Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You are correct, but how could Apple solve this issue without hashing? Syncing files alone without E2E is tricky. I can't imagine a way to sync files between devices without having some sort of hash or id.


You encrypt a file first, then you calculate hash of the encrypted file.


That would prevent file de-duplication.


Big...deal...? That wouldn't be a "you" problem. That would be an Apple problem. If you pay for cloud service (say 100GB), Apple has no business "optimizing" or de-duplicating anyways. If you want it as an option, sure.

But let's not pretend this isn't a subtle backdoor that can invalidate the entire "E2E" implementation. I believe that in the US, having the filename and/or hash/checksum is most of what is necessary to trigger the Foregone conclusion doctrine and force the person to lose their 5th amendment protection and be compelled to decrypt their data to be used against themselves.

I'd like if someone with legal knowledge could comment if my understanding is correct.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: