logoalt Hacker News

Obscurity4340 • today at 4:36 PM • 2 replies • view on HN

How are they allowed to even offer e2ee Keychain/iCloud Passwords for example? Isnt that subject to lawful access too?


Replies

spr-alex • today at 9:06 PM

That is exactly the question. I took a look and we presented some of our findings at DEF CON 34. There are paths to decrypting e2ee secrets without the passcode, some of these paths are considered vulnerabilities and have received patches (CVE-2026-28864).

0cf8612b2e1e • today at 5:44 PM

Exactly my question as well.

Especially since big tech is steaming ahead to mandating passkeys that only they are allowed to control/backup. Not long until all governments could intercept your passwords to all services.