Apple makes it easier to keep your data secret from hackers, cops, and even Apple


A woman takes a photo of an iPhone. | Justin Sullivan/Getty Images

How to encrypt most of your iCloud data — and why you should.

Apple, the company whose CEO is fond of calling privacy a human right, has added a few new privacy features to its devices. One of them, Advanced Data Protection, is adding end-to-end encryption to almost every iCloud service out there. Which means that almost everything you upload to Apple’s cloud — from backups to photos — can only be accessed by you. That’s good for your privacy, which means the FBI isn’t thrilled about it.

The updates are part of Apple’s years-long push to be known as the Big Tech company that cares and does more about its customers’ privacy than its competitors. And they come at a time when the need for this privacy is only that much more obvious. Apple products should no longer be assumed to be safe from hackers, and phishing scams — where you’re tricked into giving your account credentials to a hacker — are only getting more aggressive and convincing. At the same time, most people store a lot of personal and valuable information on cloud servers like iCloud, which only makes them that much more attractive of a target. The more options you have to help lock your data down, the better.

The company announced the update on Wednesday, although the upgraded encryption won’t be available until the end of this year for US users and early next year for everyone else. When it does roll out, you’ll have to choose to enable it in your iCloud settings.

Even if you don’t know much about internet security, you’ve probably heard at least something about encryption by this point, as the general public has become more aware of the need for it and more services that offer it have popped up. With end-to-end encryption, the data you send to iCloud can’t be read by anyone else as it travels to or from the cloud, nor can Apple see it when it’s stored on their servers. That helps protect your data from hackers (like the people who notoriously broke into hundreds of iCloud accounts in 2014, including Jennifer Lawrence’s) and law enforcement.

That’s why law enforcement generally doesn’t like encryption that doesn’t give them a way to easily obtain your data from the third party that’s hosting it, which is something they do a lot. Governments around the world have repeatedly called on tech companies not to do what Apple just did, and Reuters reported a few years ago that Apple decided not to allow users to encrypt their iCloud backups after the FBI urged it not to (Apple has denied this).

There’s been plenty of friction between Apple and the Department of Justice for years over Apple’s refusal to create a back door into its devices for law enforcement. In 2016 and in 2020, the DOJ tried to force Apple to help it break into the phones of mass shooters it suspected of having terrorist ties. Both times, Apple refused, and the FBI was (eventually and at great expense) able to hack into the phones without Apple’s help. In the 2020 case, Apple gave the FBI all of the data it had from the shooter’s iCloud account, even as the FBI groused about not being able to access the physical device. Now, with Advanced Data Protection enabled, Apple won’t even be able to give the FBI most of that iCloud data, either.

Needless to say, the agency is not a fan of Advanced Data Protection, saying in a statement that it’s “deeply concerned” with the “threat” posed by encryption, and that “the FBI and law enforcement partners need ‘lawful access by design.’”

Apple already offered end-to-end encryption for some things in iCloud, including Health data, Apple Card transactions, Keychain passwords, and Safari. This update will add device and iMessage backups, iCloud Drive, Photos, and Notes to the list. The only things that won’t have an end-to-end encryption option are Mail, Contacts, Calendars, and certain types of metadata, which Apple says is due to technical constraints.

A prompt asking if a user wants to enable Advanced Data Protection.
Apple
The Advanced Data Protection prompt that iCloud users will soon see.

If you don’t want to enable Advanced Data Protection, it’s not like your data will be left hanging out on the internet for anyone to see. Apple already encrypts all of this stuff in transit and on its servers, but it has the keys to some of it — which means law enforcement would have access to it too, as long as they have the right court order forcing Apple to give it up. When you enable Advanced Data Protection, you’re taking those keys away. There’s a downside to this: It could make it harder to regain access to your data if you lose it for whatever reason, since Apple won’t be able to access it for you.

Advanced Data Protection doesn’t make it impossible to get your data. If someone has access to your device or your account recovery key, then they’ll be able to see what’s on it. If you have data access turned on for web browsers, that will give temporary access to encryption keys to your browser and to Apple. If you’re super-protective of the stuff on your phone, you could also just avoid uploading any of the data on it to iCloud and keep it all on your device. Although that, again, won’t help you if someone gets ahold of the device itself.

Unlike some of Apple’s privacy offerings that users had to pay extra for, these will be available to every Apple customer for free (if you don’t count the fact that Apple devices are generally more expensive than its competitors). That’s obviously good for Apple users who care about cybersecurity and privacy, but it may also be good for users who don’t know much about it or how best to secure their accounts. It may also be good for people who don’t even use Apple products because it’ll put that much more pressure on companies like Google to up its security game and offer these services to its customers, too.

If you aren’t an Apple user or just don’t want to put all of your data eggs in Apple’s basket, there are plenty of services out there that offer end-to-end encryption. Instead of Apple’s keychain for your passwords, you can use one of several password managers. Messaging services like Signal, WhatsApp, and Telegram’s secret chat feature end-to-end encryption for your messages. Proton’s Mail is end-to-end encrypted, as is its cloud storage service.

So while Apple isn’t the only company expanding its encryption services, it’s surely the biggest. For a lot of people, it might be the easiest, too, since you’re not switching between various services to do various things: You can add another layer of security to your life with just a tap on your screen.

Related articles

Busted: Federal regulator hearing complaint against Ted Cruz has one of his yard signs



The regulator set to hear a campaign finance complaint about Sen. Ted Cruz (R-TX) has a yard sign for the senator's campaign at his house, reported the San Antonio Current on Wednesday.

"Trey Trainor, an attorney serving on the Federal Election Commission (FEC) — the panel scheduled to hear the complaint — recently retweeted a photo his wife Lucy Trainor shared of a yard sign outside their Austin-area home promoting the Texas Republican's campaign for a third term in the U.S. Senate," said the report. "'Got my new ⁦@tedcruz⁩ yard sign installed today,' Lucy Trainor tweeted April 19, 10 days after a pair of campaign-finance watchdogs filed their FEC complaint against Cruz. Trey Trainor retweeted the image the same day his wife posted it."

Per federal contribution records, Trainor also made three contributions to Cruz in 2013, totaling to $325.

ALSO READ: Revealed: What government officials privately shared about Trump not disclosing finances

"Trainor's retweet follows last month's report by the Current that FEC Chairman Sean J. Cooksey served as Cruz's deputy chief counsel in 2018. From 2019 until joining the FEC in 2020, Cooksey served as general counsel for Missouri U.S. Senator Josh Hawley, a GOP hardliner frequently aligned with Cruz," noted the report. "Both Trainor and Cooksey are Trump appointees to the six-member FEC, which is comprised of equal numbers of Republicans and Democrats."

The complaint in question stems from iHeartMedia, which hosts Cruz's podcast, making a $630,000 payment to Truth and Courage PAC, which supports Cruz. Senate rules prohibit senators from accepting greater than "nominal value" gifts from companies that employ lobbyists, as iHeartMedia does.

Cruz, for his part, denies that anything about this arrangement is unlawful.

The senator has personally challenged campaign finance laws in the past. For instance, in 2022, after he ran afoul of a law that limited how much he could pay himself back with campaign contributions for money he loaned to his own campaign, he got the Supreme Court to toss out the law altogether.

Louisiana bill proposes removing lunch break for employed minors

(NewsNation) — A proposed bill is threatening a Louisiana...

Service members secretly filmed, videos posted to PornHub: Warrant

(NewsNation) — More than one hundred nonconsensual and secretly...

Trump fined $9K for violating gag order in hush money case

NEW YORK (NewsNation) — Judge Juan M. Merchan ruled...