iCloud Backup Encryption
The cluster debates whether Apple's iCloud backups are truly end-to-end encrypted, highlighting how they undermine iMessage privacy by giving Apple access to user data and keys.
Activity Over Time
Top Contributors
Keywords
Sample Comments
Data backed up to iCloud is not yet encrypted in a way that Apple cannot access it.
Well for example, it is well documented that although their messages in cloud feature is "end to end encrypted", as soon as you enable icloud phone backups, apple has access to all your messages. A similar issue likely arises with this.
iCloud encrypts backups at rest but it's not encrypted with a key that only the user has, it's encrypted with Apple's key.
I thought that stuff was all encrypted, and Apple couldn't see it?
Your statement is nonsensical. Either Apple has the key, or it's end to end encrypted. Both cannot be true. And in fact Apple has the key, even if you turned off iCloud backups in most cases since the person you're talking to probably has it enabled. Which makes the marketing misleading at best, and downright fraudulent at worst.BTW both Apple and Google have a way of doing end to end encryption of backups with a recovery option in the case of device loss. Apple deliberately
Just a bit lower on the same page:> When iCloud Backup is turned on, everything inside it is end-to-end encrypted, including the Messages in iCloud encryption key.Meaning that Apple does not actually have access to that key, because it is encrypted before being saved to their servers.
Yes Apple is willingly staying quiet about your iMessage backup being accessible by them. But it does not change the fact that iCloud Keychain is end-to-end encrypted with Apple incapable of accessing your keychain.
In my understanding, iCloud is not E2E encrypted. They hold the keys. They can scan content on ingress if they want.
iCloud backups are encrypted, just not end to end. Which is as good as not encrypted.
Actually, iCloud backups are not end to end encrypted, which is a massive hole in Apple's privacy stance.