On Friday 21 February, 2025 UK government action significantly weakened data protection capability in the UK. This is an unprecedented attack on the private data of individuals.
The UK government wants access to ALL iCloud data. Access to every user's data around the world.
The UK Government has for some time been trying to force Apple to provide a backdoor into the iCloud data storage end to end encrypted security system. A Technical Capability Notice (TCN) was issued under the Investigatory Powers Act 2016 by the UK government to Apple. The TCN means that, with a warrant, the UK government can be given by Apple the iCloud data (photos, videos, documents and other data) of any UK user of iCloud.
A TCN is a secret legal notice issued to a company, i.e. the government does not wish it to be general knowledge. It is not illegal to report on the existence of a TCN, however the individual target of a notice is instructed not to disclose it and seemingly can face legal action if they do so, although there is some doubt about this interpretation of the law.
The UK government wanted Apple to create a backdoor to iCloud so that data could be extracted by Apple and given to the UK government, law enforcement and intelligence services.
Apple resisted the demands from the UK government until 3pm on 21 February when they withdrew Advanced Data Protection from the UK. New users can no longer switch the ADP option on.
How about if it is already switched on? At some point in the future Apple will be telling UK users that to continue using iCloud the ADP option must be deselected.
Apple said on Friday "We are gravely disappointed that the protections provided by ADP will not be available to our customers in the UK given the continuing rise of data breaches and other threats to customer privacy". The spokesperson added: “As we have said many times before, we have never built a backdoor or master key to any of our products or services and we never will.
Advanced Data Protection provides end to end encryption for iCloud data. Encryption is provided by a public encryption key on iCloud servers and a private decryption key on authorised devices, computers, phones, tablets.
Encryption makes your data unreadable by unauthorised people accessing your data. No one can read iCloud data apart from the account holder and those authorised to access it.
Data in iCloud will no longer be encrypted meaning that Apple, the UK government and anyone who accesses your account, e.g. a hacker can read your data.
The UK government argues that end to end encryption protects cyber criminals and endangers children online.
Let's be clear, cyber criminals and those engaged in child sexual abuse material (CASM) do not use iCloud. They use the dark web and this action by the UK government will have little or no impact on cyber crime and CSAM.
iCloud data is now vulnerable to attack for UK users of iCloud. As cyber attacks continue to increase in number iCloud data will be an easy target.
Will Cathcart, head of WhatsApp, wrote "If the UK forces a global backdoor into Apple's security, it will make everyone in every country less safe. One country's secret order risks putting all of us in danger and it should be stopped."
Senator Ron Wylden, a senior US politician, told BBC News that Apple withdrawing end-to-end encrypted backups from the UK "creates a dangerous precedent which authoritarian countries will surely follow". He believes the move will "not be enough" for the UK to drop its demands, which would "seriously threaten" the privacy of US users.
Both Senator Wylden and Representative Andy Biggs sent a letter to Director of National Intelligence Tulsi Gabbard, saying that Apple acceding to the U.K.'s request for a technical solution would “seriously threaten the privacy and security of both the American people and the U.S. government and that intelligence sharing agreements with the UK should be withdrawn.
As mentioned at the start of the article, the UK government wants global access to iCloud data. Whether Apple's actions will satisfy the UK government is not known. However, partial success at Apple will mean that they will undertake TCN's at every other tech company, and may already be doing so.
This is a very misdirected attempt by the UK government affecting the ability of every cloud user to protect their data. There will be an increase in attacks in the UK because we have become an easy target.
