Two-tier encryption in the UK (macanorak.com)
344 points by ReturnoftheHack 11 hours ago
egorfine 8 hours ago
I genuinely believe that in 2015 Apple had the balls to resist and today they don't.
I am judging by a simple fact, that "please confirm your age" screen is now mandatory during the iPhone setup in all countries, and in some it's behind a KYC. I have a strong opinion that this is insane. And once they let the foot in the door - there is no closing it.
microtonal 4 hours ago
Even in 2015 Apple put in backdoors. They have been really good at making people believe things that are not true. E.g. from the linked post:
iCloud already protects sensitive categories of data (like Passwords, Health data, Messages in iCloud, etc) with end-to-end encryption by default.
Except that there is a footnote in Apple's security document where they confirm that Messages in iCloud is not end-to-end encrypted if you don't enable ADP and have iCloud Backup enabled (which is probably most users):
Standard data protection: When iCloud Backup is enabled, the keys to your backups are secured in Apple data centers. If you use both iCloud Backup and Messages in iCloud, your backup includes a copy of the Messages in iCloud encryption key to help you recover your data.
https://support.apple.com/en-us/102651
So, there is always a backup of Messages in iCloud accessible to Apple and thus (US?) law enforcement, unless you enable ADP and the people you communicate with also use ADP.
WhatsApp is similar by the way. Unless you enable E2E backups, they end up in iCloud/Google Drive backups and are only encrypted at rest. Of the major messengers, I think only Signal completely opts out of iCloud backups and have their own real E2E-encrypted backups.
Even most technical people I talk to do not know this and don't have ADP enabled.
There are a lot of weak defaults like that.
kyralis 3 hours ago
The original implementation of iCloud included Apple's ability to recover the data. You can view this as a backdoor, and that might be fair, but the reality is that it's also a feature in the eyes of many customers - because people will lose devices and passwords, and when Apple doesn't have the keys that means they also lose data. Many customers would rather be able to get their data back.
Apple has moved more things into the bucket of "we do not have the keys for this" over time, but pretending that this isn't a tradeoff for the common customer is disingenuous. That's why ADP exists, so that those who want to make a different tradeoff can do so.
Commenters on HN tend to be technically savvy and tend to want the defaults to be tailored to a technically savvy customer base. That's fine, but that's not a real representation of all of the smartphone users out there, and in this case Apple is directly offering the choice that they usually get knocked for taking away.
briffle 8 hours ago
They never did. they had the balls to resist against western governments, where it was politically adventagous to do so. They folded to China real quick, because they wanted to make sales. All "icloud storage" in china has been on another storage platform, that follows all the local laws.
egorfine 7 hours ago
Folding before China in China is not the same as folding before totalitarian western demands.
throwawayffffas 7 hours ago
ImJamal 3 hours ago
indoordin0saur an hour ago
Wait... you mean this was all just a marketing and PR ploy?
realusername 8 hours ago
The only thing where they tried to push back very hard was the EU's DMA, beyond that they folded quickly to absolutely everything else.
PorciiVorbesc 5 hours ago
SXX 7 hours ago
Apple routinely removes VPNs and other apps from App Store in Russia even though they supposedly left the market in 2022.
They obvioualy never ever resisted anything except its a good PR stunt.
Zenul_Abidin 5 hours ago
Apple doesn't KYC in Russia though
We are quickly heading to a world where governments want us to KYC everything, and we saw with the Revolut breach what happens when very, very bad people gain access to our private data.
SXX 3 hours ago
hn_submit an hour ago
Apple is surely resisting, but there's a limit to how far they're willing to go. They won't risk losing the entire EU market, for example. Or the Chinese market.
The UK is a minor footnote. They can afford to lose it if push came to shove, but for now they're willing to make conciliatory gestures.
MisterMunchkin an hour ago
I never had to confirm my age because my account is old enough to prove I must be old enough
egorfine 23 minutes ago
Same here. Problem is, I never gave Apple permission to infer about my age. It's none of anyone's business. So when iPhone rebooted after upgrade and told me "you are old enough, I know it" I was simultaneously relieved that I won't be required to pass KYC (never an option) and furious that this shit ever came about.
GJim 7 hours ago
> "please confirm your age" screen is now mandatory during the iPhone setup in all countries
Not quite.
The request to confirm age is there, but actually completing it isn't mandatory (though granted, it does leave an 'alert' thingy on your phone settings saying you haven't finished setting it up).
EmbarrassedHelp 2 hours ago
It locks down devices like ransomware, permanently restricting functionality of web browsers, messaging apps, and other apps until the user submits to age verification. Its mandatory if you want your device to function normally without restrictions.
egorfine 7 hours ago
There is no "skip" button available.
someonebaggy 6 hours ago
Is it required to KYC in those countries?
I'm generally okay with "how old are you?" without KYC and changeable later. It just allows apps and websites to display age-appropriate content.
egorfine 6 hours ago
> I'm generally okay with "how old are you?"
It's a foot in the door. Once this question exists, the next logical one is "prove it".
someonebaggy 6 hours ago
ajsnigrutin 6 hours ago
benatkin 4 hours ago
I doubt that with the speed of thought dramatically increasing due to AI, that the door will stay closed just because it's being closed now. That decision will be revisited.
failbuffer 8 hours ago
No need to speculate that the UK government "might" one day become the bad guys: they already arrest over 30 people a day for speech that offends the prevailing political orthodoxy.
[1] https://www.forbes.com/sites/steveforbes/2025/09/09/people-a...
Aurornis 8 hours ago
Everyone should read the case of the IT consultant getting arrested in the UK because he posted a photo of him doing some target shooting during a trip to the US: https://www.lbc.co.uk/article/consultant-arrested-linkedin-s...
Stories like this quickly put to rest the idea that everyone who gets arrested must actually deserve it. The bar for posting content that violates the law is very low.
There was also the tragic story of the Cambridge professor who was completely unqualified and had a fake life story. When journalists would get close to the story he would report them to the police for harassment to spike the stories.
chmod775 4 hours ago
I don't know about that case, but the bar is as low as it can be anyways. Hapless UK police are willing to play attack dog for nearly anyone.
Someone got arrested and intimidated by police because they criticized someone with even only a modicom of authority: https://www.theguardian.com/uk-news/2025/mar/29/parents-arre...
Imagine getting six police officers sent to your house and spending 11 hours at a police station for causing "disharmony" by disagreeing with how your daughter's school operates in a WhatsApp group. In a sensible country that might've been a phone call or a single officer stopping to chat and defusing the situation if police decided to get involved at all.
foldr 4 hours ago
walrus01 18 minutes ago
Entirely aside from the getting arrested in the UK part, what sort of absolute noob posts photos of themselves shooting an AR15 that has no sights whatsoever on it?
amiga386 7 hours ago
In this particular case, the IT consultant was owed money by a failing business, and he put 1) a picture of the business premises, and 2) pictures of him firing guns, on a website where he was sure the business owner would see it.
That's textbook intimidation, which in certain cases is a crime in the UK, and even some US states. You can also do it offline, for example, by sending a letter to the victim containing a photograph of the front of their house, and a photograph of you firing guns. The implication is pretty straightforward and doesn't even need to be stated: "I have guns and I know where you live. Pay me that money you owe me or I might use them." That implication is still there, for the victim, even if you add surface text like "Hey everyone look at these cool things!"
Only _after_ he was arrested, and the police went looking around his house for guns... did he admit that the pictures were taken overseas, he doesn't actually own the guns. And yet that's what the article leads with, like it was a known fact from the get-go and those silly-billy police knew that but went looking for them in the UK anyway.
This article is a great lesson in how to mislead without saying anything untrue.
His own words in a different article make the reason for the arrest clear:
https://nypost.com/2025/12/04/us-news/british-man-says-he-wa...
> “The arrest was based on two separate social media posts,” he said. “One was the photo of myself with the shotgun, [...] And the second one was my LinkedIn banner at the top of the page.”
> “I used the photo my business partner took on his premises as a header photo on LinkedIn with the intention he would look at that and go, ‘Why’s this guy posting that? I’d better call him and find out rather than dodging me’ as it had done for months,” he said.
EDIT 2: for avoidance of doubt, he did three days in a row of LinkedIn blog posts, where
1) his PFP at the time (shown in the top-right corner) was a picture of the business premises
2) the text of the post talked about the "delinquent client"
3) the post ended with a no-context-given picture of him posing with guns
Example: https://www.linkedin.com/posts/jonrichelieu-booth_jonthehash...
EDIT: and your second example is also dangerously misleading. Jason Arday (https://en.wikipedia.org/wiki/Jason_Arday) and/or his university reported 2 professors and 1 journalist to the police, pretending their requests for comment on his plagiarism were harrassment. For all three reports, police chose to take no action (nonetheless it still had a chilling effect on speech). What spiked the story is that Jason Arday and/or his university got very expensive reputation lawyers Carter-Fuck to send a C&D to the journalist's newspaper, promising expensive litigation if they published the story. That is what spiked the story, not intimidation via false harassment claims. Expensive lawyers making baseless threats work equally well in the US and UK to chill legal speech, it's not a policy issue.
kvuj 7 hours ago
joenot443 4 hours ago
ifh-hn 7 hours ago
pepperoni_pizza 3 hours ago
Aurornis 7 hours ago
tigershark 7 hours ago
someonebaggy 6 hours ago
Quarrelsome 6 hours ago
yes, its not legal to harass women getting an abortion. That includes being in a given range of an abortion clinic and making a political statement. What part of that is hard to understand?
People know the laws and yet they still do it thinking they're some sort of Catholic Batman. You want to change the law, do what we all do; write to your fucking MP, join a political party, campaign, donate. Don't harass someone vulnerable in a difficult state of mind and impose your morality upon them. Respect their choice and their agency.
In the US you can be arrested for the following speech:
* true threats of violence
* incitement to break the law specifically
* crimes of speech: soliciting crime, fraudulent representations, lying under oath
* stalking/cyberstalking
So lets quit this idea that its some abstract of "political orthodoxy". Stop framing crime as "difference of opinion". Hate speech and incitement to racial/religious hatred or violence are crimes here. People publishing hate speech online and then being all Pikachu face when they get arrested for breaking the law are not victims. The highest profile pretend victim was the wife of a Conservative Councillor who posted a message online that hundreds of thousands of people saw that encouraged people to set fire to hotels where asylum seekers were staying. The judges sentencing remarks were particularly eye opening given she demonstrated a relative lack of respect for the court ("If I get in trouble then I'll play the mental health card").
cobbzilla 6 hours ago
Do you worry that if your worst enemies were in power, something that you or a friend might say would lead to an arrest?
Who decides what is hate speech? Apparently the current UK government has decided these things (among others) are so hateful their perpetrators must be arrested:
- private WhatsApp chats between friends
- standing still in public with hands folded in prayer
Be careful when you give sharp tools to the golem.
Quarrelsome 5 hours ago
weatherlite 4 hours ago
> Hate speech and incitement to racial/religious hatred or violence are crimes here
Unless it's hate speech against "Zionists" and/or Jews , then it's tolerated, often celebrated. Not all hate speech is created equal.
Quarrelsome 3 hours ago
nullbio 4 hours ago
https://www.foxnews.com/world/blogger-arrested-sharing-anti-...
So this is normal in your eyes?
Quarrelsome 3 hours ago
fragilerock 8 hours ago
> they already arrest over 30 people a day for speech that offends the prevailing political orthodoxy.
This is completely false and comes from a commonly misrepresented statistic; '30 arrests a day' is plainly the arrests made under section 127 of the Communications Act 2003 and section 1 of the Malicious Communications Act 1988 which includes things like online stalking and harassment. I hope you're just mistaken and not willfully implying that those issues are merely offensive to the prevailing political orthodoxy.
468854259853 2 hours ago
How convenient for the terrorist regime in the UK that wrongthink falls under Malicious Communications.
gib444 7 hours ago
You can't argue with data that doesn't exist, either. The arrests are not broken down, so nobody really knows. Both sides can argue their opinion
You can argue it's highly improbable that all arrests are over 'hurty words online', definitely – but anyone claiming zero arrests seems improbable too.
I do also feel it's quite convenient that the lack of breakdown allows people to clap back with accusations of encouraging stalking and harassment.
fragilerock 7 hours ago
crimsoneer 7 hours ago
foldr 7 hours ago
sdcfgy 6 hours ago
I think this is mostly being misrepresented.
There is speech and there are consequences for speech.
If I incite or state that I am going to commit violence, stalking, rape or murder, should I face consequences? Yes. That's what is happening.
There are outlying cases which will be used to discredit this perspective but reality is there are a hell of a lot of very not nice people out there making active threats and inciting hatred and violence.
And everyone gets their day in court.
gadders 7 hours ago
You can get arrested for making a joke that might offend someone in a private whatsapp group. Doesn't even have to be political.
I think this is the link where the chap asks for legal advice: https://www.reddit.com/r/LegalAdviceUK/comments/1vxkcic/poli...
amiga386 5 hours ago
Reddit often contains completely made up but believeable bullshit, so I wouldn't cite anything you see there. Every single post or comment could be a creative writing exercise to gain karma or sow discord.
However, if you want hard evidence what that post was claiming, I can give you a real citation from 2018:
https://www.bbc.co.uk/news/uk-46106224
> A house linked to an "offensive" video showing a model of Grenfell Tower being burned on a bonfire has been searched by police. Six men [...] were arrested on suspicion of a public order offence and have been released under investigation. A video shared on social media shows a cardboard model of the tower being set alight by a laughing crowd.
https://www.bbc.co.uk/news/uk-46112026
> Can I be offensive in my own home?
> Basically, yes. [...] if you make offensive comments in your home and they are recorded and posted online, it might be possible that you could be prosecuted.
amiga386 2 hours ago
someonebaggy 6 hours ago
Since Reddit is now login-walled, can you share what it says?
gadders 6 hours ago
makingstuffs 6 hours ago
Anyone old enough to remember the London riots should remember the fact that the acting government issued a D notice to all broadcasters, preventing them from reporting the issue.
This is part of what started the death of BBM and proliferation of news via social media. You’d go on Twitter and see all the reports or riots and burning buildings then go to the BBC and… nothing.
All of this is to say that successive British governments, over a span of decades, have been actively destroying freedom of speech and a right to privacy for its citizens.
With AI and the rise of populism combined with the absolute decimation of the average person’s attention span it is going to get a lot worse.
sdcfgy 6 hours ago
This is wrong. The BBC were reporting on it in detail both online and on TV news. I know this because I was actually working on contract for them at the time.
What we have is a lot of people changing the narrative since to discredit the BBC and divide everyone further.
makingstuffs 5 hours ago
Quarrelsome 6 hours ago
Mark Duggan was a gangster, so people trying to frame it as some sort of execution seemed to not understand that the police were seemingly doing their job. Chris Kaba's death also resulted in protests and demonstrations despite the evidence[0].
rich_sasha 8 hours ago
I’d say it is a very low quality article. There is very little detail about what the offending speech actually includes. For example:
> The wife of a conservative politician was sentenced to 31 months in prison for what police said was an unacceptable post.
What did she say? The article does not elucidate.
Inciting violence for example is not legal. I believe spaces around abortion clinics are also to be free from demonstrations. US free speech absolutists seem to vehemently disagree until you say something unkind about Charlie Kirk or ICE.
The low point might be quoting Elon Musk. This is true in any context, but in particular here. The scandal is real, but none of it is about people being arrested for non-politically-correct speech.
There’s plenty of otherwise real stuff to poke the UK about.
ljf 8 hours ago
I don't have time to dig up her post - but she was calling on people to set fire to hotels housing asylum seekers - she had around 10,000 followers, and her post was read 300,000 times: https://www.bbc.co.uk/news/articles/c5yl7p4l11po
Quarrelsome 6 hours ago
ctjr 7 hours ago
alexfoo 8 hours ago
> What did she say?
lemmetellya 8 hours ago
She advocated to burn refugees alive.
graemep 8 hours ago
UK abortion clinic laws go a lot further than banning demonstrations.
1. Holding up a sign offering help to any women being coerced into an abortion is illegal. 2. Standing silently on the road near one can be illegal. 3. parking a car with a bumper sticker near one can be illegal.
The whole paragraph about Musk and rape gangs is nonsense, of course. The biggest rape gang ever convicted in the UK was entirely white. Musk and his ilk only care about rape when the rapists are not white. On average immigrants are slightly less likely to commit sexual assaults (obviously averaging across many different groups).
> What did she say? The article does not elucidate.
She called for hotels housing asylum seekers to be burned. I think she is a nasty racist but I also think the sentence was excessive and I am not convinced it was a serious incitement to violence (and that was not what she was convicted of).
> US free speech absolutists seem to vehemently disagree until you say something unkind about Charlie Kirk or ICE.
Not American, and I entirely support the right of anyone to make unkind comments about anyone else. You are right that many people apply different standards to their own side, but right wing Americans are are from alone in that.
Quarrelsome 6 hours ago
TheOtherHobbes 7 hours ago
gadders 7 hours ago
IslandRebel 7 hours ago
The British Government has be consistently violating people's rights for decades and probably well before that.
Recently I saw a clip on GB News where one of their analyst said that anyone that opposes a war and/or conscription with Russia will need to put in prison. The show host, Jacob Rees Mogg and Lord Redwood saw nothing wrong with the statements.
None of these people have been in the armed forces and are too old to be called up for conscription.
RobotToaster 6 hours ago
> and probably well before that.
319 years, 4 months, 3 weeks, 2 days to be exact.
IslandRebel 5 hours ago
maxehmookau 8 hours ago
> The wife of a conservative politician was sentenced to 31 months in prison for what police said was an unacceptable post.
Pretty sure she called for the murder, by arson, of asylum seekers although the article missed that bit out.
crimsoneer 7 hours ago
Sigh, this is an absolute bullshit figure and people need to stop parroting it - it's 30 arrests under the mal comms act which might include for example, phoning your ex girfriend to say you're coming to stab her. Or phoning in a bomb threat via telephone. Or any number of pretty terrible things it's perfectly reasonable to get nicked for. Or posting on Facebook telling everyone we should set the local migrant hotel on fire. These are not political prisoners.
https://lordslibrary.parliament.uk/select-communications-off...
someonebaggy 6 hours ago
What was the speech? I can't read beyond the paywall.
timhh 6 hours ago
Yeah come on, that figure has been widely debunked.
clarkmoody 7 hours ago
Subjects, not citizens.
tompagenet2 7 hours ago
I'm going to assume good intent against every possible signal here. See https://www.gov.uk/types-of-british-nationality/british-subj... for why you're wrong
rorylawless 8 hours ago
This is a deeply deranged opinion piece. The author ties himself into knots to conflate a tiny number of high profile instances involving social media posts with harassment and other negative behavior involving electronic communication.
cjrp 8 hours ago
How many of those 30 are unarguably "bad" posts though? Threats of violence and so forth.
erkt 8 hours ago
250 years ago some people made some bad posts about throwing some tea into the harbor. Calling for revolution isn't a bad post.
_verandaguy 6 hours ago
monkey_monkey 8 hours ago
wooger 8 hours ago
I'd argue that nothing is "inarguable"
StrLght 8 hours ago
liveoneggs 8 hours ago
If 27/30 meet the bar for "bad" is that an acceptable level of policing speech? 19/30?
PowerElectronix 7 hours ago
I dislike harassing, threats, hate speech and everything wrong that people yell to other people.
But I dislike even more that we decide that the solution to it is to pass laws prohibiting speech, and even more that the ones in charge of passing those laws are very incentivised to prohibiting criticism to themselves or their policies or their ideologies.
someonebaggy 6 hours ago
testfrequency 8 hours ago
The chronically online anti-uk folks like to turn a blind eye to anything that’s justifiable for matter of principal.
It’s why the US has such a problem with gun control and laws.
I could argue everyone should have guns, and it’s just bad people, right?
WmWsjA6B29B4nfk 8 hours ago
DiogenesKynikos 8 hours ago
I don't know, but the UK has criminalized expressions of support for Palestine Action.
They're dragging grannies off to prison just for holding up signs, and literally accusing them of supporting terrorism.
4ndrewl 7 hours ago
spr-alex 3 hours ago
"Withdrawing ADP in the UK did not affect the 14 iCloud categories that were already end-to-end encrypted by default, including iCloud Keychain and Health. ADP increases the total from 14 to 23 categories. For UK users without ADP, the additional categories (iCloud Backup, Photos, Notes, iCloud Drive and so on) revert to Standard Data Protection. ↩
"
Unfortunately this first phrase is not strictly true in the sense that UK customers have their e2ee secrets exposed under common use cases, without requiring a passcode. My copresenter and I published some research at DEF CON 34 this year showing how the e2ee data is particularly vulnerable when ADP is off. Overall, people that do not work with extraction capabilities are currently over-estimating the strength of apple's e2ee and encryption in general. The platform security whitepaper documentation is insufficient on transparency and there are a number of best practices Apple is not following to better meet the e2ee claims they currently advertise.
palmotea 7 hours ago
> Faced with a legal order that would have required it to change the security architecture on which ADP depended, Apple found a third option: stop offering the feature that made this dilemma exist in the first place. It reverted affected UK iCloud data to Standard Data Protection, where Apple does hold the keys and can respond to lawful legal procress (except the baseline categories that stay end-to-end encrypted either way). This satisfied the underlying legal requirement without ever building a ‘backdoor’.
Maybe Apple should withdraw all encryption support from all UK government accounts? The Prime Minister can use a Huawei or some chunky thing from a military contractor.
EmbarrassedHelp an hour ago
The UK is currently demanding that Apple install mandatory OS level client side real time scanning malware on every device, bypassing all security and encryption to monitor everything. Its an insanely evil and completely unacceptable demand.
Apple should withdraw from the UK until the UK government learns to respect encryption and privacy.
y-curious 4 hours ago
Well in the article they explicitly said they can’t turn off ADP by design, so no luck. But I’m all for making the politicians suffer the consequences of their own decisions.
Obscurity4340 5 hours ago
How are they allowed to even offer e2ee Keychain/iCloud Passwords for example? Isnt that subject to lawful access too?
spr-alex 35 minutes ago
That is exactly the question. I took a look and we presented some of our findings at DEF CON 34. There are paths to decrypting e2ee secrets without the passcode, some of these paths are considered vulnerabilities and have received patches (CVE-2026-28864).
0cf8612b2e1e 4 hours ago
Exactly my question as well.
Especially since big tech is steaming ahead to mandating passkeys that only they are allowed to control/backup. Not long until all governments could intercept your passwords to all services.
Hasz 7 hours ago
A non-trivial reason I bought a fairly closed device (macbook) was that Tim Cook, at least publicly, told the FBI to get bent when asked to create a backdoor. Exactly what I want to see, a fight in court.
I would hope to see Apple pull out of the UK market over this, and certainly to stop selling Apple devices to the UK government and to remove the UK government entities from Apple services.
sdcfgy 6 hours ago
I love this. Apple aren't going to pull out of a market. They aren't pulling out of China for example.
Hasz 6 hours ago
oh, I know, but I wish they would. You can see what this looks like when someone like CMMG refuses to sell to specific law enforcement agencies based on local law.
selicos 6 hours ago
esskay 3 hours ago
They dont really need to pull out, instead on every single piece of marketing material where they talk about anything remotely close to things affected by this they mention that unfortunately they cant give it to UK users due to the governments desire to erode privacy protection, and really hammer home how bad it is.
ghostly_s 7 hours ago
This happened 18 months ago, you can stop hoping.
codedokode 9 hours ago
Interesting, the government can demand creating a backdoor and doesn't let anyone tell about it. Basically, outlawing E2EE.
someonebaggy 6 hours ago
I think it's like the EU rules against Monero: the thing itself isn't illegal, but you're not allowed to make a business around it.
pirates 9 hours ago
If Bill left the UK temporarily would the ability to turn on ADP come back? Or is a device from the UK that’s not able to enroll somehow prevented forever? Not saying that this makes it OK, just curious
jxckstr 9 hours ago
You can switch your Apple ID's region to another country, enable ADP then revert your account's region back to the United Kingdom. You've got to leave Family Sharing first and may also need to adjust/cancel subscriptions - I don't think it's totally straightforward.
ruszki 8 hours ago
I changed countries a few months ago. It took me about two months with all the roadblocks, while I already had government issued proofs from both countries about the change and new address.
selicos 6 hours ago
netsharc 9 hours ago
What a crazy answer you've written. In the sense of: it's wild that the procedure is like that.
It's almost as wild as when during the pandemic "lockdown", planes had to take off, burn tonnes of fuel and land empty some minutes later at the same airport, because there's some fucking law about landing spots and how they'd be lost if that bullshit wasn't done.
ljf 8 hours ago
SXX 7 hours ago
AFAIK reverting region to UK wont work. First of all you cant change regions more often than a year (or close to it).
Also if you do revert account to UK you will get a warning that you either need to disable ADP or lose access to iCloud features.
aDyslecticCrow 4 hours ago
philo23 8 hours ago
I've not looked into it but I suspect this uses eligibilityd, the same thing that does the location based checks to see if EU users can use 3rd party app stores.
From what I remember it uses a combination of things like your current GPS location, your SIM cards reported country and more to determine what country you're really in to restrict certain features.
So it's not as simple as swapping your location in settings, or even traveling to somewhere in the EU, theres a certain sticky-ness to what your device thinks is your current country.
Edit: bit more info on eligibilityd here https://theapplewiki.com/wiki/Eligibility#eligibilityd
ReturnoftheHack 9 hours ago
Yeah, good point. I wonder what would happen if someone without ADP in the UK changed over the region settings to the United States, switched ADP on, and then switched the region back to the UK. I wonder if anybody's tried this?
petcat 9 hours ago
I think country is associated with the iCloud/Apple ID account, not the physical device.
cassianoleal 9 hours ago
To an extent. My account is on a different country. Even using a VPN, I was still asked to verify my age to access certain websites. The only explanation I could think of is that iOS abused my consent to them using location data for that.
RandomGerm4n 4 hours ago
What I don't understand is why Apple is even responding to this absurd demand. Completely banning Apple products in the UK isn't a realistic option for the government, so Apple could simply state openly that it does not cooperate with authoritarian regimes and actively prompt British users via a pop-up to enable ADP to protect themselves from the government.
jeroenhd 22 minutes ago
Apple complies with the Chinese government's demands, that's the minimum they're willing to play along with. The UK is well above that.
stateofinquiry 4 hours ago
It seems you are suggesting that if a private corporation (a foreign one at that) is large enough it should ignore the law of the country its operating in. I don't think you will like the consequences of such a situation, and will charitably assume you have just not thought your message through for even a second before posting it.
PS: If you think the British gov is authoritarian.. well, you might not know what the term means and/or anything about the spectrum of governments operating today or in the past.
RandomGerm4n 4 hours ago
If laws aren't transparent and reasonable, you shouldn't necessarily follow them. If I were to sell encryption software that's banned in Kazakhstan, you wouldn't expect me to stop selling to customers there, would you? I see no reason why the United Kingdom should be treated any differently than Kazakhstan in this case.
The British government is certainly not as authoritarian as those in China or Russia, but that doesn’t change the fact that it’s still terrible and restricts people’s rights. For example, you can be detained for as long as they want if you refuse to unlock your encrypted device.
permalac 14 minutes ago
aDyslecticCrow 4 hours ago
But apple also cannot just stop selling or supporting their product in the UK either. So that card is dropped from both sides. As long as apple is beholden to a few million costumers and subscribers to their services in the UK; UK law is able to pressure them, fine them and restrict them because of those users.
We don't want it the other way around; companies placed outside the borders doing and selling whatever they want without a care. So we end up in a negotiation.
Apple choose to maliciously comply; subtly revealing the TCN, giving all UK users notices about what their government demanded of them to encourage public outrage, and push on the correct parts of the UK government that has their interest in mind.
EmbarrassedHelp an hour ago
> But apple also cannot just stop selling or supporting their product in the UK either.
They can do both of things. There's no law against leaving a country for not respecting human rights like privacy and encryption.
ABNW 9 hours ago
Fantastic article, and a real concern for UK Citizens.
hdgvhicv 5 hours ago
There are many real concerns for U.K. citizens, from the price of fuel and food, to extreme weather, to constant attacks on infrastructure from undeclared actors.
This is not one. Nobody (within 2%) gives a stuff.
puppycodes 3 hours ago
The UK's hostility to privacy is legendary.
Used to live there now I don't even want to visit.
jasonjei 7 hours ago
Strange and hypothetical thought: could Bill purchase a US or international model of the iPhone with US or international iCloud account capable of ADP to activate ADP? Would this allow somebody living or working in the UK the ability to use ADP?
SXX 7 hours ago
You can just register US Apple account or switch region to US and not bother with UK regulations.
Only disadvantage that you will need to pay fot services via US gift cards as you need US bank cards otherwise.
selicos 6 hours ago
If ensuring digital devices can be accessed by law enforcement (are not "beyond the law") is so important where are the task forces shutting down crypto and networks using unregulated and anonymous currency? Literally follow the money, as they say. The current admin has 'made' millions if not more off his own fraudulent coin. Take down crypto and you stop crime instead of destroying privacy.
m11a 2 hours ago
This news is about the UK. Across the channel, the EU has effectively outlawed anonymous currency. I believe the UK FCA also has such rules in force. So your post is rather moot.
bpavuk 5 hours ago
this.
crypto has a lot of theoretical value, but in practice people only really think of crypto when they want to tap into shadow economy.
I do not deny that this technology will be instrumental to network communities, provided we are ever allowed to form such. I do not deny that offline POSes and fully offline tap-to-pay may become a possibility if an existing fiat currency adopts crypto as one "interface" among traditional banking, Apple/Google Pay, and cash. (this, by the way, would be incredible in Ukraine - right now it's power off, and you can't use your bank for offline purchases.)
in practice it's only really shadow economy. at this point it's not even a speculative asset of some notable value
int32_64 5 hours ago
Did your bot malfunction and post in the wrong thread? "The current admin", this is a thread about the UK lmao.
iamnothere 4 hours ago
This has happened to me several times recently, a reply with a partisan slant that would be normal IF it made any sense at all within the current thread. Either some “influencers” are cutting back on their token budget, or we’re collectively losing our semantic comprehension.
468854259853 2 hours ago
On brand for two-tier Keir.
Grimeton 4 hours ago
>. It reverted affected UK iCloud data to Standard Data Protection, where Apple does hold the keys and can respond to lawful legal procress (except the baseline categories that stay end-to-end encrypted either way). This satisfied the underlying legal requirement without ever building a ‘backdoor’.
Ah, just like that.
Of course something that is just possible in the public eye, after a lot of public scrutiny and for all accounts at once.
A single account, in secret? IMPOSSIBLE!
They never needed to build a backdoor....
Yeah I read the next few paragraphs and I've seen the turn off button....
djoldman 4 hours ago
What happens if someone buys their iphone in the UK, sets their region to UK, then sets the region to USA? Can they then enable advanced data protection?
aDyslecticCrow 4 hours ago
This got me curious as-well. It cannot be bound to phone number or carrier, since that's not a requirement to create an apple account. It could be bound to phones sold in the UK, but that is easily avoided. It could check the GPS, but then you can just take a trip over to France to activate your account.
Cider9986 9 hours ago
It's crazy SimpleX is fine being based there. I mean, everything is open, the clients have reproducible builds, but it seems like it may end up being a hassle.
Has the UK started attacking any open source E2EE projects yet?
Apple's control over iOS is the main reason I prefer GrapheneOS so much over it. You get amazing privacy and security without sacrificing control. GrapheneOS has said they won't introduce age verification and a backdoor they obviously won't implement.
jcarrano 8 hours ago
I'm guessing they could, in theory, attack open source projects, but it would not be very effective as those could be infinitely forked. That's the reason why governments will actually support an encourage an oligopoly of proprietary platforms via regulations (e.g. mandatory automated scanning) which only companies can practically comply with.
LoganDark 8 hours ago
There's no way to obtain root access on GrapheneOS without making your own builds (which won't be affected by many of the apps adding support for GrapheneOS, who likely would only whitelist the official signing keys) or keeping the bootloader unlocked in perpetuity (because AFAIK there is currently no way to recalculate verified boot hashes on top of a systemless root like Magisk -- not that I even know if that works on GOS in the first place). Some years back I was actually working on calculating AVB2 hashes from a live system rather than ONLY through the Android build process, until TWRP wiped my phone without consent or confirmation due to an OpenRecoveryScript that I absolutely did not put there and I basically stopped tinkering with Android root due to that. I have an iPhone nowadays.
sjpb 7 hours ago
given the story there, I'm surprised apple are still allowed to apply end to end encryption the the "baseline categories" such as messages etc in the UK. Anyone understand how that's happened? To be clear I am not saying what I think should happen, just it seems inconsistent with the UK's stance
athrowaway3z 7 hours ago
What I don't understand, or what I can only guess at, is the cabal & likely global network of interests that are behind the push for this kind of legislation to exists in the first place.
Some delusional "save the children" anti-privacy extremist doesn't have the political capital or the technical insight to convince the government to create a law to issue secret gag orders.
People with good civil intention don't just propose the idea, or get the momentum, to institutionalize such mechanisms.
So who are the major influencers, and their thoughts, for pushing this?
selicos 5 hours ago
There is a 2005 political cartoon by Jonik where an Uncle Sam has a box labelled Control of Internet Speech on the table. Corporate media is asking "How would you like this wrapped," with paper labeled either "Anti-Terrorism" or "Protect Kid."
For the last 25 years certain western governments (especially the US and UK/5 eyes) have focused on control over democracy. They've sold it as protections, defense, safety, etc. It's the opposite. Control, power, abuse, and the votes/$$$ to ignore their constituents. This is usually lead by conservative or far right parties who have zero history with abusing power and control (ex McCarthyism in the US).
We live in a world of surveillance. Even if most of that is to market you ads and extract capital it's still degrading and less safe for anyone but the core in group(s).
stuartjohnson12 7 hours ago
I don't think you need a huge, wide-ranging conspiracy to end up with a strong anti-privacy movement, even in a state which otherwise tries to defend consumer rights (in varying degrees of competency) for the most part.
I think you can just start with:
1. Campaigning on behalf of a worthy victim, or against a terrible enemy, is a good way to become more socially powerful. Most people are less willing to disagree with you when you do this because it risks introducing motive uncertainty - are you criticising the means because you truly object to the means, or are you criticising the means because you don't support the worthy victim or oppose the terrible enemy? This is a socially disadvantageous position to argue from.
2. Exploited children are worthy victims, and drug traffickers and terrorists are terrible enemies.
3. Therefore, policies that nominally protect children or oppose drug traffickers and terrorists are socially advantageous, and arguing for them is likely to increase your social power.
The means here are disproportionately likely to be done in a concealed way if the underlying policy is not broadly popular, independently of the effects it has on localised politcal arguments. Many people, myself included, don't support every political cause that helps a worthy victim or opposes a terrible enemy.
Social pressure is harder to apply at a distance, so the reality-warping effects of motive uncertainty are less powerful, so it makes sense that it's kept to private pressure groups and lobbying.
someonebaggy 6 hours ago
4. Tech activists are rallying against all less-invasive options
ajsnigrutin 6 hours ago
Governments want this the most
You won't be criticizing your boss/mayor/president/local politician/whoever, if you have to do it from an account tied to your own name. Having everyine install a digital ID on their phones (to prove they're old enough to jerk off to pornhub) is the first step, the "real name" policy is the next. The encryption ... well, one of the separate steps inbetween those two.
vlyan 5 hours ago
>So who are the major influencers, and their thoughts, for pushing this?
the governments themselves. left, right, or center, their number one priority is to maintain their power.
it amuses me immeasurably when the useful idiots in the West cheer on the policies of China and Russia. think of the children, think of the terrorists, think of the racists, think of the disinformation, blah blah blah. there are a myriad excuses but only one true goal -- suppression of dissent.
the UK establishment in particular primarily feels threatened by unredacted coverage of the consequences of its immigration policy, which they know gives voters to Reform. not because Reform would reverse that policy -- every "far-right fascist racist nazi" party in Europe had at best slowed the influx, not halted or reversed it -- but simply because someone else would be receiving lobbyists' money, favors, and sinecures after retirement.
ofou 9 hours ago
The UK is becoming 1984.
jjbinx007 8 hours ago
Border agents in America can search your phone or laptop without a warrant or sufficient suspicion at the border.
Jeff Gray is a man who regularly gets arrested and/or trespassed from public places for holding up a sign saying "God bless the homeless vets". Seems to happen nearly every time he does it at various locations.
Oh, and flock cameras and ICE aren't exactly a sign that America is this beacon of freedom that it likes to portray.
rdm_blackhole 7 hours ago
The UK border agents (technically counter terrorism) can also stop you at the border, force you into a room, ask for your passwords to all your devices and you don't have the right to refuse.
You also don't have the right to a lawyer to be in a room with you and you are compelled to answer all their questions and they do not need to tell you why they stopped you.
Then if you are lucky they return your devices 7 days later after they have been through everything.
This guy went through it last year and talks bout what happens when they stop you: https://youtu.be/991kRp8KUmo?si=-5S1uLE7K9KG_gNj
wang_li 6 hours ago
> Border agents in America can search your phone or laptop without a warrant or sufficient suspicion at the border.
That is something that can happen at nearly every international border crossing. Before posting I tried to find a list of countries that require a warrant to search your stuff and the only place that came up was Hong Kong. New Zealand requires some suspicion, but that's effectively the same as they can simply state "they were acting suspiciously to my eye."
>Oh, and flock cameras and ICE aren't exactly a sign that America is this beacon of freedom that it likes to portray.
The US never said that you won't be observed in public nor that you can enter, remain, and travel freely around the country forever without permission.
nozzlegear 7 hours ago
I think the person you're replying to was talking about the UK, not the US.
iamnothere 4 hours ago
What does the comment you’re replying to have to do with the US?
This reads like Soviet-era whataboutism: https://en.wikipedia.org/wiki/And_you_are_lynching_Negroes
sgarman 4 hours ago
abcd_f 7 hours ago
Back in the early 00s the UK seemed to go all in on mass surveillance, with massive amount of cameras in public places and all that. I still remember how shocking it all looked even from Canada. So these 1984 parallels are certainly not a new development.
dingaling 4 hours ago
Yes, there are many cameras. But they're not interlinked, most of them record locally or to the chain's HQ, not some mass surveillance panopticon like TV shows portray.
alt227 7 hours ago
US has Flock, ICE, PRISM and many other privacy horrors. I would much rather live in the UK than in the land of orange.
GaryBluto 6 hours ago
crimsoneer 6 hours ago
Worth recognising this was (and still is) mostly nonsense. There were loads of figures like "3 CCTV cameras per person" that included your local shop having a camera in the back, which has nothing to do with state surveillance. The police in the UK have significantly less power to surveil people than police in the UK. Council CCTV is shockingly rare now days.
throwawayffffas 7 hours ago
At least it's not becoming 1933 like some other places.
Ylpertnodi 8 hours ago
It was 1984 when I left in 1998. Not missed.
phyalow 7 hours ago
Anyone have any steps on how I can enable this in the UK? I guess I need to update my billing details to a non UK address and hop on a VPN or something?
SXX 7 hours ago
You can change billing details to US and then activate US gift card that you can buy of Amazon.com.
But keep in mind you have to disable all subscriptions first and also your family group if you have one must also switch their accounts to US.
So yeah pretending you're US customer is no brainer with Apple and unlike Google they dont have automatic detection that will move your account to other region.
Beware you can only change account region once a year or something.
selicos 5 hours ago
Create a new account and reset. If you aren't willing due to the friction involved then it's time to decentralize anyway. If it's due to previous payments or licenses/subscriptions tied to the account then work with the vendor to transfer or pay the small cost to reset.
After spending 8-12 years in a single gmail account I learned my lesson. Don't get entrenched or you can't be flexible.
Barbing 7 hours ago
> they dont have automatic detection
I thought they at least used something complex to attempt to prevent non-EU users using third-party app stores. I also recall a legitimate EU user is not allowed to travel abroad too long before losing access to those stores.
SXX 6 hours ago
implements 8 hours ago
This’ll go down well (/s) but if you accept that the State has the right to be able to surveil public communications infrastructure (which it has been doing since paper mail was invented, through: radio, telegraph, telex, telephone, fax, email, and mobile telephony) then it’s not surprising certain commoditised public data handling services might be required to provide government access on demand or be restricted from implementing features that can effectively deny that access.
That angry’s up the blood of libertarians, but ultimately from the point of view of the State it has to be able to do its job of detecting and prosecuting serious crime, and it will redraw privacy lines whenever that is substantially impeded by new technology.
z0r 8 hours ago
The quantity and quality of communications that have been externalized and become effectively searchable and retrievable has increased by many orders of magnitude since paper mail was invented. I think even if you agreed that the State might have had that right then (which not everyone would), it would be good to reconsider what that means with the communications and information systems of today.
someonebaggy 6 hours ago
A term I've seen thrown around is "good old-fashioned police work" and to me the clear distinction is that it can't be done en masse - a real human police officer had to spend time tracking down each known suspect. E.g. clipping a pen register onto someone's telephone wires, tailing someone, asking the hotel clerk if he's been there, unlocking someone's phone to read their messages, and even watching footage on airgapped CCTV systems are all tasks that can be done one-at-a-time and require human power proportional to how much of them you do. This forces the state to only use them on actual suspects instead of using them on everyone, but still doesn't prevent the state from catching criminals.
nancyminusone 7 hours ago
They can have the right to surveil, but I don't think they should have the right to demand understanding of my messages.
adrian_b 6 hours ago
Even many dictatorship states, like many of the "socialist" countries, had in the past articles in their constitutions that guaranteed the secrecy of the mail and of the telephone communications (other telecommunications did not exist at that time). Thus it is false that there is some kind of established tradition that governments may have access to private communications.
In reality the secret police did not care about laws or constitution, so private mail correspondence was intercepted and opened, read, then closed again with care, trying to make this undetectable, and the telephone lines of persons of interest were tapped.
Nonetheless, it was understood that this surveillance is actually illegal, so it was hidden as much as possible.
Nowadays, the government institutions of most "free" states, like USA and UK have granted themselves far more rights to do surveillance of their citizens than the dictators of the past.
Detecting and prosecuting serious crime does not need any such general surveillance. The general surveillance just makes much cheaper the detecting of serious crimes, but in exchange it gives the means to the government employees to commit more serious crimes themselves.
Zenul_Abidin 5 hours ago
Just call them backdoors.
snvzz 5 hours ago
They simply do not want anyone to hear this: Millions must go.
sdcfgy 8 hours ago
Very well written article.
It relays my main concern which is that while current governments may use this in moderation and under judicial oversight, future ones may not. And we should build tools for the future not just for now.
There’s a general regression towards fascist and right wing ideologies in the last few years and I don’t want to be up against a wall one day because someone did something with ignorant best intent.
p-e-w 8 hours ago
> There’s a general regression towards fascist and right wing ideologies in the last few years
The “fascist” part (authoritarian/totalitarian tendencies) came long before the resurgence of the right, but most people seem to approve of those methods as long as they target those they dislike, so I won’t be shedding any tears for them when it’s their turn at last.
georgespencer 8 hours ago
> Very well written article
It is self-evidently written by AI. You can tell from both tropes such as “To bring this into sharper focus” and the fact that it is entirely without an opinion or argument for most of the piece.
sdcfgy 6 hours ago
I don't think it is. It's a presentation of the facts and current state more than anything. I mean I don't expect an opinion piece all the time.
Barbing 7 hours ago
Wow, which model? I really enjoyed this piece and went and read their piece on Siri recap/Siri rewind. Following this blog.
sneak 9 hours ago
The Apple-vs-FBI narrative is constructed fiction. Sure, they didn't make a custom firmware to dump the phone's contents, but that's irrelevant. Everything relevant to the investigation on that phone was in the non-E2EE iCloud Backup, which the FBI got from Apple long before, via normal search warrant means. Apple likely either got an FAA702 order (aka PRISM, aka the "backdoor" that Tim Apple says doesn't exist - it allows the USG to access anyone's iCloud data immediately, with no warrant (it's not an encryption backdoor, just an access backdoor)) or a standard search warrant and most probably turned over everything they had in iCloud instantly, just as they do constantly when receiving a search warrant or FAA702 order. (As I mentioned, the FAA702 order fulfillment is likely instantaneous/automated, which amounts to direct access to the storage servers.)
The whole "Apple won't do what the USG wants" story is farce, engineered specifically to protect Apple's brand image. Following the Snowden drop when we all learned that the USG has unfettered realtime access to everything in iCloud without a warrant via FAA702, Apple had a major fucking crisis on its hands, along with a lot of other companies. (If you think the CIA can't read any object in S3, you simply don't understand how the world works. Note also that AWS has built a custom, one-off, airgapped AWS region ON PREM for the CIA. https://aws.amazon.com/federal/us-intelligence-community/ )
Those CEOs all went to DC and sat down with Obama and talked it out. The official cover story was something like "Obama wants help with healthcare.gov".
> The top leaders from the world’s biggest technology companies pressed their case for reform of the National Security Agency’s controversial surveillance operations at a meeting with President Obama on Tuesday, resisting attempts by the White House to portray the encounter as a wide-ranging discussion of broader priorities.
https://www.businessinsider.com/tech-ceo-meeting-with-obama-... (includes photo)
It is very likely that this media plan was discussed and agreed upon in those meetings. Otherwise, nobody sane in any government in Europe would ever buy an iPhone (or let their citizens do same), given that the USG can read all their photos and messages and emails and contacts in iCloud instantly and without a warrant.
(China of course requires Apple run the iCloud servers for Chinese users in China via a joint venture with a CCP-operated company, which preserves the same realtime full access to all iCloud/iMessage data in China for the CCP as PRISM does for the USG.)
Don't believe the marketing hype.
Further reading:
https://en.wikipedia.org/wiki/PRISM
The Snowden releases support very plainly the direct realtime access of the US intelligence community to tech company servers without search warrants (just FISA orders).
It is the single most used data source by the US intelligence community.
https://en.wikipedia.org/wiki/File:Prism_slide_5.jpg
Apple began providing such data in October 2012.
https://commons.wikimedia.org/wiki/File:PRISM_Collection_Det...
https://www.cnet.com/tech/tech-industry/new-slides-reveal-gr...
alt227 9 hours ago
Heres a favourite of mine. Apple & Google were/still are syphoning off all mobile device push messages to US government. They flat out denied it for years until it got leaked from another source, as soon as it was out in the open they admitted and said they were doing it all along but weren't allowed to tell anybody due to government NDAs.
https://www.reuters.com/technology/cybersecurity/governments...
These aren't conspiracy theories, these types of secret agreements happen all the time.
EDIT: it seems the original poster I was replying to has deleted their post, and so this may not make as much sense in the thread now.
wat10000 8 hours ago
If it was irrelevant then why did the FBI make such a big deal about it? Are you saying the FBI did that just to make Apple look good? Why would they care about Apple's reputation?
axus 8 hours ago
Well in theory more people use an insecure software, the more FBI can monitor
sneak 2 hours ago
Yes. Apple is one of the largest companies in the US, and the NSA did them dirty by letting it become public that Apple is cooperating in allowing them to conduct warrantless surveillance. The alternative is Samsung, and the US government would prefer people buy iPhones. We’re also not just talking about the USA, but the 240 million iphones sold each year.
varispeed 9 hours ago
Since Epstein is no more, the governments became crazy about going after people's private data, perhaps hoping to find some spice. Like some politicians lost their source.
Havoc 8 hours ago
Just checked - I’m on the lower tier. FFS
Getting really tired of the UK govs incompetence/maliciousness around digital law making
hughw 7 hours ago
If you didn't want it before, you probably never will. It comes with a convenience cost and the risk you may permanently lose access to your iCloud stuff if you lose your password. With the normal level of privacy, Apple is there to help you or your loved ones get access to your stuff. Most people need that much more than they need inviolable privacy.
Barbing 7 hours ago
I’m rolling the dice myself. No ADP here. If I were a political activist (US) I’d definitely need it.
I guess if I lose my phone on a trip, I wanna be able to walk into an Apple store and restore it from their cloud copy that the feds have backed up & pored over by LLMs too. (not sure that’s done in realtime for 100% of the population, but tokens will be cheap enough eventually - they have their pre-LLM solution too)
I think I keep Signal data mostly out of the cloud though, declining to use their latest features. Hidden notifications too. Is it only personal family updates, yes, but the principle makes me feel good.
coldtea 8 hours ago
Maliciousness.