Apple Launches Legal Challenge Against UK Demand To Access Encrypted User Data (theguardian.com) 28
An anonymous reader quotes a report from The Guardian: Apple has launched a new legal challenge against a UK government demand to access its customers' highly encrypted data, a year after the Home Office agreed to abandon its previous request. The US tech company launched the legal complaint last month at the Investigatory Powers Tribunal (IPT), an independent court that has the power to investigate claims that the UK intelligence services have acted unlawfully. The UK government had made a second request to Apple to grant it a "back door" to encrypted iCloud data belonging to British users, according to an order issued by the court.
Britain backed down on its original demand for access to data from UK and US customers last year, after a heated transatlantic tussle over encryption between London and Washington. UK authorities subsequently issued a new "technical capability notice" (TCN) to Apple that did not apply to American users. Apple is seeking to challenge the British government's powers to issue TCNs under the UK Investigatory Powers Act, according to the details of the new legal case first reported by the Financial Times. [...] The original TCN issued last year asked Apple for the right to see users' encrypted data protected by its advanced data protection (ADP) program in the event of a national security risk.
Apple said the removal of the tool -- which not even it can access -- would make users more vulnerable to data breaches from bad actors and other threats to customer privacy. Creating a "back door" would also mean all data was accessible by Apple, which it could be forced to share with law enforcement possessing a warrant. As a result, Apple withdrew UK customers' access to its ADP program in January 2025. The Home Office has maintained that the Investigatory Powers Act, under which such orders are issued, contains robust safeguards and is used only when absolutely necessary.
Britain backed down on its original demand for access to data from UK and US customers last year, after a heated transatlantic tussle over encryption between London and Washington. UK authorities subsequently issued a new "technical capability notice" (TCN) to Apple that did not apply to American users. Apple is seeking to challenge the British government's powers to issue TCNs under the UK Investigatory Powers Act, according to the details of the new legal case first reported by the Financial Times. [...] The original TCN issued last year asked Apple for the right to see users' encrypted data protected by its advanced data protection (ADP) program in the event of a national security risk.
Apple said the removal of the tool -- which not even it can access -- would make users more vulnerable to data breaches from bad actors and other threats to customer privacy. Creating a "back door" would also mean all data was accessible by Apple, which it could be forced to share with law enforcement possessing a warrant. As a result, Apple withdrew UK customers' access to its ADP program in January 2025. The Home Office has maintained that the Investigatory Powers Act, under which such orders are issued, contains robust safeguards and is used only when absolutely necessary.
Re: (Score:3)
That's what they're doing - they're storing your encryption key on your devices. That's why they can't access it, and nor can they give it to the UK government.
Re: (Score:1)
All problematic.
Re: (Score:2)
Or they'd make private cloud devices and not be in the position of handling the data or the encryption. Maybe they could offer an offsite backup service of encrypted data, but it would be just that: encrypted files that only the user has access to.
I still don't understand why we are relying on datacenters and services for storage, it just invites government overreach.
'Robust Safeguards' (Score:5, Informative)
Robust safeguards indeed.
Re: (Score:2)
And "selling pies" used to be a euphemism for prostitution. The English certainly have a way of using normal words in a convoluted manner.
Re: (Score:3)
Yes. Always the same crap. These people are simply telling any lie they can to get their panopticon. These are not good people.
Re:'Robust Safeguards' (Score:5, Insightful)
It doesn't matter. Making it possible to open a back door "at all" puts all users at risk, regardless of how rarely the government intends to use it.
There should be no back door at all, just a solid wall. Otherwise, criminals will find a way to open the back door even if there is no government abuse (which there for sure will be).
What legal challenge? (Score:2)
Re: What legal challenge? (Score:2)
Fuck that indeed, and Apple is clearly doing the right thing here on all levels, but they can't just give such a trivial response because this is a real court, not the court of public opinion...
Re: (Score:2)
Well, Apple *appears* to be doing the right things. This may be accurate, but don't feel too certain.
Re: (Score:2)
Well, Apple *appears* to be doing the right things. This may be accurate, but don't feel too certain.
What I'm certain about is that they're doing it for simple economic reasons, no one will trust them if they don't. I suppose they could be caving behind the scenes but the odds of getting caught eventually are high...
Re: (Score:2)
Do they want them to spin up the supercomputers and brute force the passwords?
Apple uses 256 bit AES from what I remember. Theoretically using a single computer, it would take 10^59 years to crack a single key. Using all world’s computers including supercomputers, it will be less but not meaningfully less.
I assume this is really about them putting in a backdoor of some sort. Yeah, fuck that.
Yes, UK government wants Apple to modify their entire encryption scheme so that Apple can grant the UK government access to user data anytime that government asks. Existing data is protected unless Apple is forced to replace existing keys.
Re: (Score:1)
What legal challenge? "We don't have the decryption keys - Sincerely, Apple" is about all they need to respond with. I assume this is really about them putting in a backdoor of some sort. Yeah, fuck that.
The first time the UK demanded access to all of apples customers, their response was three fold: they don't have the keys, they are not backdooring their customers, and the UK has no authority outside of the UK.
So the UK responded if they don't remove the local encryption features from UK phones, they would jail all apple executives in the UK.
So now new phones sold in the UK do not have 'advanced data protection', and those devices do not pre-encrypt data sent to icloud.
Apple said they don't want to needles
"Access Encrypted User Data" (Score:1)
They are welcome to access my encrypted data.
My decryption key, OTOH....
UK is the epitome of a police state (Score:1)
I'm a
End of End-to-End Encryption (Score:1)
Re: (Score:2)
So the UK is doing a great disservice to citizens of all countries, not just their own, by pushing on this.
They know what they are doing. The UK government has never believed in privacy rights. They know they're doing a disservice to everyone. They don't care.
And the only rational answer is to cut them off. No more iCloud storage for anyone residing in the UK. And for anyone else, immediate denial of access from the minute you set foot in that country to the minute you leave. This is the only reasonable option.
E2EE is really a dog and pony show, not real math, because the apps we install are all opaque and built by opaque build systems we inherently trust, whose vendors can insert a new backdoor any time they want.
And ultimately, this is the reason why Cloud storage shouldn't even exist. The minute you depend
Do they even listen? (Score:1)
Re: (Score:2)
There's a simple way to solve this.
Identify the individuals who are demanding it, and have them come up with the backdoor that they believe is secure.
Put out a test bed and invite the world's hackers to compromise it, with a large cash prize for the first one who does.
If no one does, it becomes mandatory.
If anyone does, the individuals demanding it (and anyone involved in creating it) are criminally responsible for conspiracy to commit any crimes that might have been committed, which will almost certainly i
Re: (Score:2)
The surveillance fascists will never listen. They deeply believe that all citizens need to be monitored at all times. These are really bad people that abhor all individual freedoms.
plithy saying (Score:2)
When encryption is outlawed, only the outlaws use encryption.
So ... (Score:3)
Re: (Score:2)
No. But Cornish, however...