The software UK techies need to protect themselves now Apple's ADP won’t
- Reference: 1740403673
- News link: https://www.theregister.co.uk/2025/02/24/apple_adp_replacements_e2ee/
- Source link:
It comes in lieu of installing a fully fledged backdoor, as was [1]reportedly requested by the Home Office just weeks earlier . It also now means [2]Apple users can no longer enjoy the end-to-end encryption (E2EE) protection from which they and their iCloud data previously benefited.
That leaves users, like this reporter, who are so deeply and regrettably entrenched in the company's fabled "ecosystem" – both in terms of hardware and software – with fewer privacy-first options available to them.
[3]
Many of Apple's users choose its products for the company's longstanding pro-privacy position. With that now measurably weakened in the UK, it leaves those who relied on Notes for storing sensitive information, Freeform for scribbles, and Reminders for, well, reminders, in need of alternatives.
[4]
[5]
Not ones to sit back and just go with the flow, we've listed some substitutes to the standard iApps so you can still enjoy much of the functionality of Apple's main cloud-powered software without the threat of the UK combing through your personal data.
Notes
Perhaps the app most used by this scribe, Notes is a supremely useful tool that almost immediately syncs documents between iDevices thanks to iCloud. With ADP now revoked in the UK, the E2EE protection it used to have is no longer, and cannot be trusted for sensitive info.
When it comes to cloud-enabled note-taking apps, there are plenty on the market from which to choose, but not many offer all the advanced features of Notes, or the digital whiteboard functionality of Freeform, plus encryption in a single package.
Standard Notes is a good option that's free, provides unlimited device syncing, while using E2EE, 2FA, and offers password-protection options for individual notes on top of that. Like many alternatives to Notes, it has paid tiers that afford additional functionality such as advanced note-taking formats and note revision histories. The most expensive tier ($120/yr) also allows for hardware security key support and 100GB worth of storage for other files like media and documents. Essentially an iCloud replacement with limited storage capacity.
[6]
Joplin is another good one, an open source option offering E2EE, 2FA, and collaborative notes, but all cloud-based features come at a price and there is no on-device encryption. Obsidian is similar: Even basic features like device syncing come with a price, although that does come with E2EE via a personalized vault hosted by DigitalOcean.
Signal's Note to Self feature can be used for basic, unformatted text, as well as images, videos, and voice memos. It offers device syncing for free, and CEO Meredith Whittaker has long said Signal would exit the UK before breaking E2EE for the government. Advanced note-taking features are nonexistent though.
Microsoft OneNote is another alternative that could work. Like Standard Notes, it offers 128-bit AES password protection for individual notes for a layer of privacy for the most sensitive information, but storage falls short of using E2EE.
Reminders
Forgetful so-and-sos rely on reminder apps for all manner of things. However, in doing so those absent-minded people could reveal more than they'd perhaps bargained for about their daily goings-on, and such, which could in theory be used to surveil their past and future movements.
Lunatask offers a nice solution here, marketed as an all-in-one bundle, which also includes note-taking, as well as habit-tracking and journaling. It has the all-important E2EE even in its free tier, and the only paid tier is $6 per month when paying annually, or $220 for a lifetime plan.
[7]
A decent open source option is Proton Calendar, which uses the same E2EE it uses in its namesake email platform and is available across web and mobile. Plus, the free version will be fine for most people if it's just reminders and calendar functionality they're after. It only comes with 1GB of storage, so either pay up or look elsewhere if you want to use it as a long-term mail solution.
Photos
Screenshots, images, and videos can all reveal more about a person than they'd perhaps like. One of the better alternatives to Apple Photos is Ente – an open source app with many of the features Apple users will expect from a photos app, like collaboration, and cross-platform sharing with family members (at a cost).
It also has E2EE, and preserves encrypted photos in three different clouds in three different locations, one of which is in an underground fallout shelter – not a pleasant thought.
Voice Memos
Encrypted voice apps appear to be in short supply, which is a shame because Voice Memos is a versatile little tool. Unfortunately, these are backed up into Apple's iCloud, so we need an alternative.
There remains the opportunity to simply stick with Voice Memos and turn off iCloud backups. You can use the recording and clipping features as normal, upload the final file to whichever secure storage platform you choose, and delete it from the device.
Voice Recorder & Audio Editor is a paid alternative available on the App store and despite its data still likely to be scooped up in an iPhone or iPad's device backups, which are now at the mercy of the UK gov should they be uploaded to iCloud, each recording can be password-protected. If you go with this option, watch for naming conventions in the recording file names – they shouldn't give the file's contents away.
iCloud Drive
Apple's cloud storage offering is no longer end-to-end encrypted. Anything stored there can be snooped at by the UK government if they can secure a warrant.
As already mentioned, Proton's suite of services are all open source and end-to-end encrypted. Throwing some money there will get you close to a full iExperience and is an option many privacy-minded folks chose even before [8]Friday's news .
Filen is another popular one that is heavily marketed as an all-in-one solution designed around client-side E2EE, while also offering photo storage with a familiar UI, collaborative note-taking, and instant messaging.
A more mainstream option would be Dropbox, which added E2EE last year, although [9]previous breaches may dissuade some.
Messages and more
Encrypted messaging apps are often the focus of the UK's snooping ambitions dressed under the guise of concern over terrorism and child exploitation. Signal is the go-to for many journalists keeping their sources safe, while WhatsApp is the more mainstream option.
Like Apple, Meta has always [10]championed encryption but the world's most popular messaging app, which still uses E2EE, remains the [11]prime focus of those who want protected chats to be a thing of the past. Who's to say if Zuck will follow Apple in eventually having to ditch encryption, at least for the UK market?
It's a solid option for now, however, unlike iMessage the backups of which are now no longer safe from the UK gov in iCloud. It should be said the iMessages and FaceTime calls remain encrypted in transit, just backups are affected.
Also up for grabs are Safari bookmarks, Siri shortcuts, and Wallet passes, neither of which have suitable alternatives.
How it works
Lawyers speaking to The Register said the legal mechanisms used to acquire iCloud data hinge on the Investigatory Powers Act 2016, sometimes referred to as the Snooper's Charter.
Apple was likely served with a Technical Capability Notice (TCN) by the Home Office, which can compel telecoms operators to technically comply with warrants that demand access to information. Apple's ADP would prevent this with its E2EE, so the UK used a TCN to get rid.
Crucially, Apple will still keep data encrypted, but the encryption will be carried out server-side, meaning Apple can reverse it at will, should a law enforcement or national security body issue the company with a Judge-approved warrant under the Snooper's Charter.
Will Richmond-Coggan, partner at Freeths specializing in privacy and cybersecurity disputes, said: "Insisting on this level of access, even with judicial supervision of the process, may well place the UK on a collision course with previous decisions made in the European Court of Human Rights, which has previously ruled (in the case of a similar attempt by Russia to broaden the scope of its domestic surveillance capabilities) that this contravened people's privacy rights.
"In turn, there is concern that it may well prejudice the UK's adequacy status with the EU which underpins the current free flow of data between the EU and the UK, potentially increasing the costs of doing business in Europe."
Heavy fallout
The reaction to Apple's decision has been overwhelmingly negative and to its credit, its official response last week acknowledged its own regret at being driven to such lows.
"We are gravely disappointed that the protections provided by ADP will not be available to our customers in the UK given the continuing rise of data breaches and other threats to customer privacy," Apple told The Register .
Others have been less reserved in their criticisms, like Malwarebytes' senior privacy advocate David Ruiz, who said the whole furor "has extremely dangerous and idiotic potential" on a global scale.
"This is only bad news and it is difficult to call it anything other than a disaster. The loss of end-to-end encryption for cloud storage is wholesale bad – it leaves users less secure and private – but the global consequences tip this into far worse territory.
"To demand access to the world's data is such a brazen, imperialist maneuver that I'm surprised it hasn't come from, well, honestly, the US. This may embolden other countries, particularly those in the 'Five Eyes' [alliance] to make a similar demand of Apple."
Unsurprisingly, privacy groups like Big Brother Watch have also dispiritedly weighed in, calling it "outrageous" and "draconian."
It said in a statement: "This decision by Apple is the regrettable consequence of the Home Office's outrageous order attempting to force Apple to breach encryption. As a result, from today Apple's UK customers are less safe and secure than they were yesterday – and this will quickly prove to have much wider implications for internet users in the UK.
"No matter how this is framed, there is simply no such thing as a 'back door' that can be limited only to criminals or that can be kept safe from hackers or foreign adversaries. Once encryption is broken for anyone, it's broken for everyone, and as we have cautioned: This will not stop with Apple.
"We once again call on the Home Office to immediately rescind this draconian order and cease attempts to break encryption before the privacy rights of millions are eroded and the UK further ostracises itself from other democracies around the world."
US politicians have already voiced opposite to the UK government's request and warned this could have [12]implications for intelligence sharing . ®
Get our [13]Tech Resources
[1] https://www.theregister.com/2025/02/07/home_office_apple_backdoor_order/
[2] https://www.theregister.com/2025/02/24/rather_than_add_a_backdoor/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Z7ylsVpb01qdnHHrD3NelQAAAdE&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Z7ylsVpb01qdnHHrD3NelQAAAdE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Z7ylsVpb01qdnHHrD3NelQAAAdE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Z7ylsVpb01qdnHHrD3NelQAAAdE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Z7ylsVpb01qdnHHrD3NelQAAAdE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[8] https://www.theregister.com/2025/02/24/rather_than_add_a_backdoor/
[9] https://www.theregister.com/2024/05/02/dropbox_sign_attack/
[10] https://www.theregister.com/2023/04/21/meta_encryption_police/
[11] https://www.theregister.com/2023/04/18/wrong_time_to_weaken_encryption/
[12] https://www.theregister.com/2025/02/13/us_demand_uk_apple_backdoor_close/
[13] https://whitepapers.theregister.com/
The least worst option?
I don't know if there were any good options given the Home office was allowed to issue this and Apple could not get a reprieve. So whilst Tim Cook standing by the grand doge and the comb over has made me wonder if I can continue to be an Apple customer this decision might be the best one open to Apple. Let me qualify this is a disaster but the UK is 60 million people ish and the 6th largest economy big enough to cause an uproar and chaos but small enough to possibly contain any fallout. Simply saying this is tantamount to banning End to End Encryption (E2EE) if this is enforced we will turn it off might be Apples best chance to shine a light on this and get a u turn out of the UK. That would set a precedent for those watching like the US that this is a bridge too far. I still hate it though. I do find myslef unable to argue with Apples point you cant make a secure backdoor so don't force us to try.
Re: The least worst option?
The demand to Apple leaked. We don't know how many others received the same without leakage. If Google just discontinued a service we'd just think it was BAU.
If it's important enough to be encrypted why trust it to someone eles's computer?
Re: The least worst option?
Google, Meta and others have even less principles than Apple. They'll simply have backdoored their services at the first request from the clowns of the British government.
Re: The least worst option?
It's not about principles but from where companies draw their profits. Apple sells a hardware and software ecosystem to their customers, who are the end users; the others sell end user's data to their customers, the advertisers
Blackberry
Do wonder if Blackberry handing over details about the rioters in London all those years ago aided their demise.... Will this be the first nail in Apple's coffin, at least in the UK anyways?
An A4 pad and biro would be a solution for secure notes.
Of course Apple users would need to find a designer one costing at least £50.
It is useful that the UK government snoop on my electronic communications, in which I repeatedly point out that they are incompetent, corrupt, or both and that they have no talent whatsoever. It saves me the bother of e-mailing them and telling them.
Once they have made themselves as hated as the Tories (who drafted the legislation) by screwing with our internet access in July, they will then run scare stories about kids using VPNs to seek out pron, and ban VPNs.
If your global corporation requires the use of secure encryption to protect trade secrets, you should close your UK facilities and move them somewhere less STASI.
Re: An A4 pad and biro would be a solution for secure notes.
Interviewer: Mr[s] Member of the public, would you mind letting the police have access to other people's files so that they can:
a) stop terrorists
b) catch kiddie porn
c) delete explicit pictures you took of yourself and which your ex has posted on line?
Member of public: Let 'em at it.
This government may end up as hated as the last. But it won't be over this. The majority of the public are on-side. This is a public that has already sold their privacy to Zuckerberg so they can become ever more irate about lies.
What Apple should have done
A plug-in for each remote backup service available from their app store. Apart from iCloud, one of the pre-installed plugins should be "my NAS" and another should be Nextcloud.
Re: What Apple should have done
Or, perhaps, encourage a third-party app to add a shim/proxy layer that locally encrypts the data before sending to the iCloud, and transparently decrypts the data again when it's restored. ADP but provided by someone who isn't troubled by the Snoopers Charter.
Re: What Apple should have done
That sounds like you want Cryptomator https://cryptomator.org/
Security Theatre at best
Since it's impossible for humankind to unlearn how to do secure encryption, it's impossible for anyone to ban encryption.
Encrypt your files locally, before uploading them to iCloud. Heck you could even use steganography to make them look innocent. Let Apple give the UK/USA/RU government access to the files you uploaded: they won't be able to decrypt them without a lot of trouble.
Hmm
Vance seems to have been fairly observant to the direction in Europe.
And now as the emperor says- let the hate flow through you (commence the downvotes)
Noticed Google distinctly lacking in any of the recommendations for alternatives in the above article. Is that because Google apps on iOS also relied on ADP, or just because my naivety shows they're not really very secure in the first place?
Re: Google
Yes.
Puzzled! Again!
Surely relying on a small number of huge internet service providers for privacy......surely this represents a single point of failure. In all circumstances.
Why is no one pointing out that groups who demand privacy can arrange private encryption for themselves?
Note to snoops: thousands of groups doing privacy for themselves is A MUCH LARGER THREAT TO SNOOPING than Apple's E2EE!!
Just saying!!
But it is better for 100 innocents to lose their data to ne'er-do wells, than for the police to have to work to catch one guilty person who hides their nefarious schemes using encryption.
I look forward to someone releasing the data of those that chose to ask Apple for a backdoor.
.
.
.
Ug! I can't believe I'm supporting Apple!
But then for once the other side are a bigger bunch of twunts!