UK demands access to Apple users' encrypted data
UK demands access to Apple users' encrypted data
Author
Discussion

Murph7355

41,951 posts

284 months

Saturday 22nd February 2025
quotequote all
ATG said:
andyb28 said:
Thinking about this more. I don't think Apple have rolled over, instead I think they have done this because of the uneducated impossible requests for back doors.
Yup.
It's the simplest path open to them to comply, whilst also "blaming" government. All fair enough.

I'm not convinced the collective might of Apple cannot come up with more nuanced, elegant approaches (actually scrub that. I can. They'd need someone else to do it first and stick an Apple badge on it smile). But that's up to them.

dcb

6,057 posts

293 months

Saturday 22nd February 2025
quotequote all
130R said:
Apple just removed end-to-end encryption for the UK. So the government have successfully weakened online security / privacy for all UK based users. Great job.
I am trying to compile a list of other juristictions that don't allow ADP.

I am thinking China, Russia and North Korea. Maybe one or two places
in the Middle East.

It looks to me like UK is trying to join that list and it's not a good look.

Sadly, I have to pay for this level of stupidity.


Strangely Brown

15,214 posts

259 months

Saturday 22nd February 2025
quotequote all
130R said:
Apple just removed end-to-end encryption for the UK. So the government have successfully weakened online security / privacy for all UK based users. Great job.
No, they didn't.

They removed ADP for new users (existing users later). ADP only applies to a limited set of data categories that the majority of users were not using anyway as it was optional and had to switched on. The "important stuff" is still end-to-end encrypted.


grumbledoak

32,526 posts

261 months

Saturday 22nd February 2025
quotequote all
AlexC1981 said:
I suppose the bad guys will find somewhere else to hide their nefarious stuff.
No-one with any functioning brain cells is "hiding their nefarious stuff" on a computer connected to the internet.

This isn't aimed where they claim it is.

Evanivitch

26,233 posts

150 months

Saturday 22nd February 2025
quotequote all
Murph7355 said:
That is not the same with bit heavy encryption (as you know, because you understand it). Sure, they can ask Mr Alleged Criminal for his key and I'm sure they will all cooperate and not one will say "what key", "sorry, my hard disk failed and it was lost" or "the dog licked it".
And police and CPS already have powers to address that.

https://www.bbc.co.uk/news/uk-england-11479831

grumbledoak

32,526 posts

261 months

Saturday 22nd February 2025
quotequote all
Murph7355 said:
...

Will it materially stop the very worst of the internet. Unlikely. But just because you cannot stop 100%, doesn't mean you should not try to stop 99%, 98%, 90% etc IMO. Remember, not "not understanding", just having a different opinion.
All the weakening of encryption like this achieves is enabling mass surveillance of the general population by anyone with the resources to do it.

Which is both what they want and the price they are willing for us to pay.

130R

7,073 posts

234 months

Saturday 22nd February 2025
quotequote all
Strangely Brown said:
130R said:
Apple just removed end-to-end encryption for the UK. So the government have successfully weakened online security / privacy for all UK based users. Great job.
No, they didn't.

They removed ADP for new users (existing users later). ADP only applies to a limited set of data categories that the majority of users were not using anyway as it was optional and had to switched on. The "important stuff" is still end-to-end encrypted.
Yes they did ..

ADP is end-to-end encryption for iCloud data like backups, photos, notes, etc. With standard data protection that iCloud data is encrypted but the encryption keys are stored by Apple.

Murph7355

41,951 posts

284 months

Saturday 22nd February 2025
quotequote all
dcb said:
I am trying to compile a list of other juristictions that don't allow ADP.

I am thinking China, Russia and North Korea. Maybe one or two places
in the Middle East.

It looks to me like UK is trying to join that list and it's not a good look.

Sadly, I have to pay for this level of stupidity.
Ah the old "we'll be just like North Korea" line of logical reasoning. Always a winner. You'll be all "the world will think we're a laughing stock" next biggrin

Murph7355

41,951 posts

284 months

Saturday 22nd February 2025
quotequote all
Evanivitch said:
Murph7355 said:
That is not the same with bit heavy encryption (as you know, because you understand it). Sure, they can ask Mr Alleged Criminal for his key and I'm sure they will all cooperate and not one will say "what key", "sorry, my hard disk failed and it was lost" or "the dog licked it".
And police and CPS already have powers to address that.

https://www.bbc.co.uk/news/uk-england-11479831
And?

I'd still much sooner the authorities were able to go straight to kiddie porn, terror related stuff etc without jumping through hoop after hoop. (Maybe they're wanting to do this as the hoop you link to causes delay which in itself creates issues for people "tidying up"?).

Appreciate you feel that protecting your family photos and life's Word documents etc is more important than that. I don't. We're all different wink

Murph7355

41,951 posts

284 months

Saturday 22nd February 2025
quotequote all
grumbledoak said:
All the weakening of encryption like this achieves is enabling mass surveillance of the general population by anyone with the resources to do it.

Which is both what they want and the price they are willing for us to pay.
Still shrugging my shoulders. (I used all the tin foil up cooking bacon for breakfast).

Fill your boots. Surveil me as much as you want wink

Evanivitch

26,233 posts

150 months

Saturday 22nd February 2025
quotequote all
Murph7355 said:
Evanivitch said:
Murph7355 said:
That is not the same with bit heavy encryption (as you know, because you understand it). Sure, they can ask Mr Alleged Criminal for his key and I'm sure they will all cooperate and not one will say "what key", "sorry, my hard disk failed and it was lost" or "the dog licked it".
And police and CPS already have powers to address that.

https://www.bbc.co.uk/news/uk-england-11479831
And?

I'd still much sooner the authorities were able to go straight to kiddie porn, terror related stuff etc without jumping through hoop after hoop. (Maybe they're wanting to do this as the hoop you link to causes delay which in itself creates issues for people "tidying up"?).

Appreciate you feel that protecting your family photos and life's Word documents etc is more important than that. I don't. We're all different wink
I use commercial, government approved, AES256 encryption software as part of my work, because the government tells me I have to.

So if you could explain what MOD will require contractors to do in future that would be much appreciated, because right now it looks like the whole defence industry will need MODNET laptops from Monday...

Evanivitch

26,233 posts

150 months

Saturday 22nd February 2025
quotequote all
Murph7355 said:
Still shrugging my shoulders. (I used all the tin foil up cooking bacon for breakfast).

Fill your boots. Surveil me as much as you want wink
So you don't care about your personal data (encrypted by law under GDPR) or banking details being at risk. Righto.

Strangely Brown

15,214 posts

259 months

Saturday 22nd February 2025
quotequote all
130R said:
Strangely Brown said:
130R said:
Apple just removed end-to-end encryption for the UK. So the government have successfully weakened online security / privacy for all UK based users. Great job.
No, they didn't.

They removed ADP for new users (existing users later). ADP only applies to a limited set of data categories that the majority of users were not using anyway as it was optional and had to switched on. The "important stuff" is still end-to-end encrypted.
Yes they did ..

ADP is end-to-end encryption for iCloud data like backups, photos, notes, etc. With standard data protection that iCloud data is encrypted but the encryption keys are stored by Apple.
No, they fking didn't. End-to-end encryption still exists so they did NOT "remove end-to-end encryption for the UK" as you claimed. They have removed end-to-end encryption for some categories of data where it is stored on Apple servers.
Messages, Health etc and the important personal stuff is still as it was.

This stuff is important and misinformation helps nobody.

ETA: For the avoidance of doubt...

These iCloud data categories will no longer benefit from end-to-end encryption in the UK:

iCloud Backup
iCloud Drive
Photos
Notes
Reminders
Safari Bookmarks
Siri Shortcuts
Voice Memos
Wallet Passes
Freeform


What is not changing as part of Apple’s decision to pull Advanced Data Protection from the UK is the end-to-end encryption offered for those initial 15 different iCloud data categories. This means that the following iCloud data categories are still protected by end-to-end encryption by default for all users in the UK:

Passwords and Keychain
Health data
Journal data
Home data
Messages in iCloud
Payment information
Apple Card transactions
Maps
QuickType Keyboard learned vocabulary
Safari
Screen Time
Siri information
Wi-Fi passwords
W1 and H1 Bluetooth keys
Memoji

Edited by Strangely Brown on Saturday 22 February 19:39

InitialDave

14,984 posts

147 months

Saturday 22nd February 2025
quotequote all
Murph7355 said:
Still shrugging my shoulders. (I used all the tin foil up cooking bacon for breakfast).

Fill your boots. Surveil me as much as you want wink
It's not the government surveillance angle that's the direct problem with an engineered in back door in an encryption or other system (though you shouldn't be blasé about such a thing anyway).

It's that once said back door exists, it can be used by basically anyone.


ATG

23,573 posts

300 months

Saturday 22nd February 2025
quotequote all
Murph7355 said:
Evanivitch said:
Murph7355 said:
That is not the same with bit heavy encryption (as you know, because you understand it). Sure, they can ask Mr Alleged Criminal for his key and I'm sure they will all cooperate and not one will say "what key", "sorry, my hard disk failed and it was lost" or "the dog licked it".
And police and CPS already have powers to address that.

https://www.bbc.co.uk/news/uk-england-11479831
And?

I'd still much sooner the authorities were able to go straight to kiddie porn, terror related stuff etc without jumping through hoop after hoop. (Maybe they're wanting to do this as the hoop you link to causes delay which in itself creates issues for people "tidying up"?).

Appreciate you feel that protecting your family photos and life's Word documents etc is more important than that. I don't. We're all different wink
They won't be able to do any of that because all of that data will still be properly encrypted. It doesn't matter what Apple does. You can encrypt the data BEFORE you send it to Apple. Stopping Apple from providing end to end encryption is a minor inconvenience for anyone who wants to store or communicate data privately. If Apple put a backdoor in their own E2E encryption layer, then it ain't E2E encryption anymore. The service becomes pointless so they're withdrawing it. It is now fractionally more inconvenient to send encrypted data, that's all.

Evanivitch

26,233 posts

150 months

Saturday 22nd February 2025
quotequote all
ATG said:
They won't be able to do any of that because all of that data will still be properly encrypted. It doesn't matter what Apple does. You can encrypt the data BEFORE you send it to Apple. Stopping Apple from providing end to end encryption is a minor inconvenience for anyone who wants to store or communicate data privately. If Apple put a backdoor in their own E2E encryption layer, then it ain't E2E encryption anymore. The service becomes pointless so they're withdrawing it. It is now fractionally more inconvenient to send encrypted data, that's all.
I agree, but it raises the question of what they'll do to the commercial AES256 tool providers.

768

20,377 posts

124 months

Saturday 22nd February 2025
quotequote all
ATG said:
They won't be able to do any of that because all of that data will still be properly encrypted. It doesn't matter what Apple does. You can encrypt the data BEFORE you send it to Apple.
But, assuming you're talking about icloud backups and not manually encrypting data (not sure?) then, doesn't Apple hold the keys - isn't that the point of ADP?

ATG

23,573 posts

300 months

Saturday 22nd February 2025
quotequote all
Evanivitch said:
ATG said:
They won't be able to do any of that because all of that data will still be properly encrypted. It doesn't matter what Apple does. You can encrypt the data BEFORE you send it to Apple. Stopping Apple from providing end to end encryption is a minor inconvenience for anyone who wants to store or communicate data privately. If Apple put a backdoor in their own E2E encryption layer, then it ain't E2E encryption anymore. The service becomes pointless so they're withdrawing it. It is now fractionally more inconvenient to send encrypted data, that's all.
I agree, but it raises the question of what they'll do to the commercial AES256 tool providers.
With open source tools as simple to use and install as 7-zip, the harder life is made for commercial software vendors, the more users will become incentivised to discover and use open source alternatives. Ultimately you can't make people unlearn maths in much the same way that you can't force people to forget how guns work.

Evanivitch

26,233 posts

150 months

Saturday 22nd February 2025
quotequote all
ATG said:
Evanivitch said:
ATG said:
They won't be able to do any of that because all of that data will still be properly encrypted. It doesn't matter what Apple does. You can encrypt the data BEFORE you send it to Apple. Stopping Apple from providing end to end encryption is a minor inconvenience for anyone who wants to store or communicate data privately. If Apple put a backdoor in their own E2E encryption layer, then it ain't E2E encryption anymore. The service becomes pointless so they're withdrawing it. It is now fractionally more inconvenient to send encrypted data, that's all.
I agree, but it raises the question of what they'll do to the commercial AES256 tool providers.
With open source tools as simple to use and install as 7-zip, the harder life is made for commercial software vendors, the more users will become incentivised to discover and use open source alternatives. Ultimately you can't make people unlearn maths in much the same way that you can't force people to forget how guns work.
Unless the government makes non-compliant AES256 tools illegal to distribute in the UK...

768

20,377 posts

124 months

Saturday 22nd February 2025
quotequote all
Murph7355 said:
And?

I'd still much sooner the authorities were able to go straight to kiddie porn, terror related stuff etc without jumping through hoop after hoop. (Maybe they're wanting to do this as the hoop you link to causes delay which in itself creates issues for people "tidying up"?).

Appreciate you feel that protecting your family photos and life's Word documents etc is more important than that. I don't. We're all different wink
Even if we assumed that the CP terrorists can't manage their own E2EE, how will losing authentication and integrity guarantees make it easier for authorities to go after that stuff?