Two-tier encryption in the UK
- ID
- 28239
- Status
- summarized
- Published
- 24 Sep 2026, 6:39 PM
- Fetched
- 25 Sep 2026, 3:17 AM
- Provider
- Hacker News
- Category
- dev-community
- Original URL
- https://macanorak.com/two-tier-encryption-in-the-uk/
- Source URL
- https://hnrss.org/best
Summary
- Score
- 6.5
- Created
- 25 Sep 2026, 3:18 AM
- Tags
- Audience
- developerssaas_founders
What happened
A MacAnorak piece walks through how two UK users with identical iPhones and the same paid iCloud subscription get different protection: one enabled Apple's Advanced Data Protection before Apple withdrew it for new UK users in February 2025, the other can no longer switch it on. It traces the path from the Snowden/PRISM revelations and Tim Cook's January 2014 ABC News interview with David Muir ("there is no back door"), through the 2 December 2015 San Bernardino attack that killed 14 and wounded 22 and the FBI's seizure of the iPhone 5C used by Syed Rizwan Farook, to the current UK position. The Hacker News thread drew 297 points and 292 comments.
Why it matters
If your product's security story leans on iCloud Advanced Data Protection for user data, UK accounts created after February 2025 cannot enable it, so identical devices and identical paying customers now sit at different protection levels — that means app-level or server-side encryption you control, not the platform's strongest mode, has to be your default for UK users. If you are a founder planning UK expansion or storing customer data with US cloud providers, treat per-jurisdiction rollback of E2EE as a live risk to design around, not a hypothetical.
Discussion angle
If a platform can silently disable end-to-end encryption for new users in one country, is platform E2EE ever a defensible trust boundary in your architecture — or should every builder storing sensitive user data assume they must own the encryption keys?