43 ms·
Too right, it was far more problematic than they ever made out. > The UK government's demand came through a "technical capability notice" under the Investigato
by bArray 2y ago
Too right, it was far more problematic than they ever made out.
> The UK government's demand came through a "technical capability notice" under the Investigatory Powers Act (IPA), requiring Apple to create a backdoor that would allow British security officials to access encrypted user data globally. The order would have compromised Apple's Advanced Data Protection feature, which provides end-to-end encryption for iCloud data including Photos, Notes, Messages backups, and device backups.
One scenario would be somebody in an airport and security officials are searching your device under the Counter Terrorism Act (where you don't even have the right to legal advice, or the right to remain silent). You maybe a British person, but you could also be a foreign person moving through the airport. There's no time limit on when you may be searched, so all people who ever travelled through British territory could be searched by officials.
Let that sink in for a moment. We're talking about the largest back door I've ever heard of.
What concerns me more is that Apple is the only company audibly making a stand. I have an Android device beside me that regularly asks me to back my device up to the cloud (and make it difficult to opt out), you think Google didn't already sign up to this? You think Microsoft didn't?
Then think for a moment that most 2FA directly goes via a large tech company or to your mobile. We're just outright handing over the keys to all of our accounts. Your accounts have never been less protected. The battle is being lost for privacy and security.
- SoftTalker 2y agoYour smartphone cannot be considered a private device. You as the owner don’t have sufficient control over its operating system and applications to ever make that claim.
- bArray 2y agoIn theory you have the likes of the PinePhone where you can run a full Linux kernel [1]. You could then use something like Waydroid to run Android apps [2]. I think the biggest concern is that many of the important apps are anti-emulation, for example banking apps and authentication apps. [1] https://pine64.org/devices/pinephone_pro/ https://pine64.org/devices/pinephone_pro/ [2] https://waydro.id/ https://waydro.id/
- prmoustache 2y ago> What concerns me more is that Apple is the only company audibly making a stand. Dropping the functionality for a particular market hardly equals to making a stand. Sure they haven't added a backdoor that would give all user's data access to UK icloud user's data so in the end UK residents didn't win anything. And who knows if they simply have an agreement with US gov to have a backdoor only available to them and not the other govs.
- neop1x 2y agoFor photos, it's probably best to use an open-source (also self-hostable) service like Ente. For files it's best to self-host Nextcloud or similar. And rely on other people's computers as little as possible. Sadly, operating systems are very complex and mostly composed of proprietary blobs nowadays so there is still a risk of it leaking data but people can still do at least something.
- sameermanek 2y agoFeels like marvel was onto something with captain america and winter soldier.
- pplante 2y agoLife is imitating too many dystopian books, movies, etc these days. I think we need to put an end to all creative works before the timeline becomes irrecoverably destroyed.
- ekm2 2y agoBanning art?
- immibis 2y agoBurning books, more specifically. Can't be a dystopia if nobody knows what the word "dystopia" means *taps forehead*
- Arubis 2y agoI suspect you’re being flippant, but destruction of and restrictions on creative works as an _antidote_ to dystopia is a take I haven’t seen before.
- pplante 2y agoYes, I am being very flippant. Sometimes we need to jest in order to digest reality.
- dingdingdang 2y agoThe /s is strong with this one.
- dmonitor 2y agoThe real prescient threat in that movie was the predictive AI algorithm that tracked individual behaviors and identified potential threats to the regime. In the movie they had a big airship with guns that would kill them on sight, but a more realistic threat is the AI deciding to feed them individualized propaganda to curtail their behavior. This is the villain's plot in Metal Gear Solid 2, which is another great story. This got me thinking about MGS2 again and rewatching the colonel's dialogue at the end of the game: https://www.youtube.com/watch?v=eKl6WjfDqYA https://www.youtube.com/watch?v=eKl6WjfDqYA > Your persona, experiences, triumphs, and defeats are nothing but byproducts. The real objective was ensuring that we could generate and manipulate them. It's really brilliant to use a video game to deliver the message of the effectiveness of propaganda. 'Game design' as a concept is just about manipulation and hijacking dopamine responses. I don't think another medium can as effectively demonstrate how systems can manipulate people's behavior.
- nottorp 2y ago> have an Android device beside me that regularly asks me to back my device up to the cloud But is that backup encrypted? If it's not, all they need is <whatever piece of paper a british security official needs, if any> to access your data. This is about having access to backups that are theoretically encrypted with a key Apple doesn't have? > We're talking about the largest back door I've ever heard of. Doesn't the US have access to all the data of non US citizens whose data is stored in the US without any oversight?
- burnerthrow008 2y ago> Doesn't the US have access to all the data of non US citizens whose data is stored in the US without any oversight? Er, no...? I'm not sure where you get that idea. Access requires a warrant, and companies are not compelled to build systems which enable them to decrypt all data covered by the warrant. See, for example, the Las Vegas shooter case, where Apple refused to create an iOS build that would bypass iCloud security.
- nottorp 2y agoI asked if your Android backup is encrypted. Implies I'm talking about unencrypted data. > See, for example, the Las Vegas shooter case I am not in Las Vegas or anywhere else in the US. So as far as i know all the data about me that is stored in the US is easily accessible without a warrant unless it's encrypted with a key that's not available with the storage. > companies are not compelled to build systems which enable them to decrypt all data covered by the warrant Again, not what I was talking about. I'm merely pointing out that your data is not necessarily encrypted, and that the "rest of the world" was already unprotected vs at least one state. The UK joining in would just add another.
- grahamj 2y agoThis is why, while I applaud what Apple is doing here, they need to allow us to supply our own E2E encryption keys.
- shuckles 2y agoThat’s literally what the feature they’re removing did.
- kbolino 2y agoNot exactly. It generates the keys for you and stores them on device in the Secure Enclave. You cannot "bring your own" encryption key, but the primary benefit of doing so--that Apple does not have access to it--is intentionally accomplished anyway by the implementation.
- shuckles 2y agoI’m not sure I appreciate the value of literally bringing your own keys. My device generating them on my behalf as part of a setup process seems sufficient. You’d use openssl or something and defer to software to actually do keygen no matter what.
- grahamj 2y agoIt depends what kind of backdoor the UK is asking for but "encryption backdoor" sounds like cryptographic compromise. I don't know if that's what it means but either way the only way to be sure your keys are secure is to generate them yourself.
- kbolino 2y agoBYOK does not provide any additional security over the Secure Enclave (and similar security coprocessors). In fact, unless the Secure Enclave were to directly accept your input and bypass the OS, BYOK is worse because the software can just upload your key to a server as soon as you type it in. Whereas, a key generated on the Secure Enclave stays there, because there exists no operation to export it.
- IshKebab 2y ago> What concerns me more is that Apple is the only company audibly making a stand. Meta also said they would make a stand if a similar request comes for WhatsApp. I'm not going to hold my breath though.
- AutistiCoder 2y agoThey wouldn't even be able to. WA is end-to-end encrypted.
- figmert 2y agoIt's all lip service, because the UK Govt wouldn't ask them that. WhatsApp messages are EE2E. They probably already handover all the metadata surrounding those messages.
- alex-robbins 2y agoWhatsApp is closed source. They could backdoor it if they wanted to (or were forced to).
- AutistiCoder 2y agosure, but a) that would involve changing the code base b) more privacy minded users would just delete the messages or not update.
- bitpush 2y agoAnd so in Apple and iOS. What is your point?
- IshKebab 2y agoHis point was that it is technically possible for WhatsApp to add a backdoor. Apple could too.
- kali_00 2y agoWith almost everyones backups stored in plain-text, making it all a little silly. Think about it for a second: you can re-establish your WA account on a new device using only the SIM card from your old device. SIM cards don't have a storage area for random applications' encryption keys, and even if they did, a SIM card cannot count as "end-to-end" anymore. Same goes for whatever mobile cloud platform those backups might be stored on. And you'd hope Apple or Google aren't happily sending off your cloud decryption keys to any app that wants them. Though maybe they are?
- j-bos 2y ago> (where you don't even have the right to legal advice, or the right to remain silent) A lot is posted about LEO's lying in the US, this seems worse.
- dustingetz 2y agohow much distance between 1) tech monopoly strong enough to stand up to G7 nation state demands 2) tech monopoly strong enough to remove itself from G7 nation state jurisdiction? edit: s/monopoly/empire, apologies
- r00fus 2y agoIt's amusing to think of Apple as a "monopoly" (if anything they have a monopsony on TSMC production) but let's just replace that with "giant" for purposes of discussion. Tech giants typically devolve local operations to small companies to avoid liability - think petroleum suppliers not owning gas stations (because those typically end up as superfund sites). Not sure if this analogy this works for Google Android and all the manufacturers that deploy it for their smartphones too. So corporations have been doing this forever, trying to find legal loopholes where they can have their cake and eat it too.
- nobankai 2y ago[flagged]
- stalfosknight 2y agoApple is not a monopoly.
- deleted 2y ago[deleted]
- fdb345 2y agoYour Android and Microsoft backup aren't encrypted. They are already fair game for a warrant.
- Krasnol 2y agoIt's always hilarious to see how far people here are ready to go to twist some bad Apple news into something which might be considered good. I mean seriously. Apple making a stand? What stand? They are ripping security out of their customers hands. Customers which are already dependent on the company's decision in their locked in environment. There is absolutely nothing good about it, and you dragging Android into it and making it look like it's even worse is suspicious. You can have full control over your Android device. Something impossible on an Apple phone. You can make your Android device safer than your iPhone.
- amatecha 2y agoThere is an upside (if you trust them) -- they're pulling a feature rather than adding a back door to it. Supposedly, anyway.
- Krasnol 2y agoWell, sure it could be worse. Doesn't make that one good, though.
- yunwal 2y agoThe government forced them to pull the feature. Would you rather they left a toggle-switch that doesn't actually do anything? Or are you thinking they should just pull out of the EU altogether?
- Krasnol 2y agoMaking a stand would be leaving UK (UK is not in the EU) altogether. This is almost as bad as building a backdoor. This is leaving your customer in the rain. Fortunately for Apple, most of them won't even know or realize it.
- yunwal 2y ago> This is leaving your customer in the rain. vs. taking their phone away??? Idk if you're trolling or what but I would be incredibly pissed at Apple if they deprecated my phone over something like this.
- troupo 2y ago> What concerns me more is that Apple is the only company audibly making a stand. They are not making a stand. They roll over without a peep. And this is concerning users' privacy which they say is the core of the company. Compare it to fighting every government tooth and nail over every single little thing concerning the "we don't know if it's profitable and we don't keep meeting records" AppStore
- immibis 2y ago"Not making a stand" would be leaving everything as is, and handing your encryption keys over to the government. By loudly disabling ADP and saying this feature is illegal in the UK (they really should have said "illegal" instead of "unavailable" so people would know it was the government), they are at least making half a stand. By leaving it enabled in other regions and for visitors from other regions to the UK, they're making three quarters of a stand.
- troupo 2y ago> By loudly disabling ADP and saying this feature is illegal in the UK They didn't say anything loudly, or said it was illegal in the UK. All they had was a single comment to a single (or perhaps a handful at most) comment to a media outlet that they disabled it. They didn't even bother with a press release, or notify their users. It's not even half a stand. It's a rollover
- exodust 2y agoIs the UK law broadly against encrypted files? For example if I encrypt a file locally, a zip file containing images, am I not permitted to upload that zip file to a cloud service in the UK? Even if the UK's demands were "access to encrypted cloud services", does that also mean encrypted files within encrypted storage? It all seems so messy. Anyone who really wants to hide their files, can do so regardless of demands for backdoors.
- troupo 2y ago
- alt227 2y ago> Apple is the only company audibly making a stand Apples stand is false, they take with one hand and give with the other. There have been many times that Apple have been caught giving user data to governments at their request, lied about it, then later on admitted it once it had leaked from another source. This whole 'we will never make a backdoor' is a complete whitewash marketing stunt, why do they need to make a backdoor when they are providing any and all metadata to any government on request. https://www.macrumors.com/2023/12/06/apple-governments-surveil-push-notifications/ https://www.macrumors.com/2023/12/06/apple-governments-surve...
- jonhohle 2y agoI think that’s the whole point of their push to E2E encrypt as much as possible. Saying they can’t unencrypted something worked for a while.
- lilyball 2y ago> There have been many times that Apple have been caught giving user data to governments at their request, lied about it, then later on admitted it once it had leaked from another source. In other words, Apple complies with legal government orders, as they are required to. The government can compel them with a warrant to hand over data that they have, and can prohibit them from talking about it. That's the whole reason for the push towards end-to-end encryption and for not collecting any data Apple doesn't need to operate the products. This also ties into things like photo landmark identification, where Apple designed it such that they don't get any information about the requests and so they don't have any information that they could be compelled to hand to the government.
- tholdem 2y ago> What concerns me more is that Apple is the only company audibly making a stand. But still Apple operates in China and Google does not. This is weird to me. Google left China when the government wanted all keys to the citizens data. Apple is making a stand when it's visible and does not threaten their business too much. Apple is not really in the business of protecting your data, they are just good at marketing and keeping their image.
- timewizard 2y agoI want to buy my phone from a phone manufacturer. I want to backup my data with a managed service. I do NOT want these to be the same company. The government, with anti trust laws, could easily force this issue. On the other hand, they really love how few places they have to go with FISA warrants to just take anyones data. This is the long tail of the American security state. So it's really ironic that China takes most of the blame.
- dclowd9901 2y agoPerhaps Apple has a greater leverage in China due to its outsized manufacturing presence. And it's likely they already dont offer ADP to Chinese citizens.
- bitpush 2y agolol you think Apple has more leverage than China? What world are you living in?
- raincole 2y agoA world where HN commentators can read English.
- SXX 2y ago> And it's likely they already dont offer ADP to Chinese citizens. AFAIK before UK only region with ADP was China.
- vineyardmike 2y ago
- JumpCrisscross 2y ago> One scenario would be somebody in an airport and security officials are searching your device No Heathrow connection necessary. “The law has extraterritorial powers, meaning UK law enforcement would have been able to access the encrypted iCloud data of Apple customers anywhere in the world, including in the US” [1]. [1] https://www.ft.com/content/bc20274f-f352-457c-8f86-32c6d4df8b92 https://www.ft.com/content/bc20274f-f352-457c-8f86-32c6d4df8...
- kimixa 2y agoThe US claims the same https://en.wikipedia.org/wiki/CLOUD_Act https://en.wikipedia.org/wiki/CLOUD_Act Lots of Americans in this thread seem to be talking down to other countries laws while being completely unaware of their own
- maeil 2y agoSpot on, 727 comments, most probably by Americans, and only 2 (including yours) bringing up the CLOUD Act, the much worse US equivalent. Incredible ignorance.
- bustling-noose 2y agoProviding encrypted data and not providing encryption are two different things. The CLOUD act requires you to hand over data. It could be encrypted. The UK government is asking to hand over data that is also not encrypted. The two are not the same. Note : Not American.
- Fnoord 2y ago> There's no time limit on when you may be searched, so all people who ever travelled through British territory could be searched by officials. > Let that sink in for a moment. We're talking about the largest back door I've ever heard of. Codename 'Krasnov' is the largest backdoor I have ever heard of. And, we only need to look at his behavior. These E2EE from USA can be tainted in so many ways, and FAMAG sits on so much data, that codename 'Krasnov' can abuse such to target whoever he wants in West. Because everyone you know is or has been in ecosystem of Apple, Google, or Microsoft. Whataboutism! Fair. From my PoV, as European, the UK government is (still) one of the good guys who will protect Europe from adversaries such as those who pwn codename 'Krasnov'. Such protection may come with a huge price.
- martin_a 2y ago> We're talking about the largest back door I've ever heard of. Meh, I don't know. I can still decide to not go the UK and be fine. I think the CLOUD Act is much worse because it's independent from where I am.
- h4ck_th3_pl4n3t 2y agoRemember that the last fiasco was related to 2FA stores being stored unencrypted on google's backup cloud, namely google authenticator. And yes, it's still pwnable this way, and happens regularly. Everything in the cloud is not yours anymore, and you should always treat it like that.
- marcprux 2y ago> you think Google didn't already sign up to this? My understanding is that Android's Google Drive backup has had an E2E encryption option for many years (they blogged about it at https://security.googleblog.com/2018/10/google-and-android-have-your-back-by.html https://security.googleblog.com/2018/10/google-and-android-h...), and that the key is only stored locally in the Titan Security Module. If they are complying with the IPA, wouldn't that mean that they must build a mechanism into Android to exfiltrate the key? And wouldn't this breach be discoverable by security research, which tends to be much simpler on Android than it is on iOS?
- deleted 2y ago[deleted]
- nomel 2y agoMy assumption is that Google has keys to everything in its kingdom [1]. [1] https://qz.com/1145669/googles-true-origin-partly-lies-in-cia-and-nsa-research-grants-for-mass-surveillance https://qz.com/1145669/googles-true-origin-partly-lies-in-ci...
- tim333 2y agoI doubt it. Much to my annoyance they moved Google Maps Timeline from their database to an encrypted copy on my phone specifically so if law enforcement asks for the records of where you were at a given time and place they can say dunno, can't tell. If they had the keys it would wreck their legal strategy not to get hassled every time law enforcement are trying to track someone.
- marcprux 2y ago> My assumption is that Google has keys to everything in its kingdom If that were true, then their claims to support E2E encrypted backups are simply false, and they would have been subject to warrants to unlock backups, just like Apple had been until they implemented their "Advanced Data Protection" in 2022. Wouldn't there have been be some evidence of that in the past 7 years, either through security research, or through convictions that hinged on information that was gotten from a supposedly E2E-protected backup?
- selfmodruntime 2y agoEven more shocking that Germany - my country - leads the leaderboard with over ten times as much requests as the second place.
- zahllos 2y agoI don't really understand your comment to be honest. Section 3 of the Regulation of Regulatory Powers Act 2000 allows for compelled key disclosure (disclosure of the information sought instead of the key is also possible). Schedule 7 of the Counter-Terrorism Act allows 9 hour detention, questioning and device search at the border. With these powers it isn't necessary to get access to iCloud backups, as you can get the device and/or the data. I don't think the e2e icloud backup is problematic under existing legislation / before the TCN. While you can't disclose the key because it lives in the secure enclave, you can disclose the information that is requested because you can log into your apple account and retrieve it. IANAL, but I believe this to be sufficient (and refusing would mean jail). The Investigatory Powers Act allows for technical capability notices, and the TCN in this case says (as far as we know) "allow us a method to be able to get the contents of any iCloud backup that is protected by E2EE for any user worldwide". This means that there is no need to ask the target to disclose information and if implemented as asked, also means that any user worldwide could be a target of the order, even if they'd never been to the UK. Relevant info: - https://wiki.openrightsgroup.org/wiki/Regulation_of_Investigatory_Powers_Act_2000/Part_III https://wiki.openrightsgroup.org/wiki/Regulation_of_Investig...
- Aloisius 2y agoI imagine they want the ability to look at someone's iCloud backups without notifying the owner that they are doing so or they want to do it when the owner is unwilling or unable to provide keys. For the latter, there are a lot of cases where jail isn't much a threat (e.g. the person is dead or not in the country).
- zahllos 2y agoAlso given automatic iPhone backup it might contain information they want as part of an investigation that they'd otherwise have to demand key disclosure for (if cloud backup didn't exist)... Absolutely. The jail time for failure to comply with key disclosure is 2 years unless it is national security, then it is 5. But if you're organised crime and facing who knows what for being a snitch it might be better simply to do the time. I can see why they want it. I just don't understand why the person I'm replying to said the feature (I think) was problematic. Not really a criticism, I'm just struggling to identify the tone and why 'too right' and 'more problematic than they let on'.
- endgame 2y ago"technical capability notice" under the Investigatory Powers Act (IPA) Sounds a lot like the godawful "assistance and access" laws that were rushed through in Australia a couple of years ago, right down to the name of the secret instrument sent to the entity who gets forced into to building the intercept capability. Now that Apple has caved once, I expect to see other providers strongarmed in the same way, as well as the same move tried in other countries.
- osigurdson 2y agoWhat is going on in the UK? How do they stand for this?
- nomdep 2y agoWhen “misinformation” or “hate speech” are illegal, and the government decides what those are, you cannot risk complaining
- vixen99 2y agoIrrespective of political leanings, a lot of British people are saying this. They stand for it because they have to. It's a government that was voted in by a large margin only six months ago. Disquiet, if that's the word, is pretty much universal and I am not sure we've been quite in this position before. Keir Starmer's decline in approval ratings 'marks the most substantial post-election fall for any British prime minister in recent history'. https://politicalpulse.net/uk-polls/keir-starmer-approval-rating/ https://politicalpulse.net/uk-polls/keir-starmer-approval-ra...
- JansjoFromIkea 2y agoBy a large margin with their seat count doubling off a 1.6% swing in their favour. The decline in approval ratings should have been entirely predictable to them.
- jamiek88 2y agoThis is a law enacted by the previous government.
- osigurdson 2y agoDid Starmer run on this big brother type platform?
- firecall 2y agoAlso, I wondered if by complying with British law that they may somehow be breaking laws of another country? Hypothetically, if Apple just provide a back door to the data they have on US Senators for instance, then providing that information may be considered treason by the US. That's a totally made up example, and I have no idea, but it seems like it's possibly an issue. Which is all about the issues around data sovereignty I suppose!
- Zamiel_Snawley 2y agoThat would not be treason, by a long shot. Treason is the only crime defined in the constitution, and it is quite a high bar.
- Spooky23 2y agoThe king is a strict constitutionalist, who may disagree with you/ Pray he doesn’t.
- thaumasiotes 2y ago> Treason is the only crime defined in the constitution, and it is quite a high bar. Well, it's defined, or bounded above, in the constitution. It's not exactly a high bar: > Treason against the United States, shall consist only in levying War against them, or in adhering to their Enemies, giving them Aid and Comfort. So, if you happened to know Nicolas Maduro, thought he was looking stressed, and bought him some food, that would qualify as treason. There's no requirement that you act against the interests of the United States. The constitution will stop you from being prosecuted for treason for sleeping with Melania Trump. It won't stop you from being prosecuted for treason for completely spurious reasons.
- Zamiel_Snawley 2y agoNo. The Supreme Court has laid out well defined meanings for all the components of that phrase[0], and it is quite a high bar. [0] https://constitution.findlaw.com/article3/annotation24.html https://constitution.findlaw.com/article3/annotation24.html
- bustling-noose 2y agoYou have no laws when traveling through immigration. Thats true in US too. There was an article (trying to look for it could be arstechnica verge I dont remember where) once where a US citizen journalist was detained at the border for hours while traveling into the US and questioned. You can be in the immigration for hours or even decades until you give out what they demand which can involve your unlocked phone and password. There are no laws protecting you.
- dunham 2y ago> the largest back door I've ever heard of. Do you know of the clipper chip? https://en.wikipedia.org/wiki/Clipper_chip https://en.wikipedia.org/wiki/Clipper_chip From what I recall, we were only spared from it by someone hacking it before it was deployed.
- bboygravity 2y agoAnd now imagine for a second that the only thing the UK is doing here is getting the same direct access that the US (NSA) has already had for decades.
- HenryBemis 2y agoWhat I fund 'amusing' is the swap between Left vs Right. 'Back in the day' it was the "Right" that wanted have total access/total control over everything. So people turned a bit "left". Now the "Left" government is seeking totalitarian-style control ('because paedophiles/drugs/etc.). As a reminder, both Right and Left extremes went from 'liberal/conservatives' to "we don't need elections ever again - trust me!". I saw this happening in the US, in Saudi (e.g. Blackberry 'keys'). Now I see it in the UK. So I interpret this in two ways: 1) The "Left is the new Right" (or "Right is the new Left") 2) Left and Right are irrelevant terms when it comes down to "we need to exert control over people/knowledge/data/information/etc. And the 'guise' of Left/Right is just on the fiscal policies. So UK has been playing around with 'snooper charter' but at 'that' time Apple's encryption was not on the table. Apple (I don't blame them - very much - just a little) does what a company does. Makes money. And they prefer to sell-out the data of their clients and keep their money, than lose that money. So... yeah.. if your data is in someone else's server, that happens.
- bArray 2y agoIf you go too far right or left, both types of authoritarianism are difficult to distinguish. I think this just makes the case that every election you need to be a swing voter, make sure your politicians still overlap with your ideals. Apple today appear to be on the 'correct side of history', but even then you need to be swing consumer.
- sib 2y ago>> 'Back in the day' it was the "Right" that wanted have total access/total control over everything. It was the Clinton administration that pushed for the Clipper chip. Are you talking about a 'day' before that time?
- abalone 2y ago> One scenario would be somebody in an airport and security officials are searching your device under the Counter Terrorism Act No, it's much broader than that. The UK is asking for a backdoor to your data and backups in the cloud, not on your device. Why bother with searching physical devices when they can just issue a secret subpoena to any account they want? It's actually pretty amazing that Apple made ADP possible for the general public. This is the culmination of a major breakthrough in privacy architecture about ten years ago. Traditionally you had to make a choice between end-to-end encryption and data recoverability. If you went with E2EE, it's only useful if you use a strong password, but if you forget it then Apple can't help you recover your account (no password reset possible). So that was totally unsuitable for precious memories like photos for the average user. Apple's first attempt to make this feasible was a recovery key that you print out and stuff in a drawer somewhere. But you might lose this. The trusted contact feature is also not totally reliable either, because chances are it's your spouse and they might also lose their device at that same time as you (for example in a house fire). So while recovery keys and trusted contacts help, the solution that really made the breakthrough for ADP was iCloud Keychain Backup. This thing is low-key so cool and kind of rips up the previous assumptions about E2EE. iCloud Keychain Backup makes it possible to recover your data with a simple, weak 6 digit passcode that you are virtually guaranteed never to forget, yet you are also protected from brute force attacks on the server. It is specifically designed to work on "adversarial clouds" that are being actively attacked. This is... sort of not supposed to be possible in the traditional thinking. But they added something called hardware security modules to limit the number of guesses an attacker can make before it wipes your key. And crucially it ensures you don't forget this passcode because it's your device passcode which the OS keeps in sync with the backup key. This is part of the reason your iPhone asks you to enter your passcode now and then even though your biometrics work just fine. It is a true secret that only you know and can keep in your brain even when your house burns down and nobody (hopefully) can derive from something they can research about you. This didn't really exist for the general populace until smartphones came along. And that ultimately was the breakthrough that allowed for changing the conventional wisdom on E2EE. iCloud Keychain Backup came out about a decade ago and it has taken this long to gradually test the feasibility of going 100% E2EE without significantly risking customer data loss. The UK is kind of panicking but when people see how well ADP protects their most personal data from breaches, I think they will demand it. It just wasn't practical before.