‹ BackHN Continuity

Thread

Two-tier encryption in the UK

512 points · 472 comments · ReturnoftheHack

  1. palmotea · · focus · HN ↗
    > Faced with a legal order that would have required it to change the security architecture on which ADP depended, Apple found a third option: stop offering the feature that made this dilemma exist in the first place. It reverted affected UK iCloud data to Standard Data Protection, where Apple does hold the keys and can respond to lawful legal procress (except the baseline categories that stay end-to-end encrypted either way). This satisfied the underlying legal requirement without ever building a ‘backdoor’.

    Maybe Apple should withdraw all encryption support from all UK government accounts? The Prime Minister can use a Huawei or some chunky thing from a military contractor.

    1. Obscurity4340 · · focus · HN ↗
      How are they allowed to even offer e2ee Keychain/iCloud Passwords for example? Isnt that subject to lawful access too?
      1. 0cf8612b2e1e · · focus · HN ↗
        Exactly my question as well.

        Especially since big tech is steaming ahead to mandating passkeys that only they are allowed to control/backup. Not long until all governments could intercept your passwords to all services.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.