<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Lee Maguire &#187; Apple</title>
	<atom:link href="http://www.hexkey.co.uk/lee/log/tag/apple/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.hexkey.co.uk/lee/log</link>
	<description>graded snobberies, bawdiness, hypocrisy</description>
	<lastBuildDate>Wed, 04 Jan 2012 23:18:12 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Padlocks</title>
		<link>http://www.hexkey.co.uk/lee/log/2011/06/19/padlocks/</link>
		<comments>http://www.hexkey.co.uk/lee/log/2011/06/19/padlocks/#comments</comments>
		<pubDate>Sat, 18 Jun 2011 23:01:27 +0000</pubDate>
		<dc:creator>Lee</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[crypto]]></category>
		<category><![CDATA[email]]></category>

		<guid isPermaLink="false">http://www.hexkey.co.uk/lee/log/?p=1477</guid>
		<description><![CDATA[&#8220;How long do you want these messages to remain secret?&#8221; Randy asked, in his last message before leaving San Francisco. &#8220;Five years? Ten years? Twenty-five years?&#8221; After he got to the hotel this afternoon, Randy decrypted and read Avi&#8217;s answer. It is still hanging in front of his eyes, like the afterimage of a strobe: [...]]]></description>
			<content:encoded><![CDATA[<blockquote>
<p>&#8220;How long do you want these messages to remain secret?&#8221; Randy asked, in his last message before leaving San Francisco. &#8220;Five years? Ten years? Twenty-five years?&#8221;</p>
<p>After he got to the hotel this afternoon, Randy decrypted and read Avi&#8217;s answer. It is still hanging in front of his eyes, like the afterimage of a strobe:</p>
<p>I want them to remain secret for as long as men are capable of evil.</p>
<p>&#8211; from <a href="http://www.cryptonomicon.com/text.html">Cryptonomicon</a></p></blockquote>
<p>
Whenever I&#8217;m tempted by some shiny future tech thing, or shifting some desktop task to an online service, I still hear the dubious counsel of a much younger self. <em>It&#8217;s centralised. It&#8217;s proprietary. Don&#8217;t let them lock away your computers, man. Don&#8217;t let them own you.<br />
</em></p>
<p>
It&#8217;s the voice of the me who built his frankenstein computers partly out of parts salvaged from skips. Who wasn&#8217;t comfortable using an OS where he didn&#8217;t compile everything from scratch. A boy with too much time on his hands.
</p>
<p>
It&#8217;s the voice of the me who hasn&#8217;t become completely resentful at the amount of time that years of personal computing has eaten up just with the tending, the watering and feeding. The upgrading and backing-up and restoring.  And with every year our personal computers have become more tightly bound to our own <em>real</em> lives. What impact a broken phone when it&#8217;s also your keys or wallet? Or more. There are no &#8220;computer hobbyists&#8221; in the 21st Century.
</p>
<p>
It&#8217;s as if we&#8217;ve woken up into a world where letting a Tamagotchi die was punishable by law. Or karma. Or both.
</p>
<p>
So, while everyone else seemed to focus on the Music Match &#8220;pirate amnesty&#8221; that was offered at the end of the <a href="http://events.apple.com.edgesuite.net/11piubpwiqubf06/event/">Apple WWDC keynote</a>, the slide that caught my attention came about an hour into the presentation.
</p>
<p><img src="http://www.hexkey.co.uk/lee/log/media/2011/06/apple-smime-500.png" alt="" title="Apple S/MIME" width="500" height="272" class="aligncenter size-full wp-image-1475" /></p>
<p>
Almost as an aside, Scott Forstall mentions great features for &#8220;enterprise customers&#8221; such as encrypting email with <a href-"http://en.wikipedia.org/wiki/S/MIME">S/MIME</a>.
</p>
<p>
Of course, alluding to &#8220;enterprise customers&#8221; is like a <i>fnord-wrapping</i> it for a significant sections of the technology press. It conjures up images of the bloated, legacy-supporting suites of the Windows world. <i>Bor-ing, what&#8217;s next</i>?  Apple can&#8217;t really do <i>business</i> business software.  That&#8217;s not a slight, by the way.  More that they don&#8217;t seem interested in adopting the fiction that &#8220;enterprise users&#8221; have fundamentally different requirements from normal users.
</p>
<p>
And normal users are apparently still happily sharing their secrets with the network.
</p>
<p>But I&#8217;ve been thinking about this for a few days, and this seems like it has the potential to be something described as &#8220;controversial&#8221; in future news reports.
</p>
<p>
The me in the past started using internet email around the same time that PGP became widely available.  Keys were signed.  Fingerprints were relayed. And yet almost every mail I&#8217;ve sent since then has been clear text. Which is not to say in the clear.  All my mail these days is submitted and retrieved over TLS encrypted connections, transmitted over TLS when available.  Even DKIM-signed on some accounts. But still clear text. I haven&#8217;t sent an encrypted email in the last decade that didn&#8217;t include the word &#8220;test&#8221; in the subject line.  I can&#8217;t even remember my old pass-phrases.
</p>
<p>
But <em>just having the capability</em> seemed important, even in a country not under rule of oppression. Not dissimilar a philosophy, I suppose, to owning a firearm you hope never need use. A deliberate analogy, since crypto was treated by the US government as a munition for which they attempted to regulate exports (and to a lesser extent still do). Computer security was effectively nerfed at a critical point in the mainstream adoption of the internet. Even downloading web-browsers with SSL support was restricted based on your physical location.
</p>
<p>
This happened just at the point where encrypting communications when from being a hardware problem to being a user interface problem.  Before anyone had a chance to get it right, the webmail providers changed the game.  While they&#8217;ll now happily offer an https interface, Google doesn&#8217;t want you to use effective end-to-end privacy &#8211; how would they be able to mine your communications for behavioural data-points to sell to advertisers? How can it be searched?
</p>
<p>
But perhaps a user behaviour that&#8217;s bad for ad-funded web-centric business can be good for an app-centric business?
</p>
<p>
In the short-term S/MIME is obviously a tick-box Apple needs before big corporate BlackBerry clients consider switching.  For the same reason, I&#8217;d be surprised if the new iMessage system doesn&#8217;t end up with end-to-end encryption in the same way that iChat has supported it when the relevant certificates were available.
</p>
<p>
Full crypto tools have been available on OSX for years, but <em>(literally)</em> hidden away.  Unless you&#8217;ve generated or imported a certificate with Email capabilities, the native Mail program gives no indication that it supports encryption.  Install or generate a certificate using &#8220;Key Chain Access&#8221; and magically new &#8220;sign&#8221; and &#8220;encrypt&#8221; icons appear in the UI. <i>(&#8220;Key Chain Access&#8221; is still a bit intimidating, but it&#8217;s far easier than pouring through the OpenSSL man page.)</i>  In fact, Apple used to offer certificates for .Mac customers that worked with both iChat and Mail. (The email support mysteriously disappearing in 2006… almost as if Apple was about to release a device without S/MIME email support.)
</p>
<p>Signed tweets, anyone? Encrypted DMs? A second factor authenticator?</p>
<p>
I don&#8217;t think it&#8217;s outlandish to imagine that S/MIME (and associated key management) integrated into the iOS ecosystem might be the trigger point at which personal crypto gains significant adoption outside of corporate contexts. The same push we see today toward https for social network access we&#8217;ll might see in securing the more sensitive of our communications.
</p>
<p>
And, while I make a point of not conflating institutional transparency with personal privacy, there&#8217;s a similar mental exercise we all need to perform in separating out the merely private from the confidential. Especially in communications we know to be stored. I&#8217;d expect <em>certain high-profile politicians</em>  to be early adopters.
</p>
<p>
An open standard that&#8217;s supported out-of-the-box on the iPhone and iPad is as close to <i>de facto</i> as you&#8217;re going to get, and it might come to be expected on all competing devices (if it&#8217;s not already there). I&#8217;d expect to see signed receipts (non-repudiation) from online stores (iTunes already uses DKIM, but it&#8217;s not currently reflected in the Mail UI).  Encrypted messages from doctors, banks.  From lawyers.  From the state.
</p>
<p>
And therein, potentially the source of future headlines.  Some governments have a tendency to get grumpy when another source of intelligence ebbs away. BlackBerry has already been offering encryption, but (apart from those using its Enterprise Server) it&#8217;s <a href="http://en.wikipedia.org/wiki/BlackBerry#Government_regulation">not end-to-end</a> so &#8220;legal&#8221; interception still remains a possibility.  Not so on the iPhone if they&#8217;re offering unrestricted public-key , so I&#8217;d expect to see the threat of restrictions in some regimes.  Not that I believe there are many nations capable of effectively keeping the <em>shiny shiny</em> out of the hands of anyone who wants one.
</p>
<p>
There&#8217;s cause for caution in how the world adopts cloud technologies congruently with an unprecedented increase in the unauthorised leaking of both personal and institutional data from online sources. Yet congruously Apple may have announced a potential Crypto-Ragnarök.
</p>
<p>
It&#8217;s almost a shame my younger self isn&#8217;t around to see how it plays out.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.hexkey.co.uk/lee/log/2011/06/19/padlocks/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Night of the long queue</title>
		<link>http://www.hexkey.co.uk/lee/log/2003/10/25/night-of-the-long-queue/</link>
		<comments>http://www.hexkey.co.uk/lee/log/2003/10/25/night-of-the-long-queue/#comments</comments>
		<pubDate>Sat, 25 Oct 2003 22:30:17 +0000</pubDate>
		<dc:creator>Lee</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Apple]]></category>

		<guid isPermaLink="false">http://www.hexkey.co.uk/lee/log3/?p=286</guid>
		<description><![CDATA[Should any photos surface that show me attending the &#8220;Night of the Panther&#8221; launch last night (hint: I&#8217;ll be the only one not wearing black) let me just assure you I haven&#8217;t become one of those &#8220;switchers&#8221;. The evangelical apple-turnovers. The iPod-people. No, my serious philosophical commitment to the ideals of free-as-in-freedom software would prevent me from [...]]]></description>
			<content:encoded><![CDATA[<p>Should any photos surface that show me attending the &#8220;Night of the <a href="http://www.apple.com/uk/macosx/">Panther</a>&#8221; launch last night (hint: I&#8217;ll be the only one not wearing black) let me just assure you I haven&#8217;t become one of those &#8220;switchers&#8221;.  The evangelical apple-turnovers.  The iPod-people.</p>
<p>No, my serious philosophical commitment to the ideals of free-as-in-freedom software would prevent me from ever being tempted by the dark side. That and the fact that I&#8217;ve never been in a financial position to afford an Apple machine.  I&#8217;ve been happy enough using Macs at work and ever since OSX, I&#8217;ve thought of Macs as being the machines I&#8217;d prefer <em>other people</em> were using.  Young, rich, sophisticated urbanites with well-honed aesthetic tastes.  Those I am wont to mock but secretly envy.  Conversely, it is relatively easy <em>not</em> to aspire to owning a machine capable of running the latest Microsoft offering.</p>
<p>Perhaps it&#8217;s a shame that you&#8217;ll never see a long queue of people along<br />
Tottenham Court Road awaiting the latest release of <a href="http://www.debian.org/">Debian </a>buzzing with raw geek-energy and anticipation little removed from that of a <abbr title="science fiction">sci-fi</abbr> sequel premiere. For the hard core, the <em>&#8220;Debian unstable&#8221;</em>, every night is an upgrade.  Every apt-get promises the thrill (or the shock) of the new.</p>
<p>Drawn, cheifly by the prospect of beer &#8216;n&#8217; pizza, I was present at the scared rite of &#8220;installation&#8221; that followed &#8211; but fear not, I maintained my cool cynical distance by occasionally pointing out how the emperor was clad rather scantily on that chilly October night:</p>
<p><strong>Me:</strong> I don&#8217;t think I&#8217;d happily pay <em>another</em> 100 quid just  for a point release.</p>
<p><strong>Nick:</strong> Ahh, but it&#8217;s much more than just a point release.</p>
<p><strong>Me:</strong> So what sort of new stuff does it have?</p>
<p><strong>Matt:</strong> It doesn&#8217;t really have new stuff, it has significant improvements on previous features.  Better bindings for python and perl, that sort of thing.</p>
<p><strong>Me:</strong> Ahh, so it&#8217;s a sort of&#8230; update.  Like a&#8230; point release?</p>
<p><strong>Tom:</strong> I don&#8217;t think I like you.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.hexkey.co.uk/lee/log/2003/10/25/night-of-the-long-queue/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

