

Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- If Bill left the UK temporarily would the ability to turn on ADP come back? Or is a device from the UK that’s not able to enroll somehow prevented forever? Not saying that this makes it OK, just curiousby pirates
- The UK really needs to focus on not bankrupting and destroying ourselves rather than coming up with more rules for things.by gste
- Interesting, the government can demand creating a backdoor and doesn't let anyone tell about it. Basically, outlawing E2EE.by codedokode
- What I don't understand is why Apple is even responding to this absurd demand. Completely banning Apple products in the UK isn't a realistic option for the government, so Apple could simply state openly that it does not cooperate with authoritarian regimes and actively prompt British users via a pop-up to enable ADP to protect themselves from the government.by RandomGerm4n
- A non-trivial reason I bought a fairly closed device (macbook) was that Tim Cook, at least publicly, told the FBI to get bent when asked to create a backdoor. Exactly what I want to see, a fight in court.
I would hope to see Apple pull out of the UK market over this, and certainly to stop selling Apple devices to the UK government and to remove the UK government entities from Apple services.
by Hasz - > Faced with a legal order that would have required it to change the security architecture on which ADP depended, Apple found a third option: stop offering the feature that made this dilemma exist in the first place. It reverted affected UK iCloud data to Standard Data Protection, where Apple does hold the keys and can respond to lawful legal procress (except the baseline categories that stay end-to-end encrypted either way). This satisfied the underlying legal requirement without ever building a ‘backdoor’.
Maybe Apple should withdraw all encryption support from all UK government accounts? The Prime Minister can use a Huawei or some chunky thing from a military contractor.
by palmotea - "Withdrawing ADP in the UK did not affect the 14 iCloud categories that were already end-to-end encrypted by default, including iCloud Keychain and Health. ADP increases the total from 14 to 23 categories. For UK users without ADP, the additional categories (iCloud Backup, Photos, Notes, iCloud Drive and so on) revert to Standard Data Protection. ↩
"
Unfortunately this first phrase is not strictly true in the sense that UK customers have their e2ee secrets exposed under common use cases, without requiring a passcode. My copresenter and I published some research at DEF CON 34 this year showing how the e2ee data is particularly vulnerable when ADP is off. Overall, people that do not work with extraction capabilities are currently over-estimating the strength of apple's e2ee and encryption in general. The platform security whitepaper documentation is insufficient on transparency and there are a number of best practices Apple is not following to better meet the e2ee claims they currently advertise.
by spr-alex - I genuinely believe that in 2015 Apple had the balls to resist and today they don't.
I am judging by a simple fact, that "please confirm your age" screen is now mandatory during the iPhone setup in all countries, and in some it's behind a KYC. I have a strong opinion that this is insane. And once they let the foot in the door - there is no closing it.
by egorfine