Apple Withdraws Data Protection in UK
- Apple has suspended its most advanced safety encryption function for cloud data in Great Britain, a move that comes as a response to the British government's demands for...
- The affected function is called Advanced Data Protection (ADP), which enables end-to-end encryption for a wide range of cloud data.
- This decision means that iCloud backups in Britain will no longer have end-to-end encryption, which would otherwise protect data such as iMessages from being accessed by Apple or...
Apple Halts Advanced Data Protection in Britain Amid Government Pressure
Table of Contents
- Apple Halts Advanced Data Protection in Britain Amid Government Pressure
- Apple’s Advanced Data Protection: End-to-End Encryption and Privacy Implications
- What is Advanced Data Protection (ADP) and why is it vital?
- Why is ADP no longer available for new users in Britain?
- How does this affect existing users in Britain?
- What is the historical context of encryption debates?
- What are the broader implications of Apple’s decision for global data privacy?
- how can users protect their data in light of these changes?
- what are the views of experts on breaking encryption?
Apple has suspended its most advanced safety encryption function for cloud data in Great Britain, a move that comes as a response to the British government’s demands for access to user data. The company announced this development on Friday, marking an unprecedented reaction to the government’s claims.
The affected function is called Advanced Data Protection (ADP), which enables end-to-end encryption for a wide range of cloud data. Apple stated that this function is no longer available for new users in Britain and that existing users may have to deactivate this safety feature.
This decision means that iCloud backups in Britain will no longer have end-to-end encryption, which would otherwise protect data such as iMessages from being accessed by Apple or handed over to authorities, even if required by law. If the end-to-end encryption is activated, not even Apple can access the data.
Governments and tech giants have long been at odds over strong encryption, with authorities viewing it as an obstacle to mass surveillance and crime control programs. However, the British government’s requirement is particularly far-reaching.
Early plans to offer Apple users the opportunity to fully encrypt the backups of their devices in the company’s iCloud service were dropped around 2018 after the FBI had privately complained, as previously reported by Reuters. However, the company finally implemented the plan in 2022.
The FBI has long expressed concerns about the erosion of access to digital evidence and threat information, referring to it as “going dark.” The bureau states on its website, “The rightful access to digital evidence and threat information erodes rapidly,”
and refers to the “go dark” encryption.
Apple has consistently maintained that it would never incorporate a so-called backdoor into its encrypted services or devices, as such a feature could be exploited not only by governments but also by hackers. This stance is shared by security experts.
“Ultimately, it is only a matter of time before such a backdoor is found and malicious actors exploit it for cybersecurity at the Loughborough University in Great Britain.”
Data that was encrypted before the introduction of Apple’s protection service at the end of 2022, such as passwords and the messaging services iMessage and FaceTime, will remain encrypted.
Apple expressed disappointment, stating, “We are deeply disappointed that the protection that ADP offers will not be available to our customers in Britain, since the number of data protection violations and other threats for customers’ privacy is constantly increasing.”
The decision does not affect the encryption of data stored directly on devices. However, in the age of large photo collections, extensive messaging histories, and regular phone upgrades, many users find it impractical to store all their data solely on their devices. Exclusive storage on the device also means that if the device is lost or damaged, all user data could be lost, which, if not most consumers, British authorities can now access more easily.
Security concerns have led criminal prosecution authorities to target Apple services such as iMessage, via iCloud backups that were not end-to-end encrypted before Apple’s Advanced Data Protection was offered. These backups, which can contain photos and other sensitive information, can no longer be encrypted for British users, according to Apple.
Apple cannot deactivate ADP for existing users because it does not have an encryption key, but it will ask users to deactivate the function themselves. A spokesman for the British Ministry of the Interior refused to comment on whether such an order was granted. “We do not comment on operational matters, including confirmation or denying the existence of such communications,”
said the spokesman.
The Washington Post reported this month that Britain issued a Technical Capability Notice to Apple that requires access to the data in the context of the extensive Investigatory Powers Act from 2016, which allows law enforcement authorities to force companies to collect evidence to help.
According to the government’s website, Technical Capability Notices (TCNs) do not grant blanket access to the personal data of users. Even if there is a TCN, separate permits are still required to enable access to data.
The Apple share was largely unchanged on Friday morning. The company has long resisted the government’s efforts to weaken encryption, as in 2016, when the U.S. authorities tried to force the company to unlock the iPhone of the San Bernardino shooter.
The efforts to undermine encryption go back to the 1990s when the government of former President Bill Clinton first suggested that computer hardware be used to incorporate a physical chip that would enable police officers and spies to extract encrypted communication. The attempt failed, and since then, strong encryption has found its way into a growing number of consumer services, including Apple’s iMessage, Zoom Meetings, WhatsApp from Meta, and the Signal app geared towards data protection.
Signal has already threatened to leave Britain due to similar concerns, while Meta has faced resistance due to its plans to expand encryption on WhatsApp.
This move by Apple highlights the ongoing tension between national security interests and privacy rights. As governments worldwide seek to balance these competing priorities, tech companies like Apple are increasingly finding themselves in the crosshairs. The implications for U.S. consumers are significant, as similar pressures could emerge in the U.S., where encryption and data privacy are hot-button issues.
In the U.S., the debate over encryption has been particularly contentious. In 2016, the FBI sought to force Apple to unlock an iPhone belonging to one of the San Bernardino shooters. Apple resisted, arguing that creating a backdoor for the government would compromise the security of all iPhone users. The case ultimately ended without a resolution, but it set a precedent for future battles over encryption.
As the digital landscape continues to evolve, the need for robust encryption will only grow. Companies like Apple are at the forefront of this battle, advocating for strong encryption to protect user data from both malicious actors and government overreach. The outcome of these battles will shape the future of digital privacy and security for consumers worldwide.
For U.S. consumers, the implications of Apple’s decision in Britain are clear: encryption is a critical tool for protecting personal data, and any weakening of encryption standards could have far-reaching consequences. It is essential for consumers to stay informed about these developments and advocate for strong encryption to safeguard their digital privacy.
Apple’s Advanced Data Protection: End-to-End Encryption and Privacy Implications
Understanding the recent changes and what it means for you
What is Advanced Data Protection (ADP) and why is it vital?
- Advanced Data Protection offers end-to-end encryption for a wide range of cloud data stored in iCloud.
- This encryption ensures that even Apple cannot access user data, safeguarding messages like iMessages and FaceTime from unauthorized access and legal demands.
- ADP is crucial for maintaining privacy and security in digital communications.
Why is ADP no longer available for new users in Britain?
- The British government has issued regulations that require tech companies to provide access to encrypted data under certain conditions.
- Apple has been pressured to allow access to iCloud backups, which are no longer end-to-end encrypted for new users in Britain.
How does this affect existing users in Britain?
- Existing users can keep using ADP but may be prompted by Apple to deactivate the feature.
- Backups made after deactivating ADP will not be end-to-end encrypted, making personal data more accessible to authorities.
What is the historical context of encryption debates?
- Governments, including the U.S., have long argued that strong encryption hinders surveillance and law enforcement efforts.
- Apple resisted a 2016 FBI demand to unlock an iPhone, highlighting the company’s stance against creating backdoors.
- The push for encryption has historical roots dating back to the 1990s, under former President Bill Clinton’s administration.
What are the broader implications of Apple’s decision for global data privacy?
- A similar approach in other countries could lead to weakened encryption standards worldwide.
- Companies like Signal and Meta (WhatsApp) have faced similar pressures, highlighting the global impact of these decisions.
- Consumers must remain informed and advocate for strong encryption to protect digital privacy rights.
how can users protect their data in light of these changes?
- Always update security settings to ensure higher levels of protection are enabled were available.
- Use local storage solutions for highly sensitive data, bearing in mind backup options and their security implications.
- Stay informed about encryption standards and advocate for robust digital privacy laws.
what are the views of experts on breaking encryption?
- experts agree that introducing backdoors or access points compromises security for everyone, not just users.
- Malicious actors could possibly exploit such vulnerabilities to access personal information illegitimately.
