Two-Tier Encryption in the UK
Alice and Bill both live in the UK. Both have identical iPhones. Both use iCloud. Both pay Apple for the same services. Alice has Advanced Data Protection switched on, protecting the majority of her iCloud data with end-to-end encryption. Bill does not, and cannot switch it on. Alice enabled it before Apple withdrew the feature for new UK users in February 2025. Bill missed the window[1].
This is the story of how the UK government created a two-tier system of encryption rights, and what it means for the rest of us.
The Snowden aftermath
In January 2014, after the Snowden revelations exposed the PRISM surveillance program, Apple CEO Tim Cook told ABC News: "We have a gag order on us right now, but there is no back door. The government doesn't have access to our servers. They would have to cart us out in a box for that."[1]
Nearly two years later, the San Bernardino terrorist attack in December 2015 killed 14 people. The FBI obtained the attacker's iPhone 5C but did not know the passcode. They got a court order compelling Apple to create a custom version of iOS that would bypass the iPhone's security protections, particularly the limits on passcode attempts. Cook refused, calling the requested software the "equivalent of cancer" and arguing it would function as a master key capable of unlocking hundreds of millions of devices[1].
The FBI eventually accessed the phone using a third party, widely reported to be Cellebrite, and withdrew its legal action against Apple[1].
The UK's secret order
Skip forward almost a decade. On February 7, 2025, The Washington Post revealed that the UK government had secretly ordered Apple to provide access to data protected by its strongest level of iCloud encryption[2].
The order was issued under the Investigatory Powers Act 2016, the centrepiece of the UK's modern surveillance law. The mechanism used was a Technical Capability Notice (TCN), a legal instruction requiring a technology provider to maintain or develop the capability to comply with government requirements. A TCN requires approval from a Judicial Commissioner, and the recipient is generally gagged from revealing its existence[1].
The TCN reportedly requested that Apple create a way to access encrypted iCloud data belonging not just to UK users, but to Apple users worldwide. The sheer scope was astonishing[1].
End-to-end vs regular encryption
All iCloud data is encrypted. But there is a critical difference between encrypted and end-to-end encrypted data. iCloud already protects sensitive categories like Passwords, Health data, and Messages with end-to-end encryption by default. For everything else, Apple retains the ability to decrypt the data when necessary and can be ordered to hand it over by law enforcement[1].
With Advanced Data Protection (ADP), several more categories become end-to-end encrypted, including iCloud Backup, Photos, and Notes. Apple itself does not possess the keys needed to decrypt that protected data. It is not something Apple can unlock just because a government asks[1].
Apple's response
Apple's position showed fidelity to its previous stance. Deliberately weakening end-to-end encryption, for whatever purpose, would make every user less secure. On February 21, 2025, Apple announced that Advanced Data Protection would no longer be available to new UK users, stating: "We have never built a backdoor or master key to any of our products or services and we never will"[3].
The reported TCN itself did not order Apple to withdraw ADP. It ordered Apple to maintain the technical capability to make ADP-protected data accessible when a warrant required it. If Apple had complied, they would have needed to create a mechanism capable of unlocking private information that could potentially be exploited by hackers, hostile governments, and others[1].
The precedent problem
Compliance would have set a dangerous precedent. The "good guys" might not actually be good. Even if they were, a future government might not be, and might want to use that access for bad ends. Apple was the canary in the coal mine. Such a precedent would also affect WhatsApp, Signal, and every other encrypted messaging platform[1].
The Investigatory Powers Tribunal became involved after Privacy International and other groups argued that the government should not be able to secretly compel technology companies to weaken encryption without adequate public scrutiny[1].
Where we are now
The result is a two-tier system. UK users who enabled ADP before February 2025 keep it. Those who did not, or who buy Apple devices now, cannot. Alice's photos, backups, and notes are end-to-end encrypted. Bill's are not. Same phone, same service, same price. Different rights[1].
The story hit 437 points on Hacker News with 389 comments, reflecting broad concern about government overreach into encryption[4]. The UK government's approach, using secret orders with gag provisions, avoided public debate entirely. The outcome, a fragmented user base with inconsistent security, is arguably worse than either full encryption or no encryption. It creates the illusion of security while leaving most users exposed[1].
Sources
[1] Macanorak: "Two-Tier Encryption in the UK" (September 24, 2026)
[2] The Washington Post: "Apple faces secret UK order to break iCloud encryption" (February 7, 2025)
[3] Apple Newsroom: "Advanced Data Protection no longer available to new UK users" (February 21, 2025)
[4] Hacker News discussion (437 points, 389 comments)