Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Encryption - Britain Drops Apple ‘Backdoor’ Demand After U.S. Pushback
Encryption Data Protection Latest News News & Analysis Security Software Development Security

Britain Drops Apple ‘Backdoor’ Demand After U.S. Pushback

Kirsten DoyleBy Kirsten DoyleAugust 20, 20253 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Britain Drops Apple Backdoor
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Britain has abandoned its demand that Apple build a “backdoor” into its encryption systems. The change follows months of quiet talks between London and Washington, Reuters reports.

In a statement posted on X, U.S. Director of National Intelligence Tulsi Gabbard, said: “As a result, the UK has agreed to drop its mandate for Apple to provide a ‘backdoor’ that would have enabled access to the protected encrypted data of American citizens and encroached on our civil liberties.”

She added that the U.S. government had been working with Britain “to ensure that Americans’ civil liberties are protected.” The discussions involved President Donald Trump and Vice President JD Vance, alongside British Prime Minister Keir Starmer, who was in Washington on Monday with other European leaders for talks on Russia’s war in Ukraine.

A spokesperson for the British government declined to comment on any deal, but said London continues to balance security and privacy. “We will always take all actions necessary at the domestic level to keep UK citizens safe,” they said.

Apple, long a defender of strong encryption, has not commented. The company has resisted backdoor orders for years, most prominently in 2016 when U.S. officials sought to unlock the iPhone of a suspected extremist. In February, Apple pulled its Advanced Data Protection feature from U.K. devices after regulators ordered it to build access for government use. 

Critics of the backdoor mandate warned of the risks. Security experts told Reuters that any deliberate weakness could be discovered and exploited by cybercriminals or hostile states.

Adam McKissock, Principal Security Consultant at Black Duck, said dropping the requirement “is a win for everyone’s security and civil liberties.” He argued that forcing Apple to create a technical capability to read encrypted iCloud data “would have created a permanent weakness that criminals and hostile states could also exploit.”

“If this reversal holds, the next step is clear: allow Apple to restore Advanced Data Protection for U.K. customers and commit—explicitly—that powers under the Investigatory Powers Act will not be used to require systemic weakening of encryption,” McKissock said.

“Lawful access should remain targeted, case-by-case, and under due process. We don’t make the internet safer by making it less secure.”

Casey Ellis, Founder of Bugcrowd, also welcomed the shift. “Deliberately weakening the security posture of everyone to enable the surveillance of a few is a universally bad solution,” he said. Ellis added that once governments establish global precedents around weakening encryption, “there’s a real risk of that triggering a race to the bottom.”

For Satish Swargam, also a Principal Security Consultant at Black Duck, the danger is clear from experience. He pointed to Salt Typhoon, a state-backed hacking group that compromised U.S. telecommunications networks in 2024, including routers at major carriers and systems used for lawful intercepts.

“Attacks such as these show how the backdoor methods could be vulnerable and exploited by hackers,” Swargam said. “Even court-authorized requests to access data via backdoor should be assessed with caution and not taken for granted.”

The debate has drawn scrutiny in Washington. Earlier this year, lawmakers warned Britain’s order might have violated the CLOUD Act, which prevents either country from demanding access to the other’s citizens’ data without due process. 

For now, Britain’s reversal signals a pause in the long-running clash between governments seeking access and companies resisting systemic weaknesses. Whether Apple restores advanced protections for its U.K. users will be the next test.

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    AI-Powered Attacks Become Top Concern for Security Professionals, New Filigran Survey Reveals
  • Kirsten Doyle
    ShinyHunters targets Oracle PeopleSoft customers through critical zero-day
  • Kirsten Doyle
    SIG report: AI-generated code is linked to twice the security risk and rising technical debt
  • Kirsten Doyle
    Miasma worm spreads from Red Hat packages to Microsoft repositories

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

A Comparative Analysis of Encryption Algorithms in Protecting Sensitive Data

April 4, 202510 Mins Read

The Looming Quantum Threat: NCSC Urges Encryption Upgrades

March 24, 20255 Mins Read

Massive RSA Encryption Flaw Exposes Millions of IoT Devices to Attack

March 18, 20254 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}