Source URL: https://www.theverge.com/news/617273/apple-removes-encryption-advanced-data-protection-adp-uk-spying-backdoor
Source: Hacker News
Title: Apple pulls encryption feature from UK
Feedly Summary: Comments
AI Summary and Description: Yes
Summary: Apple has ceased providing its Advanced Data Protection (ADP) service, which offers end-to-end encryption for iCloud storage, to new users in the UK. Existing users will eventually need to disable this feature due to UK security service demands for backdoor access to encrypted data. This decision raises significant concerns about user privacy and data security in the context of regulatory pressures.
Detailed Description:
– Apple is discontinuing its Advanced Data Protection (ADP) in the UK for new users, a decision prompted by requests from UK security services for backdoor access to user encrypted backups.
– Julien Trosdorf, an Apple spokesperson, stated that current UK users will eventually be required to disable ADP in order to continue using iCloud.
– Advanced Data Protection was designed to enhance user privacy through end-to-end encryption, ensuring that only the account holder could access their data.
– Launched in late 2022, ADP was anticipated to bolster security against data breaches and threats to customer privacy.
– Apple cannot automatically disable ADP for existing users due to the nature of its encryption model, but users will have an allotted time to comply before the feature becomes unusable.
– Apple’s statement emphasizes their commitment to user privacy and security, reiterating that they have never created a backdoor or master key for any of their services.
– **Key Implications:**
– The move reflects the ongoing tension between user privacy and national security demands, particularly highlighting how regulatory requirements can influence technology companies’ security offerings.
– This situation underscores the broader issue of data sovereignty and the compliance challenges tech firms face when operating in jurisdictions with differing policies on encryption and data protection.
Overall, this case serves as a critical reminder for security and compliance professionals to navigate the complex landscape of privacy regulations, especially concerning encryption technologies.