[HN Gopher] Apple Ordered by UK to Create Global iCloud Encrypti...
       ___________________________________________________________________
        
       Apple Ordered by UK to Create Global iCloud Encryption Backdoor
        
       Author : throw0101d
       Score  : 983 points
       Date   : 2025-02-07 12:18 UTC (10 hours ago)
        
 (HTM) web link (www.macrumors.com)
 (TXT) w3m dump (www.macrumors.com)
        
       | throw0101d wrote:
       | See also "U.K. orders Apple to let it spy on users' encrypted
       | accounts":
       | 
       | > _The law, known by critics as the Snoopers' Charter, makes it a
       | criminal offense to reveal that the government has even made such
       | a demand. An Apple spokesman declined to comment._
       | 
       | * https://www.washingtonpost.com/technology/2025/02/07/apple-e...
       | 
       | * https://archive.is/https://www.washingtonpost.com/technology...
       | 
       | > _The Investigatory Powers Act 2016 (c. 25) (nicknamed the
       | Snoopers ' Charter)[1] is an Act of the Parliament of the United
       | Kingdom which received royal assent on 29 November 2016.[2][3]
       | Its different parts came into force on various dates from 30
       | December 2016.[4] The Act comprehensively sets out and in limited
       | respects expands the electronic surveillance powers of the
       | British intelligence agencies and police.[4] It also claims to
       | improve the safeguards on the exercise of those powers.[5]_
       | 
       | * https://en.wikipedia.org/wiki/Investigatory_Powers_Act_2016
        
         | reaperducer wrote:
         | _See also "U.K. orders Apple to let it spy on users' encrypted
         | accounts"_
         | 
         | Not just "see also." Your link is the original reporting.
         | 
         | Without journalists and organizations like these doing hard,
         | expensive work like this no one -- not even on HN -- would know
         | about it.
         | 
         | It's a shame that the link being used for the HN entry is to a
         | blog re-writing other people's work, and not doing any of that
         | work or sharing any of that expense themselves.
         | 
         | Correct link:
         | 
         | https://www.washingtonpost.com/technology/2025/02/07/apple-e...
         | 
         | No, I don't care if there's a paywall. Credit where credit is
         | due is something your mom should have taught you when you were
         | five.
        
       | fsflover wrote:
       | Discussion: https://news.ycombinator.com/item?id=42970412
        
       | reify wrote:
       | I doubt very much if any terrorist, criminal or child abuser is
       | going to use any google or apple cloud service to back up their
       | files.
       | 
       | Anyone with a fundamental understanding of online privacy and
       | security would encrypt any files prior to uploading them to the
       | cloud rendering any back doors and access to those files useless
       | and toothless.
       | 
       | I dont use any of these services. I have never understood the
       | thinking around uploading your private life to some server in the
       | cloud when they are more secure on an external hard drive at
       | home.
        
         | squeegee_scream wrote:
         | I think you have a very high opinion of the millions of people
         | around the globe, with varying levels of computer literacy, who
         | are terrorists, criminals, and/or child abusers.
        
           | sam_lowry_ wrote:
           | I once worked with a business lady who used her dumbphone as
           | an argument in a discussion where we were deciding whether
           | all our users have smartphones. She proudly displayed the
           | dumbphone and said that if she has one, others probably have
           | too.
           | 
           | I learned only much later that her husband was prosecuted for
           | fraud related to government funds. So she had a good reason
           | to have a dumbphone.
           | 
           | It's anecdotal evidence, but still.
           | 
           | You are of very low opinion of people, probably assuming that
           | you are smarter because you are some kind of IT guy.
           | 
           | And you are likely wrong.
        
             | jeroenhd wrote:
             | > I learned only much later that her husband was prosecuted
             | for fraud related to government funds. So she had a good
             | reason to have a dumbphone.
             | 
             | Does she? Law enforcement can wiretap and track dumbphones
             | just as easily as smart phones. The lack of encrypted
             | calling/texting options even make it easier for law
             | enforcement. If she's trying to hide more fraud, the
             | dumbphone isn't helping her. And of course if she is trying
             | to hide fraud from law enforcement, she probably shouldn't
             | be doing the fraud in the first place.
             | 
             | There are good reasons for using dumbphones (smartphones
             | distract, and it's having a serious impact on everyone
             | these days) but avoiding being prosecuted isn't one.
        
         | voidUpdate wrote:
         | Don't iPhone photos automatically sync to your iCloud?
        
           | brookst wrote:
           | You can turn it off, and it is E2EE.
        
             | InTheArena wrote:
             | You need to enable an additional iCloud secure mode for
             | true E2E to be enabled.
        
         | kotaKat wrote:
         | > I doubt very much if any terrorist, criminal or child abuser
         | is going to use any google or apple cloud service to back up
         | their files.
         | 
         | Meanwhile, the amount of local news arrests for people getting
         | busted for uploading CSAM to online platforms like Google and
         | Apple is exponentially increasing.
         | 
         | The average "criminal" is an idiot.
        
         | nicce wrote:
         | The real goldmine is WhatsApp. In most cases, WhatsApp backups
         | are enabled and uploaded by default, including when the whole
         | iPhone backup is created. And by default, backups are
         | unencrypted.
         | 
         | So if you ever wonder how they access those WhatsApp messages,
         | when you think that they would be end-to-end encrypted, reality
         | is something else.
        
           | sgt wrote:
           | I've got backups disabled on WhatsApp and the app reminds me
           | like once every few weeks "You should turn on your backups!".
           | Easier to click yes.
        
         | brookst wrote:
         | The overlap between "criminal" and "fundamental understanding
         | of online security" is fairly small.
         | 
         | I use online services and sync, but my life is so boring (and
         | data breaches have exposed so much) that a disaster that
         | destroys my house and all backups is far more likely that harm
         | from government or private snooping on my cloud files.
         | 
         | I know we're supposed to stand on principle and make data
         | storage choices as if today's cat photo were evidence of being
         | the real JFK assassin, but I don't have the energy.
        
         | diego_moita wrote:
         | > I doubt very much if any terrorist, criminal or child abuser
         | is going to use any google or apple cloud service to back up
         | their files.
         | 
         | Most of the time, people become terrorists, criminals or child
         | abusers because they're stupid, not because they're smart.
        
         | duxup wrote:
         | News stories seem to indicate that many criminals use computers
         | just like any given person does.
         | 
         | Even people concerned with security who know a little seem to
         | be terrible at it.
         | 
         | A local protest group in my area was passing around an image
         | with security tips. They were hilariously bad, suggestions
         | based on very confused understandings of risk. These people
         | weren't criminals necessarily, but they were motivated and
         | concerned and somehow just terrible at basic security.
        
           | sam_lowry_ wrote:
           | > News stories seem to indicate
           | 
           | What's the inverse of survivor bias?
        
             | duxup wrote:
             | They are still people committing crimes. I don't think
             | that's quite the same as the prototypical survivorship bias
             | would imply.
             | 
             | There is the possibility that there is a great deal more
             | crime being commuted by capable super criminals who
             | understand the nuances of security .... but I'm more of a
             | subscriber to the theory that for "most" crime, it's a lot
             | of stupid people.
        
         | jeroenhd wrote:
         | Hamas switched from smartphones, with encrypted messengers to
         | pagers, a communication device with encryption so weak it may
         | as well not be there. Criminals get caught because they used
         | plain phone calls and texts _all the time_. Hell, child abusers
         | are regularly reported to the police because someone saw a
         | suspicious picture on their phone when scrolling through the
         | gallery. Crime and an understanding of cybersecurity don't
         | necessarily overlap.
         | 
         | I agree that cloud services cannot be trusted to do encryption
         | within their clients, but on platforms like iOS it's difficult
         | to do automated backups using independent encryption. It's also
         | quite difficult not to accidentally enable backups to these
         | services because the setup flow for every phone guides you to
         | hitting the "upload everything I do to Apple/Google".
         | 
         | To Apple's credit, while they normally store a copy of the
         | encryption key, making most cloud encryption entirely useless,
         | they do offer setting a custom key at least. GDrive and
         | OneDrive sure don't.
        
           | luqtas wrote:
           | there are dumb people out there but can you sum up (just
           | talking about illegal drugs) an industry that makes $360
           | billion per year? Brazilian ghettos have army grade weapons
           | like anti-aircraft missiles [0]
           | 
           | psychopathy is a mental disease who impair people to control
           | their impulses/defected judgment; often these are permanent
           | personality traits, which either will let them sit in a
           | prison for the rest of their lives depending on what they did
           | or they will be liberated if they get caught with a high
           | chance of another incidence... search for papers/work from
           | Kent Kiehl if you are interested in this type of stuff
           | 
           | [0] https://www.globalissues.org/news/2009/10/30/3330
        
           | GeekyBear wrote:
           | > on platforms like iOS it's difficult to do automated
           | backups using independent encryption.
           | 
           | iOS allows you to perform encrypted backups to your local PC
           | or Mac out of the box.
           | 
           | https://support.apple.com/guide/iphone/back-up-iphone-
           | iph3ec...
        
           | rjmunro wrote:
           | I believe they switched to pagers because their location
           | can't be tracked. Every pager message is broadcast across the
           | whole country and the pagers just listen to all of them and
           | only tell the owner about the ones meant for them.
           | 
           | A phone has to at least tell the nearest tower that it's
           | within range so that the tower can know to send it messages.
           | After that, when it get's a message it sends some sort of
           | acknowledgement. In theory anyone can pick up those messages
           | with a phased array or set of directional antennas and get a
           | directional fix on the phone.
        
         | Terretta wrote:
         | > _I have never understood the thinking around uploading your
         | private life to some server in the cloud when they are more
         | secure on an external hard drive at home._
         | 
         | Depends on your threat model. If someone unofficial wanted at
         | what you're doing, they'd likely find it easier to go after
         | your home data than what you have in iCloud -- particularly if
         | using Advanced Data Protection for iCloud.
         | 
         | https://support.apple.com/en-us/108756
         | 
         | Also, ask the folks in Los Angeles how those external hard
         | drives at home are working out for them in the fires. There are
         | many types of threats.
        
         | lofaszvanitt wrote:
         | The average people have zero idea about these things. They just
         | use phones, and do not care how they function, what they do in
         | the background.
        
       | cpymchn wrote:
       | What's new here?
       | 
       | As mentioned in the article, Salt Typhoon and the recency of this
       | request by the UK. At this point they should know better.
       | 
       | My pet theory is anytime the US wants to do something illegal
       | under US law, they simply ask the UK to do it and vice versa.
       | That's why Salt Typhoon isn't and never will be a lesson learned.
        
         | cpymchn wrote:
         | I recommend Susan Landau as the goto person on this. She
         | recently spoke with Lawfare on the current state of play.
         | 
         | [1] Susan Landau and Alan Rozenshtein Debate End-to-End
         | Encryption (Again!)
         | https://www.lawfaremedia.org/article/lawfare-daily--susan-
         | la...!)
        
           | EdwardCoffin wrote:
           | Formatting in link is broken. This is a direct link to the
           | youtube version: https://www.youtube.com/watch?v=AWBFXiOcR88
        
           | layer8 wrote:
           | Working link: https://www.lawfaremedia.org/article/lawfare-
           | daily--susan-la...
        
         | eptcyka wrote:
         | It is actually Australia where the US goes to test out far-out
         | legislative ideas before implementing them at home.
        
           | y-curious wrote:
           | Australia does a great job of enacting wacky authoritarian
           | policies in the last 5 years; It would make sense to use them
           | as a staging ground. Does any specific legislation come to
           | mind?
        
             | throwaway290 wrote:
             | Any specific whacky examples?
        
               | MileyCyrax wrote:
               | Something like this? https://en.wikipedia.org/wiki/Mass_s
               | urveillance_in_Australia...
        
               | throwaway290 wrote:
               | I started reading and it talks about something where a
               | warrant and a case are required to request interception
               | on each case. Is that whacky? You don't think it helps
               | you know fight crime and stuff? Or you have an actual
               | specific example?
        
             | fukawi2 wrote:
             | Social media ban for under 16s is the latest half witted
             | idea enacted by the government here.
        
         | banku_brougham wrote:
         | It's not a pet theory, it's exactly how the Five-Eyes system is
         | meant to work. I remember when Total Information Awareness was
         | announced and they even had a cool badge designed for the new
         | govt department. It wasn't a popular idea.
        
           | jer0me wrote:
           | https://commons.wikimedia.org/wiki/File:IAO-logo.png
        
           | lern_too_spel wrote:
           | It is a pet theory. It is illegal for the US to access its
           | citizens' and residents' data without a warrant, and asking
           | somebody else to do it doesn't magically make it legal.
        
             | ok_dad wrote:
             | It's illegal but they do it anyways. Recall there was a man
             | named Snowden who revealed the NSA does collect USA
             | citizens' data.
        
             | cess11 wrote:
             | Why would they "access [their] data", instead of a report
             | from a foreign intelligence agency?
        
             | isaacremuant wrote:
             | It's not a pet theory when there's proof they have engaged
             | in it through five eyes. We're not saying it respects the
             | constitution or its intent. We're saying it's what happens.
             | 
             | Black CIA sites weren't legal either, nor was torture.
        
         | thewebguyd wrote:
         | It's exactly how the five-eyes information sharing works.
         | 
         | Participants spy on each other's citizens on the other's behalf
         | and share data, to avoid the legality of doing so to their own
         | citizens.
        
       | bilekas wrote:
       | > requires that Apple creates a back door that allows UK security
       | officials unencumbered access to encrypted user data worldwide
       | 
       | How could this even be enforced if Apple pulls out cloud services
       | of the UK ?
       | 
       | It's such a ridiculous request, the British Intelligence agencies
       | must be bored coming up with new ways to make Apple look good.
        
         | cmsj wrote:
         | Apple still has legal entities in the UK. Pulling out cloud
         | services would be insufficient to prevent the UK authorities
         | from interfering with their activities.
        
           | bilekas wrote:
           | > prevent the UK authorities from interfering with their
           | activities
           | 
           | I'm still missing how this could be enforced ? To my layman
           | understanding, this reads the same as if China said : "Meta,
           | Tesla, Valve etc has entities in China therefore we get to
           | see all data they store in the EU and the US.
           | 
           | The UK has Zero jurisdiction in Ireland for example where a
           | lot of EU data may be stored.
        
             | elashri wrote:
             | I have lived to the day that we give an example on china
             | not doing something stupid a western democracy does about
             | rights and freedom. Wild times to be alive. I am also
             | surprised that they demand worldwide access and not just UK
             | users data or all the data stored in UK jurisdiction. But
             | this is going too far.
        
               | mathw wrote:
               | And if you think China and the USA and Russia wouldn't
               | want it... hey I've got this bridge for sale.
        
               | idle_zealot wrote:
               | The difference is that China and Russia have the sense to
               | spy on foreign citizens with hackers, trackers, and other
               | covert means. Somehow the UK feels entitled to Apple
               | doing their espionage for them, and has the gall to ask
               | publicly.
               | 
               | Note that this is not China apologia: they do the same
               | brazen shit locally, but they're an authoritarian regime.
               | I have lower expectations for human rights there.
        
               | shafyy wrote:
               | If you, like me, didn't know where the idiom "I've got a
               | bridge to sell you" comes from, here you go:
               | https://en.wikipedia.org/wiki/George_C._Parker
               | 
               | George C. Parker was a conman in NYC who multiples times
               | sold the ownership of the Brooklyn Bridge to his victims.
               | Among other cons.
        
               | bilekas wrote:
               | I know we're going off topic but I remember hearing about
               | this, and reminded me then a similar case in Paris where
               | the Eifel Tower was being sold too.
               | 
               | https://en.wikipedia.org/wiki/Victor_Lustig
        
               | guappa wrote:
               | Here's a whole movie on various scams
               | https://www.youtube.com/watch?v=8qJuxxUoZRw
        
               | bluGill wrote:
               | There are tensions in the US.
               | 
               | Those who are charged with stopping cyber crime are very
               | must against this. End to End encryption is one of the
               | better protections they can give you against foreign
               | hackers and they want you to use it.
               | 
               | Meanwhile down the hall are people who are charged with
               | investigating crimes someone in the country commits and
               | they are want this. It is a lot easier to prove someone
               | is involved in some crime if a warrant can get their
               | data, but end to end encryption means they can only get
               | random bytes. (of course they don't want warrants either,
               | but that is a different issue not relevant here so they
               | will specify warrants in this debate)
        
               | jibe wrote:
               | China has forced Apple to outsource iCloud in China to a
               | state run company, so all data is just directly
               | controlled by the government there. It's an even worse
               | situation.
               | 
               | https://support.apple.com/en-us/111754
        
               | agloe_dreams wrote:
               | That is just China's general rules around tech. Awful?
               | Yes. But not a global issue. Most non-chinese companies
               | are forced to have their chinese properties ran by a
               | chinese company. This is shown by companies like VW
               | having cars made in china with effectively a license
               | model, these cars are designed and built by a third party
               | with a few interesting exceptions (VW actually licensed a
               | design, the Taos, back and shipped it worldwide)
               | 
               | The insane overreach was the UK wanting data on people
               | not in the UK
        
               | guappa wrote:
               | At least the CIA doesn't get it... dunno which is worse.
        
               | csomar wrote:
               | How is this worse? This only affects users in China.
        
               | lern_too_spel wrote:
               | And users who communicate with users in China using Apple
               | services.
        
               | GoblinSlayer wrote:
               | They can send encrypted PGP messages, e2e was figured out
               | in 1991.
        
               | Spivak wrote:
               | We _literally_ tried to do this with TikTok. We can 't
               | exactly stand on a high-horse when the highest level of
               | government in the US was totally fine with it.
               | 
               | Our noble "we can't have American data in the hands of
               | our enemies," their savage "forcing American companies to
               | turn over user data."
        
               | flaminHotSpeedo wrote:
               | Edit: I misread the comment tree, I thought this comment
               | was equating the TikTok situation to the UK's request.
               | 
               | I agree that the TikTok demands are pretty similar,
               | though I might quibble over whether they're literally the
               | same, since arrangements like that are the status quo in
               | China but not in the US
               | 
               | Original comment below:
               | 
               | How is "remove foreign control of data on our nation's
               | users" remotely the same as "give us access to foreign
               | users' data"?
               | 
               | They're not even figuratively the same, despite you
               | literally misusing that word
        
               | joshuaissac wrote:
               | It's not clear which scenario you are referring to.
               | 
               | If by "give us access to foreign users' data", you mean
               | TikTok, then ByteDance is only required to sell the US
               | portion of TikTok to American buyers. If you mean iCloud,
               | then Apple is only required to keep Chinese users' data
               | on local servers.
        
               | flaminHotSpeedo wrote:
               | Oh my bad, I misread the comment tree and thought this
               | comment was a response to the grandparent.
               | 
               | "give us access to foreign users' data" referred to what
               | the UK is asking for, I thought the post i was replying
               | to was equating the UK's request to the US'
        
               | pjmlp wrote:
               | It is worse than that, I never expected that most
               | democracies would go back to foregone days, because
               | people get sold out on populism and decided to ignore
               | history lessons.
               | 
               | As a child of Portuguese revolution, I am aware of plenty
               | of stories, apparently many folks nowadays think those
               | are stories to scare misbehaved kids.
        
             | layer8 wrote:
             | It would be enforced by fining the UK legal entities (or
             | worse, like charging their legal representatives) if they
             | don't comply. If the UK is serious about this, the only
             | alternative for Apple would eventually be to completely
             | cease operations in the UK.
             | 
             | By the way, this is similar to why for true GDPR
             | compliance, data centers should be operated by EU companies
             | that aren't subsidiaries of US companies, because even if
             | the latter operate data centers located in the EU, they
             | would still be bound to secret orders by the US government.
        
               | miroljub wrote:
               | That's actually the only thing that would keep Apple
               | services usable to everyone else around the world.
        
               | p0w3n3d wrote:
               | The most horrible part of the discussion we're making is
               | that we're arguing that UK intelligence should be able to
               | access only UK related data, and not that UK intelligence
               | should not undermine privacy of people
        
               | idle_zealot wrote:
               | The Overton Window has shifted.
        
               | throw0101c wrote:
               | PSA:                   The Overton window is the range of
               | subjects and arguments politically acceptable to the
               | mainstream population at a given time.[1] It is also
               | known as the window of discourse.              [...]
               | The political commentator Joshua Trevino has postulated
               | that the six degrees of acceptance of public ideas are
               | roughly:[7]                  unthinkable         radical
               | acceptable         sensible         popular
               | policy
               | 
               | * https://en.wikipedia.org/wiki/Overton_window
        
               | Mountain_Skies wrote:
               | The Clipper Chip died a quick death back when the Clinton
               | administration wanted it, as the push back against it was
               | pretty strong. Now? Seems like a matter of time before
               | every form of electronic communication has a dozen
               | different back, side, and front doors into it.
        
               | extraduder_ire wrote:
               | I don't think that was mandated to be used for every
               | device though. It was also shown to perform key escrow in
               | secret and had its security defeated before it launched.
        
               | izacus wrote:
               | What we're discussing here is whether a private company
               | should obey laws of the country they operate in or not.
        
               | wqaatwt wrote:
               | The moral thing to do would be to resist obeying such
               | laws as much as is feasible. If that fails close all your
               | legal entities and continue offering services to the
               | citizens of that country to the extent that is feasible.
               | 
               | Of course it wouldn't be very profitable. So
               | unfortunately you really can't expect a major public
               | company to take a stand like in a case like this.
        
               | p0w3n3d wrote:
               | Fully agree. Imagine giving your data to company XYZ
               | which promises you full encryption privacy. The company
               | XYZ opens a subdivision in country CBA and all's okay
               | unless CBA's law is changed to mandate all companies to
               | give all their data. Now your data is lost to CBA's
               | agents.
        
               | bilekas wrote:
               | > By the way, this is similar to why for true GDPR
               | compliance, data centers should be operated by EU
               | companies that aren't subsidiaries of US companies,
               | because even if the latter operate data centers located
               | in the EU, they would still be bound to secret orders by
               | the US government.
               | 
               | This is interesting, I know GDPR does not mandate data
               | localization but I was under the impression that the
               | requirements are a bit more difficult/stringent for
               | transferring data out of the EU region ? While not
               | perfect, it's a bit less 'open door' than it would be if
               | it was hosted in the US.
        
               | michaelt wrote:
               | The EU has a law saying "don't transfer data out of the
               | EU without the right paperwork, but of course if your
               | American sysadmins have SSH access to servers in the EU
               | to do maintenance that's no problem, just tell them not
               | to copy the data off it"
               | 
               | The US has a law saying "If our spies tell American
               | sysadmins to SSH into a server in the EU and copy data
               | off it, they must do it and they must keep it secret"
        
               | kstrauser wrote:
               | I've never worked in a company with data the gov't cared
               | about that wouldn't have sirens going off. Why is Joe
               | SSHing into the EU data center? And now why's he trying
               | to turn off the GuardDuty rule that caught him? And why
               | is he trying to delete that from CloudTrail? And why is
               | the SOC 2 auditor asking why he has access to delete
               | things from CloudTrail in the first place?"
               | 
               | You'd have to get a surprising number of people to go
               | along with it.
        
               | michaelt wrote:
               | That's why it's important to choose a sysadmin who has
               | the authority to SSH to servers. Joe SSHes in all the
               | time, it's not an anomaly.
               | 
               | If you think a SOC2 auditor would spot something like
               | this, in a company the size of Apple or Google - you've
               | probably never been through a SOC2 audit :)
        
               | kstrauser wrote:
               | I wish that I had not been through many SOC 2 audits. But
               | the point was just that in a sufficiently large org that
               | might have cross-continent data centers, it's not common
               | to have one person who can access remote data _and_ cover
               | their trail _and_ turn off the alarms and all the other
               | things required to do it surreptitiously. Possible?
               | Maybe. Likely? _Probably_ not.
        
               | michaelt wrote:
               | In my experience, every sufficiently large org with data
               | centres on multiple continents has an accretion of legacy
               | systems and special exceptions.
               | 
               | And a heuristic anomaly detection system that generates
               | masses of false alarms, and enough different teams and
               | documents and policies to bury an army of SOC2 auditors.
               | And so many log lines almost anything can get lost in the
               | noise.
               | 
               | The janitors always have keys to everything. Especially
               | when it's required by law.
        
               | wqaatwt wrote:
               | Surely if the current government were dumb enough to try
               | and ban Apple from the UK over something like this it
               | would it would make even Truss look competent in
               | comparison.
               | 
               | Not so much because British people love their iPhones to
               | such a extreme degree but because they willing to waste
               | money and resources over something this stupid.
               | 
               | IMHO Apple could bring down the government that tried
               | this if they really wanted to.
        
             | amelius wrote:
             | > I'm still missing how this could be enforced ?
             | 
             | Basically by saying that if they don't comply, they can't
             | do business in the UK.
        
               | freetanga wrote:
               | It is a relatively small market, and if Apple decides to
               | shut down while flooding the streets of London with
               | posters saying "We are forced by your government to shut
               | down in order to uphold your privacy", the UK Government
               | would take a massive blow.
               | 
               | Imagine Russian Oligarchs on android devices! Polonium
               | will roll, I tell you!
        
               | bluGill wrote:
               | There are lots of different ways to do business. UK is
               | unlikely to be able to ban the iphone, and I doubt Apple
               | has much business in the UK. As such they can lay off all
               | workers in the UK "because of legal issues" and the
               | workers feel the pain. They can still sell in the UK
               | through third parties, and go to the EU if you need
               | warranty work
        
               | gnfargbl wrote:
               | Except perhaps for people living near the border in
               | Northern Ireland, "going to the EU" for warranty work is
               | a completely unfeasible suggestion. It's not exactly a
               | short or cheap journey for most of us!
        
               | patrickmay wrote:
               | "Europeans think 100 miles is a long distance. Americans
               | think 100 years is a long time."
        
               | bluGill wrote:
               | You don't have to go in person. Put it in the mail. In
               | person can get same day service though. Next day mail is
               | expensive, but you can get it (and if Apple is serious
               | they can partner with the next day mail and do overnight
               | repairs.). It isn't uncommon for someone to ship you are
               | replacement device and then you ship your broken one back
               | after the new arrives (if the old is only partially broke
               | this can be useful). Apple has a lot of options to make
               | this not too inconvenient.
               | 
               | Though will Apple blink is still unknown. Just because
               | they can doesn't mean they will.
        
               | gnfargbl wrote:
               | The UK public would never accept this. There's basically
               | almost no interest in E2EE at all, but the idea of not
               | being able to take your iPhone to the Apple Store would
               | be riot-inducing. And I think the average Brit would be
               | more comfortable posting their phone to the US than to
               | France.
               | 
               | If Apple really has the guts to stare this one down, then
               | I would expect it's the government who blinks.
        
               | extraduder_ire wrote:
               | Ireland doesn't have a single apple store in it. The
               | closest thing that exists are stores in their authorised
               | reseller program.
        
               | gnfargbl wrote:
               | That's really odd -- Belfast but not Dublin? Why?
        
               | narag wrote:
               | The phone itself is only a piece. Apple sells multiple
               | services, without them the phone is useless. If you can't
               | access the appstore, the backups, etc. what good is an
               | iPhone? Now, the UK can say that UK citizens' data can't
               | travel outside of the UK without the UK government
               | permission.
               | 
               | So it's still a problem. This seems like a looming PR
               | battle.
        
               | wqaatwt wrote:
               | So if British voters get to chose between having access
               | to iPhones or voting for a government that wants to spy
               | on them at whatever the cost surely the choice must be
               | clear?
        
             | insane_dreamer wrote:
             | > I'm still missing how this could be enforced ?
             | 
             | By banning Apple from doing business in the UK.
             | 
             | The US used a similar strategy decades ago to break Swiss
             | Bank Secrecy laws (either Swiss banks had to give up the
             | info or they were going to be kicked out of the US).
        
               | mohamedattahri wrote:
               | Yep, and the US had a lot more leverage; out of the US
               | translates into no access to US dollars either directly
               | or via a correspondent bank, which essentially means
               | bankruptcy.
        
               | throw0101c wrote:
               | > _By banning Apple from doing business in the UK._
               | 
               | To use poker terminology: I think that if the UK made
               | this bet that Apple would call.
        
               | JoshTriplett wrote:
               | I really hope so. I would love to see that showdown.
               | Hopefully, "can't buy an iPhone in the UK and everyone
               | knows why" makes the Snooper's Charter a radioactive mess
               | that legislators fall all over themselves to repeal.
        
               | elcritch wrote:
               | Exactly, imagine the legislatures facing their irate teen
               | daughters for bricking Apple devices.
        
               | izacus wrote:
               | Apple stockholders would never allow that.
        
               | throw0101c wrote:
               | > _Apple stockholders would never allow that._
               | 
               | Then they can vote in a board of directors that agrees
               | with them, and have that board fire Tim Cook.
               | 
               | I would hazard to guess that you'll see an exodus of a
               | lot of folks leaving Apple either because (a) they won't
               | follow that order, or (b) in solidarity with those that
               | are fired.
               | 
               | Reminder that privacy is feature that Apple touts (how
               | much you believe them is up to you):
               | 
               | > _On January 28, 2021, Apple CEO Tim Cook delivered
               | remarks at Computers, Privacy & Data Protection
               | Conference: Enforcing Rights in a Changing World. The
               | virtual conference -- hosted annually in Brussels,
               | Belgium -- is one of the foremost international privacy
               | and technology conferences bringing together leaders from
               | academia, government, civil society and the private
               | sector. Learn more about the features and controls Apple
               | provides users to safeguard their privacy at
               | http://www.apple.com/privacy_
               | 
               | * https://www.youtube.com/watch?v=OaLxTz1Yw7M
               | 
               | * https://www.youtube.com/watch?v=0HjDpPnxcP0
               | 
               | * https://www.youtube.com/watch?v=1YOi0r3vptQ
        
               | izacus wrote:
               | I don't know where your ideas are coming from - Apple
               | easily folded and gave all data to Chinese government
               | when commanded to do so under leadership of Tim Cook.
               | 
               | Where does your thinking that they'll suddenly forget
               | about revenue from UK over this come from?
        
               | throw0101c wrote:
               | > _Where does your thinking that they 'll suddenly forget
               | about revenue from UK over this come from?_
               | 
               | * https://www.google.com/search?q=apple+china+revenues
               | 
               | * https://www.google.com/search?q=apple+uk+revenues
        
               | bluGill wrote:
               | Swiss banks didn't care - they didn't have a large Us
               | presence anyway. Until the US started enforcing this by
               | proxy, other banks couldn't do business with you and the
               | US and overall the US is more important to the world than
               | Swiss banks.
        
               | insane_dreamer wrote:
               | Not so sure. Yeah, they didn't have a large US presence
               | but they did a lot of business with US banks and
               | securities markets -- that's what was threatened. It's
               | wasn't the ability to have branches in the US but the
               | ability to conduct business in US markets.
        
               | christkv wrote:
               | They ban Apple from doing business and watch as the uk
               | stock market goes into the toilet as companies scramble
               | to get out.
        
               | bilekas wrote:
               | > By banning Apple from doing business in the UK.
               | 
               | As someone else here said, Apple would 100% call this
               | bluff. And you can be certain the UK won't have the US to
               | put pressure on Apple for them. All the would happen is
               | the UK Apple users would be with an expensive
               | paperweight.
        
               | mahkoh wrote:
               | That assumes that Apple's shareholders believe that
               | Apple's privacy reputation (relative to other companies)
               | is more valuable than access to the UK market.
               | 
               | All evidence that I have seen suggests that consumers by
               | and large do not care about this kind of privacy. They do
               | not buy iPhones instead of other phones due to the
               | privacy properties.
               | 
               | Therefore Apple's shareholders could order Apple to stay
               | in the UK market.
               | 
               | And if not, then Apple's customers could be compensated
               | with money and other UK-held assets that the government
               | could confiscate.
        
               | pmontra wrote:
               | According to NASDAQ [1] the two main investors are
               | Vanguard and Blackrock, but the two of them together are
               | far away from 50%. There are a number of other large
               | investors. I didn't do the sums but there must be
               | probably 30 of them to get to 50%. Do some of them care
               | about privacy of common people? Probably not. About the
               | people in their boards? Probably yes.
               | 
               | [1] https://www.nasdaq.com/market-
               | activity/stocks/aapl/instituti...
        
               | insane_dreamer wrote:
               | This is usually true of any corp. However, Apple is the
               | one big tech company that has built its reputation on
               | privacy more than any other, and Cook in particular is
               | very strong on that -- and he's not prone to Zuck-like
               | flip/flopping, at least not so far.
               | 
               | You may be right, of course. But if there's one tech
               | company who _might_ say "no", it's Apple.
               | 
               | Counterpoint: Apple in China.
        
               | HDThoreaun wrote:
               | UK can just start fining apple billions of dollars if
               | they dont want to fully kick them out of the country.
        
             | piltdownman wrote:
             | Sadly jurisdiction has nothing to do with it.
             | 
             | https://www.irishtimes.com/business/technology/uk-spy-
             | base-g...
             | 
             | This is not just a case of the British intelligence
             | services secretly "tapping into" Irish telephonic and
             | internet traffic via land and maritime cables. Rather in
             | most cases they are being provided free (or commercial)
             | access to the information by companies associated with the
             | use, ownership or maintenance of these cables.
             | 
             | Post-Snowden the Irish government retroactively legalised
             | it...
        
             | pmontra wrote:
             | It can be enforced in this way: police raids the local
             | headquarters and jail a bunch of people because their
             | company didn't comply with the law.
             | 
             | The only way to prevent that is not having any local
             | office, no employees, nothing. Sell physical objects only
             | by the means of local 3rd party resellers which will import
             | goods. Same thing for services. Of course they can ban
             | imports and services or go after those 3rd parties. It
             | depends how nasty they want to be.
        
               | elcritch wrote:
               | I suspect the UK government would back down way before
               | Apple. People aren't politically active as those of years
               | pass, but brick their iPhones you'd have a riot.
        
             | hedora wrote:
             | The US CLOUD act says something similar to your straw man
             | (though it doesn't ban E2E encryption like the UK is
             | attempting to do):
             | 
             | https://en.wikipedia.org/wiki/CLOUD_Act
             | 
             | Note that it the bar is having the ability to access the
             | server, so this law is completely incompatible with most
             | GPDR solutions: It's illegal to store European user data
             | and then refuse to hand it over to US law enforcement,
             | regardless of whether the data is stored in Europe or the
             | request breaks European law.
        
             | RobotToaster wrote:
             | I imagine they would fine apple a large sum of money. If
             | apple refuse to pay they send high court sheriffs to
             | confiscate any property they have in the UK to pay the
             | debt.
        
           | sandworm101 wrote:
           | More importantly, apple has customers in the UK. The business
           | from captured apple users is more valuable than apple's
           | privacy reputation.
           | 
           | This all seems very similar to RIM and the aftermath of the
           | riots in the UK. The backdoors became too obvious for
           | customers to ignore. Did not go well for RIM in the market
           | afterwards.
        
             | wqaatwt wrote:
             | Who has more to lose though? I mean any government that
             | would do something as stupid as banning Apple because Apple
             | didn't allow it to spy on its citizens wouldn't be very
             | popular or last that long..
             | 
             | I mean this would be even more stupid than Partygate and
             | the whole Truss debacle put together.
        
             | thewebguyd wrote:
             | > More importantly, apple has customers in the UK. The
             | business from captured apple users is more valuable than
             | apple's privacy reputation.
             | 
             | Is it though? I wonder how much of Apple's revenue is from
             | the UK, probably around 5-6%? Apple isn't exactly as
             | popular in the rest of the world as they are in the US.
             | 
             | Would damaging their privacy reputation globally be more
             | valuable than the UK market? I honestly don't know, but my
             | hunch says no - they are likely to want to keep their
             | reputation and dump the UK market. I think more likely is
             | Apple is going to be able to get the UK to cave in. Apple
             | is extremely competent with PR, and would be able to spin
             | any kind of pull-out or degraded service in the UK as the
             | government's choice and fault, to the ire of UK citizens.
        
         | mrighele wrote:
         | That's not even the main issue in my opinion: how can Apple do
         | this without breaking laws in other countries ?
         | 
         | I am not a lawyer, but I think that this would be illegal under
         | EU privacy law.
        
           | tokioyoyo wrote:
           | The same way it operates in China? I guess, China is much
           | bigger market, so it's worth the effort. Not sure how it'll
           | go in the UK.
        
             | mrighele wrote:
             | > a back door that allows UK security officials
             | unencumbered access to encrypted user data worldwide
             | 
             | As far as I can tell, China is asking to keep Chinese data
             | in China and have access to it, but it is not asking to
             | access data of American or European citizen and if it did
             | we would be pissed off.
        
         | guappa wrote:
         | Probably a manouver to make them look good but also privately
         | complying anyway.
        
         | bnjms wrote:
         | > the British Intelligence agencies must be bored coming up
         | with new ways to make Apple look good.
         | 
         | We know they collude with US intelligence serviceUS
        
           | scarface_74 wrote:
           | But as far as we know there is no encryption back door
        
             | tacomagick wrote:
             | "As far as we know" is the most important part.
        
               | madeofpalk wrote:
               | It seems apparent to me that Apple leaked this
               | information to US press in an attempt to get the UK to
               | back off. Wouldn't Apple also try to subvert the attempt
               | for US intelligence to get a backdoor? Or do we think
               | Apple has less of a leg to stand on with US and would be
               | more likely to roll over?
        
               | TechDebtDevin wrote:
               | https://en.wikipedia.org/wiki/Apple%E2%80%93FBI_encryptio
               | n_d...
        
               | mdhb wrote:
               | You are out of your mind if you think files in iCloud are
               | somehow outside the reach of US intel.
               | 
               | It's been publicly used in a bunch of prosecutions at
               | this point.
        
               | madeofpalk wrote:
               | We all know Apple (and everyone else) gives data to law
               | enforcement all over the world
               | https://www.apple.com/legal/transparency/
               | 
               | You're including end-to-end encrypted content in that as
               | well, like from Advanced Data Protection?
               | 
               | > _If you choose to enable Advanced Data Protection, the
               | majority of your iCloud data - including iCloud Backup,
               | Photos, Notes and more - is protected using end-to-end
               | encryption. No one else can access your end-to-end
               | encrypted data, not even Apple, and this data remains
               | secure even in the case of a data breach in the cloud._
               | 
               | https://support.apple.com/en-gb/108756
               | 
               | I have no opinion on whether US intel has a backdoor into
               | this e2e encryption or not. It seems like the sort of
               | thing where people non-chalantly state that it _must_
               | happen, but of course no one ever has actual proof or a
               | source.
        
               | monooso wrote:
               | We're specifically talking about files encrypted E2E
               | using ADP. Can you point to any such files being used in
               | prosecutions?
        
               | yreg wrote:
               | > It's been publicly used in a bunch of prosecutions at
               | this point
               | 
               | Can you give an example then? It would be major hacker
               | news news if supposedly E2EE iCloud data were used in a
               | prosecution.
        
               | jachee wrote:
               | Got any sources to back that up?
        
               | talldayo wrote:
               | I mean, you're right. People think "end to end"
               | encryption helps them, but they forget that Apple
               | controls both the server and client more than the user
               | does.
        
               | autoexec wrote:
               | > Or do we think Apple has less of a leg to stand on with
               | US and would be more likely to roll over?
               | 
               | Apple has no leg to stand on at all. When the NSA comes
               | to your door and demands access to everything you have
               | you don't get to say no. There is no court you can appeal
               | to, and they'll take whatever they want and order you to
               | keep your mouth shut about it. They'll walk right into
               | your headquarters and data centers, force you to move
               | your employees so they can set up an office for
               | themselves on your property, insert their equipment into
               | your network directly and take everything just like they
               | did with AT&T decades ago
               | (https://en.wikipedia.org/wiki/Room_641A)
               | 
               | Your only options are to comply or shut down
               | (https://en.wikipedia.org/wiki/Lavabit) and I'm not even
               | sure the US government would allow "shut down" as an
               | option in some cases. It seems likely that they'd keep a
               | massive target like Apple running even if the owners of
               | the company wanted to cease operations, but lets be
               | honest, Apple makes a lot of people very very rich so
               | they'd never walk away from that. They'll keep making
               | their money and just try to convince themselves that the
               | US are the "good guys" and so it must be okay.
        
               | lotsofpulp wrote:
               | https://en.wikipedia.org/wiki/Apple%E2%80%93FBI_encryptio
               | n_d...
               | 
               | Obviously, Apple is going to comply with US federal law,
               | given that their headquarters and employees are there, as
               | well as their most profitable market. But when possible,
               | they have shown themselves willing to fight against
               | intrusion.
        
               | ethersteeds wrote:
               | Two things,
               | 
               | First, that's notably the FBI and not NSA. As gp says,
               | NSA has greater powers with less legal oversight on
               | national security grounds.
               | 
               | Second, a cynic might argue that Apple put up a noisy,
               | principled fight that one time precisely to create the
               | perception that you have here. It could be the FBI
               | learned data requests to Apple are a dead end!
               | 
               | Or the two came to a mutually beneficial understanding:
               | "don't come in the front door waving a court order for
               | the cameras and we'll see what we can do when our
               | reputation isn't on the line, see? And maybe if we help
               | out, that antitrust investigation isn't necessary after
               | all!"
        
               | lotsofpulp wrote:
               | FISA courts and patriot act came way before iPhone, how
               | is Apple going to fight a law that is already on the
               | books?
               | 
               | A proposed law, or bill, like the one in the OP's
               | article, can be fought against.
        
               | jajko wrote:
               | I can't imagine all cloud providers weren't leaned on
               | heavily to provide this access long time ago. Its a
               | treasure trove too juicy to be ignored. Pro quid pro of
               | course.
               | 
               | Anything else is highly illogical or outright stupid,
               | imagine CIA or NSA having meeting on this decade and a
               | half ago and deciding 'well if they won't give us full
               | access when we asked nicely I guess that's it, we have to
               | respect the law and their wish'. LOL. They don't respect
               | basic human rights at all if you don't hold US passport,
               | and even then the list of cases breaking laws and
               | constitution is endless.
               | 
               | Apple is good with their PR, but why do folks accept
               | their every word literally and not as part of marketing
               | spin to sell more services is beyond me. Rest of the
               | market is not even trying to spin it that way which is
               | actually more respectable behavior.
        
               | scarface_74 wrote:
               | Don't you think out of the thousands of Apple employees
               | that someone would leak it?
        
               | lern_too_spel wrote:
               | Apple is famous for keeping projects secret from its own
               | employees. To be clear, I think it's unlikely that this
               | has already been set up for the US, but it would be
               | easiest to do at Apple.
        
               | dylan604 wrote:
               | Not necessarily. There's a lot of people absolutely
               | unwilling to risk loosing their salary and career. If you
               | are doxxed as the leaker, what other company would hire
               | you? I'm not even considering if there could be criminal
               | charges involved as well.
               | 
               | Snowden left an example of what kind of lifestyle is
               | possible after leaking, and I doubt snowflakes at FAANG
               | would be down for that. Or how about other examples of
               | leakers that have turned up dead? That's a cheery thought
               | to consider.
               | 
               | So yeah, at this point in time, I do believe there's a
               | lot of people that might not agree, but are not up for
               | the task.
        
               | lern_too_spel wrote:
               | Snowden chose that lifestyle. If he had stayed in the US,
               | he would be out of prison already, just without a
               | security clearance. The longest sentence anyone ever got
               | for leaking government information to the media is 63
               | months, with a release after 50 months on good behavior.
        
               | dbtc wrote:
               | It's all speculation, but perhaps he was also thinking
               | about how high his risk of 'suicide' would be.
        
               | jajko wrote:
               | Manning was released early from her 35 years prison
               | sentence only because there was Obama who had balls to do
               | it and go against extreme far right part of society and
               | government employees. Not going to happen again anytime
               | soon in US.
               | 
               | I am actually surprised she survived this and wasnt
               | suicided or sent to Guantanamo for water boarding till
               | heart stops, I guess thats only for those without US
               | passports.
        
               | autoexec wrote:
               | No. Whistleblowers are extremely rare. Snowden did it,
               | but he also worked with thousands of other employees who
               | had knowledge of some, if not all, of the abuses Snowden
               | told us about, but not one of them came forward. This is
               | pretty much always the case when it comes to
               | whistleblowers. For every one who came forward there were
               | many many more who knew and stayed silent and it's hard
               | to blame them. Whistleblowers are harshly punished, and
               | sometimes killed in retaliation.
               | 
               | Being willing to sacrifice everything you have, including
               | your career, your freedom, and potentially your life,
               | just to let the public know the truth is not something
               | you should expect people to do. It's a huge amount of
               | risk and sacrifice while the only reward is knowing that
               | you've done the right thing even though you'll be
               | vilified and punished for it. That's what makes
               | whistleblowers heroes.
        
             | spiderfarmer wrote:
             | We know.
        
           | hk1337 wrote:
           | By collude, you mean responding to subpoenas they are legally
           | obliged to respond to?
        
             | thinkingtoilet wrote:
             | Of course that's a thing. However, anyone who's ever read a
             | history book has a pretty good reason to be suspicious it
             | ends there.
        
           | mdhb wrote:
           | Collude is such a fucking weird word to describe an alliance.
        
             | abtinf wrote:
             | Collude seems like a pretty good word for an alliance
             | formed for the purpose of subverting the law.
        
               | mathieuh wrote:
               | Yes "collude" contains exactly the right connotations.
               | Slimy, sneaky, against the interests of the public.
        
           | dbg31415 wrote:
           | Funny
           | 
           | https://youtu.be/eW-OMR-iWOE
        
         | simion314 wrote:
         | >How could this even be enforced if Apple pulls out cloud
         | services of the UK ?
         | 
         | Honest question, how Apple is doing it in China? Maybe the
         | exact same scheme will work for UK.
        
         | xyst wrote:
         | MI6 probably gutted the cybersec division. Probably don't have
         | many viable sploits in their cache against Apple.
         | 
         | I suppose this is _good_ but more competent and well funded
         | groups out of Israel, Israeli military complex, Cyprus don't
         | need to "ask" for a back door.
        
           | philipwhiuk wrote:
           | Cyber-related stuff is GCHQ (black/greyhat) or NCSC
           | (whitehat)
        
         | TrueDuality wrote:
         | As long as Apple has a business presence in the UK, they are
         | subject to the laws the UK imposes on them even if they're
         | vastly overreaching and impose on other government's citizens.
         | Not supporting cloud services wouldn't be sufficient to avoid
         | the compliance requirement, they would have to formerly stop
         | doing business in the UK.
         | 
         | Looking at the market size that might be a decision that Apple
         | is willing to make as it would most likely be a temporary
         | stick. The government can spin it anyway they want, but Apple
         | devices do not work basically at all without the deep
         | integration of their services. A geoblock would effectively
         | mean UK citizens would be left with unusable devices and I
         | can't see the resulting outrage being directed exclusively at
         | Apple.
         | 
         | It'll be interesting to see how this plays out for sure.
        
           | VWWHFSfQ wrote:
           | > As long as Apple has a business presence in the UK, they
           | are subject to the laws the UK imposes on them even if
           | they're vastly overreaching and impose on other government's
           | citizens.
           | 
           | I wonder if this means that Apple would ultimately take the
           | same approach that they have in China, where the iCloud data
           | and services are entirely localized within China and allows
           | the Chinese government unrestricted access.
        
             | aucisson_masque wrote:
             | one can't compare china and the uk.
             | 
             | china had leverage because of the manufacturing happening
             | over there and the incredible market opportunity, UK
             | doesn't have much.
             | 
             | technically i believe apple could get out of the UK market
             | to provoke a backslash on the government.
             | 
             | If they concede, other government will use the exact same
             | blackmailing technique and one can say it will be the
             | absolute end of their "privacy" marketing campaign they
             | spent so much money into.
        
             | dwaite wrote:
             | Apple offers the same escrowed key and non-escrowed key
             | (advanced data protection) features in China as far as I'm
             | aware. The extra capability GCBD has would be access to
             | protected at rest data like iCloud email.
        
           | afro88 wrote:
           | The decision wouldn't involve just market size, but their
           | Irish tax haven as well. They're not going to pull out of the
           | UK entirely.
        
             | eric_h wrote:
             | Their Irish tax haven is rather specifically _not_ in the
             | UK.
        
               | booi wrote:
               | yeah isn't it in... you know... Ireland?
        
               | nichohel wrote:
               | There is the Republic of Ireland, not in UK, and Northern
               | Ireland, in UK.
        
             | martinsnow wrote:
             | Go ahead and call someone from Ireland, British.
        
       | latexr wrote:
       | > When asked by The Post whether any government had requested a
       | backdoor, Google spokesman Ed Fernandez did not provide a direct
       | answer but suggested none exist: "Google cannot access Android
       | end-to-end encrypted backup data, even with a legal order," he
       | stated.
       | 
       | No, that does not suggest none exists, it only says _they_ don't
       | have access to it. They could have chosen or have been ordered to
       | give the keys to the government agency but not keep one
       | themselves. I'm not saying that's likely, just that it's
       | important to not take these statements as saying more than they
       | do. They wouldn't hesitate to use "technically correct" as a
       | defence and you have to take that into account.
        
         | JW_00000 wrote:
         | But if they could give a key to the government agency, it
         | wouldn't be _end-to-end_ encrypted, right? Or are you thinking
         | they would have a copy of users ' keys that they gave out?
         | (Which I guess is technically possible.)
        
           | aqme28 wrote:
           | They could also cripple user key-generation. E.g. they choose
           | random primes from a known subset. It would make
           | communication crackable while also being difficult to detect.
        
           | jonhohle wrote:
           | It would be no different from how multiple devices and users
           | access the same content (chat, shared data, etc.). The
           | government's keys would always be included in set which
           | encrypts the real key. They don't need the users' key, Apple
           | doesn't need their private keys. So technically still end to
           | end encrypted, just with a hidden party involved. Users have
           | no way of knowing this doesn't already happen.
           | 
           | And when their key leaks, it's as good as no encryption, but
           | still end-to-end encrypted.
        
           | theshrike79 wrote:
           | If the other end is the government, then it's kinda valid? =)
        
         | em500 wrote:
         | Before people immediately think the worst of Google or other
         | corporate representatives, be aware that people working in
         | these companies need to weight their words carefully. From The
         | Verge's article on the issue:
         | 
         |  _The UK has reportedly served Apple a document called a
         | technical capability notice. It's a criminal offense to even
         | reveal that the government has made a demand. Similarly, if
         | Apple did cede to the UK's demands then it apparently would not
         | be allowed to warn users that its encrypted service is no
         | longer fully secure._
        
           | free_bip wrote:
           | How does this work wrt false advertising laws? If I relied
           | upon their end to end encryption and it turns out to be false
           | advertising because there's a secret backdoor, who do I sue?
        
             | grayhatter wrote:
             | no one, you'll be in secret prison before you somehow gain
             | standing
        
           | latexr wrote:
           | Which is exactly why I'm making this point. If no government
           | had requested a backdoor, they could've simply answered "no".
           | When you have to weight your words, it means you're not at
           | liberty to say whatever you want. That is itself a signal,
           | and why warrant canaries are a thing.
           | 
           | https://en.wikipedia.org/wiki/Warrant_canary
        
             | derbOac wrote:
             | You're right to point out how carefully worded these
             | statements are. But I suspect it's rare for companies of
             | Google's status to not have been asked for a backdoor. It's
             | not really an informative question to ask Google.
        
               | Take8435 wrote:
               | Can you elaborate on why you say it is not informative?
        
               | derbOac wrote:
               | My guess is Google, Microsoft, Signal, Apple, Cloudfare,
               | etc etc etc have all been asked if they could make
               | backdoors. I expect they have all been _asked_. It 's not
               | the same as asking if they have _made_ a backdoor.
               | 
               | So I think a journalist asking an organization like
               | Google if they've been asked isn't really informative,
               | because they almost certainly have been.
               | 
               | I'm not sure how it's relevant other than to say an
               | answer from Google's response might seem oblique, but
               | they're also being asked obliquely and that colors how
               | you might interpret their response.
        
               | robertlagrant wrote:
               | Presumably because the answer is "of course yes".
        
               | latexr wrote:
               | _Of course they were asked._ That doesn't matter, my
               | point is the author is assuming more from the reply than
               | what was said.
               | 
               | It's like if you conspired with your brother to steal
               | from the cookie jar. He stole the cookies while you
               | distracted your parents. Later on your mother reports to
               | your father:
               | 
               | > When asked whether they stole from the cookie jar,
               | derbOac did not provide a direct answer but suggested
               | they didn't didn't know who did it: "I did not see anyone
               | removing cookies from the jar," they stated.
               | 
               | Your statement is factually correct, but it doesn't say
               | what your mother concluded.
        
             | lysace wrote:
             | That concept has always sounded like tech people trying to
             | hack the law without the proper real-world legal knowledge,
             | IMO.
             | 
             |  _Bruce Schneier wrote in a blog post that "[p]ersonally, I
             | have never believed [warrant canaries] would work. It
             | relies on the fact that a prohibition against speaking
             | doesn't prevent someone from not speaking. But courts
             | generally aren't impressed by this sort of thing, and I can
             | easily imagine a secret warrant that includes a prohibition
             | against triggering the warrant canary._
             | 
             | Lots of similar discussion on HN already, e.g. in
             | https://news.ycombinator.com/item?id=5871541.
        
             | bloppe wrote:
             | Simply answering "no" when that's the truth could be
             | illegal too. The ability to say no creates the ability to
             | say yes as well. If I ask Apple whether they got an order
             | and they say "no", then a year later they say "we cannot
             | confirm nor deny", well then that's a yes.
             | 
             | Kinda depends on judicial interpretations of free speech,
             | but that's how warrant canaries work. Are warrant canaries
             | legal in the UK? They seem to be in the US but idk how well
             | established that is.
        
           | atonse wrote:
           | But they can still notify the public, through those canary
           | statements. (I forgot the name commonly used).
           | 
           | For example (a simplistic one), you can have a statement like
           | "we do not have any backdoors in our software" added to your
           | legal documents (TOS, etc). But once a backdoor is added, you
           | are compelled by your lawyers to remove that statement. So
           | you aren't disclosing that you have added a backdoor. You're
           | just updating your legal documents to make accurate claims.
        
             | SkyBelow wrote:
             | Such actions, even just the act of deleting text, conveys a
             | message you were ordered to not convey and the government
             | is not likely to take too kindly to that.
        
           | thewebguyd wrote:
           | > if Apple did cede to the UK's demands then it apparently
           | would not be allowed to warn users that its encrypted service
           | is no longer fully secure.
           | 
           | One would think this runs afoul of other laws though, truth
           | in advertising and similar.
           | 
           | Its such a legal minefield, and the UKs request borders on
           | violating the sovereignty of other nations I can't see Apple
           | complying, but maybe that's hopium talking.
        
         | arccy wrote:
         | if google were to transfer the keys elsewhere, they would have
         | (temporary) custody of the keys, granting them access, and
         | invalidating the statement.
        
           | jonhohle wrote:
           | My layman's understanding is that a user's private key is
           | used to decrypt a random key, which is then used to protect
           | data. Shared files then only require adding key access to
           | that small secret by someone who knows the original key. If
           | one of the original public keys is always one held by
           | authorities, Google never needs to have custody of the
           | private key and can't access the data themselves making the
           | statement true, but misleading.
        
           | latexr wrote:
           | > they would have (temporary) custody of the keys
           | 
           | No, they would have _had_ custody of the keys. Meaning it
           | would still be true they cannot (now) access the data.
        
         | cesarb wrote:
         | > No, that does not suggest none exists, it only says they
         | don't have access to it. They could have chosen or have been
         | ordered to give the keys to the government agency but not keep
         | one themselves.
         | 
         | The whole _definition_ of  "end-to-end encrypted" is that
         | _only_ the two ends have the keys. If anyone or anything other
         | than the two ends (the one sending and the one receiving) has
         | access to the keys, it 's not end-to-end encrypted.
        
           | bux93 wrote:
           | Whatsapp has had end-to-end encryption since 2016. But it
           | only added encryption to cloud backups in 2021. They didn't
           | share any key material with Google, just backed up the
           | messages and media without any encryption to begin with.
        
       | botanical76 wrote:
       | This is so disheartening. I thought we were making progress in
       | the anti-surveillance privacy narrative, but this says otherwise.
       | As a UK citizen, is there anything I can do to dissuade this?
       | 
       | edit: typo
        
         | csmattryder wrote:
         | > I thought we were making progress in the anti-surveillance
         | privacy na[rra]tive
         | 
         | What lead to to believe that? The Conservatives and
         | Conservative-Continuity governments both agree that our data
         | simply must be in the hands of the police, DEFRA, and your
         | local council.
         | 
         | RIPA will never be repealed and only strengthened.
        
           | snapcaster wrote:
           | I don't disagree with your analysis but i wouldn't be so
           | fatalistic. This stuff _isn't_ inevitable and i think it's
           | possible to win people over to our side. Things can change
           | for the better, but they won't unless people who care don't
           | give up
        
             | csmattryder wrote:
             | Ahh, I used to have that opinion, but I've encountered too
             | many "It's fine if they want it, I've got nothing to hide"
             | people. (They never give you their Facebook password if you
             | ask, though. Funny, that.)
             | 
             | Change what you can, I say, VPN on the network device.
        
               | dijksterhuis wrote:
               | focus on the John Oliver dick pic argument.
               | 
               | https://www.wired.com/2015/04/john-oliver-edward-snowden-
               | dic...
               | 
               | > When Oliver shows Snowden evidence that all typical
               | Americans care about is whether the government can see
               | our "dick pics," he encourages Snowden to go through a
               | list of every government surveillance program and explain
               | its capabilities in terms of access to "dick pics."
        
               | chupasaurus wrote:
               | One of my all-time favorites:
               | https://news.ycombinator.com/item?id=41595924
        
               | snapcaster wrote:
               | Yeah totally see your point, i'm just not ready to give
               | up yet
        
         | maeil wrote:
         | > As a UK citizen, is there anything I can do to dissuade this?
         | 
         | If you voted for this Tory-lite government, then you can stop
         | voting for any future Tory-lite governments. If you did not,
         | there's not much you can do in practice without devoting your
         | life to it.
        
           | galangalalgol wrote:
           | Coupd protest on weekends and holidays as a hobby, bring a
           | Bluetooth speaker and blast the kinks.
        
             | gambiting wrote:
             | Well, in the UK _just planning_ a non-violent protest can
             | get you 5 years in prison as many people have already
             | discovered. Protesting has been pretty much made illegal by
             | a very broad legislation that defines any protest that
             | causes  "disruption" as illegal - what "disruption" means
             | is up to interpretation of course.
        
               | bluGill wrote:
               | Which just means you need a large group to protest. They
               | can arrest 10,000 people no problem, but get several
               | million together and you have an army. Best is to get
               | some of the actually army/police with you so that when
               | (not if!) they try to get violent you can make it clear
               | this is a revolution they won't win.
               | 
               | I hope it never reaches the above level, but always
               | remember that remains an option.
        
               | gambiting wrote:
               | Yeah but to get a million people together you need to
               | plan for it first, and that's where they get you :P It's
               | honestly shocking the state of things in the UK in that
               | regard. I'm surprised there isn't more outrage around it,
               | even the people I know who used to say they _hate_ the
               | Just Stop Oil protesters expressed shock that they 've
               | been given 5 years for just talking about a protest, not
               | actually doing it.
        
               | foldr wrote:
               | I don't support the legislation you're referring to, but
               | I think you're painting an exaggerated picture
               | (unfortunately a common theme of these threads on HN
               | about the UK). You can easily find examples of recent
               | protests in London:
               | https://news.google.com/search?q=protests%20london&hl=en-
               | GB&...
        
               | gambiting wrote:
               | Note how I didn't say that protests don't happen in the
               | UK. They obviously do. But the problem is that now that
               | effectively every protest has been made illegal due to
               | the fluid definition of what "disruptive" means, the
               | enforcement is arbitrary. Just stop oil protesters?
               | Thrown in jail. Protesting in front of the Chinese
               | embassy? Carry on. That's the problem with the broad
               | legislation in the UK - government wants to have the
               | power to spy on everyone, but obviously it doesn't mean
               | everyone will be spied on. Just people who do something
               | the government doesn't like.
        
           | InTheArena wrote:
           | Yeah know, at some point a historical review would suggest
           | that the constant stream of labour led initiatives to end
           | privacy might indicate that the problem is not just the
           | tories.
        
           | wkat4242 wrote:
           | But the Tories are not in power. Can't labour just repeal it?
        
             | bluehatbrit wrote:
             | Labour have no problem with it, just the same as the Online
             | Safety Act which is causing chaos right now. They're fine
             | with the legislation and have never expressed a desire to
             | see it repealed. They didn't even do much to prevent it in
             | the first place.
             | 
             | This is what the parent comment is getting at when they say
             | "Tory-lite".
        
               | robertlagrant wrote:
               | What they're not getting at is that this isn't
               | particularly a Tory thing.
        
             | yunruse wrote:
             | "Tory-lite" is a pejorative for Labour, the implication
             | being that they are almost identical in behaviour.
             | 
             | (I very much agree with the sentiment...)
        
             | briandear wrote:
             | Labour caused it. Why would they repeal what they want?
        
             | Jigsy wrote:
             | Which party do you think passed the "Tell us your password
             | or go to prison law" to begin with?
             | 
             | (Hint: It certainly isn't Tory.)
             | 
             | It's also one of the reasons why I will never vote Labour
             | as long as I live.
        
             | isaacremuant wrote:
             | My sweet summer child. It's a false dichotomy, like most of
             | these types of issues, it has actual bipartisan support.
             | 
             | Same thing happens in many other countries no matter how
             | strongly HN users want to tell you A is literally hitler
             | and B is great.
        
           | briandear wrote:
           | Wait. The Tories aren't in power yet you want to attribute
           | this to "Tory-lite?" It's the Labour Party that is in charge,
           | so why not put the blame on the actual perpetrators? Is it
           | because you don't want Labour getting blamed? I am confused.
           | The Labour Party is the one jailing people for speech, so it
           | follows that they would want backdoors into iCloud so they
           | can better investigate ThoughtCrime.
           | 
           | The director of public prosecutions of England and Wales,
           | Stephen Parkinson (appointed by the Labour Attorney General),
           | warned against "publishing or distributing material which is
           | insulting or abusive which is intended to or likely to start
           | racial hatred. So, if you retweet that, then you're
           | republishing that and then potentially you're committing that
           | offense [incitement to racial hatred]."
           | 
           | He added further, "We do have dedicated police officers who
           | are scouring social media. Their job is to look for this
           | material, and then follow up with identification, arrests,
           | and so forth."
           | 
           | This isn't "Tory-lite," this is Labour.
           | 
           | Sources: https://freespeechunion.org/labours-war-on-free-
           | speech/
           | 
           | https://x.com/skynews/status/1821178852397477984?s=46
        
             | madeofpalk wrote:
             | Parent seems to be attempting to discredit, not protect,
             | Labour by calling them "Tory-lite".
        
               | maeil wrote:
               | I'm very surprised that I got as many as three replies by
               | people who interpred my comment this way! You got it
               | right indeed.
               | 
               | I'm a bit confused though, surely if I call someone
               | "Hitler-lite" this couldn't possibly be inteprered as
               | something positive, haha. Maybe it's just tribalist
               | reflexes, or maybe I did word things strangely.
        
             | tim333 wrote:
             | This stuff started from the Online Safety Act 2023 passed
             | under Rishi Sunak's Tory government.
             | 
             | For some reason Americans, including Musk, go all partisan
             | and feel the need to blame speech restriction on the lefty
             | party but it's not what happened.
        
               | robertlagrant wrote:
               | No, it started with the Regulation of Investigatory
               | Powers Act 2000 (RIPA), passed under Tony Blair's Labour
               | government.
               | 
               | I'll skip the same extreme partisan rant, but replacing
               | Musk with Soros or whoever.
        
           | Lio wrote:
           | Which party, with a realistic chance of being first past the
           | post, could you vote for that wouldn't bring this in?
           | 
           | This is Hobson's choice as far as I can see.
           | 
           | I don't think there's anyone you could currently vote for
           | that wouldn't do this.
        
             | maeil wrote:
             | You know the answer, of course with FPTP there's only two
             | parties with a realistic chance. But why do they? Because
             | you keep voting on them. Your votes made e.g. Corbyn lose
             | but Starmer win. What signal does this give off? A very
             | different signal than if _both_ would 've lost. Would
             | another Tory government would have been even worse? In the
             | short term, maybe. But this kind of short-termism is what
             | has got Labour (and all of the other similar parties all
             | over Europe) in this exact predicament. Better to make them
             | lose for picking an awful candidate that's a Tory-lite and
             | bite the bullet. It's not like the Tories would have kept
             | winning for decades on end with the way things were going.
        
               | Lio wrote:
               | I'm sorry but Corbyn was a terrible choice as Labour
               | leader, and I vote Labour in that election!
               | 
               | He was unelectable for a variety of reasons.
               | 
               | Here's three:
               | 
               | Wanting to pull out of NATO and instead appease Putin.
               | 
               | Lying about being forced to sit on the floor of what was
               | later shown to be an empty train.
               | 
               | Basically doing nothing during the Brexit fiasco.
               | 
               | He was just gaff after gaff.
        
           | rvz wrote:
           | > If you voted for this Tory-lite government
           | 
           | If you agree that Brexit happened under the Tories and not
           | Labour, then we can also agree that THIS order is happening
           | under the newly elected "Labour Party" and not the "Tories",
           | or so-called "Tory-lite" names.
           | 
           | It's completely pointless trying to remove accountability of
           | this government's illogical actions and then to immediately
           | resort to blaming the previous government for bad decisions
           | like this one.
           | 
           | Just admit that this is under the Labour government.
        
             | zahllos wrote:
             | RIPA and key disclosure law came in under Tony Blair's
             | labour government as well, along with https://en.m.wikipedi
             | a.org/wiki/Communications_Data_Bill_200..., arguably the
             | precursor idea to the IPA that this notice was issued
             | under.
        
             | maeil wrote:
             | Huh? You completely misunderstood what I meant by that
             | moniker. In no way at all does it absolve them of blame -
             | quite the opposite, it's calling them nearly as bad, so
             | close that the difference doesn't really matter.
        
         | snapcaster wrote:
         | In my mind, the only way to beat these efforts for good is to
         | win hearts and minds of the larger public. Currently because
         | only weirdos like us care about this stuff, we have to
         | constantly be on top of these things and writing letters making
         | posts etc.
         | 
         | Overall i agree with you, it is really disheartening. That
         | being said, i've made progress with my family on valuing
         | privacy and the dangers of surveillance. I think people might
         | be changing their minds slowly but still lots of work to do.
         | 
         | A breakthrough with my sisters was when abortion was threatened
         | here in the states. Mentioned to them that it would be easy for
         | authorities to enforce abortion punishments by subpoenaing data
         | from menstruation cycle tracker apps. This kind of "clicked"
         | for them and they became more open to the other parts (not
         | given ratukan or whatever their purchase history, etc. etc.)
        
           | scarface_74 wrote:
           | Thought experiment: let's say that Trump said that he thinks
           | Apple is helping hide illegal immigrants because they are
           | communicating with each other over channels that ICE can't
           | decrypt, how much pressure do you think he could put on
           | legislatures to pass a law here?
           | 
           | Now let's say that some Republican Senators and
           | Representatives were ethically opposed to but then threatened
           | to be primaried and President Musk said he would throw all of
           | his money behind a potential opponent, how long do you think
           | it would take a law to be passed?
           | 
           | Even without a law, we already see that Cook will willingly
           | bend a knee to Trump as will Google.
           | 
           | Right now in my home state the governor was trying to get a
           | law passed banning Western Union from allowing illegal
           | immigrants from sending money overseas.
        
             | snapcaster wrote:
             | I'm not sure what the hypothesis is in your experiment, i
             | agree that all that stuff is really bad
        
               | scarface_74 wrote:
               | That all it takes is the co-presidents to say that by
               | giving up your freedom we can get rid of those "evil
               | illegal immigrants" and enough people will give up their
               | rights.
        
         | brandon272 wrote:
         | > I thought we were making progress in the anti-surveillance
         | privacy narrative, but this says otherwise.
         | 
         | I think we are perhaps the lowest point ever in terms of anti-
         | surveillance efforts. There seems to be bipartisan effort among
         | many (most?) western governments that the government should
         | have unfettered access to all data, regardless of any
         | reasonable expectation of privacy.
         | 
         | Encryption seems barely tolerated these days. Governments are
         | insisting on backdoors, they are making it illegal in some
         | cases for companies to even discuss what is going on or that
         | monitoring is happening.
         | 
         | We barely know what is going on with the programs and efforts
         | that get leaked to the media, much less the programs that
         | operate in total secret.
        
         | cbeach wrote:
         | Let's start supporting parties that have principles.
         | 
         | And stop making excuses for parties that don't (i.e. Labour,
         | Lib Dems and Conservatives).
         | 
         | At the moment, the UK public (and media) considers it a sport
         | to disparage and smear parties like Reform, whose leaders want
         | to shrink the power and over-reach of the state.
         | 
         | We are so concerned with appearing virtuous and internationally
         | generous, we cannot be seen to align with a party that wants to
         | put UK citizens first (border security? deporting dangerous
         | criminals back to their home nation? gasp, how could we be so
         | ghastly!)
         | 
         | This self-defeating attitude needs to change if we want a
         | better future for our children.
        
           | rvz wrote:
           | > Let's start supporting parties that have principles.
           | 
           | The problem is that there are none.
           | 
           | The correct assessment of all these political parties is that
           | by default, they all cannot be trusted. Especially both
           | labour and the conservatives.
           | 
           | > This self-defeating attitude needs to change if we want a
           | better future for our children.
           | 
           | Yes. The second problem is that the United Kingdom is
           | incapable to changing itself historically and is
           | fundamentally destined to _never_ be open to change.
        
         | isaacremuant wrote:
         | Probably helps if the next time they try to remove the rights
         | of large segments of the populace based on medical choices,
         | lock people down, track them and propose vaccine passports,
         | that you realize where everything is headed and oppose it
         | vocally.
         | 
         | It's always through the appearance of good intentions and a
         | public that pushes for whatever narrative they're fed that they
         | normalize this.
         | 
         | People love and want more of this, not less.
        
       | maeil wrote:
       | From the macrumors thread:
       | 
       | > So much for personal liberties. I'd like to give Labour the
       | benefit of the doubt and assume this is a holdover from the last
       | government knowing how fast the civil service actually works but
       | given the Tory 3.0 plan they are going with I wouldn't put it
       | passed them.
       | 
       | >We didn't vote for this.
       | 
       | You very much did vote for this, you voted for Labour under Keir
       | Starmer and he did not particularly hide his being tory-lite. If
       | one is surprised by this they must not have paid any attention
       | before voting.
        
         | scrlk wrote:
         | Have people forgotten the authoritarian tendencies of the
         | 1997-2010 Labour governments? This is nothing new.
        
         | blibble wrote:
         | quite why Labour deserve the benefit of the doubt on anything
         | authoritarian I don't know
         | 
         | Labour was behind:                   - forced key disclosure
         | (Regulation of Investigatory Powers Act 2000), still in force
         | - 72 day detention without charge (Terrorism Act 2006),
         | defeated before it became an Act         - national identity
         | register and mandatory id cards (Identity Cards Act 2006),
         | ripped up by the next Tory government         - various
         | attempts at removal of ancient right to trial by jury
         | (partially successful)
         | 
         | they are as bad, if not worse than the tories
        
           | zahllos wrote:
           | As I posted under another comment, https://en.m.wikipedia.org
           | /wiki/Communications_Data_Bill_200... - communications data
           | bill 2008 / interception modernisation programme. A precursor
           | to what became the IPA.
        
           | Jigsy wrote:
           | Didn't they abolish double jeopardy and introduce secret
           | trials as well?
        
             | blibble wrote:
             | yes, more Jack Straw specials
        
         | physicsguy wrote:
         | Labour are social democrats, not classical liberals...
        
         | mistercheph wrote:
         | Yeah yeah vote for the other clowns next time, they'll
         | definitely roll back these totalitarian policies :)
        
       | sharpshadow wrote:
       | Question: Would it be technically feasible to make an Apple app
       | which encrypts/decrypts the files used in iCloud and is able to
       | use iCloud itself?
       | 
       | As a solution to never have unencrypted files in iCloud.
        
         | layer8 wrote:
         | That's only possible for the files owned by the app. Apps have
         | no access to other unrelated apps' iCloud data.
        
         | EVa5I7bHFq9mnYK wrote:
         | My gf doesn't have iCloud. She makes a backup from time to time
         | by connecting her iphone to her macbook, encrypts the backup
         | folder with 7z, and then I store the resulting file in my
         | dropbox.
         | 
         | I follow the same procedure with my Android phone, no google
         | cloud.
         | 
         | BTW anything I upload to Dropbox is encrypted first.
        
           | echelon_musk wrote:
           | In case you don't already know, if you don't encrypt an
           | iPhone backup with macOS first the backup won't contain _all_
           | of your data.
           | 
           | Apple says "Encrypted backups can include information that
           | unencrypted backups don't" however the list they give is non-
           | exhaustive. You might find yourself disappointed when trying
           | to restore a non-encrypted backup that you've encrypted
           | yourself in a disaster scenario.
        
             | EVa5I7bHFq9mnYK wrote:
             | Thanks, will tell her to encrypt twice. Anyway, there is no
             | critical info there, mainly photos.
        
         | UniverseHacker wrote:
         | Apple basically already has this built into macos - you can
         | create an encrypted disk image and mount it to access the
         | files. I'm not sure if it is possible to open these on ios.
        
         | fotta wrote:
         | Cryptomator does this and it's on the App Store. And it's open
         | source! https://github.com/cryptomator/ios
        
       | captainbland wrote:
       | Given recent polling, we have to assume that what is MI5's today
       | will be Reform's tomorrow. We have to ask what our government and
       | judiciary are doing putting our privacy in the hands of the far-
       | right.
        
         | ajsnigrutin wrote:
         | I never understood this kinds of arguments... both sides want
         | to read your private data, but it's bad if 'the other side'
         | does it? It's your current MI5/government that wants access to
         | apples data.
        
           | janice1999 wrote:
           | One side wants to purge large parts of the population and the
           | other one doesn't. Yes, all parties can abuse data, but their
           | policies do actually matter.
        
             | snapcaster wrote:
             | I think if you value privacy this isn't the right place to
             | be making distinctions between parties. This only serves to
             | alienate people and isn't the core argument.
             | 
             | I think it's more likely to get broad support when framed
             | as us vs. them where "us" is normal working people
             | regardless of political affiliation and "them" is our
             | government elites trying to spy on us.
        
               | captainbland wrote:
               | No, sorry, I've read too much history to buy into this
               | line of reasoning. Authoritarians are a concrete threat
               | to people's safety and they have a long history of
               | abusing sensitive information about people to do so.
        
               | snapcaster wrote:
               | I think maybe we're talking past each other. I'm saying
               | that when advocating for privacy, an effective framing
               | (if winning privacy rights battles is the goal) is to
               | make it "us" vs. "them" instead of some kind of party
               | based push.
               | 
               | If it's associated too strongly with a specific party it
               | alienates too many people to ever get mass support and
               | become a fundamental value that "everyone" agrees on
        
               | captainbland wrote:
               | I do see what you're trying to say. It's just that
               | authoritarian supporters of privacy are a bit of an
               | internal contradiction. Either they're fooled or are
               | being disingenuous.
               | 
               | It's no good having people arguing for "privacy for me
               | but not for thee", which is what it will boil down to.
               | Ultimately authoritarians will use anything which gives
               | them influence and control, with digital privacy
               | violations being one of the easiest to rationalise (no
               | violence, no physical theft).
               | 
               | So I don't see it as worthwhile trying to include such
               | individuals in such a consensus. It's like trying to
               | include foxes in a discussion about how we should best
               | secure hen houses.
        
               | snapcaster wrote:
               | Yeah that makes sense, can't really disagree. i'm just
               | always wary of othering large swaths of the population as
               | beyond hope. I think so many powerful groups are invested
               | in making us all hate eachother and in my experience
               | we're all a lot more similar than we think
        
               | captainbland wrote:
               | Yeah I do actually relate a lot to what you're saying. I
               | should emphasise though that such individuals may still
               | be worth reaching. I don't think most people stay lost
               | causes indefinitely. But you have to break down the
               | desire to support authoritarianism first before it makes
               | sense to tackle digital privacy.
               | 
               | Unfortunately that just means there's a lot more sticky
               | work untangling the kind of tribalistic politics we find
               | ourselves in today.
        
               | snapcaster wrote:
               | 100%. It's an uphill battle for sure
        
             | ajsnigrutin wrote:
             | The other one isn't even voted in yet, hasn't done anything
             | yet, and the current one already wants the data, that they
             | shouldn't get.
             | 
             | The current ones are already abusing their power, and the
             | other one might hypothetically do something, if and when
             | and if at all.
             | 
             | This is like Alice making it legal and then punching you in
             | the face and instead of you "punching back", you say "this
             | is fine, but Bob is bad, because if he gets voted in, he'll
             | punch harder".
        
           | captainbland wrote:
           | Generally speaking it is worse if a party who is
           | ideologically inclined to do something bad to you reads it,
           | yes.
        
           | Retr0id wrote:
           | One is bad in principle and the other is also bad in
           | practice. Both are very bad but the latter is more likely to
           | move people to action.
        
           | botanical76 wrote:
           | My interpretation is that it is an argument against trust in
           | authority in privacy discussions.
           | 
           | A: Privacy matters! B: Why should you care if you have
           | nothing to hide? A: If you have nothing to hide, then give me
           | the password to your Facebook. B: I don't trust you with
           | that, but I trust my governments and relevant authorities.
           | 
           | The point is that B's faith in authority is flawed as the
           | "powers that be" are an eternally shifting target. By
           | agreeing to government surveillance, you place trust in every
           | subsequent government, even the ones you would rather not.
        
             | captainbland wrote:
             | Exactly this. What I'm talking about is just a specific
             | instance of the generalised rule you've stated.
        
             | ajsnigrutin wrote:
             | I always look at this from the other side...
             | 
             | Side A abuses (legal, governmental) power, and instead of
             | "lynching" them for that, we turn the issue into "this will
             | become bad only because of side B will do the same". To me
             | it looks like someone supports side A, and wants to limit
             | the "badness" of whatever they did, but still can't support
             | the thing, so they find the way out by claiming that the
             | other side will do something bad with that data, as if the
             | collecting the data (chats,...) isn't bad enough by itself.
             | 
             | I understand your analogy with friends and facebook, and
             | explaining that stuff to your grandma in this way would
             | probably work... maybe even better if you used "your
             | neighbor Sally works for the government, she could read
             | your chats too, do you really want that?"... but on a
             | technical "forum", it (to me) gives off very politically
             | biased vibes.
        
               | captainbland wrote:
               | For what it's worth I don't support this Labour
               | government one iota. I fully admit to being extremely
               | biased against the Reform party, much in the same way
               | that I'm biased against standing in front of a fully
               | loaded 16 wheeler moving at 60mph.
        
         | Oras wrote:
         | Does it matter who has access to the data? It's the principal
         | not the actor
        
           | captainbland wrote:
           | The actor informs the principal
        
           | wizzwizz4 wrote:
           | If there were a way to magically ensure that only the good
           | guys had access to the information, I'd be way less concerned
           | about these measures. (There are only a few things that I
           | care about being secret for the sake of secrecy, and I can
           | easily keep those off of computers.)
           | 
           | Every encryption backdoor is a huge vulnerability. Even if we
           | somehow ensure that the powers-that-be remain entirely
           | trustworthy (something that, historically, we can't even
           | manage for a century), they're not the only people who'll
           | have access to the backdoor. It's not _possible_ to make an
           | encryption backdoor that only authorised parties can use: as
           | they say, the laws of mathematics do not respect the laws of
           | Australia.
        
         | briandear wrote:
         | It's a Labour government, not a "far right" government.
        
           | captainbland wrote:
           | I see from your history you may have knee jerked this one. I
           | am referencing the far-right Reform party's current polling
           | success and how this may be reflected in our government in
           | the future.
        
       | aaomidi wrote:
       | Gross behavior. But not surprised. UK is a real surveillance
       | state.
       | 
       | In my honest opinion, in this specific context UK should be
       | treated with the same scrutiny we treat China.
        
       | hardlianotion wrote:
       | Apple should tell those ignorant fuckwits to do one.
        
       | ksec wrote:
       | Just make TimeCapsule for iOS and iPadOS. With option to store it
       | fully encrypted in AWS cold storage as Apple subscription.
        
         | odyssey7 wrote:
         | This might sidestep the current order, but the U.K.'s lawyers
         | will just write a new order.
        
         | reaperducer wrote:
         | Any time someone on HN starts a reply with "Just..." you know
         | they didn't think it through.
        
       | jonplackett wrote:
       | I was hoping this dreamland thinking on encryption had died with
       | our last sorry excuse for a government.
       | 
       | I thought we had grown ups running the show now. Clearly that was
       | optimistic.
        
       | GeekyBear wrote:
       | It will be interesting to see if Apple will follow up on comments
       | they made when this change was first floated, and remove effected
       | services from the UK.
       | 
       | > Apple says it will remove services such as FaceTime and
       | iMessage from the UK rather than weaken security if new proposals
       | are made law and acted upon.
       | 
       | https://www.bbc.com/news/technology-66256081
        
       | flanked-evergl wrote:
       | The writing is on the wall for the UK, has been for long, and the
       | Labour government is going out of the way to ensure there can
       | never be any reform, even if they have no mandate. There is one
       | way they want to go, and they will drag their population along
       | kicking and screaming. Anyone who can should get out.
        
         | krn1p4n1c wrote:
         | The question is increasingly becoming "where?". Every place
         | seems to be moving in this direction.
        
           | flanked-evergl wrote:
           | Probably South American somewhere.
        
           | s_dev wrote:
           | Not Ireland -- Ireland so far has been immune to any global
           | veering to the right. There are efforts though -- just not
           | successful.
        
         | alkonaut wrote:
         | What are you trying to say exactly? What kind of reform are you
         | suggesting they make impossible? And how?
        
       | negus wrote:
       | Not surprised, considering UK's ridiculous key disclosure law
       | (United Kingdom The Regulation of Investigatory Powers Act 2000
       | (RIPA), Part III, activated by ministerial order in October 2007,
       | requires persons to decrypt information and/or supply keys to
       | government representatives to decrypt information without a court
       | order.) that makes anyone with high-entropy random data (which is
       | undistinguishable from the crypto-container) a criminal for "not
       | providing the keys to decrypt"
        
         | Chance-Device wrote:
         | This is the way that the UK has passed laws for a while now,
         | make them so broad that they potentially criminalise everyone,
         | then selectively prosecute. This is a very obvious setup for
         | future totalitarianism. I'm surprised that the British public
         | stands for it, but I guess they must not care.
        
           | filcuk wrote:
           | People here are very passive and used to being pulled around.
           | It's insane how far people's rights have eroded already. No
           | right to protest, no right for privacy - what's next on the
           | chopping block?
        
             | varispeed wrote:
             | No right to own money. That will be taken away when cash is
             | phased out.
        
             | curtisblaine wrote:
             | No right to be mean on social media, too.
        
               | nxm wrote:
               | Who defines what is mean? Oh yes, some unelected
               | bureaucrat
        
           | yesco wrote:
           | Future totalitarianism? Is the UK's government restricted in
           | anyway right now? What line have they not crossed yet?
        
             | Chance-Device wrote:
             | As far as I know they haven't started murdering political
             | opponents yet, so that's something. But I take your point,
             | the UK is today not a serious country for a variety of
             | reasons.
        
               | ninalanyon wrote:
               | Are there really any political opponents any more? Al the
               | parties that matter are either explicitly in favour of
               | these ideas or at least behave as though they are.
        
           | doublerabbit wrote:
           | > I'm surprised that the British public stands for it, but I
           | guess they must not care.
           | 
           | I can educate people but it always comes back to "I've not
           | got anything to hide". What are we suppose to do, go out to
           | the streets and protest? Start a petition, right to a PM who
           | has no idea what encryption is?
           | 
           | Mentioning Linux to my family opens a can of worms. We are
           | naive to think protesting actually changes something, it's
           | old fashion. Those with power just don't care so unless
           | people attack with their wallets nothing will come from.
           | 
           | It's not 1995 so unless you have PS for lobbying surrounded
           | by people in suites there is nothing public of any nation can
           | do against anyone in power.
        
             | Chance-Device wrote:
             | Don't you think maybe this attitude is part of the problem?
        
               | doublerabbit wrote:
               | Not at all. We should be banding together to make the
               | next best thing but people are lazy, but who can blame
               | them? Easier to just press the big red NetFlix button and
               | then order food on GrubEats.
               | 
               | I'm being realistic, in the capitalist world we live in
               | unless you have assets, power your worth nothing.
               | 
               | You have no voice, no power, ever. Where's the futuristic
               | project that saves the world? I'm sure the next
               | JavaScript library posted on the front page of HN will be
               | it.
               | 
               | I hate to be "woke" and break it to you that in this
               | reality that your just a schmuck to an entity who's
               | paying you to ensure that your powering their machine
               | with bare benefits; if your lucky. Many homeless folk out
               | there.
               | 
               | Heck, if you've got a job after this ML/AI fluff, you
               | must be good at it. I'm 35 and above cynical at this
               | point, I see no hope in this world from both people and
               | those who run the show.
               | 
               | Take it as you wish, I wouldn't hold it against mother
               | earth imploding herself because of the vile the homo
               | sapiens race has become. Anyway, back to our designated
               | cubicles within the walled gardens we opted for.
        
               | robertlagrant wrote:
               | > I'm being realistic, in the capitalist world we live in
               | unless you have assets your worth nothing. You have no
               | voice, no power, ever.
               | 
               | Describe a better (on average) world and let's try it.
        
               | doublerabbit wrote:
               | Less convenience, more care. More respect, less extreme
               | actions. Effective penalities issued to those who break
               | the rules.
               | 
               | A fine to a $multinational company isn't punishment.
               | Strip their assets from.
               | 
               | More respect for one another would uphold so much more
               | positivity in this world, but no we must judge and align
               | folk in to groups. We are still divided by diversity.
               | It's 2025 and we still have issues over someone being
               | black, white or in-between.
        
               | robertlagrant wrote:
               | I don't know how any of that would translate into a
               | replacement for capitalism, except for capitalism with
               | less plastic?
        
               | doublerabbit wrote:
               | Capitalism isn't inherently bad. It works well with
               | respect.
               | 
               | But in this day and age capitalism has gotten so rootless
               | that nothing is done when the power in question abuses
               | their power. There is no respect in today's capitalism,
               | upgrade respect and you'll have upgraded capitalism. we
               | only go to war because of lack of respect.
               | 
               | Turn the page of the plastic age. I'm now rate limited so
               | that's my digital protesting done for today. Not that
               | anyone has taken side and protested with but would rather
               | point how my ideology is wrong and not contributing to
               | what they would do. But I'm sure you'll be buying your
               | pickets off amazon and walking around town with them only
               | to be tossed aside after the rally this Saturday for them
               | to do something comfy either whether it being Netflix,
               | gaming or porn.
               | 
               | But that's okay it's why I do litter picking out of civil
               | respect; not enough. That way I can pick up the crap that
               | people think they are fighting for as my power of
               | fighting back. When you do go for a smoke, throw the butt
               | on the street, spit on the pavement I'll be there
               | scrubbing that too. Where's the respect? But, hey. People
               | suck we know this. Companies suck more.
               | 
               | Can you threaten class-action lawsuits? If so: Donald,
               | Elon, Jeff, America, UK, Israel, Russia, Microsoft,
               | Google, Apple; you name it. If $entity has treated the
               | world with hurt, you have no respect. Is that what you
               | want to hear? Because that's true capitalism.
               | 
               | Sugar coated? Close your eyes and turn on the TV;
               | especially the news. Pick a side and enjoy the slaughter.
               | You'll be dead soon.
        
               | robertlagrant wrote:
               | Sorry, I'm genuinely confused about what you're saying.
               | If you think no one is worried about plastic except you I
               | honestly don't know how you could possibly get that
               | impression.
        
               | doublerabbit wrote:
               | You keep bringing up plastic yet I've not mentioned.
               | Maybe read my first post you replied to again and
               | understand the world is fucked because of faults.
               | 
               | Turn the page of the plastic age? We all live in a
               | plastic age. Everything is plastic your phone is too.
               | Wars are plastic. Plastic is OLD. Turn the page.
        
               | robertlagrant wrote:
               | You agree. You did mention plastic.
        
               | doublerabbit wrote:
               | I do agree. I had edited my original topic post as I
               | didn't like how I had phased my sentence. For sentence
               | coherency; I do that.
               | 
               | Is this a problem?
        
             | 63 wrote:
             | They have this power precisely because you have given up.
             | Government power is derived from the consent of the
             | goverened. Collective action does work and always will, but
             | it needs to be coordinated. If enough people in the UK
             | stopped going to work, they could affect change pretty
             | quickly I reckon.
        
               | doublerabbit wrote:
               | > They have this power precisely because you have given
               | up.
               | 
               | I've not given up, I just don't follow outdated methods
               | of means to take back power. I use my wallet, I don't
               | shop at amazon.
               | 
               | Stop being a consumer and supporting a ego who supports
               | the wars, causes your protesting against. That would be
               | the next greatest thing but we are too convenienced by
               | these services.
               | 
               | Contradiction much? One where we would rather go and
               | protest, head home and then go and support companies that
               | do the opposite of what your fighting for. That is why
               | protests are flawed. I'd rather be out on a Saturday
               | picking up litter (like I do) than be at a protest and
               | that's not just because I don't support the cause.
               | 
               | I just see the it as a old-fashioned method that doesn't
               | apply to today's new powers. You can't fight for power
               | and then oppositely go and do the opposite nor can you
               | fight when the power is to corrupt. Level the playing
               | field is all you can do.
               | 
               | Innovate, create and throw it back in their faces and
               | don't sell out when the FANG bites you with your cheque.
               | 
               | > Collective action does work and always will, but it
               | needs to be coordinated.
               | 
               | Of course, but who wants to coordinate it. Why not
               | yourself, adding to who wants to be put on a hit list? I
               | get executed and then what, It all goes back to how it
               | was. The Boeing whistleblowers ended up dead, any
               | recourse from that?
        
           | tim333 wrote:
           | Brit here. Yeah from my experience people don't care. Hardly
           | anyone gets prosecuted and those who do have often done
           | something bad.
           | 
           | Most day to day complaints are they don't prosecute enough,
           | often related to the bastard that snatched your phone. We
           | have approximately zero people sitting in jail for failing to
           | decrypt and similar.
           | 
           | >This is a very obvious setup for future totalitarianism.
           | 
           | No it really isn't. If they are planning a totalitarian
           | takeover they are being very sneaky about it. There is a
           | strong anti totalitarianism tradition here including
           | elections since 1265, writing books like 1984 and bombing
           | nazis.
        
             | Chance-Device wrote:
             | Today, maybe, even so it probably depends on who you ask.
             | 
             | The thing about giving your rights away is that it's very
             | difficult to get them back, and you never know who "they"
             | are going to be in the future.
        
               | tim333 wrote:
               | I'm not sure "giving your rights away" quite sums up the
               | process. It's more as a Brit, and probably most of us,
               | weren't even aware this bill was happening - the
               | government passes many pages of dull legislation - but if
               | it proves a pain you can always vote for whoever offers
               | to repeal it. I suspect the encryption law vs Apple is
               | going to result in the government backing down to some
               | extent.
               | 
               | We did rebel over ID cards. Passed in 2006, repealed in
               | 2011.
               | https://en.wikipedia.org/wiki/Identity_Cards_Act_2006
        
             | kypro wrote:
             | Brit here.
             | 
             | > Hardly anyone gets prosecuted and those who do have often
             | done something bad.
             | 
             | Perhaps often they've done something bad, but sometimes
             | they haven't, that's the point. Obviously this is wrong and
             | you shouldn't be so passive about it.
             | 
             | > If they are planning a totalitarian takeover they are
             | being very sneaky about it. There is a strong anti
             | totalitarianism tradition here including elections since
             | 1265, writing books like 1984 and bombing nazis.
             | 
             | I'd argue people in the UK today like to adopt the label of
             | being anti-authoritarian and anti-totalitarian, but in
             | reality most people here, including our politicians, quite
             | like authoritarianism.
             | 
             | For example, people here often argue things like "I support
             | free speech, but obviously insulting someone for their
             | identity is wrong". So in the UK we apparently have free
             | speech and I can apparently criticise religious people, but
             | at the same time just this week someone in the UK was
             | arrested for burning a bible.
             | 
             | You see this hypocrisy constantly in the UK... "I'm not an
             | authoritarian, but smoking is bad". "I'm not an
             | authoritarian, but you can't be saying that". "I'm not an
             | authoritarian, but if you're worried about mass
             | surveillance you probably have something to hide". "I"m not
             | authoritarian, but you can't just let people have private
             | data on an encrypted device which the government can't
             | access".
             | 
             | The UK is very authoritarian these days, but unlike other
             | parts of the world people here deny it while arguing in
             | favour of more of it.
             | 
             | There's nothing necessarily wrong with being authoritarian
             | and wanting the government to have more control either.
             | Clearly many countries find this type of government
             | appealing, but lets at least be honest about it. We don't
             | want kids on social media. We don't want people smoking. We
             | don't want people being about to call people names on
             | Twitter. We don't want people burning religious texts. We
             | don't want people being free from government surveillance.
        
           | cbeach wrote:
           | I've tried to explain the issues with the UK government's
           | stance on digital privacy to my friends. The responses I get:
           | 
           | * I have nothing to hide, I don't care
           | 
           | * Oh come on, our government doesn't care what I'm up to
           | 
           | * The UK will never be totalitarian. I'm not scared of the
           | government
           | 
           | * The UK civil service is incompetent and could never pull
           | this off (fair point, although I worry about the safety of my
           | personal data in the hands of such people)
           | 
           | Let's not forget we had a hard-left (Corbyn) socialist regime
           | come close to power, whose cabinet members called for "direct
           | action" against political opponents, just a few years ago.
           | 
           | https://www.spectator.co.uk/article/watch-john-mcdonnell-
           | s-c...
           | 
           | I don't think people realise how quickly things could go
           | wrong with these surveillance mechanisms in place, and
           | spiteful, authoritarian politicians taking power.
        
           | varispeed wrote:
           | This is fuelled by notion that law enforcement is incompetent
           | and doesn't work.
           | 
           | If law enforcement won't catch criminal even if you had them
           | all the details, evidence, witnesses, then average person
           | thinks there laws are dead anyway as there is no one
           | competent to enforce them.
        
           | trallnag wrote:
           | I'm not surprised at all
        
         | varispeed wrote:
         | It seems like perfect case to make multi-container encryption
         | as default. That is different data will be revealed using
         | different key and there is no way of knowing how many
         | containers there are in the blob of data and not possible to
         | prove someone is hiding a key.
        
       | Puts wrote:
       | This would mean that they would have access to everything stored
       | in Keychain too if you have that synced with iCloud... Which I
       | believe probably most people have. So they will essentially have
       | access to millions of peoples email accounts then.
        
         | bflesch wrote:
         | They already have
        
       | reacharavindh wrote:
       | Does it mean they already have such a backdoor on all Android
       | phones?
        
       | Funes- wrote:
       | Further proof against the idea that we live in "democracies", if
       | anyone still believes that. We're at the hands of petty tyrants.
       | Modern societies are surveillance hellholes, and it seems to only
       | get worse and worse. So much for "progress".
        
         | pentel-0_5 wrote:
         | I think Technofeudalism, as Yanis Varoufakis put it, creates
         | inverted totalitarianism where people are controlled not
         | directly by government with guns but with corporations with
         | access control and moderation power over apps that form the
         | majority of the public commons, personal, and work lives. To
         | resist this subjugation, individuals, municipalities, and
         | groups, large and small, need to build their castles on the
         | bedrock of non-profit co-op services in countries with strong
         | privacy safeguards rather than on the uncertain sands of
         | corporate shores where they will be swept away by the next
         | wave. It's expensive, it's starting from scratch it many cases,
         | and not going to be as immediately polished as corporate
         | offerings, but the socioeconomic and human capital won't be as
         | easily destroyed, manipulated, or raided by police or corporate
         | whims.
        
         | IceHegel wrote:
         | Certainly this decision seems intended to defend the state more
         | than the people.
        
         | alkonaut wrote:
         | I think this is unnecessarily defeatist. The UK is still a well
         | functioning democracy. Using scare quotes around proper
         | democracy just blurs the line to authoritarians and dictators.
         | 
         | We elect our politicians. We demand they stop serious crime and
         | terrorism. When they have bad ideas about how to do that, we
         | let them know that it's a bad idea. Or we don't elect them
         | again. This works.
        
         | lern_too_spel wrote:
         | I think you'll find that the majority of UK's citizens believe
         | its government should be able to access data with a warrant.
         | Whether the demos agree with your particular values is another
         | matter, but this is not obviously undemocratic, unlike royal
         | assent.
        
         | _trampeltier wrote:
         | Thats nothing yet, just wait until we have no reals cash, just
         | electronic money. This will be fun _NOT_
        
       | throwaway290 wrote:
       | Surprising that UK specifically demanded a worldwide backdoor,
       | not just backdoor for UK citizens. Looks like a good workaround
       | for this US gov to get info on Americans via 5 eyes.
       | 
       | DOGE was recently unable to obtain data on Americans
       | (https://www.msn.com/en-us/news/politics/elon-musks-doge-
       | deal...), maybe related...
        
         | Take8435 wrote:
         | > DOGE was recently unable to obtain data on Americans
         | (https://www.msn.com/en-us/news/politics/elon-musks-doge-
         | deal...), maybe related..
         | 
         | They had read/write data for a few days before being denied
         | access https://www.wired.com/story/elon-musk-associate-bfs-
         | federal-...
        
       | mrcwinn wrote:
       | You cannot acknowledge the existence of a request by the UK. You
       | cannot tell users you implemented the proposed system. And you
       | must do all of this to citizens who have no representation in
       | your system, without the consent of their governments.
       | 
       | It all begs the question, what else have they requested, and of
       | those which requests were accepted secretly?
       | 
       | Truly a pathetic example of a democracy.
        
         | alkonaut wrote:
         | There is only one way to respond to this. You just do not
         | comply with this. If you are Apple you withdraw from the UK
         | completely if necessary. But a better option is probably to
         | just take the punishment for not complying while you appeal.
         | The cost will be large regardless. But the reputational damage
         | if Apple complies seems it will be larger than both the fine
         | for noncompliance or the cost of losing all business in a large
         | market like the UK.
         | 
         | I think Apple has a very short window for a powerful response
         | here. It should be re-using the famous Pirate Bay wording for
         | maximum effect.
        
       | gadders wrote:
       | Imagine all the unfinished screenplays they will get access to.
        
       | Lio wrote:
       | I don't think the UK government would try to put Apple out of
       | business if they don't comply it's more likely that they would
       | just get heavily fined until they do so.
       | 
       | The most likely outcome, I would guess, is that Apple just stop
       | offering Advanced Data Protection as a service in the UK rather
       | than create some kind of backdoor.
       | 
       | It's a weak proposition from the government because anyone with
       | something to hide will just move it somewhere else with
       | encryption. Honest UK consumers are the one's getting the shitty
       | end of the stick because we're about to loose protection from
       | criminals.
       | 
       | Daft waste of time.
        
         | matthewdgreen wrote:
         | You're assuming that turning off ADP in the U.K. is sufficient
         | to appease the British Government. The Investigatory Powers Act
         | can also be interpreted to give the U.K. the right to ask for
         | encrypted data from users outside of the U.K. (see Apple making
         | this exact point in a filing here [1].) Turning off ADP in the
         | U.K. doesn't end the controversy if that's what's at stake.
         | 
         | [1]
         | https://bsky.app/profile/matthewdgreen.bsky.social/post/3lhl...
        
           | Spoom wrote:
           | I mean, "Apple refuses to hand over private data to
           | government at cost of UK business" is a pretty good headline.
        
             | lenerdenator wrote:
             | Give me that sort of commitment to privacy and translucent
             | colorful cases for future Macs and Tim Apple's got my money
             | for the next five years at least.
        
             | snapcaster wrote:
             | Yes, this would be something i would love to read
        
             | docmars wrote:
             | Give Apple a big enough incentive to negotiate with and
             | they may very well cave. If I've learned anything about
             | corporations, it's that money and incentives always speak
             | louder than their purported values.
        
               | convolvatron wrote:
               | this isn't apple weighing ethics against revenue. this is
               | apple being forced to decide how much their pro-privacy
               | marketing is really getting them in the market.
        
           | hackernewds wrote:
           | I will stop using a service or hardware that could grant
           | peaking rights into my folders to a possible administration
           | like the one currently in the US. On day 1, zero hesitation
        
             | ForHackernews wrote:
             | I have bad news for you...
        
           | TechnicalVault wrote:
           | It creates a nasty precedent doesn't it? If Apple can provide
           | the UK government with foreign data, what's to stop Russia or
           | China making them provide data on UK minister's phones, or
           | more likely dissidents in exile? I can't see on what basis
           | the government thinks they're going to get to be exceptional
           | here?
        
             | aunty_helen wrote:
             | Why are you using Russia and China as examples of the bad
             | guys here. They're not asking for global access to
             | everyones data, the UK is. The UK are the bad guys.
        
               | outside1234 wrote:
               | He is just trying to show how it would feel if the shoe
               | was on the other foot.
        
               | cbsks wrote:
               | Because the UK is "on our side". We've always been at war
               | with Eastasia.
        
               | Paradigma11 wrote:
               | I dont think that is actually true in those cases.
               | 
               | Relations with China were pretty cosy till they did a 180
               | around the second Bush administration and started all
               | that Wolf Warrior diplomacy, 9 dotted line stuff,
               | Hongkong crackdowns.......
               | 
               | Regarding Russia, nobody really cared at all till it was
               | absolutely impossible to ignore. Putin seems to think
               | that he needs the west as an enemy to bolster his
               | standing and power. Just remember after starting the full
               | scale invasion he proudly declared "I hope I will now be
               | heard" or something to that effect. In Russian mass media
               | the imperial project has long been clear and accepted.
        
               | cbsks wrote:
               | It's a reference to 1984 by George Orwell. https://en.m.w
               | ikipedia.org/wiki/Political_geography_of_Ninet...
        
               | Paradigma11 wrote:
               | I know. I just dont think it fits particularly well with
               | those cases.
        
               | autoexec wrote:
               | > Regarding Russia, nobody really cared at all till it
               | was absolutely impossible to ignore.
               | 
               | Regarding Russia, people have cared since the Bolshevik
               | Revolution in 1917. The fear of communism and concerns
               | about Russia grew until the red scare in the 1920s,
               | through the cold war, and continues to do this day. There
               | has never been a single point in your life when "nobody
               | really cared at all" about Russia.
               | 
               | America's concerns over Russia died down a lot from what
               | it was after the collapse of the USSR but never really
               | went away. That said, if Putin hadn't been doing his best
               | to fan the flames America would probably still be focused
               | on the middle east as their new favorite boogeyman.
        
               | sepositus wrote:
               | Why did you assume the context was "bad guys?" It's a
               | well-known fact that there's a lot of geopolitical
               | tension between Russia/China and Western Europe. The
               | comment is raising the point that by setting this
               | precedent they are opening the doors for their
               | geopolitical rivals to publicly do the same (we already
               | know it happens through private state-sponsored cyber
               | gangs).
        
               | koiueo wrote:
               | Because russia is a bag guy? (Idk about China, but
               | considering they support russia...)
               | 
               | Have you been living under a rock?
        
               | koiueo wrote:
               | I'll be explicit: russia is a terrorist state. Majority
               | of russian population supports the unprovoked genocidal
               | war it currently wages on Ukraine.
        
               | SlavikCA wrote:
               | Russia is no more terrorist state, than USA is.
               | 
               | That was USA scorched Vietnam. That was USA killing
               | civilians in Iraq and Afganistan. That was USA
               | overthrowing foreign goverments, including Ukrainian...
               | And then it preached to Russia on what to do with
               | neighboring states...
        
               | int_19h wrote:
               | USA did a lot of nasty things. But since WW2, it did not
               | invade other countries with explicit intent to annex them
               | and forcibly assimilate their population.
        
               | zimpenfish wrote:
               | > But since WW2, it did not invade other countries with
               | explicit intent to annex them and forcibly assimilate
               | their population.
               | 
               | True but the current lunatic POTUS is essentially
               | threatening that to 2 territories (Canada, Greenland),
               | making noises towards part of a 3rd (Panama), and
               | explicitly calling for ethnic cleansing in a 4th (Gaza).
               | I think the USA's "we're not as bad as Russia" sheen is
               | rapidly disappearing (which makes sense when you consider
               | the two lunatics at the top are essentially considered to
               | be Putin lackeys.)
        
               | shwouchk wrote:
               | Are you the speaker for the majority of the population?
               | 
               | Or is that claim based on the election results, in a
               | state where opposition leaders, journalists, war critics,
               | or even simple lesbians get jailed for said "crimes"?
        
               | koiueo wrote:
               | Like any generalizing claim, mine has exceptions.
               | 
               | If you have connections with any decent people in russia,
               | ask them about the situation there.
               | 
               | > simple lesbians get jailed for said "crimes"
               | 
               | That's exactly the point.
        
               | reverendsteveii wrote:
               | I read it as using Russia and China as the other guys,
               | rather than the bad guys. The idea is to eliminate any
               | pre-existing feelings of trust and illustrate the fact
               | that once your data is held by anyone in the global
               | intelligence community you should think of it as being
               | held by everyone in the global intelligence community.
        
             | dathinab wrote:
             | > If Apple can provide the UK government with foreign data,
             | what's to stop Russia or China making them provide data on
             | UK minister's phones, or more likely dissidents in exile?
             | 
             | nothing
             | 
             | the first precedence of not-draft law here was Cloud Act I
             | think
             | 
             | through I would be surprised if China doesn't "de-facto"
             | requires Chineese companies operating outside of China
             | (including Subsidiaries) to cooperate with their secret
             | service in whatever way they want
             | 
             | and if we go back to the "crypto wars" of the ~2000th then
             | there is a lot of precedence of similar law _ideas_ by the
             | US which where turned down
             | 
             | similar we can't say for sure that there aren't secret US
             | court orders which already did force apple to do "something
             | like that" for the FBI or similar, SURE there is a lot of
             | precedence of Apple pushing back against backdoor when it
             | comes to police and offline device encryption, but one
             | thing is in the public and the other fully in secret with
             | gag orders and meant for usage in secret never seeing the
             | light of courts so while it's somewhat unlikely it would be
             | foolish to just assume it isn't the case, especially if we
             | go forward one or two years with the current government...
             | 
             | Anyway UK might realize that now they have left the US they
             | have very little power to force US tech giants to do
             | anything _in the UK_ not even speaking about regulation
             | which is a direct attack on the sovereignty of other states
             | to own/control/decide about their population(s data).
             | 
             | IMHO ignoring the US for a moment because they are in chaos
             | the EU, or at least some key EU states should make a
             | statement that a UK backdoor allowing UK to access EU
             | citizen data would be classified as espionage and isn't
             | permittable if Apple wants to operate in the EU (but
             | formulated to make it clear it's not to put pressure on
             | Apple but on the UK). Sadly I don't see this happening as
             | there are two many politcans which want laws like that,
             | too. Often due to not understanding the implications
             | undermining encryption has on national security, industry
             | espionage and even protection of democracy as a whole...
             | Sometimes also because they are greedy corrupt lobbyist
             | from the industry which produces mass surveillance tools.
        
             | 8338550bff96 wrote:
             | At what point is this just extortionary cash grab from U.S.
             | tech companies?
             | 
             | Want to fund some expensive grand program? Find a reason to
             | fine U.S. companies.
        
               | eastbound wrote:
               | Why not. Their hegemony is used as a weapon of war, since
               | 1998 when Microsoft was condemned-but-not-penalized for
               | its monopoly. Make it costly for USA to spy & conquer.
        
               | 8338550bff96 wrote:
               | Let us see how that works out for you
        
             | RobotToaster wrote:
             | It's also worth noting that one of the ways the five eyes
             | get around domestic spying laws is to spy on each other's
             | citizens. So the CIA spy on British citizens the UK
             | government want to spy on, and GCHQ spy on American
             | citizens the US government want to spy on. So this would
             | indirectly allow the US government to spy on US citizens
             | (even more than it already does, anyway)
        
               | ekianjo wrote:
               | Why do you think 3 letters agencies care about the law?
               | Ever heard of Snowden leaks?
        
               | nemomarx wrote:
               | one of the Snowden leaks was exactly about the five eyes
               | countries coordinating in this way to dodge oversight
               | though?
        
               | 0xCMP wrote:
               | Right, but the point is they went through the motions to
               | attempt to follow the law. They weren't simply saying
               | someone else was doing the work and then doing it
               | themselves. They _at least attempt_ to follow the law
               | internally. Which is not something we knew for certain or
               | not in the public.
        
               | taurknaut wrote:
               | I think stuff like Parallel Reconstruction show that they
               | _do_ care about the law. They care about working around
               | it.
        
               | autoexec wrote:
               | That doesn't mean they care about the law, it just means
               | that they care about maintaining the public perception
               | that they care about the law. They're perfectly happy to
               | keep up the pretense as long as they can still get what
               | they want anyway, even if they have to add a couple extra
               | inconvenient steps to the process. What they won't do is
               | allow the law to stop them from getting what they want.
        
               | r3trohack3r wrote:
               | Actually my takeaway from the Snowden leaks was that the
               | government tried really hard to stay within the confines
               | of the law, even if they wildly stretched the legal
               | theory to get there.
               | 
               | https://www.blankenship.io/essays/2020-07-13/
               | 
               | Doesn't justify what they were doing, or make it legal,
               | but it's an important distinction when trying to reason
               | about government surveillance programs.
        
               | reverendsteveii wrote:
               | You don't have to have a sound legal theory that will
               | hold up in court. You just have to have a sound bite that
               | you can vomit up when someone says "Wait a minute, isn't
               | that blatantly illegal?"
        
               | nozzlegear wrote:
               | > You don't have to have a sound legal theory that will
               | hold up in court.
               | 
               | What? Why? The natural continuation of "Wait a minute,
               | isn't that blatantly illegal?" is "We're going to sue you
               | to make you stop."
        
               | r3trohack3r wrote:
               | At least in the context of the presidential surveillance
               | program, the ACLU did sue to make them stop. But the
               | program was classified which made getting evidence of the
               | program's existence a crime. The supreme court ruled that
               | they couldn't make a decision without evidence. Shortly
               | after, Snowden leaked the evidence the supreme court had
               | requested. That leak provided the ACLU the evidence
               | necessary to bring the case back to the supreme court and
               | win, "stopping" the program.
        
               | thaumasiotes wrote:
               | So... what part of the program stopped?
        
               | r3trohack3r wrote:
               | It's in air quotes for a reason. Obama ran on promises to
               | end it and protect whistleblowers like Snowden. Then he
               | kept it alive under new branding and doubled down on
               | vilifying whistleblowers like Snowden.
        
               | throwing_away wrote:
               | Well when you say it like that, it sounds like the
               | government is an unstoppable bureaucracy that only cares
               | about its own expansion.
        
               | reverendsteveii wrote:
               | "We're going to sue you to make you stop" is exactly
               | where you deploy the semilegal sound bite. You then use
               | that as the public justification to stall, deny,
               | countersue, delay, appeal, defend, depose and do
               | everything you can to avoid a decision happening one way
               | or the other until you've already gotten and done what
               | you wanted to get and do.
        
               | nozzlegear wrote:
               | That strategy relies on courts always being slow and
               | expensive though. It often feels like it, but that's not
               | a universal truth of the court system. If the damage is
               | high enough, courts can fast-track cases. Judges can also
               | issue injunctions before the delays start, and if the
               | argument is _too_ flimsy it can backfire on the
               | defendant.
               | 
               | I'll concede that if whoever's being sued is going to
               | rely on secret legal interpretations like the
               | NSA/intelligence agencies did with the FISA court
               | rulings, then it makes things a lot trickier.
        
               | reverendsteveii wrote:
               | >That strategy relies on courts always being slow and
               | expensive though.
               | 
               | It doesn't rely on them being slow and expensive, it
               | forces them to be slow and expensive, or to abrogate your
               | rights as a litigant in such a way that any decision they
               | make will be overturned on appeal (which drags out the
               | process even further). Courts can issue injunctions, and
               | those injunctions can be appealed, dragging things out
               | further. If the damage is high enough courts can fast
               | track cases but what do you do about the 99.99% of cases
               | where the damage isn't high enough, and who gets to
               | decide when it is? If this doesn't work why does it keep
               | working?
        
               | kergonath wrote:
               | Didn't these leaks precisely show that the agencies were
               | effectively above the law? I mean, they tried to make it
               | look like they were abiding by the regulations, but
               | effectively tried every work around they could come up
               | with. Including subcontracting domestic spying to foreign
               | intelligence agencies, using the exact mechanism the
               | parent mentioned? It seems you're contradicting them by
               | making their point.
        
             | palmotea wrote:
             | > what's to stop Russia or China making them provide data
             | on UK minister's phones, or more likely dissidents in
             | exile?
             | 
             | Realistically: Apple is a US company (with lots of foreign
             | entanglements) with US leaders, and the US and UK are close
             | allies with extradition treaties and the like. I'd expect
             | the US government to put _lots_ of pressure on Apple to
             | prevent it from acting on such requests from Russia or
             | China, and I wouldn 't be surprised if Apple execs would
             | get slapped with espionage charges if they didn't head the
             | warnings (especially if they "provide data on UK minister's
             | phones").
        
             | Habgdnv wrote:
             | Imagine Kim Jong-un goes to a few police stations in North
             | Korea. It might not work on the first try, but eventually,
             | he manages to trick one officer into believing that Trump
             | threatened him on Facebook. Now, the police of a given
             | country can legally request Apple to provide all
             | information from Trump's iCloud for an "investigation" into
             | threats of violence-- even if they are completely
             | fabricated.
        
             | oneplane wrote:
             | What stops them is one of two things:
             | 
             | Option 1: they operate a separate shard in that country and
             | that shared is only accessible by that country. Companies
             | like Apple, AWS, Cloudflare etc. have been doing it this
             | way in China for a while now. Result: they can spy on the
             | stuff in their country, but the only stuff in their country
             | is their own stuff.
             | 
             | Option 2: no longer operate in an official capacity in that
             | country. Have no people and no assets. Mostly works when
             | the country is not a significant market. This usually means
             | some things are only available grey market, black market or
             | not at all. This is why certain products have lists of
             | "supported countries" - it's not just ITAR stuff but also
             | "we don't want to deal with their regime" stuff. Result:
             | country gets nothing, no matter how loud they ask. Side-
             | effect: you can't really risk your employees visiting such
             | a country as they will be "leveraged".
        
             | JusticeJuice wrote:
             | There are tangentially similar precedents already, such as
             | the American FACTA law. It is obviously a quite different
             | context, as it just relates to financial information, not
             | all information - but it's a law from the US government,
             | that demands foreign companies send information back to the
             | US.
             | 
             | The wild thing is that foreign companies actually do it. To
             | avoid annoying the US, a lot of other governments ensure
             | that the data is reported.
             | 
             | https://en.wikipedia.org/wiki/Foreign_Account_Tax_Complianc
             | e...
        
               | fauigerzigerk wrote:
               | The key difference being that it is perfectly legal for
               | the US to request data on income and gains received by US
               | taxpayers while it is illegal for the US to spy (in
               | certain ways) on US residents.
               | 
               | It is completely routine for countries to exchange data
               | on financial accounts [1]. The only aspect that makes
               | FATCA somewhat unusual is that the US taxes US persons
               | even when they are residents of other countries.
               | 
               | [1] https://www.gov.uk/hmrc-internal-
               | manuals/international-excha...
        
               | lmz wrote:
               | It's legal in the same way this UK thing is legal -
               | because there's a law justifying it. It may make more
               | _moral_ sense, depending on your political persuasion.
        
               | Miraste wrote:
               | The US can get away with this through its immense power
               | and economic influence (for the moment, at least). The UK
               | is a small market of middling relevance, and their
               | government's belief that they're a global power is an
               | anachronism. I hope these decisions cause enough
               | companies to break ties that they're forced to realize
               | their position.
        
             | unyttigfjelltol wrote:
             | We are watching the redefinition of the idea of territorial
             | sovereignty that emerged from the Peace of Westphalia in
             | 1648. We in the US see our expectations of privacy shaped
             | in the UK, and the reverse.
        
             | NoMoreNicksLeft wrote:
             | What if Apple just stops operating in the UK? They could
             | start selling "English language" iPhones in France, let
             | people go on a day trip if they wanted to buy them. There
             | are ways of sidestepping this bullshit if you're an
             | international company. Supposing they have any integrity, I
             | mean. How far will the UK double down?
        
           | arghwhat wrote:
           | They might have to settle for it. The power of a government
           | is not equal to what legislation they pass - they are heavily
           | limited by the economic and publicity consequences of
           | decisions.
           | 
           | As such, any outcome where this is enforced will be a
           | compromise.
        
           | gist wrote:
           | Guess what? Trump will (hopefully) come to the rescue here.
           | Don't laugh at that. I'd imagine he will be helpful possibly
           | even with some of the EU rules such as in particular the one
           | which makes even small US companies liable (as I recal) for
           | notifying users of cookies on a website.
        
             | coolspot wrote:
             | Tim Apple has been on inauguration, so very possible.
        
         | varispeed wrote:
         | Me thinks pervs connected to government want to see people
         | nudes and look for crypto.
        
           | chewz wrote:
           | Don't know but from what I read current UK government is
           | openly pervs friendly.
        
           | talldayo wrote:
           | They should work at an Apple store then:
           | https://www.theverge.com/2021/6/7/22522560/apple-repair-
           | mult...
        
         | sneak wrote:
         | > _The most likely outcome, I would guess, is that Apple just
         | stop offering Advanced Data Protection as a service in the UK
         | rather than create some kind of backdoor._
         | 
         | First, these are the same thing.
         | 
         | Second, ADP is already off by default so approximately nobody
         | uses it. It is irrelevant from a privacy standpoint whether or
         | not they offer it.
        
           | shwouchk wrote:
           | ADP is a relatively new thing. it makes sense to roll it out
           | gradually both from engineering POV as well as marketing.
           | 
           | Further, as all other forms of e2ee, it makes you responsible
           | for the encryption keys.
           | 
           | As a user on the platform I am quite happy it is offered.
           | Considering that these days it is quite difficult not to have
           | a mobile device associated with "you" (you open links sent to
           | "you" on your mobile device? consider that device compromised
           | from privacy perspective), id rather it be on the platform
           | with stronger protections.
        
         | altairprime wrote:
         | The UK government can't put Apple out of business; Apple can
         | easily afford to simply exit all business in the UK. The UK is
         | betting that Apple's greed outweighs their principles. Long
         | odds.
        
           | reaperducer wrote:
           | _The UK is betting that Apple's greed outweighs their
           | principles. Long odds._
           | 
           | Three weeks ago, I would have agreed with you.
           | 
           | Then Tim Cook wrote a check for $1,000,000.00 to help pay for
           | Donald Trump's inauguration party.+
           | 
           | In spite of what they led us to believe over the last couple
           | of decades, Tim Cook and Apple are no different than any of
           | the other tech companies genuflecting before the new emperor,
           | whose stated goals are the opposite of the "mission, vision
           | and values" lies we were fed by the tech industry.
           | 
           | + In case you (or anyone else) missed it:
           | https://variety.com/2025/biz/news/apple-ceo-tim-cook-
           | donates...
        
             | altairprime wrote:
             | As Apple isn't based in the UK and owes no fealty to their
             | government. I don't agree that your citation is relevant
             | here. Apple is a US company. Bribing local officials to
             | overlook the gay founder is sensible corporate practices,
             | however uncomfortable that is to consider. Revoking privacy
             | guarantees globally, reversing years of public opinion
             | gains overnight, is not. The UK cannot do anything to
             | materially harm Apple in any way that Apple can't afford
             | short of sending a double-oh to Cupertino.
        
               | talldayo wrote:
               | > As Apple isn't based in the UK and owes no fealty to
               | their government
               | 
               | Apple isn't based in China, they owe nothing to them
               | either. Apple's willingness to backdoor and modify their
               | services for actual authoritarianism is well[0]
               | documented[1], at no point did they ever threaten to
               | leave the respective markets. Every single spectator
               | knows that Apple leaving these markets would be an
               | admission of guilt.
               | 
               | > Bribing local officials to overlook the gay founder is
               | sensible corporate practices
               | 
               | That hasn't been "sensible corporate practice" since
               | American civil rights were instated. If that is the real
               | motivation for Apple to pen their donation, it would be
               | even more pathetic than a global encryption backdoor.
               | It's not "uncomfortable" to consider, it's illegally
               | discriminatory to a nonsense extent.
               | 
               | What both of you are overlooking, and clearly what this
               | entire thing is about, is antitrust enforcement. Tim Cook
               | knows that Apple cannot survive if they are investigated
               | by a fair commission, so he's trying to manipulate Trump
               | into dropping the DOJ's cases, giving Apple unfair
               | advantages vis-a-vis China and pressuring the EU into
               | stopping their regulation. This is literally surface-
               | level stuff if you even remotely understand Apple's
               | commitment to shareholders and what drives their hardware
               | and software margins in 2025. Everything else is
               | advertisement and a chasing after wind.
               | 
               | [0] https://www.theverge.com/2021/4/1/22361762/iphone-
               | russia-sta...
               | 
               | [1] https://support.apple.com/en-us/111754
               | 
               | [2] https://www.bbc.com/news/articles/cj4d75zl212o
        
               | Miraste wrote:
               | Apple needs China. It's a big market that still
               | manufactures most iPhones, despite their efforts to
               | change that. The surveillance bill the UK has passed is
               | in some ways _worse_ than China 's (a UK shard would not
               | satisfy it), and the UK is far less important.
        
               | Tyrannosaur wrote:
               | > That hasn't been "sensible corporate practice" since
               | American civil rights were instated.
               | 
               | About that... https://www.cbsnews.com/news/trump-equal-
               | employment-opportun...
        
               | int_19h wrote:
               | One thing of note in those other cases is that they only
               | required Apple to comply wrt its customers in the
               | jurisdiction of the country in question. So in China,
               | everything is backdoored, but it doesn't affect users
               | elsewhere.
               | 
               | In this case, the claim is that UK wants global
               | backdoors, so Apple cannot comply quite so easily.
        
             | ustad wrote:
             | For $1 million, you're promised intimate access to Trump
             | and his inner circle. This isn't just about tradition or
             | unity-it's about buying influence and maintaining power. In
             | a world where we're supposedly pushing for fairness,
             | equality, and transparency, this feels incredibly
             | hypocritical. It's as if we're endorsing a system where
             | money talks louder than public interest or ethical
             | considerations. It makes you wonder where the line is
             | between modern capitalism and a system that operates more
             | like an oligarchy.
        
             | Miraste wrote:
             | Of course Apple doesn't have principles, they're a for-
             | profit company. What's in question here is whether they
             | believe the UK is financially worth opening this can of
             | worms. Following US government whims is good business for
             | them in almost all cases, but that math isn't the same for
             | the UK.
        
         | hassleblad23 wrote:
         | Governments have much more power than global companies, even
         | though it seems that they are untouchable from the outside.
        
         | karel-3d wrote:
         | UK government wants a backdoor access to _all users, worldwide,
         | irrespective of their nationality_.
        
         | reverendsteveii wrote:
         | You're assuming people's actual motivations match up with their
         | stated motivations. If your motivation is to be re-elected to a
         | government post by appearing to be tough on terrorism and
         | drugs, every possible outcome of this course of action benefits
         | you. Apple leaves? They were terrorist enablers and you're
         | better off without them. Apple acquiesces? You're the David who
         | took on Apple's goliath and won safety for everyone (again,
         | regardless of whether this actually improves safety for
         | anyone). Apple ignores you? You have an ongoing feud with
         | Dangerous Big Tech that you can campaign and fundraise on for
         | as long as it lasts.
        
         | mtillman wrote:
         | A backdoor for one is an opportunity for many. Given the UK is
         | completely incapable of outspending most of the world on
         | compute, this effectively hands their enemies that data they're
         | looking for.
        
         | GeekyBear wrote:
         | > The most likely outcome, I would guess, is that Apple just
         | stop offering Advanced Data Protection as a service in the UK
         | 
         | Agreed.
         | 
         | > Apple previously made its stance public when it formally
         | opposed the UK government's power to issue Technical Capability
         | Notices in testimony submitted in March 2024 and warned that it
         | would withdraw security features from the UK market if forced
         | to comply.
         | 
         | https://arstechnica.com/tech-policy/2025/02/uk-demands-apple...
        
         | caycep wrote:
         | I feel like the UK always tries to do this w/ encryption. I
         | don't know if it's a cultural sway GCHQ has on legislators and
         | such but it happens w/ every generation of cryptography.
         | Weren't they the one that neutered GSM encryption such that it
         | was essentially ineffective from the get go?
        
         | st3fan wrote:
         | "It's a weak proposition from the government because anyone
         | with something to hide will just move it somewhere else with
         | encryption."
         | 
         | This. Whether it is an app to install on your phone or desktop
         | or simply a website to use. People who need encryption to make
         | sure their communication is private will _easily_ find ways
         | around any kind of government snooping.
        
         | SilasX wrote:
         | >I don't think the UK government would try to put Apple out of
         | business if they don't comply it's more likely that they would
         | just get heavily fined until they do so.
         | 
         | Sufficiently advanced "escalating fines until they comply" is
         | indistinguishable from "putting them out of business".
        
         | lakjsljlkj wrote:
         | Sounds like you're assuming that UK's goal is to stop
         | criminals. I don't think that's their goal. I think that's
         | their cover story.
         | 
         | As for Apple, their daily/hourly/whatever fines might be less
         | than cost of a major ad campaign if they were to buy that
         | publicity directly. Sounds like a good deal for them to refuse
         | to honor the request.
        
       | greenavocado wrote:
       | It wouldn't be the first time Apple did extremely shady things
       | for the government https://tidbits.com/2020/08/17/the-case-of-
       | the-top-secret-ip...
        
         | resource_waste wrote:
         | PRISM, blocking of apps in china, giving over that data to the
         | CCP. I believe they did similar in Russia. The FBI hackings and
         | Pegasus stuff (Although, this is more like bad security)
         | 
         | I should emphasize that 'I personally don't care'. I find it
         | more interesting that people believe there is some safety in
         | Apple products because their marketing says so.
         | 
         | When I was younger, I used to care about these people getting
         | taken advantage of. Today, I wonder how I can replicate the
         | formula. Sorry pals, Apple did it and people were happy about
         | it. I'll make people happy too, its a Noble lie... err Paternal
         | lie :)
        
       | pastyboy wrote:
       | "Stupid is as stupid does...", this is the same Home Office
       | Minister, Yvette Cooper (Flipper) that says pointy kitchen knives
       | and Amazon orders are the reason for knife crime epidemic in the
       | UK. Next up x.com banned from the UK.
        
         | n1b0m wrote:
         | What is the reason?
        
       | joey_spaztard wrote:
       | My response would be along the lines of:
       | 
       | "The USA fought a war in part because they did not like the use
       | of general writs of assistance to allow agents of the British
       | King to search peoples houses and papers where their suspicion
       | chanced to fall. The UK lost that war so no way!"
        
         | axus wrote:
         | Apple Shrugged
        
         | autoexec wrote:
         | Not the strongest argument these days. There's no way that the
         | US hasn't already backdoored apple's systems. They might not be
         | sharing that access with your local law enforcement agencies,
         | but you can bet that the NSA has a backdoor. They've likely set
         | up camp inside Apple. (see
         | https://en.wikipedia.org/wiki/Room_641A). It seems the US lost
         | the war to stop kings from spying too.
        
       | tempodox wrote:
       | Maybe the EU should be glad that the UK is not a member any more.
        
       | cedws wrote:
       | The UK government drops the ball on just about every matter the
       | public care about, but when it comes to overreaching digital
       | surveillance, they're absolutely obsessed.
        
         | talldayo wrote:
         | _glances at FIVE-EYES_
         | 
         | I wouldn't characterize the rest of the world as _not_
         | obsessed, really.
        
       | ChrisArchitect wrote:
       | [dupe] https://news.ycombinator.com/item?id=42970412
        
       | bn-l wrote:
       | That is an extremely corrupt and authoritarian government.
        
       | Malidir wrote:
       | I assume its the USA using the UK to do its dirty work, as
       | always?
       | 
       | Hence why Trump was cheering on Starmer the other day, despite
       | all that has gone on between them.
       | 
       | Americans need to wake up and realise their state uses uk/israel
       | to do what they don't want to be seen to be doing.
        
       | devwastaken wrote:
       | time to pull business out of the U.K. then.
        
         | switch007 wrote:
         | U.K. is as correct as U.S.A.
        
       | octacat wrote:
       | EU/UK is like: - we care about your privacy and will not allow
       | censorship.
       | 
       | And the next day this or blocking DeepSeek (in Italy).
        
       | ARandomerDude wrote:
       | In 10 years we'll all be shocked to discover this headline should
       | have read "US Tells UK to Demand Apple Create Global iCloud
       | Encryption Backdoor".
        
         | brink wrote:
         | Why would you suspect that the US pushed their hand on this?
         | This is not out of character at all for the UK.
        
       | ninalanyon wrote:
       | Surely any moderately sophisticated group of criminals can simply
       | create there own end to end encryption apps. So even if the UK,
       | or other governments, get there own way they will only et to see
       | the content related to the less competent criminals. Perhaps it's
       | still worth it to some.
        
         | zahllos wrote:
         | As Encrochat/ANOM/Sky ECC show, not only is this possible, it
         | actually happens.
        
           | cherryteastain wrote:
           | Encrochat was almost certainly a honeypot:
           | 
           | > After the Dutch and Canadian police compromised their
           | server in 2016, EncroChat turned into a popular alternative
           | among criminals for its security-oriented services in
           | 2017-2018. The founders and owners of EncroChat are not
           | known. According to Dutch journalist Jan Meeus, a Dutch
           | organized crime gang was involved and financed the
           | developers.
        
         | talldayo wrote:
         | Surely they can make their own apps, but whether or not Apple
         | will let them install it has always been a point of contention.
        
       | f4c39012 wrote:
       | Where is my iCloud data stored? If I visit China, is a copy
       | stored there? If my phone is from China, but i live in the USA,
       | where is my iCloud data? Is it replicated globally? I once asked
       | in an Apple store, but no-one knew the answer
        
         | f4c39012 wrote:
         | don't know why the downvote, this is a genuine question. If i
         | bought my iPhone on holiday in Vietnam and created my iCloud
         | account there, but live in France, where is my iCloud?
        
         | tredre3 wrote:
         | Where your data is stored depends on the country set in your
         | Apple Account. In your scenario your data will never be stored
         | in China but I don't know if your USA-based account data is
         | replicated in the EU, though.
         | 
         | 1. https://support.apple.com/en-us/111754 says you can change
         | your country to opt-out of GCBD.
         | 
         | 2. https://www.bbc.com/news/business-42631386 says "iCloud
         | accounts registered outside of China are not affected."
        
       | sneak wrote:
       | There is already a global iCloud encryption backdoor.
       | 
       | iCloud Backup is not end to end encrypted. iCloud Photos is not
       | end to end encrypted.
       | 
       | Apple can read all of your iMessages and see all of your photos.
       | 
       | The governments where they operate can compel them to turn over
       | this data. They can and do. Often.
       | 
       | Operationally this doesn't really change much.
        
         | traceroute66 wrote:
         | > iCloud Backup is not end to end encrypted. iCloud Photos is
         | not end to end encrypted.
         | 
         | DO NOT SPREAD FUD.
         | 
         | If you could be bothered to spend two microseconds on a search
         | engine, you would find this[1] which states IN THE FIRST
         | PARAGRAPH :
         | 
         |  _For users who turn on Advanced Data Protection, the total
         | number of data categories protected using end-to-end encryption
         | rises from 14 to 23 and includes iCloud Backup, Photos, Notes
         | and more._
         | 
         | [1] https://support.apple.com/en-
         | gb/guide/security/sec973254c5f/...
        
           | switch007 wrote:
           | Whatever the opposite of fud is, you're spreading it
        
         | lupusreal wrote:
         | Came here for your comment. Thank you for your dedication to
         | the truth.
        
       | zimpenfish wrote:
       | It's pretty funny that as the US implodes, UKGOV, instead of
       | grasping the opportunity to show that they're the new good option
       | for your internet service needs, decides to blow not one but both
       | kneecaps clean off with the doubly whammy of the OSA/Ofcom
       | debacle[0] and now this farce.
       | 
       | (I suppose the silver lining is that Starmer is merely sidling
       | towards Trump as his new best mate rather than the full-throated
       | slobbering that Johnson/Truss/Sunak would have given him.)
       | 
       | [0] I know this is primarily the fault of the last lot but this
       | shower of onions haven't done anything to roll it back and/or
       | clarify WTF is going on.
        
       | xyst wrote:
       | Black hats love this
        
       | stainablesteel wrote:
       | well it was nice knowing you, UK
        
       | arghandugh wrote:
       | Love swinging through here to collect the latest crop of:
       | 
       | - that's silly - they can't do that legally - this makes no
       | technical sense - this is a bad idea - this will never happen
       | 
       | The entire globe becomes Xi Jinpeng's China with American
       | Characteristics after the iCloud encryption system is neutered
       | and a court warrant is no longer needed.
        
         | talldayo wrote:
         | To be fair, Apple seemingly has no qualms letting the CCP
         | surveil iCloud: https://support.apple.com/en-us/HT208351
        
           | r00fus wrote:
           | Because iCloud in China is complete separate from the rest of
           | the world.
           | 
           | China is not asking to see other countries' iCloud data.
        
       | m3kw9 wrote:
       | lol the f they will
        
       | maxglute wrote:
       | Is this something UK demanded, or a FVEY loophole from other
       | partners. Does US still need to fiddle with legal loop holes to
       | surveille on domestic citizens after Cloud?
        
       | m3kw9 wrote:
       | Why not just require all data on the icloud be sent to a server
       | all unencrypted? Ain't no difference. Apple isn't gonna do it and
       | Trump will tell UK to shove it
        
         | bdangubic wrote:
         | surely UK is going to give two shits what Trump says :)
        
       | StackTopherFlow wrote:
       | I'd love to see a collection of every attempt to add encryption
       | back doors to apple/iPhone products. It feels like they never
       | stop trying.
        
       | lasermike026 wrote:
       | How about NO. Fuck off.
        
       | rtkwe wrote:
       | It'd be nice to not have to have this fight every 3-5 years but
       | privacy is antithetical to the role of the security services so
       | they're never going to give it up.
        
       | biohcacker84 wrote:
       | Constitutionally guaranteed privacy and free speech have made
       | America... the world leader.
       | 
       | America used to push the rest of the world to give their people
       | those rights. Used to....
        
       | smeeger wrote:
       | the UK needs to be slapped in the face. wake up man!
        
       | nico wrote:
       | If it happens, likely the main beneficiary of this would be the
       | US govt
       | 
       | Through Five Eyes the US agencies could, via the UK, get global
       | access to iCloud accounts
       | 
       | No need to change US law
        
       | jrexilius wrote:
       | So UK gov is demanding similar access as China? Not a good look
       | for a supposed free democracy..
        
       | Kim_Bruning wrote:
       | For years, law enforcement pushed for encryption backdoors,
       | arguing they were necessary to combat crime and terrorism.
       | 
       | In the US, after Salt Typhoon compromised telecom networks--
       | including court-authorized wiretap systems--the FBI has now
       | (somewhat reluctantly, I think) started advising government
       | officials to use end-to-end encrypted apps like Signal and
       | WhatsApp to protect _themselves_. [1]
       | 
       | I think the UK government is running a bit behind wrt Encryption.
       | 
       | [1] https://www.npr.org/2024/12/17/nx-s1-5223490/text-
       | messaging-...
        
         | pmlnr wrote:
         | No, the government is always exempt. Citizens shouldn't be
         | allowed e2e, the government, that's ok.
        
           | selendym wrote:
           | The problem with this line of thinking is that the government
           | is, of course, composed of... individual citizens.
        
             | pmlnr wrote:
             | I don't want them to be, they make themselves exempt.
             | 
             | It's bad. It's one of the causes that triggered the French
             | Rebellion in 1793: one rule for them, one for us?
        
       | b8 wrote:
       | Not surprising as the UK wants to ban E2EE too.
        
       | renecito wrote:
       | good luck with that :D
        
       | hassleblad23 wrote:
       | Complete waste of time. At this point I am not sure if its Europe
       | not wanting to understand, or the lack of abilityto understand.
        
       | elevatedastalt wrote:
       | I feel Apple is one of the few companies that has the market
       | power to say, Fuck you, we will just not sell or offer any
       | services in your market, and I suspect that would be enough for
       | voters to knock some sense into their government.
        
         | switch007 wrote:
         | What makes you think they'll do that? Any previous examples?
         | China maybe?
        
           | bagels wrote:
           | They probably won't, but it'd probably work
        
           | GeekyBear wrote:
           | It is what Apple publicly said they would do if the UK
           | attempted this.
           | 
           | https://www.bbc.com/news/technology-66256081
        
             | switch007 wrote:
             | Well that's just negotiation and PR. That's why I asked
             | about previous examples - judge them by what they do, not
             | say
             | 
             | Guess we'll have to see what happens in a few months
        
               | GeekyBear wrote:
               | It' s also what they testified they would do.
               | 
               | >Apple previously made its stance public when it formally
               | opposed the UK government's power to issue Technical
               | Capability Notices in testimony submitted in March 2024
               | and warned that it would withdraw security features from
               | the UK market if forced to comply.
               | 
               | https://arstechnica.com/tech-policy/2025/02/uk-demands-
               | apple...
        
               | cherioo wrote:
               | Apple may withdraw security feature, which is unclear
               | what that achieves at all. Apple will not withdraw all
               | sales in a country for privacy of that country's
               | citizens, as evidenced in China.
               | 
               | UK demanding to see private information for citizens in
               | other countries though..
        
             | drawkward wrote:
             | Of course companies always do what they say they will!
        
       | localghost3000 wrote:
       | This kind of thing makes me furious. I know there's the EFF but
       | what can someone concerned with privacy advocacy do in the face
       | of these kinds of things? Are there orgs and political movements
       | that are out there already? Privacy is a human right. IMO it's
       | one of the big issues of our time.
        
       | blindriver wrote:
       | The US is the only country with codified freedoms from the
       | government. Every other country has rights given by the
       | government to their citizens.
       | 
       | The US may suck every now and then, but the US constitution is
       | one of the best things in human history. It protects us from
       | governments like the UK that don't think they have any limits to
       | control their citizens.
        
         | smodo wrote:
         | How do you mean? Who upholds those codified freedoms? Many
         | democratic countries have similar fundamental laws that are
         | explicitly hard to change or bypass. In the end though all
         | rules are either enforced by some authority or they are mere
         | suggestions. The USA doesn't seem like a special case to me?
        
           | gsk22 wrote:
           | > Many democratic countries have similar fundamental laws
           | that are explicitly hard to change or bypass.
           | 
           | What exactly constitutes "hard to change"? In many countries,
           | fundamental freedoms are regular legislation which can be
           | overturned in the usual manner. Even a threshold of 2/3 or
           | 3/4 to change is much easier to overcome than the federated
           | constitutional amendment process in the US.
        
             | trinix912 wrote:
             | There are also countries that have a constitution that
             | cannot be overturned like a regular legislation. It's not
             | like the US is the only place that has it that way.
        
               | gsk22 wrote:
               | Right, I didn't mean to imply it was a US-only phenomenon
               | -- plenty of countries have fundamental rights enshrined
               | in their constitutions, with varying degrees of
               | difficulty to amend. I was specifically responding to the
               | claim about countries that instead have "hard to change"
               | laws, since laws are typically much easier to repeal than
               | constitutions.
        
         | drexlspivey wrote:
         | Did the US constitution protect you from NSA conducting mass
         | surveillance on all US citizens like the Snowden files showed?
        
           | wrycoder wrote:
           | Constitution, yes - but following it, not so much. I would
           | really like the Federal government to improve in that regard.
        
         | LeoPanthera wrote:
         | While the US does have a written Constitution that explicitly
         | limits government power (notably in the Bill of Rights), many
         | other countries also have codified documents or legal
         | frameworks that protect citizens from government overreach.
         | 
         | For example, Germany's Basic Law (Grundgesetz) was created
         | after World War II to ensure the protection of human rights,
         | including freedoms of speech, assembly, and religion, among
         | others. In Canada, the Charter of Rights and Freedoms is part
         | of the Constitution Act of 1982 and guarantees a range of civil
         | liberties. India's Constitution, too, contains an extensive
         | list of fundamental rights that are designed to restrict
         | arbitrary government action, such as the rights to equality,
         | freedom of expression, and personal liberty. South Africa's
         | Constitution is also highly regarded for its strong emphasis on
         | human rights protections.
         | 
         | Even in the United Kingdom, where there is no single written
         | constitution in the US sense, many rights are protected by
         | statutes (such as the Human Rights Act 1998) and established
         | common law principles that limit government power.
         | 
         | Many democracies enshrine rights in law, reflecting the widely
         | accepted idea that such rights are inherent and must be
         | protected against undue governmental interference, rather than
         | merely being granted as privileges.
        
           | tines wrote:
           | Hello ChatGPT
        
         | drawkward wrote:
         | >the US constitution is one of the best things in human
         | history. It protects us from governments like the UK that don't
         | think they have any limits to control their citizens.
         | 
         | The next 4 years will certainly prove or disprove this
         | statement!
        
         | maronato wrote:
         | > The US is the only country with codified freedoms from the
         | government.
         | 
         | This is not true, both because it's not the only one[1], and
         | because the constitution hasn't prevented state censorship in
         | the US[2-4].
         | 
         | > It protects us from governments like the UK that don't think
         | they have any limits to control their citizens.
         | 
         | How would it do that? The US constitution has no power over the
         | UK.
         | 
         | [1]: https://worldpopulationreview.com/country-
         | rankings/countries...
         | 
         | [2]:
         | https://journals.ala.org/index.php/jifp/article/view/7208/10...
         | 
         | [3]: https://historycollection.com/10-situations-in-history-
         | when-...
         | 
         | [4]:
         | https://en.m.wikipedia.org/wiki/Censorship_in_the_United_Sta...
        
           | jmull wrote:
           | > and because the constitution hasn't prevented state
           | censorship in the US[2-4]
           | 
           | That the constitution hasn't been upheld to a perfect
           | standard all the time doesn't mean it doesn't codify
           | freedoms. Also, precisely what the standard is isn't
           | universally agreed upon and changes over time.
        
         | 14 wrote:
         | Well didn't Snowden reveal that is a bit of a stretch in what
         | actually happens? Don't the 5 eyes just just look over each
         | other citizens and report to each other? The constitution only
         | protects up until a national security threat and then ignored
         | is it not? Still I think the US is an amazing country with some
         | of the strongest protections from the government. I just don't
         | think it is as rock hard as you believe.
        
         | DiogenesKynikos wrote:
         | The US Constitution also guarantees birthright citizenship, but
         | that doesn't mean the government will actually respect that
         | right. The US Constitution only holds as long as people are
         | willing to defend it.
        
         | dragonwriter wrote:
         | > The US is the only country with codified freedoms from the
         | government.
         | 
         | No, its not. Plenty of other countries have written
         | constitutions with codified rights against the government. Many
         | of them are more explicit about how the conflict between
         | explicit grants of power to the government and explicit rights
         | of the people balance in conflict, which may make them seem
         | superficially less strong; OTOH, the fact that the US
         | Constitution has both unqualified grants of power and
         | unqualified enumerated rights has led to that conflict being
         | resolved by the courts, by...qualifying the rights based in
         | large part on the grants of power.
         | 
         | > Every other country has rights given by the government to
         | their citizens.
         | 
         | That's no more true of "every other country" than it is of the
         | US. The Constitution itself is a deal negotiated between
         | representatives of and ratified by state governments, so all of
         | the rights it protects are, _ipso facto_ , granted by
         | government.
        
       | isaacremuant wrote:
       | The funny thing is that anyone pointing out authoritarianism will
       | get downvoted with a whole bunch of partisan arguments or
       | left/right false dichotomies.
       | 
       | Here we are, though, at the point where the government overreach
       | for these "beacons of democracy" such as US and UK do this often
       | and by design and we're all supposed to pretend "thing are fine,
       | trust us". Next they'll push some other overreach using children,
       | terrorism, drugs or some other usual excuse and people will
       | defend it pretending the government has good intentions and
       | largely works for the people.
        
       | pmarreck wrote:
       | I hope Apple's answer is simply:
       | 
       | "No."
        
       | adamtaylor_13 wrote:
       | The complete lack of any kind of technological understanding by
       | the people in power of most major governments is a huge
       | existential risk. Thankfully businesses like Apple are completely
       | staked on privacy, but Apple is actually big enough to give a
       | middle finger to the UK. Other companies might not be able to.
        
       | stalfosknight wrote:
       | Why must the UK be like this?
        
       | caycep wrote:
       | Does apple have a canary provision in their EULA / TOS somewhere?
        
       | rchivalry wrote:
       | Encryption is encryption. Purposely breaking it defeats the
       | purpose.
        
       | rchivalry wrote:
       | Encryption is encryption. If this is for dirt digging or evidence
       | for police... then make the person provide it instead. Spy
       | agencies just have to deal with it. Sure there are other ways of
       | tapping information.
        
       | Andrew_nenakhov wrote:
       | New tariffs on UK in 3... 2... 1... ?
        
       | joemazerino wrote:
       | All of a sudden, 100 nerds start seeing the UK government for
       | what it's been: tyrannical.
        
       | aucisson_masque wrote:
       | > the law actually makes it a criminal offense to reveal that the
       | government even made such a demand.
       | 
       | Why is it tho ? The government has something to hide ? i mean
       | it's complete bullshit, citizen have the right to privacy and
       | government has the obligation of transparency and being
       | accountable to its citizens.
       | 
       | When did the UK turned into a middle east dictatorship ?
       | 
       | > Google has enforced default encryption for Android phone
       | backups since 2018. When asked by The Post whether any government
       | had requested a backdoor, Google spokesman Ed Fernandez did not
       | provide a direct answer but suggested none exist: "Google cannot
       | access Android end-to-end encrypted backup data, even with a
       | legal order," he stated.
       | 
       | That is absolutely laughable. If the uk government couldn't
       | access google data, they would have ordered google the same thing
       | they did with apple.
       | 
       | Apple theoretically can't access their user data when e2e
       | encryption is enabled yet the uk government doesn't care. how
       | does that differ from google ?
       | 
       | once again, if you want your data to be safe from google, apple,
       | and the others you got to avoid all cloud and resort to use good
       | old hard drive with encryption.
       | 
       | the only ones getting fcked are once again the average people who
       | don't have much to hide in the first place, the pedophiles and
       | terrorist they are much more aware than the old fart at the
       | government on how to stay hidden.
        
       | mistercheph wrote:
       | UK is a dystopian nightmare, very grateful to the founding
       | fathers for sending them back to the island.
        
       | bsimpson wrote:
       | > We do not comment on operational matters, including for example
       | confirming or denying the existence of any such notices
       | 
       | Cloaking mass privacy violations under "operational matters" is
       | the most doublespeak bullshit I've ever heard.
        
       ___________________________________________________________________
       (page generated 2025-02-07 23:00 UTC)