[HN Gopher] NCSC, GCHQ, UK Gov't expunge advice to "use Apple en...
       ___________________________________________________________________
        
       NCSC, GCHQ, UK Gov't expunge advice to "use Apple encryption"
        
       Author : jjgreen
       Score  : 159 points
       Date   : 2025-03-05 19:34 UTC (3 hours ago)
        
 (HTM) web link (alecmuffett.com)
 (TXT) w3m dump (alecmuffett.com)
        
       | martinsnow wrote:
       | Did the site get hugged to death?
        
         | dizhn wrote:
         | works fine for me
        
           | marcellus23 wrote:
           | not working for me.
           | 
           | edit: it did load eventually after waiting for a minute or
           | two
        
         | bigfatkitten wrote:
         | Yes. Here's the substance of the post:
         | 
         | https://archive.is/YZF6r
        
           | martinsnow wrote:
           | Thank you
        
           | dang wrote:
           | I've made a (shortened) copy of your comment and pinned it to
           | the top of the thread. I hope that's ok with you! I just
           | thought it's only fair for you to get the karma.
           | 
           | (If not, let me know and I'll undo.)
        
             | bigfatkitten wrote:
             | It was fine, but I inadvertently deleted it before I saw
             | your comment. I saw it in my comment history and thought I
             | double-posted!
        
               | dang wrote:
               | Ha! I guess I'll make a new one. Sorry for the
               | confusion...
        
       | sarcasticfish wrote:
       | Could someone that understands more than a third of what was
       | written explain what's going on?
        
         | nickthegreek wrote:
         | Uk Govt wanted Apple to give them backdoor keys to all
         | accounts. Not even just UK accounts, all accounts. Apple said
         | no and said they will remove encryption from iCloud for UK
         | users. Apple then sued UK govt to try and get the whole thing
         | stopped so that they dont need to remove the encryption from
         | UK. But some parts of the govt were telling other parts to use
         | some of the encryption features.
        
         | Hizonner wrote:
         | One part of the UK government is trying to force Apple to
         | introduce back doors in cloud data encryption. The back doors
         | are intended for UK government access to user data. This
         | undermines the whole feature. Meanwhile, other parts of the UK
         | government have been encouraging at-risk people to use the same
         | feature, including to hide information from hostile _foreign_
         | governments. The UK government as a whole has apparently
         | realized that this is embarrassing and taken down the advice.
        
           | dingdingdang wrote:
           | Surely Apple's lawyers can use this information in court -
           | the fact that the government itself is relying on, and
           | recommending, citizens and (presumably) intelligence assets
           | to use Apple's encryption technology abroad makes it VERY
           | clear that outlawing said technology will systematically
           | weaken ALL UK information infrastructure and make it 110%
           | easier for foreign powers to exploit and sabotage the UK as
           | whole.
           | 
           | edit: removed political quip since, as evidenced by sub-
           | comments, it too easily derails from the primary discussion
           | point, excuse-moi.
        
             | miohtama wrote:
             | Apple is not planning to fight for the UK citizens over
             | encryption.
             | 
             | It's a job for the democracy and voters.
        
               | Hizonner wrote:
               | Well, the rumor is that Apple has secretly appealed the
               | order (which is officially secret) to whatever secret
               | tribunal reviews such secret orders to create secret
               | features giving secret government investigations access
               | to various people's secrets. The Court of the Star
               | Chamber, I think it's called.
               | 
               | Which is at least Apple doing something vaguely like
               | fighting. But, yeah, UK citizens might want to think hard
               | about doing something about the situation themselves. For
               | one thing, Apple will probably lose. And the US
               | government isn't going to have Apple's back against the
               | UK, either.
        
             | jen20 wrote:
             | If you think Reform are likely to be in favour of anything
             | other than the most authoritarian implantation of whatever
             | law enforcement suggests they want, I don't think you've
             | been paying attention to who Reform are.
        
             | danparsonson wrote:
             | > Do we really need Reform in power for common sense to
             | flourish in the UK to any degree?!
             | 
             | No. You've mistaken demagoguery for common sense I'm
             | afraid. That's one of their favourite tricks though, so you
             | could be forgiven for the mistake.
        
           | HPsquared wrote:
           | Notice which side wins out.
        
         | dark-star wrote:
         | As I understand it (which might be incorrect), they don't want
         | to tell people "use Apple encryption" anymore and e silently
         | removed that advice from their websites. Probably due to the
         | fact that they didn't get their Backdoor access to user data,
         | so now they want people to just now encrypt stuff
        
       | ohgr wrote:
       | Wankers! Sorry that's not constructive. But that's what they are.
       | 
       | Especially when government ministers regularly accidentally
       | delete everything and get away with it...
        
         | gred wrote:
         | Muppets!
         | 
         | (As an American, I love UK slang. It's both familiar and exotic
         | at the same time.)
        
           | petecooper wrote:
           | >I love UK slang
           | 
           | I recommend checking your preferred book source for Roger's
           | Profanisaurus:
           | 
           | https://en.wikipedia.org/wiki/Roger%27s_Profanisaurus
        
       | bigyabai wrote:
       | Fights like this only legitimize the EU's DSA to me. UK users
       | would not be beholden to Apple for E2EE if their clients had
       | legitimate alternatives to the first-party iCloud service. There
       | would be no world where Apple could even threaten to disable it.
       | 
       | Break the walled garden down, and all of the sudden it doesn't
       | matter what Apple's stance on E2EE is. But Apple wouldn't want
       | that, since then you might realize they aren't the sole arbiters
       | of online privacy.
        
         | nkellenicki wrote:
         | I'm all for the DSA as well, but this argument doesn't hold
         | water. Any sufficiently large cloud provider alternative (ie.
         | Google, Microsoft, etc) would likely be the target of similar
         | government instructions. In fact, I bet they already are - they
         | just can't talk about it.
         | 
         | And of course, it's already possible to disable iCloud backups
         | and use a smaller provider or host your own alternatives. I
         | already do, through Nextcloud, etc. It's not as fully
         | integrated of course, but you bet that if it was, then the
         | largest alternatives would be targeted all the same.
        
           | petedoyle wrote:
           | If Apple were to add new APIs, it might be possible to use
           | personal cloud storage (NAS, Decentralized Web Nodes, etc.)
           | with the same UX as iCloud with E2EE.
        
             | zimpenfish wrote:
             | > it might be possible to use personal cloud storage [...]
             | with E2EE
             | 
             | Which would quickly become illegal if UKGOV is set on
             | getting access to people's iOS backups / cloud storage /
             | etc. Hell, it's already a legal requirement to hand over
             | your keys if UKGOV demands them[0].
             | 
             | [0] "Regulation of Investigatory Powers Act 2000 part III
             | (RIPA 3) gives the UK power to authorities to compel the
             | disclosure of encryption keys or decryption of encrypted
             | data by way of a Section 49 Notice." https://wiki.openright
             | sgroup.org/wiki/Regulation_of_Investig...
        
               | doublerabbit wrote:
               | I would be less pissed with this if the UK actually kept
               | the data to the UK.
        
               | timewizard wrote:
               | You'd be fine with _domestic surveillance_ as long as
               | it's kept within country? The average jurisprudence of a
               | UK citizen is mind blowing to me.
        
         | alecmuffett wrote:
         | OP here. I am sympathetic, really I am, but the challenge then
         | is a diversity of solutions tends to lack really good high
         | quality security systems integration, meaning that data leaks
         | differently. It's hard to have a high integrity solution which
         | is an open standard and implemented equally well by all
         | players.
        
           | bigyabai wrote:
           | I would rather that Apple invests in solving hard problems.
           | Spending that money on legal representation only kicks the
           | can down the road.
        
             | alecmuffett wrote:
             | One of the hardest problems you can face is getting a
             | community of disparate developers to do the right thing at
             | scale; sometimes the easiest solution for that is a
             | monolithic integrated blob.
        
               | bigyabai wrote:
               | I agree, that's why I applaud smart regulation. Apple is
               | a disparate business too, you have no way to bring them
               | to the table for doing "the right thing" unless there's
               | some threat of repercussions.
               | 
               | It's really easy for Apple to back themselves into a
               | vulnerable corner with the "ecosystem" mentality drawn
               | out to it's logical extremes. I'd argue it's our
               | democratic duty to stop businesses from endangering their
               | customers like that, but that really depends on how you
               | feel about consumer protections.
        
         | easytiger wrote:
         | The EU and the EUC are not your friend when it comes to privacy
         | 
         | https://home-affairs.ec.europa.eu/networks/high-level-group-...
        
           | bigyabai wrote:
           | Nor is the jurisdiction Apple is headquartered in:
           | https://arstechnica.com/tech-policy/2023/12/apple-admits-
           | to-...
           | 
           | It feels like a moot point, to me.
        
             | easytiger wrote:
             | How is an exploration of broad spectrum legislative attacks
             | on all forms of encryption regardless of hosting and
             | corporate ownership and data communication moot?
        
         | freehorse wrote:
         | > There would be no world where Apple could even threaten to
         | disable it.
         | 
         | They did not "threaten to disable it" and apple's stance on
         | E2EE is not the issue here, UK's stance is. UK essentially made
         | icloud E2EE by demanding apple to make a global backdoor into
         | it, and essentially thus forced them to disable it. It is not
         | disabled anywhere else in the world.
         | 
         | Essentially the UK (and other states) want somehow to have
         | their pie and eat it too, but that's just not possible.
        
           | doublerabbit wrote:
           | If UK is already doing this, then what's them from banning
           | all new iPhones? Some countries do.
        
             | mikestew wrote:
             | _then what 's them from banning all new iPhones?_
             | 
             | The torches and pitchforks that are soon to follow? You
             | might get away with that in oppressive "some countries",
             | but I just can't imagine it ending well in someplace like
             | the UK.
        
         | ziddoap wrote:
         | > _UK users would not be beholden to Apple for E2EE if their
         | clients had legitimate alternatives to the first-party iCloud
         | service._
         | 
         | Any sufficiently popular alternative would be subject to the
         | same issue: you can't backdoor encryption without making it
         | insecure.
         | 
         | > _There would be no world where Apple could even threaten to
         | disable it._
         | 
         | Your framing of this seems to blame Apple, and I don't
         | understand why.
        
         | jeroenhd wrote:
         | The UK demands a backdoor in the backups, so having an
         | alternative backup app isn't the solution here. All the
         | alternatives would just get forced into also adding backdoors,
         | or everyone working for the companies that provide alternatives
         | find themselves unable to ever enter the UK again.
         | 
         | That said, I do wish there were more backup solutions for
         | mobile platforms. Android has an API for this, but it's only
         | available to software signed with manufacturer keys. LineageOS
         | and various other custom ROMs use this to allow Seedvault
         | backups, but as a stock Android user I can only pick between
         | Google backups and no backups.
         | 
         | On the other hand, these backups do contain material you don't
         | necessarily want random apps to have access to. Seeing how
         | powerful stalkerware/"parental control" already is on Android,
         | I recognise that there are dangers that the general population
         | might not realise. Adding additional warnings and messages
         | about backups (even when the backups are made using
         | manufacturer software) would probably strike a balance, though.
        
       | mig39 wrote:
       | Man, you know you're the baddies when you have to have "secret
       | courts."
        
         | ndegruchy wrote:
         | Didn't realize he was _also_ talking about the US secret
         | courts. Sorry.
         | 
         | Uh...[1] yeah. Secret courts are the worst! Those British and
         | their secrets!
         | 
         | [1]:
         | https://en.wikipedia.org/wiki/United_States_Foreign_Intellig...
        
           | mig39 wrote:
           | Like I said, you know you're the baddies when you have to use
           | "secret courts."
        
           | abtinf wrote:
           | A charge of hypocrisy necessarily implies you agree with the
           | principle.
        
             | ndegruchy wrote:
             | I don't. I was merely pointing out the hypocrisy, not
             | understanding that he meant it as a blanket statement for
             | both/all countries with secret courts.
        
               | mig39 wrote:
               | I'm not American. But if my country had (or has) secret
               | courts, I'd think they were evil too.
        
         | crimsoneer wrote:
         | ... this is very silly. Sometimes the government needs to have
         | secret stuff, and that needs an oversight body... _and they
         | need to see the secret stuff_
        
           | timewizard wrote:
           | The oversight body is the legislature. The judiciary has no
           | ability to provide oversight. The judiciary cannot act on
           | it's own. It cannot conduct investigations. It can only act
           | on cases and motions within those cases. The two ideas you've
           | presented do not have anything to do with eachother.
        
           | paulddraper wrote:
           | Specific details, sure.
           | 
           | Locations of military assets, passcodes, officials' personal
           | details, etc.
           | 
           |  _But you cannot have a democracy without the people knowing
           | what their government is doing._
        
       | ChrisArchitect wrote:
       | Related:
       | 
       |  _Apple takes UK to court over 'backdoor' order_
       | 
       | https://news.ycombinator.com/item?id=43270079
        
       | rvz wrote:
       | Why would you want to live in the UK, especially under this
       | government?
       | 
       | Unless you want to enjoy a full surveillance state close to
       | China?
       | 
       | Even if you are running away from the US, you should just ignore
       | the UK as a destination at this point.
        
         | ajsnigrutin wrote:
         | Most people were born there and have nowhere to go.
         | 
         | The problem is, that it's spreading... EU already wants "AI" to
         | read our private messages, US and it's patriot act was not much
         | better (+ everything within wikileaks), etc.
        
       | bigfatkitten wrote:
       | https://archive.is/YZF6r
        
       | cs02rm0 wrote:
       | _So the question in my mind is: is the UK Government attempting
       | to cover-up its previous advocacy of ADP, by censoring this old
       | document?_
       | 
       | In a word, yes.
       | 
       | I'd be fascinated to know who in the hive mind decided to do it
       | though; I can't see someone too senior coming up with an http
       | redirect as the answer. I guess the scrub order came down the
       | chain and an automaton jumped into action.
        
         | mike-the-mikado wrote:
         | Perhaps they know that ADP security is broken. That would
         | justify both changing the recommendation and asking to read it.
        
       | st3fan wrote:
       | Lock Down Mode is for when you think your phone is compromised.
       | Not for enhanced encryption or even day to day use.
        
       ___________________________________________________________________
       (page generated 2025-03-05 23:00 UTC)