Apple removes advanced security tool over UK government row | Science, Climate & Tech News
Apple will no longer offer customers in the UK its most advanced, end-to-end security encryption feature for cloud data – following a security row with the government.
The Advanced Data Protection (ADP) tool is an optional feature which means only account holders can see things like photos or documents that they have stored online. Apple itself does not have access to the data.
However, the UK government reportedly requested the right to see the data earlier this month.
In response, Apple has removed the tool from use in the UK.
The company is switching it off as an option for those not already using it, and will introduce a process to move existing users away from it.
Security officials argue that encryption hinders criminal investigations, while tech firms defend it as essential to user privacy.
The loss of end-to-end encryption for iCloud backup means Apple would be able in some instances to read user data such as iMessages that would otherwise be protected and pass it on to authorities if legally compelled.
However, if a user has end-to-end encryption, Apple cannot read the data under any circumstances.
What has Apple said?
“We are gravely disappointed that the protections provided by ADP will not be available to our customers in the UK given the continuing rise of data breaches and other threats to customer privacy,” Apple said in a statement.
“Enhancing the security of cloud storage with end-to-end encryption is more urgent than ever before.
“Apple remains committed to offering our users the highest level of security for their personal data and are hopeful that we will be able to do so in the future in the United Kingdom.”
Apple customers who already had the data protection tool turned on “will eventually need to disable this security feature”, said the company.
It is already unavailable for customers who weren’t using the feature, who now see a message reading: “Apple can no longer offer Advanced Data Protection (ADP) in the United Kingdom to new users.”
What has the UK government said?
The government said it will not confirm or deny whether it requested a Technical Capability Notice (TCN), which is what would give it the right to see the encrypted data.
“We do not comment on operational matters, including for example confirming or denying the existence of any such notices,” a Home Office spokesperson told Sky News.
According to a Home Office source, however, even if a TCN was issued, it wouldn’t give the government blanket access to people’s data.
Separate authorisations or warrants would still be required.