISM, aka the "backdoor" that Tim Apple says doesn't exist - it allows the USG to access anyone's iCloud data immediately, with no warrant (it's not an encryption backdoor, just an access backdoor)) or a standard search warrant and most probably turned over everything they had in iCloud instantly, just as they do constantly when receiving a search warrant or FAA702 order. (As I mentioned, the FAA702 order fulfillment is likely instantaneous/automated, which amounts to direct access to the storage servers.)

The whole "Apple won't do what the USG wants" story is farce, engineered specifically to protect Apple's brand image. Following the Snowden drop when we all learned that the USG has unfettered realtime access to everything in iCloud without a warrant via FAA702, Apple had a major fucking crisis on its hands, along with a lot of other companies. (If you think the CIA can't read any object in S3, you simply don't understand how the world works. Note also that AWS has built a custom, one-off, airgapped AWS region ON PREM for the CIA. https://aws.amazon.com/federal/us-intelligence-community/ )

Those CEOs all went to DC and sat down with Obama and talked it out. The official cover story was something like "Obama wants help with healthcare.gov".

The top leaders from the world’s biggest technology companies pressed their case for reform of the National Security Agency’s controversial surveillance operations at a meeting with President Obama on Tuesday, resisting attempts by the White House to portray the encounter as a wide-ranging discussion of broader priorities.

https://www.businessinsider.com/tech-ceo-meeting-with-obama-... (includes photo)

It is very likely that this media plan was discussed and agreed upon in those meetings. Otherwise, nobody sane in any government in Europe would ever buy an iPhone (or let their citizens do same), given that the USG can read all their photos and messages and emails and contacts in iCloud instantly and without a warrant.

(China of course requires Apple run the iCloud servers for Chinese users in China via a joint venture with a CCP-operated company, which preserves the same realtime full access to all iCloud/iMessage data in China for the CCP as PRISM does for the USG.)

Don't believe the marketing hype.

Further reading:

https://en.wikipedia.org/wiki/PRISM

The Snowden releases support very plainly the direct realtime access of the US intelligence community to tech company servers without search warrants (just FISA orders).

It is the single most used data source by the US intelligence community.

https://en.wikipedia.org/wiki/File:Prism_slide_5.jpg

Apple began providing such data in October 2012.

https://commons.wikimedia.org/wiki/File:PRISM_Collection_Det...

https://www.cnet.com/tech/tech-industry/new-slides-reveal-gr...

30m agoHN ↗

Heres a favourite of mine. Apple & Google were/still are syphoning off all mobile device push messages to US government. They flat out denied it for years until it got leaked from another source, as soon as it was out in the open they admitted and said they were doing it all along but weren't allowed to tell anybody due to government NDAs.

https://www.reuters.com/technology/cybersecurity/governments...

These aren't conspiracy theories, these types of secret agreements happen all the time.

EDIT: it seems the original poster I was replying to has deleted their post, and so this may not make as much sense in the thread now.

6m agoHN ↗

Very well written article.

It relays my main concern which is that while current governments may use this in moderation and under judicial oversight, future ones may not. And we should build tools for the future not just for now.

There’s a general regression towards fascist and right wing ideologies in the last few years and I don’t want to be up against a wall one day because someone did something with ignorant best intent.