• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

UK demands access to Apple users' encrypted data

Status
Not open for further replies.

sram

[H]ard|Gawd
2FA
Joined
Jul 30, 2007
Messages
1,850
https://www.bbc.com/news/articles/c...2bb2ec04cf0e920bbd530d7e8f46b9b02f669f4b6c481

The UK's Home Office has reportedly served a Technical Capability Notice (TCN) under the Investigatory Powers Act (IPA) compelling Apple to give the government backdoor access to worldwide users' encrypted data in the company's cloud service. Although "under the law, the demand cannot be made public," and while the Home Office will neither confirm nor deny "any such notices," both the Washington Post, who first reported the news, and the BBC have spoken with anonymous "sources familiar with the matter." The alleged demand specifically targets Apple's end-to-end encrypted Advanced Data Protection (ADP) measures, and may apply in cases of national security risk, requiring a legal permission process to access the backdoor. Apple's history with similar cases and the company's prior statements show a pattern of opposing or refusing such demands. In the UK specifically, out of over 6,000 requests for iCloud data between 2020 and 2023, Apple complied only four times. Cybersecurity experts and privacy groups have expressed deep concern over the serious risks to users' security and privacy posed by breaking encryption with backdoors; the Electronic Frontier Foundation notes that "any 'backdoor' built for the government puts everyone at greater risk of hacking, identity theft, and fraud," and the UK's Big Brother Watch states that such a backdoor "will not make the UK safer, but it will erode the fundamental rights and civil liberties of the entire population."

https://click.email.sans.org/?qs=1e...df07fe5576ddb12b44fb78f789166d056f94c5b12a523

"It seems that the UK government and its advisors have not being paying attention to the recent Salt Typhoon attacks against US telcos where lawful intercept capabilities built into those networks were abused by hostile nation state actors to intercept traffic travelling over those networks. As I have said many times, "we can have strong encryption and accept that the cost will be its abuse by criminals while the internet is made more secure, or we can weaken encryption and accept that the cost will be its abuse by criminals while the internet is made insecure."

Remember Telegram?

What will Apple do??? I think they will just decline such a request!
 
access encrypted data stored by Apple users worldwide in its cloud service.
And withdrawing the product from the UK might not be enough to ensure compliance - the Investigatory Powers Act applies worldwide to any tech firm with a UK market, even if they are not based in Britain.


So they want to make illegal end to end encryption for cloud data worldwide, that or Apple (and all the other provider of such service) cannot sell anything in the UK I imagine would be the position of their government... feel like Apple will win that one. A bit like the French-euro zone and Telegram because they did not accept backdoors....
 
Last edited:
Some people are thinking Apple may not be able to stop this and will instead disable end to end encryption for Englishers.
 
Some people are thinking Apple may not be able to stop this and will instead disable end to end encryption for Englishers.
The new updated order is secret, but according to the bbc-washington post, the ask is worldwide users, so even doing this could be not enough, not sure how accurate the reporting is or an extreme interpretation pushed per Apple..:

Rather than break the security promises it made to its users everywhere, Apple is likely to stop offering encrypted storage in the U.K., the people said. Yet that concession would not fulfill the U.K. demand for backdoor access to the service in other countries, including the United States.
The law, known by critics as the Snoopers’ Charter, makes it a criminal offense to reveal that the government has even made such a demand ... Apple can appeal the U.K. capability notice to a secret technical panel, ... Apple would be barred from warning its users that its most advanced encryption no longer provided full security.
 
Last edited:
Likely has already happened and this is an attempt to measure the outrage factor without inciting massive reduction in sales and bankrupting Apple.
 
Bankrupting Apple.....the company that made over 100 billions of free cash flow in 2024 if they go back to 2021 cloud security.... chance are that very few Apple users use this. If you are not a Russian not for the regime type of customer, you probably do not care much or even know about this feature.

attempt to measure the outrage factor
By who ? it was "illegal" to talk about it from Apple, government do not want to talk about it and wanted it to "secret", it could Apple wanting to leak it to gain support to change the UK government mind
 
Last edited:
is there a link between reading data on an encrypted iCloud account with social media post ? like some way to find out the anonymous person behind the account ?
 
UK can just go FUCK themselves. First they wanna sell our Naval base on Diego Garcia now this shit. Maybe it's time for another war between US and those self righteous pricks.
 
Bankrupting Apple.....the company that made over 100 billions of free cash flow in 2024 if they go back to 2021 cloud security.... chance are that very few Apple users use this. If you are not a Russian not for the regime type of customer, you probably do not care much or even know about this feature.
FileVault (the encryption service) has been enabled by default since 2014, so if you’ve purchased an Apple device in the last decade then you are using it. It would be safer to say just about every Apple user is using it.

The average Apple user doesn’t really know about it because it’s just on, you have to spend time in looking how to turn it off, they first made it an optional thing in 2011, but you needed to enable it to use iCloud or iMessage.

How many Apple users do you know who don’t use iMessage??? So to comply with this Apple would need to go back to 2010 security.
 
Last edited:
FileVault (the encryption service) has been enabled by default since 2014, so if you’ve purchased an Apple device in the last decade then you are using it. It would be safer to say just about every Apple user is using it.
the article is extremely misleading then, they claim the thing they are talking about started in 2022 and users must opt-in (because if you are too loose your password access no one will ever be capable to access the file and lost forever, which is not usually what people want)

Wikipedia say the same:
https://en.wikipedia.org/wiki/Apple_ecosystem

Advanced Data Protection Program​

[edit]
Launched in December 2022,[14] Advanced Data Protection (ADP) is an Apple ecosystem setting that uses end-to-end encryption to ensure that the iCloud data types — messages, photos, notes, voice memos, wallet passes, and more — can only be decrypted on devices authorized by the user.

The instruction from apple does not make it like it is on by default or that it would interest the average user:
https://support.apple.com/en-ca/108756#:~:text=On iPhone or iPad,Turn on Advanced Data Protection.
Advanced Data Protection for iCloud is an optional setting that offers Apple’s highest level of cloud data security. If you choose to enable Advanced Data Protection, the majority of your iCloud data — including iCloud Backup, Photos, Notes, and more — is protected using end-to-end encryption. No one else can access your end-to-end encrypted data, not even Apple, and this data remains secure even in the case of a data breach in the cloud. Before you turn on Advanced Data Protection, you can learn more about how your data is protected with standard data protection and if you enable Advanced Data Protection.

You need to setup a recovery contact or a 28 character recovery key, I do not remember doing that, this is more do you think the Mossad, advanced team of NK hackers that infiltrated Apple or the government with a warrant in hand will look at your stuff because you are an high value target type of security.
 
Last edited:
Sounds like it is time to nuke the UK.
No need, according to every "migrant" that I've seen interviewed, the British people will be bred out of existence in 20 years.
With the way things are going, I don't think it is even going to take that long. :whistle:

Why, so they can arrest more people for sharing anti immigration posts!?
image0 (1).png


UK can just go FUCK themselves. First they wanna sell our Naval base on Diego Garcia now this shit. Maybe it's time for another war between US and those self righteous pricks.
You both beat me to the punch, the UK is the most fascist western nation on the planet, and they have no right to force a USA-based corporation to expose such personal data.
image0.png


We know how this will end. :D
image0 (2).png
 
Last edited:
the article is extremely misleading then, they claim the thing they are talking about started in 2022 and users must opt-in (because if you are too loose your password access no one will ever be capable to access the file and lost forever, which is not usually what people want)

Wikipedia say the same:
https://en.wikipedia.org/wiki/Apple_ecosystem

Advanced Data Protection Program​

[edit]
Launched in December 2022,[14] Advanced Data Protection (ADP) is an Apple ecosystem setting that uses end-to-end encryption to ensure that the iCloud data types — messages, photos, notes, voice memos, wallet passes, and more — can only be decrypted on devices authorized by the user.

The instruction from apple does not make it like it is on by default or that it would interest the average user:
https://support.apple.com/en-ca/108756#:~:text=On iPhone or iPad,Turn on Advanced Data Protection.
Advanced Data Protection for iCloud is an optional setting that offers Apple’s highest level of cloud data security. If you choose to enable Advanced Data Protection, the majority of your iCloud data — including iCloud Backup, Photos, Notes, and more — is protected using end-to-end encryption. No one else can access your end-to-end encrypted data, not even Apple, and this data remains secure even in the case of a data breach in the cloud. Before you turn on Advanced Data Protection, you can learn more about how your data is protected with standard data protection and if you enable Advanced Data Protection.

You need to setup a recovery contact or a 28 character recovery key, I do not remember doing that, this is more do you think the Mossad, advanced team of NK hackers that infiltrated Apple or the government with a warrant in hand will look at your stuff because you are an high value target type of security.
They made it available globally then, I didn’t realize it wasn’t available everywhere.
Some of the more advanced features they were showing off in 2018 with the A14 chips.

Maybe now that it’s available everywhere it’s gotten enough usage that it’s annoying.

I feel like this is one of those requests where they are talking about a handful of countries but they can’t say that they want this to look at those countries because it would be politically unfavourable to say it out loud.
 
Maybe now that it’s available everywhere
the instruction for it date of 2022 on apple website, Apple announced the new feature in 2022:
https://www.apple.com/newsroom/2022...-security-with-powerful-new-data-protections/
December 7, 2022
Now with iMessage Contact Key Verification, users who face extraordinary digital threats — such as journalists, human rights activists, and members of government — can choose to further verify that they are messaging only with the people they intend. ... For users who opt in,

In the past Apple refused goverment-police request because it was possible for them to not refuse and acquiesce to them and from time to time they did, with this it is impossible for Apple to do anything even if they would want to do so (and they cannot help you to restore your account if you loose your access for it, they are like anyone else without any special knowledge or ability to help you with this). Are you sure you are talking about the same thing, filevault is not even on apple cloud.... that local encryption... this for the iCloud storage.

if you did not actively opted-in or knew you could that would confirm my hunch that most user (outside government with good security clearance, journalist in rocky affair, Russian dissident, Hezbollah etc...) would not know or care about it much, in no way removing this would hurt Apple revenues. (With marketing term maybe it is just rebranding of previous offer, but that feel new)
 
Last edited:
the instruction for it date of 2022 on apple website, Apple announced the new feature in 2022:
https://www.apple.com/newsroom/2022...-security-with-powerful-new-data-protections/
December 7, 2022
Now with iMessage Contact Key Verification, users who face extraordinary digital threats — such as journalists, human rights activists, and members of government — can choose to further verify that they are messaging only with the people they intend. ... For users who opt in,

In the past Apple refused goverment-police request because it was possible for them to not refuse and acquiesce to them and from time to time they did, with this it is impossible for Apple to do anything even if they would want to do so. Are you sure you are talking about the same thing, filevault is not even on apple cloud.... that local encryption... this for the iCloud storage.

if you did not actively opted-in or knew you could that would confirm my hunch that most user (outside government with good security clearance, journalist in rocky affair, Russian dissident, Hezbollah etc...) would not know or care about it much, in no way removing this would hurt Apple revenues.
All of that is a fancy way of saying they now allow 3’rd party verification products, like a Yubikey for keychain and the rest instead of just the device.

Which I guess they could be extra pissy about because it wouldn’t be enough to have their phone and account but then need an extra key too.

But that had already been a function available in Apple Business Manager for years at that point.

Apple Big Announcement 101, take a thing they are already doing or others have been doing and rebrand it as something innovative and new.
 
Only a bit under 70 million people live in the UK. Not all of them are even Apple users. It's a valuable market to be sure, but it's a market that Apple can afford to just ignore if they want to. Besides, if people in the UK want iPhones, they will just cross the channel for them if Apple were to pull out of the UK.
 
Every country pulls this sort of crap ... yet people get more upset when it isn't their country. We should get equally upset across the board at this stuff. Whether it is China, the USA, or the UK ... nobody should get back doors.
 
sfsuphysics liked the post "How many Apple users do you know who don’t use iMessage??? So to comply with this Apple would need to go back to 2010 security."

More I wish...
 
Was I unclear? Their government has alienated their (native)population with laws that dictate language by imprisoning people who "incite racial violence" by voicing their disdain about terrible immigration policy on social media platforms. The first step towards totalitarianism. They are alienating America by selling our long standing Western Pacific Naval Base Diego Garcia (1971) and the only one that services our Pacific submarine fleet outside of the US. I may be a little uptight and let my anger speak out about their total bullshit foreign and domestic policy as of late but if your a resident of the UK do not be upset when the US turns their back on the UK if they ever face another situation like they did in 1940's. Better brush up on your German and/or Russian language skills.
 
Do you remember when [H]ardforum kept politics in General Mayhem? Pepperidge Farms does.

(1) Absolutely NO FLAMING, NAME CALLING OR PERSONAL ATTACKS, NO TROLLING. Mutual respect and civilized conversation is the required norm, this includes personal attacks in signatures. NO POLITICAL DISCUSSION OUTSIDE OF THE SOAPBOX SUBFORUM. http://hardforum.com/account/upgrades
 
Status
Not open for further replies.
Back
Top