Tech giant Apple will remove its highest level of data protection from customers in the UK following a Home Office demand for access.
The Home Office had issued an order asking for access to encrypted files stored in the cloud. In response, the tech giant has now confirmed it was removing a tool called Advanced Data Protection (ADP) from use in the UK, which had meant only account holders could view files as they were end-to-end encrypted.
American politicians have reacted with fury over the request, urging Washington to stop sharing sensitive intelligence with the UK.
Senator Ron Wyden and Congressman Andy Biggs have written to national intelligence director Tulsi Gabbard saying the demand threatens the privacy and security of the US.
They urged her to give the UK an ultimatum: “Back down from this dangerous attack on US cybersecurity, or face serious consequences.”
“While the UK has been a trusted ally, the US government must not permit what is effectively a foreign cyberattack waged through political means,” the US politicians wrote.
Dray Agha, senior manager of security operations at cybersecurity firm Huntress said: “Apple’s decision to pull Advanced Data Protection in the UK is a direct response to increasing Government demands for access to encrypted user data.
“Weakening encryption not only makes UK users more vulnerable to cyber threats but also sets a dangerous precedent for global privacy.
“Governments argue this helps law enforcement, but history shows that any backdoor created for one party can eventually be exploited by bad actors. The broader concern is that this move could pressure other companies to weaken their security, putting personal data worldwide at greater risk.”
In a statement, the tech giant said: “Apple can no longer offer Advanced Data Protection (ADP) in the United Kingdom to new users and current UK users will eventually need to disable this security feature. ADP protects iCloud data with end-to-end encryption, which means the data can only be decrypted by the user who owns it, and only on their trusted devices.
“We are gravely disappointed that the protections provided by ADP will not be available to our customers in the UK given the continuing rise of data breaches and other threats to customer privacy.
“Enhancing the security of cloud storage with end-to-end encryption is more urgent than ever before. Apple remains committed to offering our users the highest level of security for their personal data and are hopeful that we will be able to do so in the future in the United Kingdom.
“As we have said many times before, we have never built a backdoor or master key to any of our products or services and we never will.”
But some campaigners welcomed the move, saying it will give police more opportunities to snare paedophiles online.
Rani Govender, Policy Manager for Child Safety Online at the NSPCC, said: “We know that end-to-end encryption allows offenders to groom and manipulate children and build communities where they can share vile child sexual abuse material without detection.
“As Apple changes their approach to encryption on their services, they must take this opportunity to ensure that they are considering other measures they can put in place to better protect children.
“All tech companies should be finding ways to tackle online risks to children whilst upholding privacy of their users, and Ofcom and Government should hold them accountable for doing so.”

