Alice and Bill have identical Apple devices. Only one gets Apple’s strongest iCloud protection.

509 points•ReturnoftheHack•7 days ago•472 comments•

472 comments

egorfine6 days ago
I genuinely believe that in 2015 Apple had the balls to resist and today they don't.

I am judging by a simple fact, that "please confirm your age" screen is now mandatory during the iPhone setup in all countries, and in some it's behind a KYC. I have a strong opinion that this is insane. And once they let the foot in the door - there is no closing it.

microtonal6 days ago
Even in 2015 Apple put in backdoors. They have been really good at making people believe things that are not true. E.g. from the linked post:

iCloud already protects sensitive categories of data (like Passwords, Health data, Messages in iCloud, etc) with end-to-end encryption by default.

Except that there is a footnote in Apple's security document where they confirm that Messages in iCloud is not end-to-end encrypted if you don't enable ADP and have iCloud Backup enabled (which is probably most users):

Standard data protection: When iCloud Backup is enabled, the keys to your backups are secured in Apple data centers. If you use both iCloud Backup and Messages in iCloud, your backup includes a copy of the Messages in iCloud encryption key to help you recover your data.

https://support.apple.com/en-us/102651

So, there is always a backup of Messages in iCloud accessible to Apple and thus (US?) law enforcement, unless you enable ADP and the people you communicate with also use ADP.

WhatsApp is similar by the way. Unless you enable E2E backups, they end up in iCloud/Google Drive backups and are only encrypted at rest. Of the major messengers, I think only Signal completely opts out of iCloud backups and have their own real E2E-encrypted backups.

Even most technical people I talk to do not know this and don't have ADP enabled.

There are a lot of weak defaults like that.

kyralis6 days ago
The original implementation of iCloud included Apple's ability to recover the data. You can view this as a backdoor, and that might be fair, but the reality is that it's also a feature in the eyes of many customers - because people will lose devices and passwords, and when Apple doesn't have the keys that means they also lose data. Many customers would rather be able to get their data back.

Apple has moved more things into the bucket of "we do not have the keys for this" over time, but pretending that this isn't a tradeoff for the common customer is disingenuous. That's why ADP exists, so that those who want to make a different tradeoff can do so.

Commenters on HN tend to be technically savvy and tend to want the defaults to be tailored to a technically savvy customer base. That's fine, but that's not a real representation of all of the smartphone users out there, and in this case Apple is directly offering the choice that they usually get knocked for taking away.

danhor6 days ago
> WhatsApp is similar by the way. Unless you enable E2E backups, they end up in iCloud/Google Drive backups and are only encrypted at rest

One of the few good things about WhatsApp is that Meta can very credibly claim that they can't access the backups (as they're not stored by Meta). Meta holds the encryption key & Google/Apple hold the backups, so at least you now have deal with two entities to get the data.

I don't think without forcing more customers to loose data (e.g. by requiring them keeping an encryption pin/key) it's possible to perform backups in a (much) better way.

commandersaki3 days ago
Please stop with the hyperbole, weak defaults are not backdoors, know the difference. A backdoor is precisely what the UK was commanding, that is a secret way to siphon the cleartext data while purporting E2EE. Messages and other data syncing to iCloud using standard encryption (that is both you and Apple know the key) is simply a different trust model. It has its own set of benefits because there is less technical burden on the user which would usually arise in the event of a disaster and attempting to recover the data.

Yes, because Apple knows the key, they can yield your cleartext data to law enforcement or whoever they authorise, but that is implied in the trust model, it isn't kept a secret or done dishonestly. A backdoor would is a devious or dishonest mechanism to siphon data, which nothing of the sort is happening here, because the trust model is transparent to the user.

ipython5 days ago
the default is weak because it's the most user-friendly option. Otherwise, you end up with edge cases where the user lost their only device, or they forgot their password, or ... the list goes on and on, and they lose all their previous chat data.

That's a very user-unfriendly place to be. Most users won't understand why their data is gone, become unhappy, and distrust their devices to safely store their data. It's not even about buying more Apple products at that point - it's just literally reinforcing the stigma that "I can't understand tech, it's too complex".

You can't be security-maxxing and user-experience-maxxing at the same time. I do like Apple's approach which at least gives you the option.

sandworm1016 days ago
The week default is having an OS owned/run/managed/backdoored by a publicly traded company. If you are using anything other than open source, anything other than linux, consider all your communications to be availible for subpeona or outright sale to whoever wants them. Signal is great, but only as good as the OS of its host.
briffle6 days ago
They never did. they had the balls to resist against western governments, where it was politically adventagous to do so. They folded to China real quick, because they wanted to make sales. All "icloud storage" in china has been on another storage platform, that follows all the local laws.
egorfine6 days ago
Folding before China in China is not the same as folding before totalitarian western demands.
realusername6 days ago
The only thing where they tried to push back very hard was the EU's DMA, beyond that they folded quickly to absolutely everything else.
indoordin0saur6 days ago
Wait... you mean this was all just a marketing and PR ploy?
SXX6 days ago
Apple routinely removes VPNs and other apps from App Store in Russia even though they supposedly left the market in 2022.

They obvioualy never ever resisted anything except its a good PR stunt.

Zenul_Abidin6 days ago
Apple doesn't KYC in Russia though

We are quickly heading to a world where governments want us to KYC everything, and we saw with the Revolut breach what happens when very, very bad people gain access to our private data.

hn_submit6 days ago
Apple is surely resisting, but there's a limit to how far they're willing to go. They won't risk losing the entire EU market, for example. Or the Chinese market.

The UK is a minor footnote. They can afford to lose it if push came to shove, but for now they're willing to make conciliatory gestures.

GJim6 days ago
> "please confirm your age" screen is now mandatory during the iPhone setup in all countries

Not quite.

The request to confirm age is there, but actually completing it isn't mandatory (though granted, it does leave an 'alert' thingy on your phone settings saying you haven't finished setting it up).

EmbarrassedHelp6 days ago
It locks down devices like ransomware, permanently restricting functionality of web browsers, messaging apps, and other apps until the user submits to age verification. Its mandatory if you want your device to function normally without restrictions.
egorfine6 days ago
There is no "skip" button available.
spr-alex6 days ago
"Withdrawing ADP in the UK did not affect the 14 iCloud categories that were already end-to-end encrypted by default, including iCloud Keychain and Health. ADP increases the total from 14 to 23 categories. For UK users without ADP, the additional categories (iCloud Backup, Photos, Notes, iCloud Drive and so on) revert to Standard Data Protection. ↩

"

Unfortunately this first phrase is not strictly true in the sense that UK customers have their e2ee secrets exposed under common use cases, without requiring a passcode. My copresenter and I published some research at DEF CON 34 this year showing how the e2ee data is particularly vulnerable when ADP is off. Overall, people that do not work with extraction capabilities are currently over-estimating the strength of apple's e2ee and encryption in general. The platform security whitepaper documentation is insufficient on transparency and there are a number of best practices Apple is not following to better meet the e2ee claims they currently advertise.

palmotea6 days ago
> Faced with a legal order that would have required it to change the security architecture on which ADP depended, Apple found a third option: stop offering the feature that made this dilemma exist in the first place. It reverted affected UK iCloud data to Standard Data Protection, where Apple does hold the keys and can respond to lawful legal procress (except the baseline categories that stay end-to-end encrypted either way). This satisfied the underlying legal requirement without ever building a ‘backdoor’.

Maybe Apple should withdraw all encryption support from all UK government accounts? The Prime Minister can use a Huawei or some chunky thing from a military contractor.

EmbarrassedHelp6 days ago
The UK is currently demanding that Apple install mandatory OS level client side real time scanning malware on every device, bypassing all security and encryption to monitor everything. Its an insanely evil and completely unacceptable demand.

Apple should withdraw from the UK until the UK government learns to respect encryption and privacy.

KaiserPro6 days ago
> UK is currently demanding that Apple install mandatory OS level client side real time scanning malware on every device,

it is?

stephbook6 days ago
Yep, normalize US tech bros punishing a democracy for some laws. What could go wrong? "I never thought the leopard would eat MY face?!"
y-curious6 days ago
Well in the article they explicitly said they can’t turn off ADP by design, so no luck. But I’m all for making the politicians suffer the consequences of their own decisions.
Obscurity43406 days ago
How are they allowed to even offer e2ee Keychain/iCloud Passwords for example? Isnt that subject to lawful access too?
spr-alex6 days ago
That is exactly the question. I took a look and we presented some of our findings at DEF CON 34. There are paths to decrypting e2ee secrets without the passcode, some of these paths are considered vulnerabilities and have received patches (CVE-2026-28864).
0cf8612b2e1e6 days ago
Exactly my question as well.

Especially since big tech is steaming ahead to mandating passkeys that only they are allowed to control/backup. Not long until all governments could intercept your passwords to all services.

Hasz6 days ago
A non-trivial reason I bought a fairly closed device (macbook) was that Tim Cook, at least publicly, told the FBI to get bent when asked to create a backdoor. Exactly what I want to see, a fight in court.

I would hope to see Apple pull out of the UK market over this, and certainly to stop selling Apple devices to the UK government and to remove the UK government entities from Apple services.

esskay6 days ago
They dont really need to pull out, instead on every single piece of marketing material where they talk about anything remotely close to things affected by this they mention that unfortunately they cant give it to UK users due to the governments desire to erode privacy protection, and really hammer home how bad it is.
sdcfgy6 days ago
I love this. Apple aren't going to pull out of a market. They aren't pulling out of China for example.
Hasz6 days ago
oh, I know, but I wish they would. You can see what this looks like when someone like CMMG refuses to sell to specific law enforcement agencies based on local law.
negura6 days ago
I really don't understand this. That's how you make your security decisions? Based on something you've read about Tim Cook in the news? But no third party audit, no open source code, no decentralization, zero self-hosted infrastructure? You put all your data in a black box that someone else controls fully, but hey, at least they took the FBI to court once? And on top of that considering this is Apple, well known for dazzling people with superficial first-impressions, into making bad long-term choices?
Hasz5 days ago
I sent an RFP to all the hardware makers, but no one was willing to cough up a third party audit, let me audit their flashing process, crack open the IME, let me review the chain of custody for every chip, and opensource the bootloader for my n=1 order quantity.

Could I flash coreboot/libreboot, (mostly) disable IME, get opensource firmware for every peripheral, and get a chain of custody for every part from boule to finished part? perhaps, but this is not realistic for most people.

You're making a long list of assumptions that are not true. Incremental, improved privacy offered by apple over something like Windows is a significant improvement for most people.

Going to court is the pretty good "put up or shut up", idk what else you are expecting here.

unsane5 days ago
Word. The comment you replied to also gave me a thought.

Tim's public displays for privacy would be a perfect cover story for a gagged backdoored device.

Not likely the case in 2015 Apple nor probably even now, but perhaps a technique for the future or elsewhere to watch out for.

ghostly_s6 days ago
This happened 18 months ago, you can stop hoping.
RandomGerm4n6 days ago
What I don't understand is why Apple is even responding to this absurd demand. Completely banning Apple products in the UK isn't a realistic option for the government, so Apple could simply state openly that it does not cooperate with authoritarian regimes and actively prompt British users via a pop-up to enable ADP to protect themselves from the government.
jeroenhd6 days ago
Apple complies with the Chinese government's demands, that's the minimum they're willing to play along with. The UK is well above that.
autoexec6 days ago
If apple didn't comply with the Chinese government they'd probably be asked to pack up their suicide nets and find somewhere else with sophisticated manufacturing facilities filled with slaves to make their products.
aDyslecticCrow6 days ago
But apple also cannot just stop selling or supporting their product in the UK either. So that card is dropped from both sides. As long as apple is beholden to a few million costumers and subscribers to their services in the UK; UK law is able to pressure them, fine them and restrict them because of those users.

We don't want it the other way around; companies placed outside the borders doing and selling whatever they want without a care. So we end up in a negotiation.

Apple choose to maliciously comply; subtly revealing the TCN, giving all UK users notices about what their government demanded of them to encourage public outrage, and push on the correct parts of the UK government that has their interest in mind.

EmbarrassedHelp6 days ago
> But apple also cannot just stop selling or supporting their product in the UK either.

They can do both of things. There's no law against leaving a country for not respecting human rights like privacy and encryption.

stateofinquiry6 days ago
It seems you are suggesting that if a private corporation (a foreign one at that) is large enough it should ignore the law of the country its operating in. I don't think you will like the consequences of such a situation, and will charitably assume you have just not thought your message through for even a second before posting it.

PS: If you think the British gov is authoritarian.. well, you might not know what the term means and/or anything about the spectrum of governments operating today or in the past.

RandomGerm4n6 days ago
If laws aren't transparent and reasonable, you shouldn't necessarily follow them. If I were to sell encryption software that's banned in Kazakhstan, you wouldn't expect me to stop selling to customers there, would you? I see no reason why the United Kingdom should be treated any differently than Kazakhstan in this case.

The British government is certainly not as authoritarian as those in China or Russia, but that doesn’t change the fact that it’s still terrible and restricts people’s rights. For example, you can be detained for as long as they want if you refuse to unlock your encrypted device.

epihelix6 days ago
To be more charitable, I think they're more suggesting that Apple should call the UK's bluff, knowing that democracies have to be accountable to their citizens.

Can Apple afford to lose the UK market? Almost certainly yes -- it's a fairly minor global player. Can the current UK government afford to deal with the massive fallout of banning all Apple products right now? That might be, as Sir Humphrey Appleby would say, a very courageous move.

In other words, Apple could simply state that in order to protect their users they cannot and will not do this, and will withdraw from the market rather than comply. That puts the onus on the UK government to either put up or shut up.

It would be fascinating to see how this would play out. Would "think of the children" and "OMG, terrorists!!" win against, "but I still want my iProducts"?

Read the full thread on Hacker News →

Related stories