frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

The UK is still trying to backdoor encryption for Apple users

https://www.eff.org/deeplinks/2025/10/uk-still-trying-backdoor-encryption-apple-users
146•CharlesW•1h ago

Comments

bigyabai•1h ago
If your OEM can be coerced into pushing a backdoor in an OTA update, maybe our software habits are to blame.

We'll always be powerless to stop top-down attacks like this until we demand real audits and accountability in the devices we own. Shaming the UK only kicks the can down the road and further highlights the danger of trusting a black box to remain secure.

beeflet•1h ago
When a company has the ability to push OTA updates to a device locked down with trusted computing, it's not even a backdoor at that point, it's a frontdoor.

I agree political action here is totally fruitless. The UK government and Apple could already be cooperating and you would have no way of telling the difference.

JoshTriplett•1h ago
> When a company has the ability to push OTA updates to a device locked down with trusted computing, it's not even a backdoor at that point, it's a frontdoor.

Ideally, everything that runs outside of an app sandbox would be 100% Open Source. Anything short of that is not sufficient to give people full confidence against a backdoor. (Even that also relies on people paying attention, but it at least gives the possibility that people outside of a company whistleblower could catch and flag a backdoor.)

zzo38computer•1h ago
I think so too. It should include full free open source specifications of hardware, as well as fully FOSS for all software that is not inside of the sandbox system, and probably also FOSS for most of the stuff that is using the sandbox, too. Other things should also be done rather than this way alone, but this will be a very important part of it.
mulmen•22m ago
Open source alone isn’t enough. You also need a way to build and deploy the code yourself.
hunter2_•58m ago
> you would have no way of telling the difference

If only specific individuals are targeted, I agree. But if it's pushed to all users, wouldn't we expect a researcher to notice? Maybe not immediately, so damage will be done in the meantime, but sooner than later.

SV_BubbleTime•50m ago
How long was HeartBleed exploitable? How many people looked at that code? Now, take the source away and make the exploit intentional.
michaelt•33m ago
> But if it's pushed to all users, wouldn't we expect a researcher to notice?

Think of the security a games console has - every download arrives encrypted, all storage encrypted, RAM encrypted, and security hardware in the CPU that makes sure everything is signed by the corporation before decrypting anything. To prevent cheating and piracy.

Modern smartphones are the same way.

We can't expect independent researchers to notice a backdoor when they can't access the code or the network traffic.

thewebguyd•1h ago
That’s the trick. We don’t own the devices. We merely license their use. No root, no ownership.

People have been warning of this outcome for years and years. Stallman was right and all that. We got laughed out of the room and called paranoid weirdos.

Ever since smartphones were a thing it’s been obvious that this is where we were heading.

ktallett•1h ago
As someone who lives in the UK, I hope Apple tell the government where to shove their requests, and that they don't bow down like they did in China. I would prefer a company withdraws from the UK than listens to these over reaching requests of a power hungry government.
bigyabai•1h ago
> I would prefer a company withdraws from the UK than listens to these over reaching requests of a power hungry government.

That doesn't sound super profitable. Apple made money by the truckload bending over to accommodate surveillance in China.

Normal_gaussian•26m ago
Whilst this is true; its also worth considering:

If Apple did not stay in the Chinese market they will very quickly have a competitor appear in that market that will then threaten other markets. Arguably, there are already Apple competitors in it and Apple's position keeps them from occupying a space that quickly leads to competing with Apple globally.

China is generally viewed as a unique market and capitulating to the Chinese government may lead to capitulation to the US, but not to any other nation as they are incomparable.

The UK market will neither create an Apple competitor nor will it provide enough scope to allow existing competitors to meaningfully grow.

Capitulating to the UK government will lead to many other countries requiring similar capitulations.

beeflet•1h ago
Keep hoping
jeroenhd•11m ago
> I hope Apple tell the government where to shove their requests

They complied with the previous request, and stopped because the US government pressured the UK government because they didn't want US nationals to also fall victim to reduced security.

I'd love to see Apple stand up this time, but given their history I don't think it'll happen beyond a miffed comment on a blog somewhere.

sneak•1h ago
They don’t need to. All of the photos and iMessages are stored in iCloud without e2ee (nobody has ADP turned on, and it’s blocked in the UK anyway) and Apple provides the data to the Five Eyes without a warrant.

This is already the status quo in the US. The fact that ADP is offered as an option is irrelevant.

zer00eyz•1h ago
https://support.apple.com/en-us/102651#:~:text=Advanced%20Da...

Lots of things to fault apple about. This likely is not one of them.

bigyabai•1h ago
> likely

These load-bearing assumptions are part of Apple's issue.

Anyone can write a whitepaper, keeping a transparent SBOM is a different level of commitment.

throawy•1h ago
This must be a response to the headline, without reading the article. It's specifically users' ADP content that the UK gov wants to be able to access.
leakycap•35m ago
It's encrypted iCloud backups, not ADP.

ADP hasn't been available in the UK for some time now.

throawy•29m ago
It's ADP. That's why Apple didn't reinstate ADP in the UK. The UK wants a backdoor for UK users of ADP.

And there are plenty of UK users of ADP - those who got in before it was banned still have it.

From the article:

> After the U.K. government first issued the TCN in January, Apple was forced to either create a backdoor or block its Advanced Data Protection feature

> the US claimed the U.K. withdrew the demand, but Apple did not re-enable Advanced Data Protection

> The new order provides insight into why: the U.K. was just rewriting it to only apply to British users

leakycap•16m ago
perhaps you overlooked the literal first line?

> The Financial Times reports that the U.K. is once again demanding that Apple create a backdoor into its encrypted backup services.

If you read further, or click the FT link, you'll see the UK is now demanding access to encrypted iPhone backups.

ADP is not relevant beyond the history; the UK is not doing anything with ADP but I understand the confusion if you don't know that "iPhone iCloud backup" is a separate service for iPhones.

leakycap•32m ago
> nobody has ADP turned on

This isn't the type of question I normally ask people, so it sounds like you've made a bad guess here and are treating your own assumption as fact. You are incorrect; I have ADP turned on.

> Apple provides the data to the Five Eyes without a warrant.

Source? Or are you assuming here, too?

> The fact that ADP is offered as an option is irrelevant.

Only if you think no one uses it.

ChrisArchitect•1h ago
Discussion:

https://news.ycombinator.com/item?id=45440226

pipes•46m ago
The article states that apple removed the feature in the UK. So what are the UK government demanding access to?
leakycap•37m ago
Advanced Data Protection, where Apple does not keep a copy of your encryption keys (essentially), was removed in the UK.

The UK seems to now want Apple to decrypt/provide access to encrypted iPhone backups. This is where your device backs itself up in a restorable format to the cloud, including passwords and private data. Since Apple has a way to decrypt non-ADP iCloud data, UK wants it.

throawy•28m ago
It's not removed in the UK for users who enabled it before the ban. There may be existing users of it that the UK gov are interested in.
holoduke•41m ago
What is happening in the UK really?. I see numerous clips of the desperate state of many parts of various cities. It seems the country is in a steep decline. The once mighty UK sailing the world now became an island of elitists and many more poor low class folks. Sad reality
mulmen•38m ago
They didn’t just “sail the world”. They brutally conquered the world. Over time those conquered colonies said no thanks to being ruled. Hard to maintain a great empire when you can’t keep stealing from your subjects.
monero-xmr•37m ago
I have been following this thread for a long time. The UK is poor, simply put, but it has taken a long time to realize it. But the chickens are coming home to roost now. The blame is primarily the rich and immigrants. The real problem is socialism and heavy taxes, plus a denigration of entrepreneurs and business owners. They will learn, once everything has gone to utter shit
leakycap•14m ago
> The UK is poor, simply put

That's far too simply put

The UK has incredible wealth, it is just more concentrated than ever in a few select pockets

crimsoneer•35m ago
Clips don't tell you anything. The UK is suffering in the same way as every other developed country outside of the US and China - low growth that isn't propped up by booming AI and demographic issues.
Normal_gaussian•16m ago
I'd be very curious to see the desperate state you are talking about.

For physical infrastructure, there are certainly less well maintained areas and historical policies causing issues, but I'm not aware of any areas that are structurally/physically unsafe.

There are 'rougher' areas, places where theft is more likely but very, very few areas that are genuinely unsafe to walk through. The only ones I'm really aware of are two very small areas in London (basically 2-3 buildings) and certain kinds of traveller camps.

For pretty much everything else, it seems to be on par with other European nations - generally behind the Nordics of course.

Share the videos - I'd love to understand where you are coming from.

lucasRW•15m ago
What, so JD Vance was right ?!

More My News Feedback Inspired by Thatcher, Japan's PM-in-Waiting Takaichi

https://www.reuters.com/world/asia-pacific/inspired-by-thatcher-japans-pm-in-waiting-takaichi-sma...
1•rawgabbit•6m ago•0 comments

I analyzed 1000 GTM Engineering jobs – here is what I learned

https://bloomberry.com/blog/i-analyzed-1000-gtm-engineering-jobs-here-is-what-i-learned/
1•healsdata•10m ago•0 comments

I built Mindbit to stop wasting time on social media–and start learning with IA

http://mindbit.online
1•Seralbla•14m ago•1 comments

Make Python Talk, Make Python Listen – Al Sweigart [video]

https://www.youtube.com/watch?v=bHUvzkuf3Qk
1•znpy•15m ago•0 comments

Hunger Hotspots FAO–WFP early warnings on acute food insecurity [pdf]

https://docs.wfp.org/api/documents/WFP-0000166954/download/
1•mhb•15m ago•0 comments

Exploring .NET Core platform intrinsics: Accelerating SHA-256 on ARMv8 (2018)

https://mijailovic.net/2018/06/06/sha256-armv8/
2•ashvardanian•16m ago•0 comments

Mnemonic Devices Memory Tools

https://www.mnemonic-device.com/
1•rolph•17m ago•0 comments

The M23 takeover: In DR Congo's Walikale, forced labour and fears of arrest

https://www.thenewhumanitarian.org/news-feature/2025/10/01/m23-takeover-part-one-drc-walikale-for...
2•mhb•18m ago•1 comments

Show HN: Zhi – A Zero-Trust End-to-End Encrypted Messaging App

https://www.txthinking.com/zhi.html
1•txthinking•21m ago•0 comments

Show HN: An open-source, RL-native observability framework we've been missing

https://github.com/kaushikb11/verifiers-monitor
1•kaushikbokka•23m ago•0 comments

From Nothing, Everything

https://aeon.co/essays/how-nothing-has-inspired-art-and-science-for-millennia
1•andsoitis•25m ago•0 comments

Stephen King is the most banned author in US schools

https://apnews.com/article/stephen-king-pen-america-book-bans-6e55e4b48e0f1b6c2addc02e9baeaf79
1•geox•25m ago•2 comments

Show HN: Boilerplate auth server implementing RBAC

https://github.com/farhan0167/auth-serve
1•farhan0167•29m ago•0 comments

Sam Altman suggests humanity create Dyson sphere to power AI

2•itbcharles•30m ago•3 comments

OpenAI said they wanted to cure cancer. They announced a TikTok Al Slop Machine

https://old.reddit.com/r/Futurology/comments/1nxpz0p/openai_said_they_wanted_to_cure_cancer_this_...
2•doener•31m ago•1 comments

Creating custom kernels for the AMD MI300

https://huggingface.co/blog/mi300kernels
1•skidrow•35m ago•0 comments

Implementing a Fast Tensor Core Matmul on the Ada Architecture

https://www.spatters.ca/mma-matmul
2•skidrow•36m ago•0 comments

Matrix Core Programming on AMD GPUs

https://salykova.github.io/matrix-cores-cdna
2•skidrow•36m ago•0 comments

$912 energy independence without red tape

https://sunboxlabs.com/
18•nikodunk•36m ago•3 comments

New California law restricts HOA fines to $100 per violation

https://calmatters.org/politics/2025/10/california-hoas-fines-capped/
7•JumpCrisscross•44m ago•1 comments

C3 Language 0.7.6 adds generic inference and shebang compatibility

https://c3-lang.org/blog/c3-language-at-0-7-6-shebang,-generic-inference-and-lengthof()/
2•lerno•46m ago•1 comments

Show HN: Melony – Stream AI-generated React UIs in real-time

https://www.melony.dev/
1•ddaras•48m ago•0 comments

From Data to Reports – Instantly with AI

https://www.speedylytics.com
1•itrummer•49m ago•0 comments

Prevalence of left-handers and their role in antagonistic sports

https://royalsocietypublishing.org/doi/10.1098/rsos.250303
1•PaulHoule•49m ago•0 comments

Anduril and Palantir communication system 'high risk,' says US Army memo

https://www.reuters.com/business/aerospace-defense/anduril-palantir-battlefield-communication-sys...
3•1vuio0pswjnm7•49m ago•1 comments

Join the Committee for the First Amendment

https://www.committeeforthefirstamendment.com/join
2•mistersquid•52m ago•1 comments

The E-Commerce Trap: How ChatGPT Tracks You

https://msukhareva.substack.com/p/you-are-being-tracked-openais-e-commerce
3•msukhareva•56m ago•2 comments

YOLOv8 Image Recognition on RPi 5 with 26 TOPS M.2 Hailo AI Hat+

https://doleron.substack.com/p/deploying-a-custom-yolov8-model-on
1•walterbell•58m ago•0 comments

Why Data Is the New Gold

https://estimateproperty.blogspot.com/2025/10/why-data-is-new-gold.html
1•cerumopazuali•1h ago•1 comments

Rare fossil reveals ancient leeches weren't bloodsuckers

https://news.ucr.edu/articles/2025/10/01/rare-fossil-reveals-ancient-leeches-werent-bloodsuckers
1•gmays•1h ago•0 comments