this post was submitted on 07 Feb 2025
87 points (100.0% liked)
Apple
17883 readers
237 users here now
Welcome
to the largest Apple community on Lemmy. This is the place where we talk about everything Apple, from iOS to the exciting upcoming Apple Vision Pro. Feel free to join the discussion!
Rules:
- No NSFW Content
- No Hate Speech or Personal Attacks
- No Ads / Spamming
Self promotion is only allowed in the pinned monthly thread
Communities of Interest:
Apple Hardware
Apple TV
Apple Watch
iPad
iPhone
Mac
Vintage Apple
Apple Software
iOS
iPadOS
macOS
tvOS
watchOS
Shortcuts
Xcode
Community banner courtesy of u/Antsomnia.
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
I had thought that 5+ years ago, Google, Apple, Meta, etc. all created "master" private keys that would allow them to unencrypt users' data. At the time, the argument used was to combat CSA material/trafficking. I could be wrong, though. I'll try looking it up later.
Edit:
I did a quick search while on break at work.
Apple claims they have no master key and do not allow governments direct access to their servers. They only provide data when legally required to;
https://www.apple.com/privacy/government-information-requests/
Google claims the same thing.
As for Meta, I could only find anecdotal Reddit posts that seem to somewhat contradict the E2EE claims from Meta, as an example:
https://www.reddit.com/r/privacy/comments/1g6tqg7/meta_ai_scanning_private_conversations/
https://www.reddit.com/r/facebook/comments/1al9dk9/messenger_has_access_to_the_endtoend_encrypted/
So it seems that Meta is likely scanning content before the encryption takes place. So they can still claim that messages are indeed E2EE, but that's useless when their AI tools are still scanning the content beforehand.
There's also this recent development:
https://www.medianama.com/2024/03/223-meta-end-to-end-encryption-europe-interoperability-2/
Tldr; I wouldn't trust Meta's E2EE.
I think trusting Meta's (or Google's) E2EE at any point would have been a bad decision. Facebook thrived on collecting user data, and end-to-end encryption of private conversations spits in the face of that. If it's antithetical to their profits, there's incentive to bypass the intent but still technically be implementing it (on-device keyword scanning, maybe?).
Would like to know that!