• Apple Removes Cloud Encryption Feature From UK After Backdoor Order

    Home » Forums » Cyber Security Information and Advisories » Code Red – Security/Privacy advisories » Apple Removes Cloud Encryption Feature From UK After Backdoor Order

    • This topic has 5 replies, 3 voices, and was last updated 3 months ago.
    Author
    Topic
    #2750196

    https://www.bloomberg.com/news/articles/2025-02-21/apple-removes-end-to-end-encryption-feature-from-uk-after-backdoor-order

    Apple Inc. is removing its most advanced encrypted security feature for cloud data in the UK, a stunning development that follows the government ordering the company to build a backdoor for accessing user data.

    The company said Friday that Advanced Data Protection, an optional feature that adds end-to-end encryption to a wide assortment of user data, is no longer available in the UK for new users. ..

    * Apple can’t disable ADP remotely nor decrypt current encrypted iCloud data.

    * iMessage, FaceTime, password management and health data will remain end-to-end encrypted.

    ADP

    1 user thanked author for this post.
    Viewing 4 reply threads
    Author
    Replies
    • #2750717

      This is a bit more complicated than it seems at first. There are some types of data in iCloud that are never E2EE encrypted. There are other types of data that are always E2EE encrypted. Then, finally, there are about 20 or so types of data that can either be encrypted with good E2EE encryption or bad encryption, depending on whether ADP is enabled or not. I don’t know how many categories of data Apple has in iCloud but it is over 40.

      More here https://defensivecomputingchecklist.com/SecureFileStorage.php

       

      Get up to speed on router security at RouterSecurity.org and Defensive Computing at DefensiveComputingChecklist.com

      1 user thanked author for this post.
    • #2750727

      Bloomberg link is behind paywall… here is an article from Reuters on same subject.

      And… EFfs take on it: Cornered by the UK’s Demand for an Encryption Backdoor, Apple Turns Off Its Strongest Security Setting

      It never used to be a matter for debate, people had ways of privately communicating. That pedophiles or terrorists communicated privately did not mean that everyone should be prohibited from private conversations. Weakening Encryption Violates Fundamental Rights

      I agree with Apple that it is better to be clear that British data is poorly protected, than put in a back door that weakens encryption and privacy for Apple users world wide.

      Non-techy Win 10 Pro and Linux Mint experimenter

      5 users thanked author for this post.
    • #2750734

      There are some types of data in iCloud that are never E2EE encrypted.

      The data that is uploaded to iCloud and isn’t E2EE encrypted is encrypted by Apple and Apple holds the key.
      Apple can decrypt the data following court order.

    • #2750752

      Agreed. I call this bad encryption, Apple calls it “Standard Data Protection”. Among the types of data that is always badly encrypted is iCloud mail, contacts and calendar. From the horse’s mouth here https://support.apple.com/en-us/102651

      Get up to speed on router security at RouterSecurity.org and Defensive Computing at DefensiveComputingChecklist.com

      2 users thanked author for this post.
    • #2750814

      I call this bad encryption, Apple calls it “Standard Data Protection”.

      Yet, iCloud has been never hacked

    Viewing 4 reply threads
    Reply To: Apple Removes Cloud Encryption Feature From UK After Backdoor Order

    You can use BBCodes to format your content.
    Your account can't use all available BBCodes, they will be stripped before saving.

    Your information: