https://alecmuffett.com/article/112522 Dropsafe by Alec Muffett * Blog + Blog (All) * RSS + RSS (All) + RSS (Comments) * Tools + Search + Pre-Flight Travel Checklist + Muffett on Passwords * About + About + Login NCSC, GCHQ, UK Gov't expunge advice to "use Apple encryption" for Barristers, Solicitors (etc...) -- co-incidental with Apple lawsuit against HMG's demanding a backdoor in the same (HT @DavidDavisMP @PrivacyMatters @zsk) This is some really embarrassing timing on the Home Office's (HO's) part: a few weeks ago when news first broke of the HO's demand for a backdoor in Apple ADP, I pointed out to MP David Davis that the HO actually extolled use of ADP by at-risk groups: --------------------------------------------------------------------- Hi David, we met at an @OpenRightsGroup thing a few years ago. In your work you may want to reference this advice from NCSC/GCHQ "Cyber security tips for barristers, solicitors and legal professionals"https://t.co/i27tiooooK pic.twitter.com/ksZt3k2ZbR -- Alec Muffett (@AlecMuffett) February 21, 2025 That screenshot was current to that day. What I did not expect was that in the interim between then and the new revelation that Apple are taking the matter to (again, secret) court, the people at NCSC would apparently rewrite the whole document, rename it, broaden the audience, and water it down by eliding the advice to enable and use ADP, as discovered by Pat Walshe... or at least that's what happened on the face of it: 15/ from current web pages. The word 'encryption' appears missing from the current @NCSC page - go figure https://t.co/YJMctyz0Zs so here's their old guidance to 'turn on encryption' https://t.co/sy2H3IXTZG You heard em! Turn it on. pic.twitter.com/opc3CGt0z3 -- Privacy Matters ? (@PrivacyMatters) March 5, 2025 Instead they now call for use of Apple's "Lockdown Mode", and I checked with noted Lockdown Mode advocate Runa Sandvik who confirms for me that Lockdown Mode is a separate feature from ADP, with a different remit from cloud data protection. Enabling one does not enable the other. But this is where it gets weird, because suddenly I noticed a different URL was being shown in the browser bar, and then I found that writing in April 2024, Runa observed some weaknesses in NCSC's (contemporary) "Defending Democracy" guidance: "Also missing are any mentions of encrypted phone backups for Android and iOS; end-to-end encryption for iCloud; and end-to-end encryption for WhatsApp backups. [...] should also include Google's Advanced Protection Program (and Google should mention it more too)." So the document we are looking at today also existed back then, with the same deficiencies ... which leads us to presume that the politically inconvenient ADP-promoting "for barristers" document has actually been wholesale deleted from the internet, with a HTTP redirect put in place to point to the inferior "defending democracy" documents. And lo, what do we find? $ curl -s -L -I -A "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:110.0) Gecko/20100101 Firefox/110.0" https://www.ncsc.gov.uk/ guidance/ cyber-security-tips-for-barristers-solicitors-and-legal-professionals | grep location: location: /collection/defending-democracy/ guidance-for-high-risk-individuals Confirmation. So the question in my mind is: is the UK Government attempting to cover-up its previous advocacy of ADP, by censoring this old document? Or does it instead want the UK legal profession to avoid use of ADP and to what end? [?] apple backdoor end to end encryption feed home office surveillance tcn -Breaking WhatsApp or Signal encryption: a dangerous political chimera | Le Monde, via Google Translate If Age Verification is to be done at all, it should be like this: a bearer-token signed by the App Store, Browser Provider or Device, and trusted by the Age-Consumer e.g. Age-Restricted Service Vendor- Comments Leave a Reply Cancel reply Your email address will not be published. Required fields are marked * [ ] [ ] [ ] [ ] [ ] [ ] [ ] Comment * [ ] Name * [ ] Email * [ ] Website [ ] [Post Comment] [ ] [ ] [ ] [ ] [ ] [ ] [ ] D[ ] More posts * CGNAT frustrates all IP address-based technologies | Cybersecurity | SIDN 2025/03/05 * If Age Verification is to be done at all, it should be like this: a bearer-token signed by the App Store, Browser Provider or Device, and trusted by the Age-Consumer e.g. Age-Restricted Service Vendor 2025/03/05 * NCSC, GCHQ, UK Gov't expunge advice to "use Apple encryption" for Barristers, Solicitors (etc...) -- co-incidental with Apple lawsuit against HMG's demanding a backdoor in the same (HT @DavidDavisMP @PrivacyMatters @zsk) 2025/03/05 * Breaking WhatsApp or Signal encryption: a dangerous political chimera | Le Monde, via Google Translate 2025/03/05 Dropsafe Proudly powered by WordPress