Slashdot Mirror


Tim Cook Says Apple Can't Read Users' Emails, That iCloud Wasn't Hacked

Apple CEO Tim Cook insists that Apple doesn't read -- in fact, says Cook, cannot read -- user's emails, and that the company's iCloud service wasn't hacked. ZDNet presents highlights from Cook's lengthy, two-part interview with Charlie Rose. One selection of particular interest: Apple previously said that even it can't access iMessage and FaceTime communications, stating that such messages and calls are not held in an "identifiable form." [Cook] claimed if the government "laid a subpoena," then Apple "can't provide it." He said, bluntly: "We don't have a key... the door is closed." He reiterated previous comments, whereby Apple has said it is not in the business of collecting people's data. He said: "When we design a new service, we try not to collect data. We're not reading your email." Cook went on to talk about PRISM in more detail, following the lead from every other technology company implicated by those now-infamous PowerPoint slides.

14 of 191 comments (clear)

  1. Lie. by jddj · · Score: 2, Insightful

    Since when is anyone's SMTP email secure in transit, when is anyone running a mailserver unable to read the mail?

    Since when is any company immune from subpoena or contempt of court?

    1. Re:Lie. by jddj · · Score: 3, Insightful

      Look, where would ./ be if posters read TFA?

      Looks to me like the ./ summary is claiming something that the ZDNet article does not. So yeah, not a lie on Cook's part, or not one the ZDNet article demonstrates anyway.

      I still wouldn't trust any company not to hand over my information to the government. Lavabit was one hell of an exception, and one geeks the world over should be proud of.

      Neither would I trust that email content I didn't personally encrypt with my own keys couldn't be seen by others.

      Apple doesn't have to be relaying email for others in order for Apple to be able to see the contents of all SMTP traffic that transits or terminates at their mail servers. SSL for SMTP means nothing if the mail server is pwned or intentionally logging stuff due to a business mandate or government subpoena or pressure.

      So Tim Cook didn't tell that particular lie. Good. But "We don't read your email" is an assertion, and one generally impossible to prove true (though more easily possible to prove false, given a certain amount of evidence).

    2. Re:Lie. by gnasher719 · · Score: 2, Insightful

      I still wouldn't trust any company not to hand over my information to the government. Lavabit was one hell of an exception, and one geeks the world over should be proud of.

      But then Lavabit made the big mistake of being _capable_ of decrypting your data. Once they were _capable_ of decrypting it, that was it, and they started a fight with the government that they couldn't win.

      With Apple's iMessage system, they _can't_ read your data. And since they _can't_ read your data, Tim Cook can refuse to give them your data (actually, he can't give them your data anyway because he just can't) without fear of having to go to jail for this refusal. So no heroics needed for Apple. Much better solution than Lavabit.

  2. Whoops by Anonymous Coward · · Score: 2, Insightful

    The partial quote distorts what he said. The "Apple cannot read" part is specifically about iMessage, not email.

  3. Re:Is this technically impossible - no. by Pieroxy · · Score: 5, Insightful

    He makes a fair point. The data stored at Apple does not generate revenue for Apple, at the contrary of Google - where your emails are scanned for content to target ads at your eyeballs.

    Now, jumping from that to "We cannot do it even if we wanted to" is quite a leap forward. I'm not sure I trust that part of the statement.

  4. Re:Is this technically impossible - no. by fustakrakich · · Score: 5, Insightful

    Is he required to lie about this?

    Very likely, if I can read my mail, so can he. It's only logical.

    --
    “He’s not deformed, he’s just drunk!”
  5. Re:Not Hacked? by jratcliffe · · Score: 5, Insightful

    Actually, it's more the distinction between "they broke into the bank vault and went through your safety deposit box" and "they pickpocketed you, and used your key and a fake ID to get into your safety deposit box."

  6. Re:Is this technically impossible - no. by Anonymous Coward · · Score: 5, Insightful

    Wrong! They have the ability to reset your password without losing your data so they would need to have either have access to the password itself or the keys to decrypt stored data.

  7. The old Jackie Mason routine by superwiz · · Score: 3, Insightful

    Reagan was happy, he was always smiling

    They asked him, "what about the defiicit?"

    He said, "there is no deficit!"

    They told him, "but there is!"

    So he said, "so there is."

    ...

    30 years later

    There is is no emal theft! But there is!.... waaaait for it.

    --
    Any guest worker system is indistinguishable from indentured servitude.
  8. Re:Not Hacked? by fustakrakich · · Score: 3, Insightful

    It's why you can't sentence a corporation to death...

    Ah, but you can. Its charter can be revoked, should we ever vote for people who would do such a thing, but that's not very likely.

    --
    “He’s not deformed, he’s just drunk!”
  9. Re:Is this technically impossible - no. by knightghost · · Score: 2, Insightful

    That is the best proof I've seen in this discussion.

    Summary for the unwashed masses: Tim Cook is a big fat liar!

  10. False Headline by Bob9113 · · Score: 4, Insightful

    Tim Cook Says Apple Can't Read Users' Emails,

    No he didn't.

    Apple previously said that even it can't access iMessage and FaceTime communications, stating that such messages and calls are not held in an "identifiable form." [Cook] claimed if the government "laid a subpoena," then Apple "can't provide it." He said, bluntly: "We don't have a key... the door is closed." He reiterated previous comments, whereby Apple has said it is not in the business of collecting people's data. He said: "When we design a new service, we try not to collect data. We're not reading your email."

    He said they cannot read iMessage and FaceTime, and they are not reading your email. That is a very important distinction. It might be one he was hoping you would miss, and you did miss it, but he did not say they can't access your email.

    And I'm not blowing sunshine up his skirt. I came here intending to kick him in the balls (metaphorically, of course) for lying, but he didn't.

    Pro-tip: If any system includes a password recovery mechanism that allows you to get back messages, then the administrator of the password recovery system can read your back messages.

  11. Re:Is this technically impossible - no. by Trailer+Trash · · Score: 5, Insightful

    People are conflating the "iMessage & Facetime" part of the quote with the "email" part. He says that they cannot (that is to say "do not have the ability") to read iMessage & Facetime. He then states that they do not read your email. People are pulling the "cannot" along with them when they read that sentence, but it doesn't say that they cannot read email, only that they choose to not read your email.

    Your description of the iMessage encryption is good, but what the original poster said was true given a few constraints. So let me restate it in a logically consistent manner: if I can read my icloud email on any browser then apple also has the ability to read it.

    But, but, maybe they encrypt it using your password on their server! If they did, "change password" would always require the old password and if you forgot your password your email would be lost forever. So, no, they're not doing that.

    The bottom line is that if they can show me my email in any browser (which they can) then they can also read it trivially.

    This isn't inconsistent with Cook's statement - he merely says that they choose to not do that.

  12. Re:If true thats great by NotDrWho · · Score: 2, Insightful

    If it were true, the U.S. government would have already come after them full force. No one tells the U.S. government "No" without serious consequences. Just ask Yahoo.

    --
    SJW's don't eliminate discrimination. They just expropriate it for themselves.