Remix.run Logo
▲ palmotea 8 hours ago

> Faced with a legal order that would have required it to change the security architecture on which ADP depended, Apple found a third option: stop offering the feature that made this dilemma exist in the first place. It reverted affected UK iCloud data to Standard Data Protection, where Apple does hold the keys and can respond to lawful legal procress (except the baseline categories that stay end-to-end encrypted either way). This satisfied the underlying legal requirement without ever building a ‘backdoor’.

Maybe Apple should withdraw all encryption support from all UK government accounts? The Prime Minister can use a Huawei or some chunky thing from a military contractor.

▲EmbarrassedHelp 2 hours ago | parent | next [-]

The UK is currently demanding that Apple install mandatory OS level client side real time scanning malware on every device, bypassing all security and encryption to monitor everything. Its an insanely evil and completely unacceptable demand.

Apple should withdraw from the UK until the UK government learns to respect encryption and privacy.

▲y-curious 5 hours ago | parent | prev | next [-]

Well in the article they explicitly said they can’t turn off ADP by design, so no luck. But I’m all for making the politicians suffer the consequences of their own decisions.

▲Obscurity4340 5 hours ago | parent | prev [-]

How are they allowed to even offer e2ee Keychain/iCloud Passwords for example? Isnt that subject to lawful access too?

▲spr-alex an hour ago | parent | next [-]

That is exactly the question. I took a look and we presented some of our findings at DEF CON 34. There are paths to decrypting e2ee secrets without the passcode, some of these paths are considered vulnerabilities and have received patches (CVE-2026-28864).

▲0cf8612b2e1e 4 hours ago | parent | prev [-]

Exactly my question as well.

Especially since big tech is steaming ahead to mandating passkeys that only they are allowed to control/backup. Not long until all governments could intercept your passwords to all services.