UK Encryption Order Splits iCloud Users Into Two Security Tiers
A quiet consequence of the UK’s push against Apple is that two people with identical iPhones now get different protection. Anyone who enabled Advanced Data Protection (ADP) — Apple’s opt-in setting that end-to-end encrypts iCloud backups, Photos, Notes and more, with keys Apple itself doesn’t hold — before February 2025 keeps it. Everyone else in the UK is locked out, because Apple pulled the feature for new users rather than comply with a secret government demand.
The demand came via a Technical Capability Notice under the Investigatory Powers Act 2016, reported by The Washington Post in early 2025. A TCN compels a provider to build and maintain the ability to hand over data when a warrant arrives; it arrives in secret, with a gag order, and the one Apple reportedly received sought access to ADP-protected data for users worldwide, not just in Britain. Apple’s long-standing position — argued publicly since the FBI’s 2016 San Bernardino fight — is that any mechanism to break end-to-end encryption is a master key that inevitably weakens security for everyone, good actors and bad alike.
Rather than engineer a backdoor, Apple took a third path: it stopped offering ADP to new UK users and reverted affected accounts to Standard Data Protection, where Apple holds the keys and can respond to lawful requests. That technically satisfied the order without building the capability the government wanted. The episode is a live test of whether a democratic government can secretly force a company to undermine encryption — a precedent that would reach WhatsApp, Signal, password managers and any service built on genuine E2EE, and one being challenged before the Investigatory Powers Tribunal by Apple and privacy groups.
Read the full article
Continue reading at Hacker News →This is an AI-generated summary. Read the original for the full story.