Sources: the UK Home Office issued an order to Apple in early September to create a backdoor into its cloud storage service, this time targeting only UK users
Order issued in September comes after Trump administration said London had backed down in fight over encryption
Financial Times
Context & Ripple Effects
The reported September order follows a January demand that reportedly sought access to iCloud content worldwide, a far broader request than the current UK-only scope. It also conflicts with signals that London might retreat after US pressure.
An August court filing indicated the government’s position remained expansive, including claimed access beyond Advanced Data Protection, despite reports of a backdown. The new order suggests the dispute has shifted toward a jurisdiction-specific route rather than disappeared.
First-order effects
Apple must assess whether and how it can answer a UK-only access mandate, creating an immediate legal, technical and policy decision around its cloud-storage security.
UK users become the specifically targeted population in the reported order, potentially placing their cloud-data protections on a different footing from those available elsewhere if Apple complies.
Second-order effects
A country-specific requirement would pressure Apple to separate UK cloud-service handling from its broader product architecture, while giving other governments a more tailored model for seeking exceptional access.
The renewed conflict puts cross-border political pressure back on Apple: the earlier reported prospect of a UK retreat had implied a de-escalation, while this order reopens the question of whether US-based providers can resist foreign access demands.
Third-order effects
If governments increasingly pursue user- or territory-limited mandates, encryption policy may move from one-off global backdoor demands toward fragmented national compliance regimes.
The durable issue is whether providers can preserve a uniform security model while governments claim jurisdiction over locally connected users; the answer will shape the practical boundary of state access to cloud data.
The trend: This is one data point in the shift from broad encryption-access demands toward jurisdiction-specific pressure on cloud platforms.
NEW: the UK asked Apple to backdoor iCloud encryption. Backdoor create a new, massive target for hackers & criminal groups. And dictators will inevitably demand Apple do the same same. Once again the @ukhomeoffice is putting your privacy at risk. 1/ [image]
So “we want a backdoor to access iCloud encryption” could mean access to those password vaults and secure health data. This means Apple would have to disable those features in the UK as well, or deploy new insecure encryption code that could affect users globally.
So here we are again. This time the UK is narrowly targeting their request at UK users only. But this is baffling for two reasons. First, Apple no longer offers the ADP encrypted backup feature to new UK users, and existing users are being migrated. So what is the UK asking for?
Second, how is Apple supposed to make a single encryption system that's secure for US users but not for UK users? This would require that they partition their software globally and have many versions, which seems like a disaster. Are you sure you're running the “secure” OS?
As to question (1), the article isn't super clear. But it's worth pointing out that Apple doesn't just provide end-to-end encryption for backups through their ADP feature. They also provide end-to-end encrypted backup for health data, web history and passwords, even without ADP.
The government ordering Apple to break its encryption is stupid, counter-productive and unworkable: — takes.jamesomalley.co.uk/p/ask-the- co... [embedded post]
“The UK government has issued a new order to Apple to create a backdoor into its cloud storage service, this time targeting only British users' data, despite US claims that Britain had abandoned all attempts to break the tech giant's encryption.”
‘The UK Home Office demanded in early September that Apple create a means to allow officials access to encrypted cloud backups, but stipulated that the order applied only to British citizens’ data, according to people briefed on the matter.' www.ft.com/content/d101...
At a time when new cyberattacks debilitate British businesses seemingly daily, the UK government is demanding that security is made worse for UK users. [embedded post]