Live data from Hacker News

Apple pulls data protection tool after UK government security row

bbc.com

221–230 of 1001 posts

Re: Apple pulls data protection tool after UK government security row

#221

Note that this doesn’t satisfy the government’s original request, which was for worldwide backdoor access into E2E-encrypted cloud accounts. But I have a more pertinent question: how can you “pull” E2E encryption without data loss? What happens to those that had this enabled? Edit: Part of my concern is that you have to keep in mind Apple's defense against backdooring E2E is the (US) doctrine that work cannot be comp…

When you disable ADP, your local encryption keys are uploaded to Apple's servers to be read by them.

Apple could just lock you out of iCloud until you do this.

Re: Apple pulls data protection tool after UK government security row

#222

Earlier quoted context omitted.

It's literally the number one story on https://www.bbc.co.uk/news/ as I type this comment.

And I guarantee that the reaction from most people will be "good, I have nothing to hide so I have nothing to worry about". The apathy around this stuff in the UK is unbelivable - I've been trying to point out that hey, for years now something like 17 government agencies(including DEFRA - department of agriculture lol) can access your internet browsing history WITHOUT A WARRANT and that's absolutely fine. ISPs are re…

The same is happening Europe-wide too. Everybody always points to the GPDR legislation. You know what is a feature of the GPDR too?

Every European government (even some non-EU ones) can grant any exception to anyone to the GPDR for any reason. And, of course, every last one has granted an exception to the police, to courts, to the secret service, their equivalent of the IRS, and to government health care (which imho is a big problem when we're talking mental health care), and when I say government health care, note that this includes private providers of health care, in other words insurances.

Note: these GPDR exclusions includes denying patients access to their own medical records. So if a hospital lies about "providing you" with mental health treatment (which they are incentivized to do, they get money for that), it can helpfully immediately be used in your divorce. For you yourself, however, it is conveniently impossible to verify if they've done this. Nor can you ask (despite GPDR explicitly granting you this right) to have your medical records just erased.

In other words. GPDR was explicitly created to give people control over their own medical records, and to deny insurance providers and the IRS access. It does the exact opposite.

Exactly the sort of information I would like to hide, exactly the people I would find it critical to hide it from. In other words: GPDR applies pretty much only to US FANG companies ... and no-one else.

So: if you don't pay tax and use that money to pay for a cancer treatment, don't think for a second the GPDR will protect you. If you have cancer and would like to get insured, the insurance companies will know. Etc.

Re: Apple pulls data protection tool after UK government security row

#223

Earlier quoted context omitted.

That was Apple's interpretation : That to comply with what the UK requested they would have to have the same thing everywhere. But of course that is nonsense, and Apple could theoretically have a nation-specific backdoor (e.g. for accounts in a given country a separate sequestered decryption key is created and kept in escrow for court order). I mean, Apple "complied" by disabling ADP just in the UK. They undermined t…

> of course that is nonsense Organizations like the EFF do not agree. > most concerning, the U.K. is apparently seeking a backdoor into users’ data regardless of where they are or what citizenship they have. https://www.eff.org/deeplinks/2025/02/uks-demands-apple-brea...

So Apple is non-compliant, given that all they did is disable ADP in the UK.

Right?

Re: Apple pulls data protection tool after UK government security row

#224

Ok, I am not very technical. Can someone help me understand this. I don't have Advanced data Protection on. Does that mean UK Gov can see my data now?

It means Apple has the encryption keys to your backed-up data. So they can, in theory, access it, if the UK Gov demands that they do. That might never happen to you, but with ADP it would have been impossible, because even Apple can't access it.

See https://support.apple.com/en-us/102651

Re: Apple pulls data protection tool after UK government security row

#225

Note that this doesn’t satisfy the government’s original request, which was for worldwide backdoor access into E2E-encrypted cloud accounts. But I have a more pertinent question: how can you “pull” E2E encryption without data loss? What happens to those that had this enabled? Edit: Part of my concern is that you have to keep in mind Apple's defense against backdooring E2E is the (US) doctrine that work cannot be comp…

We are told the encryption keys reside only on your device. But Apple control “your” device so they can just issue an update that causes your device to decrypt data and upload it.

Re: Apple pulls data protection tool after UK government security row

#226

Think about it.. You don't even have to be an Apple user to be affected by this issue. If someone backs up their conversations with you to apple cloud, your exchange is now fair game. You get no say in it either. We all lose.

That's why it's important to use apps like Signal where you can set the retention of your messages. I've got everybody I know using it now!

Given historical backups are the norm here, retention only does so much.

Really, apps should encrypt their own storage with keys that aren't stored in the backups. That's how you get security/privacy back.

Re: Apple pulls data protection tool after UK government security row

#227
post #38

Earlier quoted context omitted.

> other than the possibility of leaks of the nation’s most sensitive data Amusing when you consider the National Cyber Security Centre (NCSC, a part of GCHQ), along with the Information Commissioners Office, both publish guidance recommending, and describing how to use, encryption to protect personal and sensitive data. Our government is almost schizophrenic in its attitude to encryption.

Correct me if I'm wrong here, and maybe this is too charged for HN, but looking over at you guys from the US: The US has problems (don't get me wrong, look at our politics, enough said); but the UK seems to be speedrunning a collapse. The NHS having patients dying in hallways; Rotherham back in the popular mind; a bad economy even by EU standards; a massive talent exodus (as documented even on HN regarding hardware e…

There's a lethargy, but it's hardly speedrunning. Things will be the same or slightly worse in a decade. I'm not sure I can say the same for the US, it seems different this time.

> The NHS having patients dying in hallways

Sadly routine in winter. Nobody wants to spend the money to fix this. Well, the public want the money spent, but they do not want it raised in taxes.

> Rotherham back in the popular mind

The original events were between 1997 and 2013. The reason they're back in the mind is the newspapers want to keep them there to maintain islamophobia. Other incidents (more recently Glasgow grooming gangs) aren't used for that purpose.

> a bad economy even by EU standards

Average by EU standards. But stagnant, yes.

> the government increasingly acting in every way like it is extremely paranoid of the citizens.

They've been like this my entire life. Arguably it was a bit worse until the IRA ceasefire. Certainly the security services have been pushing anti-encryption for at least three decades.

Re: Apple pulls data protection tool after UK government security row

#228

Note that this doesn’t satisfy the government’s original request, which was for worldwide backdoor access into E2E-encrypted cloud accounts. But I have a more pertinent question: how can you “pull” E2E encryption without data loss? What happens to those that had this enabled? Edit: Part of my concern is that you have to keep in mind Apple's defense against backdooring E2E is the (US) doctrine that work cannot be comp…

> how can you “pull” E2E encryption without data loss? What happens to those that had this enabled?

They'll keep your data hostage and disable your iCloud account. Clever, huh? So they are not deleting it, just disabling your account. "If you don't like it, make your own hardware and cloud storage company" kind of a thing.

Re: Apple pulls data protection tool after UK government security row

#229

Note that this doesn’t satisfy the government’s original request, which was for worldwide backdoor access into E2E-encrypted cloud accounts. But I have a more pertinent question: how can you “pull” E2E encryption without data loss? What happens to those that had this enabled? Edit: Part of my concern is that you have to keep in mind Apple's defense against backdooring E2E is the (US) doctrine that work cannot be comp…

The iOS screenshot displays a message saying it's no longer available for new users.

Re: Apple pulls data protection tool after UK government security row

#230

It's the right choice: don't bow to government pressure, let the people pressure the government.

This is Apple condeeding. Apple lost. UK Government got (almost) what they wanted - a backdoor into iCloud accounts.

Apple's only consolation prize is that its limited to UK users for now. But it seems inevitable that ADP will gradually be made illegal all around the world.

Post reply on HN