U.K. orders Apple to let it spy on users’ encrypted accounts

i see a lot of people commenting that Apple will refuse because they will lose a lot of money, would it be possible that Apple will actually accept secretly to do that and nobody will know (until maybe 5 or 10 years later) ?
i dont want to sound too much of a conspiracy theorist, but there have been cases of surveillance that we knew only years after !

2 Likes

Apple will only refuse because of their quote “Privacy” Promises. They market privacy quite a lot so with this being in the news puts Apple at ridk if they comply, they’d much rather leave or otherwise at least remove ADP in the UK but yeah.

Apple will only refuse because of their quote “Privacy” Promises

I understand that, my point is, will people ever know if Apple accepts the UK gov request? I mean, their software is closed source, is it audited by an independent company? or how can people know if this really happens?

1 Like

This has been mentioned in several other posts in this forum, Apple software is audited by independent third parties.

There is no guarantee that these audits would correctly identify that Apple has a backdoor to E2EE, or that they would reveal that information publicly if uncovered. However, I suspect if something that serious were uncovered in such an audit it would not stay secret for long.

Well unless you code and host by yourself otherwise you cannot be 100.00% sure about it,

You need to draw a line and start trusting from somewhere. If you dont feel comfortable trusting something (someone), it would be better not using (relying on) it.

2 Likes

If Apple isn’t allowed to talk about a backdoor in the E2EE implementation, it seems likely the independent third party wouldn’t be able to, either.

2 Likes

That would depend on whether or not the third party is subject to the legal jurisdiction of the United Kingdom.

For instance, if a US or South Korean based auditor found something there is nothing stopping them from reporting it.

1 Like

That actually is exactly what they did in China. Apple does not offer iCloud ADP nor iMessage/FaceTime in China. And China is a FAR more important market than the UK.

Here’s a potential motivation for that order. Apparently, Apple has only granted iCloud data to the UK government four times .

Between January 2020 and the end of June 2023 Apple received more than 6,000 legal requests from British authorities seeking customer data related to specific Apple accounts. In only four of those cases did Apple provide any content. More recent data is unavailable.

The figures, published in Apple’s own biannual transparency reports, suggest a potential motivation behind the British government’s reported attempt to serve the company with a special and secret legal order that would force Apple to be technically capable of providing iCloud content upon receipt of a valid warrant.

That is an impressive amount of stonewalling.

3 Likes

I think this probably has less to do with Apple going out of their way to push back and more to do with the UK Government going way beyond what is reasonable even under UK law. Apples rate of non compliance is no where near this extreme in most jurisdictions.

Many of the request were probably also for accounts with ADP enabled, where Apple couldn’t comply even if they wanted.

Seems murican politicians care when it is their people for once.

2 Likes

It’s funny to think the 5 eyes will now fight about this.

Nah, they care about themselves here and for once they like us…

1 Like

well yeah the US is doing great at upsetting their allies this week.

So far… we have tomorrow and the remaining 4 years. Even sounds exhuasting to know this.

Weirdly enough it seems the recent Chinese hacks of American telecom infrastructure have scared the U.S. straight on encryption being a good thing for everyone.

The UK, Australia, and EU don’t seem to have gotten the message. Sadly this is now a theme when it comes to security issues…

5 Likes

It is not unreasonable to now believe these other countries don’t really understand jack about what’s important and why and how to keep it safe and secure.

No will power to do anything until the house burns down. Yep, sad state of affairs.

From 1500GMT on Friday, any Apple user in the UK attempting to turn it on has been met with an error message.

Any members in the UK can check if ADP is already pulled?

3 Likes

I’ll ask some of my contacts to check.

How would existing UK iCloud accounts with ADP be turned off? I am concerned that this would compromise a lot of folks if they can’t figure out a way to migrate their data.

1 Like

While the company cannot disable ADP for current ADP users in the U.K., they will eventually be required to disable it to keep using their iCloud account using guidance provided by Apple over the coming weeks or days.[1]


  1. https://www.bleepingcomputer.com/news/security/apple-pulls-icloud-end-to-end-encryption-feature-in-the-uk/ ↩︎