Two-tier encryption in the UK
331 points - today at 10:39 AM
SourceComments
I am judging by a simple fact, that "please confirm your age" screen is now mandatory during the iPhone setup in all countries, and in some it's behind a KYC. I have a strong opinion that this is insane. And once they let the foot in the door - there is no closing it.
[1] https://www.forbes.com/sites/steveforbes/2025/09/09/people-a...
"
Unfortunately this first phrase is not strictly true in the sense that UK customers have their e2ee secrets exposed under common use cases, without requiring a passcode. My copresenter and I published some research at DEF CON 34 this year showing how the e2ee data is particularly vulnerable when ADP is off. Overall, people that do not work with extraction capabilities are currently over-estimating the strength of apple's e2ee and encryption in general. The platform security whitepaper documentation is insufficient on transparency and there are a number of best practices Apple is not following to better meet the e2ee claims they currently advertise.
Maybe Apple should withdraw all encryption support from all UK government accounts? The Prime Minister can use a Huawei or some chunky thing from a military contractor.
I would hope to see Apple pull out of the UK market over this, and certainly to stop selling Apple devices to the UK government and to remove the UK government entities from Apple services.
Used to live there now I don't even want to visit.
Ah, just like that.
Of course something that is just possible in the public eye, after a lot of public scrutiny and for all accounts at once.
A single account, in secret? IMPOSSIBLE!
They never needed to build a backdoor....
Yeah I read the next few paragraphs and I've seen the turn off button....
Has the UK started attacking any open source E2EE projects yet?
Apple's control over iOS is the main reason I prefer GrapheneOS so much over it. You get amazing privacy and security without sacrificing control. GrapheneOS has said they won't introduce age verification and a backdoor they obviously won't implement.
Some delusional "save the children" anti-privacy extremist doesn't have the political capital or the technical insight to convince the government to create a law to issue secret gag orders.
People with good civil intention don't just propose the idea, or get the momentum, to institutionalize such mechanisms.
So who are the major influencers, and their thoughts, for pushing this?
That angryâs up the blood of libertarians, but ultimately from the point of view of the State it has to be able to do its job of detecting and prosecuting serious crime, and it will redraw privacy lines whenever that is substantially impeded by new technology.
It relays my main concern which is that while current governments may use this in moderation and under judicial oversight, future ones may not. And we should build tools for the future not just for now.
Thereâs a general regression towards fascist and right wing ideologies in the last few years and I donât want to be up against a wall one day because someone did something with ignorant best intent.
The whole "Apple won't do what the USG wants" story is farce, engineered specifically to protect Apple's brand image. Following the Snowden drop when we all learned that the USG has unfettered realtime access to everything in iCloud without a warrant via FAA702, Apple had a major fucking crisis on its hands, along with a lot of other companies. (If you think the CIA can't read any object in S3, you simply don't understand how the world works. Note also that AWS has built a custom, one-off, airgapped AWS region ON PREM for the CIA. https://aws.amazon.com/federal/us-intelligence-community/ )
Those CEOs all went to DC and sat down with Obama and talked it out. The official cover story was something like "Obama wants help with healthcare.gov".
> The top leaders from the worldâs biggest technology companies pressed their case for reform of the National Security Agencyâs controversial surveillance operations at a meeting with President Obama on Tuesday, resisting attempts by the White House to portray the encounter as a wide-ranging discussion of broader priorities.
https://www.businessinsider.com/tech-ceo-meeting-with-obama-... (includes photo)
It is very likely that this media plan was discussed and agreed upon in those meetings. Otherwise, nobody sane in any government in Europe would ever buy an iPhone (or let their citizens do same), given that the USG can read all their photos and messages and emails and contacts in iCloud instantly and without a warrant.
(China of course requires Apple run the iCloud servers for Chinese users in China via a joint venture with a CCP-operated company, which preserves the same realtime full access to all iCloud/iMessage data in China for the CCP as PRISM does for the USG.)
Don't believe the marketing hype.
Further reading:
https://en.wikipedia.org/wiki/PRISM
The Snowden releases support very plainly the direct realtime access of the US intelligence community to tech company servers without search warrants (just FISA orders).
It is the single most used data source by the US intelligence community.
https://en.wikipedia.org/wiki/File:Prism_slide_5.jpg
Apple began providing such data in October 2012.
https://commons.wikimedia.org/wiki/File:PRISM_Collection_Det...
https://www.cnet.com/tech/tech-industry/new-slides-reveal-gr...
Getting really tired of the UK govs incompetence/maliciousness around digital law making