{"id":46667,"date":"2025-02-07T16:44:22","date_gmt":"2025-02-07T21:44:22","guid":{"rendered":"https:\/\/mjtsai.com\/blog\/?p=46667"},"modified":"2025-04-08T13:36:23","modified_gmt":"2025-04-08T17:36:23","slug":"uk-orders-apple-to-break-icloud-advanced-data-protection","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2025\/02\/07\/uk-orders-apple-to-break-icloud-advanced-data-protection\/","title":{"rendered":"UK Orders Apple to Break iCloud Advanced Data Protection"},"content":{"rendered":"<p><a href=\"https:\/\/www.theverge.com\/news\/608145\/apple-uk-icloud-encrypted-backups-spying-snoopers-charter\">Dominic Preston<\/a> (<a href=\"https:\/\/news.ycombinator.com\/item?id=42970412\">Hacker News<\/a>, <a href=\"https:\/\/www.macrumors.com\/2025\/02\/07\/uk-government-orders-access-icloud\/\">MacRumors<\/a>):<\/p>\n<blockquote cite=\"https:\/\/www.theverge.com\/news\/608145\/apple-uk-icloud-encrypted-backups-spying-snoopers-charter\"><p>Apple has reportedly been ordered by the UK government to create a backdoor that would give security officials access to users&rsquo; encrypted iCloud backups. If implemented, British security services would have access to the backups of any user worldwide, not just Brits, and Apple would not be permitted to alert users that their encryption was compromised.<\/p><p><a href=\"https:\/\/www.washingtonpost.com\/technology\/2025\/02\/07\/apple-encryption-backdoor-uk\/\"><em>The Washington Post<\/em> reports<\/a> that the secret order, issued last month, is based on rights given under the UK&rsquo;s Investigatory Powers Act of 2016, also known as the Snoopers&rsquo; Charter. Officials have apparently demanded blanket access to end-to-end encrypted files uploaded by any user worldwide, rather than access to a specific account.<\/p><p>[&#8230;]<\/p><p>The UK has reportedly served Apple a document called a technical capability notice. It&rsquo;s a criminal offense to even reveal that the government has made a demand. Similarly, if Apple did accede to the UK&rsquo;s demands then it apparently would not be allowed to warn users that its encrypted service is no longer fully secure.<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/sixcolors.com\/link\/2025\/02\/uk-orders-apple-to-implement-secret-global-backdoor-for-end-to-end-encryption\/\">Dan Moren<\/a>:<\/p>\n<blockquote cite=\"https:\/\/sixcolors.com\/link\/2025\/02\/uk-orders-apple-to-implement-secret-global-backdoor-for-end-to-end-encryption\/\"><p>While law enforcement has long been able to access encrypted data for which Apple holds the keys, this move would reportedly apply to end-to-end data in which the <em>user<\/em> holds the keys, such as Apple&rsquo;s <a href=\"https:\/\/support.apple.com\/en-us\/108756\">Advanced Data Protection<\/a>. This law would target end-to-end encrypted data from Google and Meta as well.<\/p><p>This is red alert, five-alarm-fire kind of stuff. Providing a backdoor would be worrying enough for reasons that should be obvious to anybody who knows the barest inkling about technology&mdash;to wit, <a href=\"https:\/\/sixcolors.com\/link\/2016\/02\/tim-cook-government-requirement-for-a-backdoor-is-an-overreach\/\">that there exists no mechanism to keep such a tool out of the hands of malicious actors<\/a>&mdash;but the fact that it would apply beyond the UK borders to other countries is a staggering breach of sovereignty. And, moreover, as Menn points out, such a move would no doubt embolden other powers to ask for access to the same capabilities&mdash;such as China.<\/p>\n<p>[&#8230;]<\/p>\n<p>Ironically, the biggest impediment might come in the form of the European Union, as Apple apparently argued that the implementation would undermine the European right to privacy.<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/pxlnv.com\/linklog\/uk-encrypted-icloud-access\/\">Nick Heer<\/a>:<\/p>\n<blockquote cite=\"https:\/\/pxlnv.com\/linklog\/uk-encrypted-icloud-access\/\">\n<p>In any case, the reported demands by the U.K. government are an extraordinary abuse of their own. It has <a href=\"https:\/\/bsky.app\/profile\/matthewdgreen.bsky.social\/post\/3lhlll4ckus2o\">global implications<\/a> for both U.K. access and, I would venture, access by its allies. As a reminder, U.S. and U.K. spy agencies <a href=\"https:\/\/www.theguardian.com\/uk\/2013\/jun\/21\/gchq-cables-secret-world-communications-nsa\">routinely<\/a> <a href=\"https:\/\/www.liberties.eu\/en\/stories\/gchq-access-bulk-data\/2400\">shared<\/a> collected data while avoiding domestic legal protections. This order explicitly revives the bad old days of constant access.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/www.macrumors.com\/2025\/02\/07\/could-apple-pull-icloud-services-from-uk\/\">Tim Hardwick<\/a>:<\/p>\n<blockquote cite=\"https:\/\/www.macrumors.com\/2025\/02\/07\/could-apple-pull-icloud-services-from-uk\/\">\n<p>According to sources that spoke to the publication, Apple is likely to stop offering encrypted storage in the UK as a result of the demand. Specifically, Apple could withdraw Advanced Data Protection, an opt-in feature that provides end-to-end encryption (E2EE) for iCloud backups, such as Photos, Notes, Voice Memos, Messages backups, and device backups.<\/p>\n<p>In this scenario, UK users would still have access to basic iCloud services, but their data would lack the additional layer of security that prevents even Apple from accessing it.<\/p>\n<\/blockquote>\n\n<p>Previously:<\/p>\n<ul>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2025\/01\/01\/privacy-of-photos-apps-enhanced-visual-search\/\">Privacy of Photos.app&rsquo;s Enhanced Visual Search<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2024\/10\/09\/china-possibly-hacking-us-lawful-access-backdoor\/\">China Possibly Hacking US &ldquo;Lawful Access&rdquo; Backdoor<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2024\/06\/04\/proposed-eu-chat-control\/\">Proposed EU Chat Control<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2023\/12\/06\/icloud-advanced-data-protection-uptake\/\">iCloud Advanced Data Protection Uptake<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2023\/08\/24\/u-k-proposal-to-weaken-messaging-security\/\">UK Proposal to Weaken Messaging Security<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2023\/07\/24\/apple-opposes-updated-uk-investigatory-powers-act\/\">Apple Opposes Updated UK Investigatory Powers Act<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2022\/12\/07\/advanced-data-protection-for-icloud\/\">Advanced Data Protection for iCloud<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2020\/01\/21\/apple-dropped-plans-for-end-to-end-encrypted-icloud-backups-after-fbi-objected\/\">Apple Dropped Plans for End-to-End Encrypted iCloud Backups After FBI Objected<\/a><\/li>\n<\/ul>\n\n<p id=\"uk-orders-apple-to-break-icloud-advanced-data-protection-update-2025-02-10\">Update (2025-02-10): <a href=\"https:\/\/www.techdirt.com\/2025\/02\/07\/uk-orders-apple-to-break-encryption-worldwide-while-world-is-distracted\/\">Mike Masnick<\/a>:<\/p>\n<blockquote cite=\"https:\/\/www.techdirt.com\/2025\/02\/07\/uk-orders-apple-to-break-encryption-worldwide-while-world-is-distracted\/\">\n<p>While officials <a href=\"https:\/\/www.techdirt.com\/2023\/09\/13\/uk-government-pauses-demands-for-broken-encryption-in-its-online-safety-bill\/\">repeatedly insisted<\/a> they weren&rsquo;t trying to break encryption entirely, those of us following closely <a href=\"https:\/\/www.techdirt.com\/2023\/09\/19\/uk-government-concession-on-breaking-end-to-end-encryption-in-the-online-safety-act-just-passed-turns-out-not-to-be-one\/\">saw this coming<\/a>. Apple even warned it might have to <a href=\"https:\/\/www.techdirt.com\/2023\/07\/21\/apple-says-it-will-exit-the-uk-market-if-government-passes-update-to-investigatory-powers-act\/\">exit the UK market<\/a> if pushed too far.<\/p>\n<p>[&#8230;]<\/p>\n<p>The UK government is demanding that Apple fundamentally compromise the security architecture of its products <strong>for every user worldwide<\/strong>. This isn&rsquo;t just about giving British authorities access to British users&rsquo; data &mdash; it&rsquo;s about creating a master key that would unlock everyone&rsquo;s encrypted data, everywhere.<\/p>\n<p>This is literally <strong>breaking the fundamental tool that protects our privacy and security<\/strong>. Backdoored encryption is not encryption at all.<\/p>\n<p>[&#8230;]<\/p>\n<p>This global reach is particularly concerning given the UK&rsquo;s membership in the Five Eyes intelligence alliance. Any backdoor created for British authorities would inevitably become a tool for intelligence and law enforcement agencies across the US, Australia, Canada, and New Zealand &mdash; effectively creating a global surveillance capability without any democratic debate or oversight in those countries.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/www.schneier.com\/blog\/archives\/2025\/02\/uk-is-ordering-apple-to-break-its-own-encryption.html\">Bruce Schneier<\/a>:<\/p>\n<blockquote cite=\"https:\/\/www.schneier.com\/blog\/archives\/2025\/02\/uk-is-ordering-apple-to-break-its-own-encryption.html\"><p>Apple is likely to turn the feature off for UK users rather than break it for everyone worldwide. Of course, UK users will be able to spoof their location. But this might not be enough. According to the law, Apple would not be able to offer the feature to anyone who is in the UK at any point: for example, a visitor from the US.<\/p><p>And what happens next? Australia has <a href=\"https:\/\/www.homeaffairs.gov.au\/about-us\/our-portfolios\/national-security\/lawful-access-telecommunications\/assistance-and-access-industry-assistance-framework\">a law<\/a> enabling it to ask for the same thing. Will it? Will even more countries follow?<\/p><p>This is madness.<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/www.mnot.net\/blog\/2025\/02\/09\/decentralize-icloud\">Mark Nottingham<\/a> (via <a href=\"https:\/\/news.ycombinator.com\/item?id=42997647\">Hacker News<\/a>):<\/p>\n<blockquote cite=\"https:\/\/www.mnot.net\/blog\/2025\/02\/09\/decentralize-icloud\">\n<p>The UK is presumably interested in Apple providing this functionality because iCloud&rsquo;s design conveniently makes a massive amount of data convenient to access in one location: Apple&rsquo;s servers. If that data is instead spread across servers operated by many different parties, it becomes less available.<\/p>\n\n<p>In effect, this is the <strong>decentralize iCloud<\/strong> option. Apple would open up its implementation of iCloud so that third-party and self-hosted providers could be used for the same functions. They would need to create interfaces to allow switching, publish some specifications and maybe some test suites, and make sure that there weren&rsquo;t any intellectual property impediments to implementation.<\/p>\n<p>[&#8230;]<\/p>\n<p>This isn&rsquo;t a perfect option. Orders could still force weakened encryption, but now they&rsquo;d have to target many different parties (depending on the details of implementation and deployment), and they&rsquo;d have to get access to the stored data. If you choose a provider in another jurisdiction, that makes doing so more difficult, depending on what legal arrangements are in place between those jurisdictions; if you self-host, they&rsquo;ll need to get physical access to your disks.<\/p>\n<\/blockquote>\n\n<p id=\"uk-orders-apple-to-break-icloud-advanced-data-protection-update-2025-03-14\">Update (2025-03-14): <a href=\"https:\/\/pxlnv.com\/linklog\/google-backdoor-demand\/\">Nick Heer<\/a>:<\/p>\n<blockquote cite=\"https:\/\/pxlnv.com\/linklog\/google-backdoor-demand\/\">\n<p>If Google had not received a technical capabilities notice, it would be able to simply say &ldquo;no&rdquo;. Because it says it cannot say anything &ldquo;if it had&rdquo;, it seems likely it has also been issued a similar demand for access to user data in a decrypted form.<\/p>\n<\/blockquote>\n\n<p id=\"uk-orders-apple-to-break-icloud-advanced-data-protection-update-2025-03-18\">Update (2025-03-18): <a href=\"https:\/\/www.macrumors.com\/2025\/03\/14\/activist-groups-challenge-uk-apple-backdoor\/\">Tim Hardwick<\/a>:<\/p>\n<blockquote cite=\"https:\/\/www.macrumors.com\/2025\/03\/14\/activist-groups-challenge-uk-apple-backdoor\/\"><p>Two human rights groups have filed a legal complaint with the UK&rsquo;s Investigatory Powers Tribunal (IPT) in an attempt to quash the UK government&rsquo;s demand for Apple to allow backdoor access to its encrypted data (via <em><a href=\"https:\/\/www.ft.com\/content\/330291f9-e765-47c1-8a29-f22a95674de9\">Financial Times<\/a><\/em>).<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/techcrunch.com\/2025\/03\/14\/us-lawmakers-urge-uk-spy-court-to-hold-apple-backdoor-secret-hearing-in-public\/\">Zack Whittaker<\/a> (via <a href=\"https:\/\/daringfireball.net\/linked\/2025\/03\/14\/us-lawmakers-letter-to-ipt\">John Gruber<\/a>):<\/p>\n<blockquote cite=\"https:\/\/techcrunch.com\/2025\/03\/14\/us-lawmakers-urge-uk-spy-court-to-hold-apple-backdoor-secret-hearing-in-public\/\">\n<p>A group of bipartisan U.S. lawmakers are urging the head of the U.K.&rsquo;s surveillance court to hold an open hearing into Apple&rsquo;s anticipated challenge of an alleged secret U.K. government legal demand.<\/p>\n<\/blockquote>\n\n<p id=\"uk-orders-apple-to-break-icloud-advanced-data-protection-update-2025-04-08\">Update (2025-04-08): <a href=\"https:\/\/www.macrumors.com\/2025\/04\/07\/apple-challenges-uk-government-back-door-demand\/\">Tim Hardwick<\/a> (<a href=\"https:\/\/news.ycombinator.com\/item?id=43619315\">Hacker News<\/a>):<\/p>\n<blockquote cite=\"https:\/\/www.macrumors.com\/2025\/04\/07\/apple-challenges-uk-government-back-door-demand\/\"><p>Apple has filed a legal appeal against a UK government order requiring the company to create a &ldquo;back door&rdquo; to its encrypted cloud storage systems, the Investigatory Powers Tribunal (IPT) confirmed on Monday (via <em><a href=\"https:\/\/www.reuters.com\/technology\/apple-appealing-against-uk-governments-back-door-order-tribunal-confirms-2025-04-07\/\">Reuters<\/a><\/em>). The confirmation means that the Home Office cannot keep all the details of its demand out of the public domain.<\/p><p>[&#8230;]<\/p><p>According to the IPT ruling, the British government had sought to keep details of the case private. The Home Office argued that publicizing the existence of the appeal could damage national security, but Judges Rabinder Singh and Jeremy Johnson rejected this claim.<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/pxlnv.com\/linklog\/uk-adp-hearing-public\/\">Nick Heer<\/a>:<\/p>\n<blockquote cite=\"https:\/\/pxlnv.com\/linklog\/uk-adp-hearing-public\/\">\n<p>The <a href=\"https:\/\/www.judiciary.uk\/wp-content\/uploads\/2025\/04\/Apple-v-Secretary-of-State-for-the-Home-Department.pdf\">public copy of the ruling<\/a> (PDF) is kind of funny to read because of the secrecy rules around the technical capability notice. Presumably, this judge would know whether Apple had been issued this demand, but cannot say so. They therefore extensively refer to media reporting about the demand; in response to U.S. lawmakers&rsquo; request to &ldquo;discuss an <em>alleged<\/em> technical capability notice&rdquo;, emphasis my own.<\/p>\n<\/blockquote>","protected":false},"excerpt":{"rendered":"<p>Dominic Preston (Hacker News, MacRumors): Apple has reportedly been ordered by the UK government to create a backdoor that would give security officials access to users&rsquo; encrypted iCloud backups. If implemented, British security services would have access to the backups of any user worldwide, not just Brits, and Apple would not be permitted to alert [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2025-02-07T21:44:24Z","apple_news_api_id":"93e0368c-0c96-4bf1-8046-df7a83a79fc4","apple_news_api_modified_at":"2025-04-08T17:36:26Z","apple_news_api_revision":"AAAAAAAAAAAAAAAAAAAABw==","apple_news_api_share_url":"https:\/\/apple.news\/Ak-A2jAyWS_GARt96g6efxA","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[146,16,2729,31,2586,209,30,2598,355,2166],"class_list":["post-46667","post","type-post","status-publish","format-standard","hentry","category-technology","tag-backup","tag-icloud","tag-icloud-advanced-data-protection","tag-ios","tag-ios-18","tag-legal","tag-mac","tag-macos-15-sequoia","tag-privacy","tag-united-kingdom"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/46667","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=46667"}],"version-history":[{"count":9,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/46667\/revisions"}],"predecessor-version":[{"id":47343,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/46667\/revisions\/47343"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=46667"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=46667"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=46667"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}