Apple says most iCloud data can now be end-to-end encrypted

7 December 2022, 22:24

Apple’s iPhone
Apple’s iPhone to be unveiled. Picture: PA

The loophole that law enforcement had for getting at iPhone data will now be considerably narrowed.

Apple has said it will now offer full end-to-encryption for nearly all the data its users store in its global cloud-based storage system, which will make it more difficult for hackers, spies and law enforcement agencies to access sensitive user information.

The world’s most valuable company has long placed customer security and privacy at a premium. Its iMessage and Facetime communications services are fully encrypted end-to-end and it has sometimes locked horns with law enforcement agencies including the FBI over its refusal to unlock devices.

But nearly everything that customers backed up remotely using Apple’s iCloud service — including photos, videos and chats — has not been protected by encryption. That made it far easier for crooks, spies — and criminal investigators with court orders — to get at it.

The loophole that law enforcement had for getting at iPhone data will now be considerably narrowed.

Cybersecurity experts have long argued that attempts by law enforcement to weaken encryption with back doors are ill-advised because they would inherently make the internet less reliable and more dangerous.

Last year, Apple announced, then withdrew after a flood of objections, a plan to scan iPhones for photos of child sexual abuse.

“Where Apple was hesitant about deploying encryption features last year… it now feels like they’ve decided to put the gas pedal down,” said Johns Hopkins cryptography professor Matthew Green on Twitter.

Apple’s encryption announcement offers what the company calls Advanced Data Protection, to which users of its devices must opt in. It adds iCloud Backup, Notes and Photos to data categories that are already protected by end-to-end encryption in the cloud, including health data and passwords.

Not included in the iCloud encryption scheme are email, contacts and calendar items because they must inter-operate with products from other vendors, Apple said.

It said Advanced Data Protection for iCloud would be available to US users by the end of the year and start rolling out to the rest of the world in early 2023.

In a blog post, Apple said “enhanced security for users’ data in the cloud is more urgently needed than ever”, citing research that says data breaches have more than tripled over the past eight years.

Other tech products that already offer end-to-end encryption include the world’s most popular messaging app, WhatsApp, and Signal, a communications app prized by journalists, dissidents, human rights activists and other dealers in sensitive data.

Apple announced a few other advanced security features on Wednesday, including one geared toward journalists, human rights activists and government officials who “face extraordinary digital threats” — such as from no-click spyware.

iMessage Contact Key Verification will automatically alert users to eavesdroppers who succeed in inserting a new device into their iCloud via a breach.

In July, Apple announced a new optional feature called Lockdown Mode which is designed to protect iPhones and its other products against intrusions from state-backed hackers and commercial spyware.

Apple said at the time that it believed the extra layer of protection would be valuable to targets of hacking attacks launched by well-funded groups.

Users are able to activate and deactivate lockdown mode at will.

By Press Association

More Technology News

See more More Technology News

Hands on a laptop

Estimated 7m UK adults own cryptoassets, says FCA

A teenager uses his mobile phone to access social media,

Social media users ‘won’t be forced to share personal details after child ban’

Google Antitrust Remedies

US regulators seek to break up Google and force Chrome sale

Jim Chalmers gestures

Australian government rejects Musk’s claim it plans to control internet access

Graphs showing outages across Microsoft

Microsoft outage hits Teams and Outlook users

The Google logon on the screen of a smartphone

Google faces £7 billion legal claim over search engine advertising

A person holds an iphone showing the app for Google chrome search engine

Apple and Google ‘should face investigation over mobile browser duopoly’

UK unveils AI cyber defence lab to combat Russian threats, as minister pledges unwavering support for Ukraine

British spies to ramp up fight against Russian cyber threats with launch of cutting-edge AI research unit

Pat McFadden

UK spies to counter Russian cyber warfare threat with new AI security lab

Openreach van

Upgrade to Openreach ultrafast full fibre broadband ‘could deliver £66bn boost’

Laptop with a virus warning on the screen

Nato countries are in a ‘hidden cyber war’ with Russia, says Liz Kendall

Pat McFadden

Russia prepared to launch cyber attacks on UK, minister to warn

A Google icon on a smartphone

Firms can use AI to help offset Budget tax hikes, says Google UK boss

Icons of social media apps, including Facebook, Instagram, YouTube and WhatsApp, are displayed on a mobile phone screen

Growing social media app vows to shake up ‘toxic’ status quo

Will Guyatt questions who is responsible for the safety of children online

Are Zuckerberg and Musk responsible for looking after my kids online?

Social media apps on a phone

U16s social media ban punishes children for tech firm failures, charities say