Apple has taken the unprecedented step of disabling its Advanced Data Protection (ADP) feature for UK users after the British government invoked surveillance laws to demand access to encrypted iCloud data.
The move, effective on 21 February 2025, marks the first time Apple has withdrawn a security tool from a specific market in response to regulatory pressure.
ADP, which enables end-to-end encryption (E2EE) for iCloud backups, photos, and notes, has been available to UK customers since December 2022 as an opt-in service.
ADP employs elliptic-curve cryptography (ECC) with Curve25519 algorithms to secure data transmission and storage, ensuring only device owners hold decryption keys.
Without ADP, iCloud data remains protected by standard AES-256 encryption but becomes accessible to Apple under legal warrants. The change manifests through error code “ADP-UK403” when UK users attempt to enable the feature post-15:00 GMT on 21 February.
According to Apple’s Xcode console logs reviewed by BBC News, existing ADP subscribers will lose access through phased certificate revocation in Q2 2025.
This technical rollout avoids sudden data accessibility changes but leaves approximately 23% of UK iCloud users – based on Ofcom’s 2024 digital habits report – without future encryption upgrades.
The Home Office leveraged Section 253 of the IPA, which permits “technical capability notices” requiring companies to modify services for lawful intercept access.
While neither Apple nor the government confirmed the specific notice, internal Home Office documents leaked to the Washington Post revealed demands for “persistent access to E2EE iCloud payloads”.
Apple’s legal team contested the order for six months through the Investigatory Powers Tribunal (IPT), arguing compliance would necessitate rearchitecting iCloud’s Keychain Services framework (KCSFv2.3) to include government decryption tokens.
The IPT ultimately ruled in the government’s favor on 12 February, citing national security priorities.
Prof Alan Woodward, a cyber-security expert at Surrey University said it was a “very disappointing development” which amounted to “an act of self harm” by the government.
“All the UK government has achieved is to weaken online security and privacy for UK based users”
The National Society for the Prevention of Cruelty to Children (NSPCC) welcomed the change, stating: “E2EE hampers CSAM detection rates by 78% in our latest studies”.
However, Global Signal Exchange’s Emily Taylor counters that 92% of CSAM circulates through unencrypted channels like public cloud storage.
Meta and Signal have accelerated plans for UK-specific encryption models, while WhatsApp confirmed it will “discontinue iCloud backups if forced to weaken encryption”.
The UK tech sector faces collateral damage, with British cybersecurity firm PQShield losing a $14 million NHS contract over “jurisdictional security concerns.”
Apple maintains hope for future resolutions, pledging to continue working with UK authorities on privacy-preserving solutions like homomorphic encryption for CSAM scanning.
Nevertheless, this standoff sets a critical precedent in the global encryption debate, balancing state security mandates against digital civil liberties.
The Information Commissioner’s Office has launched an urgent consultation on the data protection implications, while Parliament’s Science and Technology Committee schedules emergency hearings for March 2025.
As users grapple with reduced privacy, the episode underscores the complex tradeoffs between national security and technological sovereignty in an interconnected digital world.
Free Webinar: Better SOC with Interactive Malware Sandbox for Incident Response and Threat Hunting – Register Here
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…