I genuinely believe that in 2015 Apple had the balls to resist and today they don't.
I am judging by a simple fact, that "please confirm your age" screen is now mandatory during the iPhone setup in all countries, and in some it's behind a KYC. I have a strong opinion that this is insane. And once they let the foot in the door - there is no closing it.
show comments
failbuffer
No need to speculate that the UK government "might" one day become the bad guys: they already arrest over 30 people a day for speech that offends the prevailing political orthodoxy.
"Withdrawing ADP in the UK did not affect the 14 iCloud categories that were already end-to-end encrypted by default, including iCloud Keychain and Health. ADP increases the total from 14 to 23 categories. For UK users without ADP, the additional categories (iCloud Backup, Photos, Notes, iCloud Drive and so on) revert to Standard Data Protection. ↩
"
Unfortunately this first phrase is not strictly true in the sense that UK customers have their e2ee secrets exposed under common use cases, without requiring a passcode. My copresenter and I published some research at DEF CON 34 this year showing how the e2ee data is particularly vulnerable when ADP is off. Overall, people that do not work with extraction capabilities are currently over-estimating the strength of apple's e2ee and encryption in general. The platform security whitepaper documentation is insufficient on transparency and there are a number of best practices Apple is not following to better meet the e2ee claims they currently advertise.
palmotea
> Faced with a legal order that would have required it to change the security architecture on which ADP depended, Apple found a third option: stop offering the feature that made this dilemma exist in the first place. It reverted affected UK iCloud data to Standard Data Protection, where Apple does hold the keys and can respond to lawful legal procress (except the baseline categories that stay end-to-end encrypted either way). This satisfied the underlying legal requirement without ever building a ‘backdoor’.
Maybe Apple should withdraw all encryption support from all UK government accounts? The Prime Minister can use a Huawei or some chunky thing from a military contractor.
show comments
Hasz
A non-trivial reason I bought a fairly closed device (macbook) was that Tim Cook, at least publicly, told the FBI to get bent when asked to create a backdoor. Exactly what I want to see, a fight in court.
I would hope to see Apple pull out of the UK market over this, and certainly to stop selling Apple devices to the UK government and to remove the UK government entities from Apple services.
show comments
codedokode
Interesting, the government can demand creating a backdoor and doesn't let anyone tell about it. Basically, outlawing E2EE.
show comments
pirates
If Bill left the UK temporarily would the ability to turn on ADP come back? Or is a device from the UK that’s not able to enroll somehow prevented forever? Not saying that this makes it OK, just curious
show comments
RandomGerm4n
What I don't understand is why Apple is even responding to this absurd demand. Completely banning Apple products in the UK isn't a realistic option for the government, so Apple could simply state openly that it does not cooperate with authoritarian regimes and actively prompt British users via a pop-up to enable ADP to protect themselves from the government.
show comments
ABNW
Fantastic article, and a real concern for UK Citizens.
show comments
jasonjei
Strange and hypothetical thought: could Bill purchase a US or international model of the iPhone with US or international iCloud account capable of ADP to activate ADP? Would this allow somebody living or working in the UK the ability to use ADP?
show comments
selicos
If ensuring digital devices can be accessed by law enforcement (are not "beyond the law") is so important where are the task forces shutting down crypto and networks using unregulated and anonymous currency? Literally follow the money, as they say. The current admin has 'made' millions if not more off his own fraudulent coin. Take down crypto and you stop crime instead of destroying privacy.
show comments
puppycodes
The UK's hostility to privacy is legendary.
Used to live there now I don't even want to visit.
Cider9986
It's crazy SimpleX is fine being based there. I mean, everything is open, the clients have reproducible builds, but it seems like it may end up being a hassle.
Has the UK started attacking any open source E2EE projects yet?
Apple's control over iOS is the main reason I prefer GrapheneOS so much over it. You get amazing privacy and security without sacrificing control. GrapheneOS has said they won't introduce age verification and a backdoor they obviously won't implement.
show comments
sjpb
given the story there, I'm surprised apple are still allowed to apply end to end encryption the the "baseline categories" such as messages etc in the UK. Anyone understand how that's happened? To be clear I am not saying what I think should happen, just it seems inconsistent with the UK's stance
468854259853
On brand for two-tier Keir.
Grimeton
>. It reverted affected UK iCloud data to Standard Data Protection, where Apple does hold the keys and can respond to lawful legal procress (except the baseline categories that stay end-to-end encrypted either way). This satisfied the underlying legal requirement without ever building a ‘backdoor’.
Ah, just like that.
Of course something that is just possible in the public eye, after a lot of public scrutiny and for all accounts at once.
A single account, in secret? IMPOSSIBLE!
They never needed to build a backdoor....
Yeah I read the next few paragraphs and I've seen the turn off button....
djoldman
What happens if someone buys their iphone in the UK, sets their region to UK, then sets the region to USA? Can they then enable advanced data protection?
show comments
athrowaway3z
What I don't understand, or what I can only guess at, is the cabal & likely global network of interests that are behind the push for this kind of legislation to exists in the first place.
Some delusional "save the children" anti-privacy extremist doesn't have the political capital or the technical insight to convince the government to create a law to issue secret gag orders.
People with good civil intention don't just propose the idea, or get the momentum, to institutionalize such mechanisms.
So who are the major influencers, and their thoughts, for pushing this?
show comments
ofou
The UK is becoming 1984.
show comments
phyalow
Anyone have any steps on how I can enable this in the UK? I guess I need to update my billing details to a non UK address and hop on a VPN or something?
show comments
implements
This’ll go down well (/s) but if you accept that the State has the right to be able to surveil public communications infrastructure (which it has been doing since paper mail was invented, through: radio, telegraph, telex, telephone, fax, email, and mobile telephony) then it’s not surprising certain commoditised public data handling services might be required to provide government access on demand or be restricted from implementing features that can effectively deny that access.
That angry’s up the blood of libertarians, but ultimately from the point of view of the State it has to be able to do its job of detecting and prosecuting serious crime, and it will redraw privacy lines whenever that is substantially impeded by new technology.
show comments
Zenul_Abidin
Just call them backdoors.
snvzz
They simply do not want anyone to hear this: Millions must go.
sdcfgy
Very well written article.
It relays my main concern which is that while current governments may use this in moderation and under judicial oversight, future ones may not. And we should build tools for the future not just for now.
There’s a general regression towards fascist and right wing ideologies in the last few years and I don’t want to be up against a wall one day because someone did something with ignorant best intent.
show comments
sneak
The Apple-vs-FBI narrative is constructed fiction. Sure, they didn't make a custom firmware to dump the phone's contents, but that's irrelevant. Everything relevant to the investigation on that phone was in the non-E2EE iCloud Backup, which the FBI got from Apple long before, via normal search warrant means. Apple likely either got an FAA702 order (aka PRISM, aka the "backdoor" that Tim Apple says doesn't exist - it allows the USG to access anyone's iCloud data immediately, with no warrant (it's not an encryption backdoor, just an access backdoor)) or a standard search warrant and most probably turned over everything they had in iCloud instantly, just as they do constantly when receiving a search warrant or FAA702 order. (As I mentioned, the FAA702 order fulfillment is likely instantaneous/automated, which amounts to direct access to the storage servers.)
The whole "Apple won't do what the USG wants" story is farce, engineered specifically to protect Apple's brand image. Following the Snowden drop when we all learned that the USG has unfettered realtime access to everything in iCloud without a warrant via FAA702, Apple had a major fucking crisis on its hands, along with a lot of other companies. (If you think the CIA can't read any object in S3, you simply don't understand how the world works. Note also that AWS has built a custom, one-off, airgapped AWS region ON PREM for the CIA. https://aws.amazon.com/federal/us-intelligence-community/ )
Those CEOs all went to DC and sat down with Obama and talked it out. The official cover story was something like "Obama wants help with healthcare.gov".
> The top leaders from the world’s biggest technology companies pressed their case for reform of the National Security Agency’s controversial surveillance operations at a meeting with President Obama on Tuesday, resisting attempts by the White House to portray the encounter as a wide-ranging discussion of broader priorities.
It is very likely that this media plan was discussed and agreed upon in those meetings. Otherwise, nobody sane in any government in Europe would ever buy an iPhone (or let their citizens do same), given that the USG can read all their photos and messages and emails and contacts in iCloud instantly and without a warrant.
(China of course requires Apple run the iCloud servers for Chinese users in China via a joint venture with a CCP-operated company, which preserves the same realtime full access to all iCloud/iMessage data in China for the CCP as PRISM does for the USG.)
The Snowden releases support very plainly the direct realtime access of the US intelligence community to tech company servers without search warrants (just FISA orders).
It is the single most used data source by the US intelligence community.
Since Epstein is no more, the governments became crazy about going after people's private data, perhaps hoping to find some spice. Like some politicians lost their source.
Havoc
Just checked - I’m on the lower tier. FFS
Getting really tired of the UK govs incompetence/maliciousness around digital law making
I genuinely believe that in 2015 Apple had the balls to resist and today they don't.
I am judging by a simple fact, that "please confirm your age" screen is now mandatory during the iPhone setup in all countries, and in some it's behind a KYC. I have a strong opinion that this is insane. And once they let the foot in the door - there is no closing it.
No need to speculate that the UK government "might" one day become the bad guys: they already arrest over 30 people a day for speech that offends the prevailing political orthodoxy.
[1] https://www.forbes.com/sites/steveforbes/2025/09/09/people-a...
"Withdrawing ADP in the UK did not affect the 14 iCloud categories that were already end-to-end encrypted by default, including iCloud Keychain and Health. ADP increases the total from 14 to 23 categories. For UK users without ADP, the additional categories (iCloud Backup, Photos, Notes, iCloud Drive and so on) revert to Standard Data Protection. ↩
"
Unfortunately this first phrase is not strictly true in the sense that UK customers have their e2ee secrets exposed under common use cases, without requiring a passcode. My copresenter and I published some research at DEF CON 34 this year showing how the e2ee data is particularly vulnerable when ADP is off. Overall, people that do not work with extraction capabilities are currently over-estimating the strength of apple's e2ee and encryption in general. The platform security whitepaper documentation is insufficient on transparency and there are a number of best practices Apple is not following to better meet the e2ee claims they currently advertise.
> Faced with a legal order that would have required it to change the security architecture on which ADP depended, Apple found a third option: stop offering the feature that made this dilemma exist in the first place. It reverted affected UK iCloud data to Standard Data Protection, where Apple does hold the keys and can respond to lawful legal procress (except the baseline categories that stay end-to-end encrypted either way). This satisfied the underlying legal requirement without ever building a ‘backdoor’.
Maybe Apple should withdraw all encryption support from all UK government accounts? The Prime Minister can use a Huawei or some chunky thing from a military contractor.
A non-trivial reason I bought a fairly closed device (macbook) was that Tim Cook, at least publicly, told the FBI to get bent when asked to create a backdoor. Exactly what I want to see, a fight in court.
I would hope to see Apple pull out of the UK market over this, and certainly to stop selling Apple devices to the UK government and to remove the UK government entities from Apple services.
Interesting, the government can demand creating a backdoor and doesn't let anyone tell about it. Basically, outlawing E2EE.
If Bill left the UK temporarily would the ability to turn on ADP come back? Or is a device from the UK that’s not able to enroll somehow prevented forever? Not saying that this makes it OK, just curious
What I don't understand is why Apple is even responding to this absurd demand. Completely banning Apple products in the UK isn't a realistic option for the government, so Apple could simply state openly that it does not cooperate with authoritarian regimes and actively prompt British users via a pop-up to enable ADP to protect themselves from the government.
Fantastic article, and a real concern for UK Citizens.
Strange and hypothetical thought: could Bill purchase a US or international model of the iPhone with US or international iCloud account capable of ADP to activate ADP? Would this allow somebody living or working in the UK the ability to use ADP?
If ensuring digital devices can be accessed by law enforcement (are not "beyond the law") is so important where are the task forces shutting down crypto and networks using unregulated and anonymous currency? Literally follow the money, as they say. The current admin has 'made' millions if not more off his own fraudulent coin. Take down crypto and you stop crime instead of destroying privacy.
The UK's hostility to privacy is legendary.
Used to live there now I don't even want to visit.
It's crazy SimpleX is fine being based there. I mean, everything is open, the clients have reproducible builds, but it seems like it may end up being a hassle.
Has the UK started attacking any open source E2EE projects yet?
Apple's control over iOS is the main reason I prefer GrapheneOS so much over it. You get amazing privacy and security without sacrificing control. GrapheneOS has said they won't introduce age verification and a backdoor they obviously won't implement.
given the story there, I'm surprised apple are still allowed to apply end to end encryption the the "baseline categories" such as messages etc in the UK. Anyone understand how that's happened? To be clear I am not saying what I think should happen, just it seems inconsistent with the UK's stance
On brand for two-tier Keir.
>. It reverted affected UK iCloud data to Standard Data Protection, where Apple does hold the keys and can respond to lawful legal procress (except the baseline categories that stay end-to-end encrypted either way). This satisfied the underlying legal requirement without ever building a ‘backdoor’.
Ah, just like that.
Of course something that is just possible in the public eye, after a lot of public scrutiny and for all accounts at once.
A single account, in secret? IMPOSSIBLE!
They never needed to build a backdoor....
Yeah I read the next few paragraphs and I've seen the turn off button....
What happens if someone buys their iphone in the UK, sets their region to UK, then sets the region to USA? Can they then enable advanced data protection?
What I don't understand, or what I can only guess at, is the cabal & likely global network of interests that are behind the push for this kind of legislation to exists in the first place.
Some delusional "save the children" anti-privacy extremist doesn't have the political capital or the technical insight to convince the government to create a law to issue secret gag orders.
People with good civil intention don't just propose the idea, or get the momentum, to institutionalize such mechanisms.
So who are the major influencers, and their thoughts, for pushing this?
The UK is becoming 1984.
Anyone have any steps on how I can enable this in the UK? I guess I need to update my billing details to a non UK address and hop on a VPN or something?
This’ll go down well (/s) but if you accept that the State has the right to be able to surveil public communications infrastructure (which it has been doing since paper mail was invented, through: radio, telegraph, telex, telephone, fax, email, and mobile telephony) then it’s not surprising certain commoditised public data handling services might be required to provide government access on demand or be restricted from implementing features that can effectively deny that access.
That angry’s up the blood of libertarians, but ultimately from the point of view of the State it has to be able to do its job of detecting and prosecuting serious crime, and it will redraw privacy lines whenever that is substantially impeded by new technology.
Just call them backdoors.
They simply do not want anyone to hear this: Millions must go.
Very well written article.
It relays my main concern which is that while current governments may use this in moderation and under judicial oversight, future ones may not. And we should build tools for the future not just for now.
There’s a general regression towards fascist and right wing ideologies in the last few years and I don’t want to be up against a wall one day because someone did something with ignorant best intent.
The Apple-vs-FBI narrative is constructed fiction. Sure, they didn't make a custom firmware to dump the phone's contents, but that's irrelevant. Everything relevant to the investigation on that phone was in the non-E2EE iCloud Backup, which the FBI got from Apple long before, via normal search warrant means. Apple likely either got an FAA702 order (aka PRISM, aka the "backdoor" that Tim Apple says doesn't exist - it allows the USG to access anyone's iCloud data immediately, with no warrant (it's not an encryption backdoor, just an access backdoor)) or a standard search warrant and most probably turned over everything they had in iCloud instantly, just as they do constantly when receiving a search warrant or FAA702 order. (As I mentioned, the FAA702 order fulfillment is likely instantaneous/automated, which amounts to direct access to the storage servers.)
The whole "Apple won't do what the USG wants" story is farce, engineered specifically to protect Apple's brand image. Following the Snowden drop when we all learned that the USG has unfettered realtime access to everything in iCloud without a warrant via FAA702, Apple had a major fucking crisis on its hands, along with a lot of other companies. (If you think the CIA can't read any object in S3, you simply don't understand how the world works. Note also that AWS has built a custom, one-off, airgapped AWS region ON PREM for the CIA. https://aws.amazon.com/federal/us-intelligence-community/ )
Those CEOs all went to DC and sat down with Obama and talked it out. The official cover story was something like "Obama wants help with healthcare.gov".
> The top leaders from the world’s biggest technology companies pressed their case for reform of the National Security Agency’s controversial surveillance operations at a meeting with President Obama on Tuesday, resisting attempts by the White House to portray the encounter as a wide-ranging discussion of broader priorities.
https://www.businessinsider.com/tech-ceo-meeting-with-obama-... (includes photo)
It is very likely that this media plan was discussed and agreed upon in those meetings. Otherwise, nobody sane in any government in Europe would ever buy an iPhone (or let their citizens do same), given that the USG can read all their photos and messages and emails and contacts in iCloud instantly and without a warrant.
(China of course requires Apple run the iCloud servers for Chinese users in China via a joint venture with a CCP-operated company, which preserves the same realtime full access to all iCloud/iMessage data in China for the CCP as PRISM does for the USG.)
Don't believe the marketing hype.
Further reading:
https://en.wikipedia.org/wiki/PRISM
The Snowden releases support very plainly the direct realtime access of the US intelligence community to tech company servers without search warrants (just FISA orders).
It is the single most used data source by the US intelligence community.
https://en.wikipedia.org/wiki/File:Prism_slide_5.jpg
Apple began providing such data in October 2012.
https://commons.wikimedia.org/wiki/File:PRISM_Collection_Det...
https://www.cnet.com/tech/tech-industry/new-slides-reveal-gr...
Since Epstein is no more, the governments became crazy about going after people's private data, perhaps hoping to find some spice. Like some politicians lost their source.
Just checked - I’m on the lower tier. FFS
Getting really tired of the UK govs incompetence/maliciousness around digital law making