deniz.in

Markets

Weather

Loading weather

· via Hacker News – Front Page (hnrss.org)

UK Apple users split into two iCloud encryption tiers after ADP withdrawal

Identical iPhones in the UK now get different iCloud security: users who enabled Advanced Data Protection before February 2025 keep end-to-end encryption, while everyone else is locked out of the feature.

UK Apple users split into two iCloud encryption tiers after ADP withdrawal

Two iPhones, two levels of protection

A post published on Macanorak and surfaced on the Hacker News front page frames the situation with two fictional users, Alice and Bill. Both live in the UK, own identical iPhones and pay for the same iCloud services. Alice's data — backups, photos, notes and more — is covered by Advanced Data Protection (ADP), Apple's optional end-to-end encryption layer. Bill's is not, and he has no way to switch it on. The only difference between them is timing: Alice enabled the feature before Apple stopped offering it to new UK users in February 2025. Bill missed the window.

How the UK ended up here

According to reporting by The Washington Post on 7 February 2025, as recounted by Macanorak, UK security officials had secretly issued a Technical Capability Notice (TCN) to Apple the previous month. The notice was served under the Investigatory Powers Act 2016 and, strikingly, asked Apple to build the means to access encrypted iCloud data not only for UK accounts but for users worldwide.

A TCN does not itself authorise anyone to read data; it obliges a provider to maintain or develop a capability so a future warrant can be executed. Issuing one requires approval from a Judicial Commissioner, and recipients are generally prohibited from disclosing that a notice exists — the Home Office typically refuses to confirm or deny whether one has been served.

Apple's position, per Macanorak, was that it could not weaken ADP for one purpose without weakening it for everyone. On 21 February 2025 the company announced that ADP would no longer be available to new UK users, stating it had "never built a backdoor or master key" and never would, and describing itself as "gravely disappointed". Crucially, the piece notes that Apple only blocked new activations — people who already had ADP enabled kept it, which is precisely what produced the Alice and Bill split.

What ADP actually changes

All iCloud data is encrypted, but not all of it is end-to-end encrypted. Categories such as passwords, health data and Messages in iCloud are end-to-end encrypted by default. For the rest — including device backups, photos and notes under standard protection — Apple holds the keys and can decrypt and hand over content in response to lawful demands. ADP extends end-to-end encryption to those additional categories, meaning Apple itself cannot unlock them. Bill's data falls back to Standard Data Protection, where Apple retains the keys; Alice's remains end-to-end encrypted for as long as she keeps the feature on.

A rerun of an old fight

Macanorak traces the standoff back nearly a decade. After the December 2015 terrorist attack in San Bernardino, the FBI obtained a court order compelling Apple to build a modified version of iOS that would defeat passcode-attempt limits on the attacker's iPhone 5C. Apple refused, with Tim Cook calling the requested software the "equivalent of cancer" and warning it would function as a master key for hundreds of millions of devices. In interviews, Cook argued that any back door would be available to "good guys and bad guys" alike. The FBI eventually accessed the phone through a third party, widely reported to be Cellebrite, and dropped its legal action.

The piece argues the UK demand was the same argument relocated: since Apple said it could not decrypt the data, the state's effective answer was to make the company change the system so that it could.

Why it matters

The two-tier outcome means UK customers buying identical hardware and paying the same subscriptions receive materially different security, determined purely by when they flipped a switch. It also shows the practical result of secret legal pressure: the reported TCN never ordered Apple to withdraw ADP, only to guarantee access — and rather than build a capability that hackers or hostile states could exploit, Apple removed the feature instead. Privacy International and other groups have taken the matter to the Investigatory Powers Tribunal, arguing the state should not be able to secretly compel companies to weaken encryption without public scrutiny. The precedent reaches well beyond Apple to WhatsApp, Signal, password managers, cloud storage and any service that depends on genuine end-to-end encryption — and to every other government watching how this played out.

  • #encryption
  • #icloud
  • #privacy
  • #apple
  • #uk

Related posts