cross-posted from: https://monero.town/post/462856
Looking for an answer more detailed than just switch to pixel and use graphene or calyx.
What are the recommended changes to use in the Settings App to make Apple more secure and private? Should I just use the Safari browser due to all the browsers being the same as they all use WebKit
I’m looking for suggested changes to staying minimal but increasing privacy and security on iPhone
In the digital age, protecting your personal information might seem like an impossible task. We’re here to help.
This is a community for sharing news about privacy, posting information about cool privacy tools and services, and getting advice about your privacy journey.
You can subscribe to this community from any Kbin or Lemmy instance:
Check out our website at privacyguides.org before asking your questions here. We’ve tried answering the common questions and recommendations there!
Want to get involved? The website is open-source on GitHub, and your help would be appreciated!
This community is the “official” Privacy Guides community on Lemmy, which can be verified here. Other “Privacy Guides” communities on other Lemmy servers are not moderated by this team or associated with the website.
Moderation Rules:
Additional Resources:
E2E refers to data in transit: the data will be encrypted between its source and destination. It says nothing about how that data is protected once it has arrived.
E2E iCloud means a third party won’t be able to snoop on the data while you are reading from iCloud or writing to iCloud. But Apple employees can still log into your account and decrypt the data at rest on iCloud in many circumstances because the data at rest is encrypted against a key held by Apple.
A recent example of how this can go wrong was seen with Azure (which hosts some of iCloud) where a Microsoft dev key leaked and attackers were able to use it to generate a working decryption key for the US Government Azure service (a different product) and read terabytes of government data off the cloud services.
The attackers could have targeted iCloud hosting services instead of the US government and done the same thing for all data in all iCloud accounts not specifically encrypted against a personal key held only in your personal keychain.
And if you use iCloud Keychain of course, the same technique can be used to attack your keychain by pretending to be Apple Support and “recover” the contents of the keychain.
According to Apple they do not have the keys when you enable Advanced Data Protection, which is why they force you to have your own backup recovery methods (recovery key, recovery contacts). When they talk about E2E the endpoints they are referring to are user-owned devices.
iCloud Keychain recovery is also much more complex than you are describing.