Apple disables strongest encryption for UK users after government pressure
UK government order forced Apple to withdraw Advanced Data Protection for new users, creating two-tier security among identical devices.
What to know
- Apple disabled Advanced Data Protection—its strongest encryption standard—for new UK users in February 2025 after the government issued a Technical Capability Notice under the Investigatory Powers Act 2016.
- The company chose to withdraw the feature entirely rather than build a backdoor, but existing UK users who enabled it before the deadline retain full protection while new users do not.
- The move contradicts Apple's 2015 public stand against the FBI, showing how regulatory pressure can achieve what courts could not—encryption access without technically breaching the company's stated principles.
The dispute Commenters dispute whether the '30 arrests a day' statistic cited as evidence of UK speech suppression accurately represents the scope and nature of arrests, with pushback that the figure conflates legitimate harassment enforcement with political censorship. · positions read across 37 posts and comments
Apple has abandoned its encryption principles and will continue compromising across jurisdictions.
-
“I genuinely believe that in 2015 Apple had the balls to resist and today they don't.”
egorfine · Hacker News ↗
Apple found a legitimate compromise by withdrawing the feature rather than building a backdoor, avoiding the technical architecture violation it warned about in 2015.
-
“Apple found a third option: stop offering the feature that made this dilemma exist in the first place… This satisfied the underlying legal requirement without ever building a 'backdoor'.”
palmotea · Hacker News ↗
The UK government's speech enforcement regime makes encryption withholding reasonable, as the state cannot be trusted with access.
-
“No need to speculate that the UK government "might" one day become the bad guys: they already arrest over 30 people a day for speech that offends the prevailing political orthodoxy.”
failbuffer · Hacker News ↗
Tim Cook Apple CEOUK Government Regulatory authorityApple Technology company
How it unfolded 0 developments, newest first · click a bar or a number to jump
-
background
UK government orders Apple to weaken iCloud encryption via Technical Capability Notice — The Washington Post reveals the UK government has issued a Technical Capability Notice under the Investigatory Powers Act 2016, ordering Apple to maintain or develop capability to provide access to data protected by its strongest level of iCloud encryption (Advanced Data Protection).
-
background
Apple withdraws Advanced Data Protection from new UK users — Faced with the legal order, Apple discontinues offering Advanced Data Protection to new UK users rather than create a backdoor. Existing users who enabled the feature before the withdrawal retain it; new users can only access Standard Data Protection where Apple holds encryption keys.
-
background
San Bernardino attack prompts FBI to demand iPhone backdoor — After the December 2, 2015 terrorist attack killing 14 and wounding 22, the FBI obtains a court order compelling Apple to create a version of iOS that would bypass security protections on the shooter's iPhone 5C.
-
background
Apple refuses FBI demand, Cook calls requested tool 'equivalent of cancer' — Cook defends Apple's position in multiple interviews, describing the requested software as a 'master key' capable of unlocking hundreds of millions of devices. He warns that once built, there is no guarantee it would only be used against one phone.
-
background
Tim Cook affirms Apple's encryption stance after Snowden revelations — In an ABC News interview, Cook states there is no backdoor and the government does not have access to Apple's servers, saying they would have to "cart us out in a box" to compel compliance.
What people are saying 24 voices from 1 site · best of 37 · verbatim
- Yesterday
-
As I have said before, all these wannable surveillance measures should start with first making data and lives of the involved ministers/law-makers, public, 24x7, over internet, for anyone to access. All data. Including private ones. Including their family members, and bank records.. of course, not passwords. Let's see how they feel.
-
Apple is surely resisting, but there's a limit to how far they're willing to go. They won't risk losing the entire EU market, for example. Or the Chinese market.The UK is a minor footnote. They can afford to lose it if push came to shove, but for now they're willing to make conciliatory gestures.
-
"Withdrawing ADP in the UK did not affect the 14 iCloud categories that were already end-to-end encrypted by default, including iCloud Keychain and Health. ADP increases the total from 14 to 23 categories. For UK users without ADP, the additional categories (iCloud Backup, Photos, Notes, iCloud Drive and so on) revert to Standard Data Protection…
-
Even in 2015 Apple put in backdoors. They have been really good at making people believe things that are not true. E.g. from the linked post:iCloud already protects sensitive categories of data (like Passwords, Health data, Messages in iCloud, etc) with end-to-end encryption by default.Except that there is a footnote in Apple's security document…
-
>. It reverted affected UK iCloud data to Standard Data Protection, where Apple does hold the keys and can respond to lawful legal procress (except the baseline categories that stay end-to-end encrypted either way). This satisfied the underlying legal requirement without ever building a ‘backdoor’.Ah, just like that.Of course something that is…
-
I think whether there is closing it depends on what we do with the intelligence explosion. I expect such decisions will be revisited. It will probably not be closed, but it won't be open after that point because it was opened back then, it will be specifically decided to keep it open.
-
What I don't understand is why Apple is even responding to this absurd demand. Completely banning Apple products in the UK isn't a realistic option for the government, so Apple could simply state openly that it does not cooperate with authoritarian regimes and actively prompt British users via a pop-up to enable ADP to protect themselves from the…
-
If ensuring digital devices can be accessed by law enforcement (are not "beyond the law") is so important where are the task forces shutting down crypto and networks using unregulated and anonymous currency? Literally follow the money, as they say. The current admin has 'made' millions if not more off his own fraudulent coin. Take down crypto and…
-
I think this is mostly being misrepresented.There is speech and there are consequences for speech.If I incite or state that I am going to commit violence, stalking, rape or murder, should I face consequences? Yes. That's what is happening.There are outlying cases which will be used to discredit this perspective but reality is there are a hell of a…
-
yes, its not legal to harass women getting an abortion. That includes being in a given range of an abortion clinic and making a political statement. What part of that is hard to understand?People know the laws and yet they still do it thinking they're some sort of Catholic Batman. You want to change the law, do what we all do; write to your…
-
Anyone old enough to remember the London riots should remember the fact that the acting government issued a D notice to all broadcasters, preventing them from reporting the issue.This is part of what started the death of BBM and proliferation of news via social media. You’d go on Twitter and see all the reports or riots and burning buildings then…
-
What I don't understand, or what I can only guess at, is the cabal & likely global network of interests that are behind the push for this kind of legislation to exists in the first place.Some delusional "save the children" anti-privacy extremist doesn't have the political capital or the technical insight to convince the government to create a law…
-
given the story there, I'm surprised apple are still allowed to apply end to end encryption the the "baseline categories" such as messages etc in the UK. Anyone understand how that's happened? To be clear I am not saying what I think should happen, just it seems inconsistent with the UK's stance
-
> "please confirm your age" screen is now mandatory during the iPhone setup in all countriesNot quite.The request to confirm age is there, but actually completing it isn't mandatory (though granted, it does leave an 'alert' thingy on your phone settings saying you haven't finished setting it up).
-
You can get arrested for making a joke that might offend someone in a private whatsapp group. Doesn't even have to be political.I think this is the link where the chap asks for legal advice:
-
Strange and hypothetical thought: could Bill purchase a US or international model of the iPhone with US or international iCloud account capable of ADP to activate ADP? Would this allow somebody living or working in the UK the ability to use ADP?
-
> Faced with a legal order that would have required it to change the security architecture on which ADP depended, Apple found a third option: stop offering the feature that made this dilemma exist in the first place. It reverted affected UK iCloud data to Standard Data Protection, where Apple does hold the keys and can respond to lawful legal…
-
A non-trivial reason I bought a fairly closed device (macbook) was that Tim Cook, at least publicly, told the FBI to get bent when asked to create a backdoor. Exactly what I want to see, a fight in court.I would hope to see Apple pull out of the UK market over this, and certainly to stop selling Apple devices to the UK government and to remove the…
-
They never did. they had the balls to resist against western governments, where it was politically adventagous to do so. They folded to China real quick, because they wanted to make sales. All "icloud storage" in china has been on another storage platform, that follows all the local laws.
-
> they already arrest over 30 people a day for speech that offends the prevailing political orthodoxy.This is completely false and comes from a commonly misrepresented statistic; '30 arrests a day' is plainly the arrests made under section 127 of the Communications Act 2003 and section 1 of the Malicious Communications Act 1988 which includes…
-
Everyone should read the case of the IT consultant getting arrested in the UK because he posted a photo of him doing some target shooting during a trip to the US: https://www.lbc.co.uk/article/consultant-arrested-linkedin-s...Stories like this quickly put to rest the idea that everyone who gets arrested must actually deserve it. The bar for…
-
> The wife of a conservative politician was sentenced to 31 months in prison for what police said was an unacceptable post.Pretty sure she called for the murder, by arson, of asylum seekers although the article missed that bit out.
-
I genuinely believe that in 2015 Apple had the balls to resist and today they don't.I am judging by a simple fact, that "please confirm your age" screen is now mandatory during the iPhone setup in all countries, and in some it's behind a KYC. I have a strong opinion that this is insane. And once they let the foot in the door - there is no closing…
-
No need to speculate that the UK government "might" one day become the bad guys: they already arrest over 30 people a day for speech that offends the prevailing political orthodoxy.[1]