UK Government’s Apple iCloud Backdoor Secrecy Called “Farcical” in Court

The British government’s policy of neither confirming nor denying that it had ordered Apple to put a backdoor into iCloud has been described as “farcical” during a court hearing.

The London-based Royal Courts of Justice is the venue of the Investigatory Powers Tribunal, which on Thursday heard that the “neither confirm nor deny” (NCND) stance was “logically unsustainable” given that everybody already knows the fact.

Ben Jaffey KC, who represents the campaign groups Privacy International and Liberty, told the court that the government was defending a secret that no longer exists.

The tribunal is hearing Apple’s complaint alongside the complaint from Privacy International and Liberty, challenging the home secretary’s power to issue secret orders, known as technical capability notices (TCNs).

The January 2025 leak to the Washington Post revealed that the Home Office had issued a TCN to Apple, requiring access to end-to-end encrypted messages and data stored by Apple customers worldwide in iCloud. Apple did not comply with the order and instead pulled its Advanced Data Protection service from UK users.

But within hours of the Washington Post story, Home Office sources confirmed the report to the Times. In October 2025, the Home Office issued a new TCN, reportedly narrower in scope and aimed at UK users.

As the tribunal was told, this was not the only confirmation of the original order. A post on X by former US director of national intelligence Tulsi Gabbard in August 2025 was seen by more than three million people, while in December 2025, the investigatory powers commissioner, Brian Leveson, said that “lawful access can be achieved in a way that strikes a balance between maintaining strong encryption and ensuring law enforcement and the government can protect the public from terrorism, serious crime, and hostile state activity.”

Gabbard had reported that the UK had agreed to “drop its mandate” for Apple to provide a “backdoor” that would have enabled access to the protected encrypted data of American citizens.

Jaffey told the court that it was unlikely that Home Office sources would have confirmed the TCN without “tacit approval” from the government. “But here, within hours of reporting by the Washington Post, multiple sources were confirming to the Times the existence of the orders,” he said.

Leveson’s statement, Jaffey continued, “gives the game away.” The commissioner’s report would have been “clearly prejudicial to issues that might come in front of him in the future” had there been no TCN issued at all.

And while the Home Office is sticking to its NCND policy, WhatsApp and Google have confirmed in witness statements that they have not received any such orders – something they are free to say because there is no legal bar on disclosing that you have NOT received a TCN.

Apple, on the other hand, is in a different position because it did receive the order, and is now in court trying to force the government to confirm this, and by extension, admit that the TCN is still in force.

Another argument made by Jaffey is that Apple had to ask for permission before it could discuss the order with the US government, and that permission was granted. “The fact that Apple even needed to ask permission confirms there is a TCN,” he said.

The government’s argument against abandoning the NCND policy is that it would damage national security and hinder the investigation and prosecution of “serious crime,” including terrorism and online child abuse. But Jaffey said that “the horse has long bolted” as far as secrecy around the TCN is concerned, and that the government’s stance is “ridiculous” and “understates the principle of open justice.”

Keep reading

Republican Lawmakers Demand Answers on UK’s iCloud Encryption Backdoor Order

Two senior Republican lawmakers are demanding answers from the British government about its secret order forcing Apple to break its own encryption. The UK has until March 11 to respond.

House Judiciary Committee Chairman Jim Jordan and Foreign Affairs Committee Chairman Brian Mast sent a joint letter on Wednesday to Home Secretary Shabana Mahmood, pressing for a formal briefing on the Technical Capability Notice (TCN) served on Apple under the UK’s Investigatory Powers Act.

We obtained a copy of the letter for you here.

It’s the latest move in a surveillance fight that began over a year ago and has rattled the US-UK relationship at the highest levels.

In January 2025, UK security officials secretly ordered Apple to build a backdoor into iCloud that would allow them to decrypt any user’s data, anywhere in the world. Not just suspected criminals, not just UK citizens. Everyone.

The order targeted Apple’s Advanced Data Protection (ADP) feature, the optional end-to-end encryption that ensures even Apple can’t read iCloud backups. Apple’s response was to pull ADP from the UK market entirely in February 2025, stripping strong encryption options from roughly 35 million iPhone users rather than comply with a demand it couldn’t legally discuss.

UK law makes it a criminal offense for companies to confirm or deny the existence of such orders, even to their own government.

Apple couldn’t tell the US Department of Justice that the order existed. The DOJ couldn’t verify whether it complied with the CLOUD Act, the bilateral agreement governing how the two countries share access to digital evidence. That agreement explicitly states it “shall not create any obligation that providers be capable of decrypting data.” The UK’s order appears to do exactly that.

The reaction in Washington was bipartisan. Senator Ron Wyden and Congressman Andy Biggs slammed the order as “effectively a foreign cyber attack waged through political means.”

President Trump compared the UK’s conduct directly to China’s. Speaking to the Spectator after meeting Prime Minister Keir Starmer, Trump said: “We actually told [Starmer] . . . that’s incredible. That’s something, you know, that you hear about with China.” DNI Secretary Tulsi Gabbard called any attempt to compel Apple to create security weaknesses an “egregious violation” of privacy and confirmed legal and intelligence teams were assessing the implications.

Keep reading

West Virginia sues Apple, saying iCloud distributed ‘child porn’

West Virginia’s attorney general sued Apple (AAPL.O) on Thursday, accusing the iPhone maker of allowing its iCloud service to become what the company’s own internal communications called the “greatest platform for distributing child porn.”

Attorney General JB McCuskey, a Republican, accused Apple of prioritizing user privacy over child safety. His office called the case the first of its kind by a government agency over the distribution of child sexual abuse material on Apple’s data storage platform.

“These images are a permanent record of a child’s trauma, and that child is revictimized every time the material is shared or viewed,” McCuskey said in the statement.

Apple in a statement said it has implemented features that prevent children from uploading or receiving nude images and was “innovating every day to combat ever-evolving threats and maintain the safest, most trusted platform for kids.”

“All of our industry-leading parental controls and features, like Communication Safety — which automatically intervenes on kids’ devices when nudity is detected in Messages, shared Photos, AirDrop and even live FaceTime calls — are designed with the safety, security, and privacy of our users at their core,” Apple said.

Apple on Thursday said it plans to roll out a feature in the coming weeks that allows users in the U.S. to flag inappropriate content such as nudity directly to Apple via a “Report to Apple” feature. This is already available in Australia and the United Kingdom. Apple said the expansion was previously planned and not in response to West Virginia’s lawsuit.

The U.S. has seen a growing national reckoning over how smartphones and social media harm children. So far, the wave of litigation and public pressure has mostly targeted companies like Meta, Snap, and Google’s YouTube, with Apple largely insulated from scrutiny.

Keep reading

Secret details of Israel’s mammoth deal with Google and Amazon revealed – media

Israel has forced US tech giants Google and Amazon to violate their own legal obligations under a 2021 cloud services contract with West Jerusalem, according to a joint investigation by several news media outlets, including The Guardian.

The Jewish state’s contracts with US tech platforms have been under close scrutiny following widespread accusations, including from the UN, that its military response to the October 7, 2023 Hamas attack that killed over 1,200 people constitutes a genocide.

Known as Project Nimbus, the $1.2 billion deal reportedly bars the firms from restricting the Israeli government’s access to cloud services they provide, even if it violates their terms of use, the reports, carried by The Guardian along with +972 Magazine and Local Call, suggest.

The deal also reportedly requires the two companies to secretly notify West Jerusalem using a so-called “winking mechanism” should any foreign state or court seek access to Israeli data stored in the cloud.

Keep reading

Microsoft Word To Save New Files to the Cloud by Default

Microsoft is preparing to change how documents are saved in Word for Windows, shifting new file storage to the cloud by default.

Instead of asking users to activate AutoSave or select a cloud location manually, Word will now store all newly created documents directly in OneDrive or another designated cloud service automatically.

Raul Munoz, a product manager on Microsoft’s Office shared services and experiences team, described the change by saying, “We are modernizing the way files are created and stored in Word for Windows. Now you don’t have to worry about saving your documents: Anything new you create will be saved automatically to OneDrive or your preferred cloud destination.”

Currently being rolled out to Microsoft 365 Insiders, this new setup is presented as a way to prevent lost work and provide immediate access to files across mobile platforms and browsers.

However, for anyone working outside Microsoft’s cloud ecosystem, this change introduces additional steps to avoid online storage.

The update also comes with adjustments to how documents are named. Rather than appending sequential numbers to new files, Word will now assign file names based on the date of creation.

Users will have the option to set a preferred default save location or opt out of automatic cloud saves entirely, though doing so requires manual reconfiguration.

Microsoft has been steadily nudging its user base toward cloud reliance. AutoSave already defaults to cloud storage, and persistent prompts in Windows have encouraged, or pressured, users to turn on OneDrive backups.

These reminders have drawn complaints, especially from those who feel Microsoft is eroding straightforward local file access.

Keep reading

Microsoft Failed To Disclose Key Details About Use Of China-Based Engineers In U.S. Defense Work, Record Shows

Microsoft, as a provider of cloud services to the U.S. government, is required to regularly submit security plans to officials describing how the company will protect federal computer systems.

Yet in a 2025 submission to the Defense Department, the tech giant left out key details, including its use of employees based in China, the top cyber adversary of the U.S., to work on highly sensitive department systems, according to a copy obtained by ProPublica. In fact, the Microsoft plan viewed by ProPublica makes no reference to the company’s China-based operations or foreign engineers at all.

The document belies Microsoft’s repeated assertions that it disclosed the arrangement to the federal government, showing exactly what was left out as it sold its security plan to the Defense Department. The Pentagon has been investigating the use of foreign personnel by IT contractors in the wake of reporting by ProPublica last month that exposed Microsoft’s practice.

Our work detailed how Microsoft relies on “digital escorts” — U.S. personnel with security clearances — to supervise the foreign engineers who maintain the Defense Department’s cloud systems. The department requires that people handling sensitive data be U.S. citizens or permanent residents.

Microsoft’s security plan, dated Feb. 28 and submitted to the department’s IT agency, distinguishes between personnel who have undergone and passed background screenings to access its Azure Government cloud platform and those who have not. But it omits the fact that workers who have not been screened include non-U.S. citizens based in foreign countries. “Whenever non-screened personnel request access to Azure Government, an operator who has been screened and has access to Azure Government provides escorted access,” the company said in its plan.

The document also fails to disclose that the screened digital escorts can be contractors hired by a staffing company, not Microsoft employees. ProPublica found that escorts, in many cases former military personnel selected because they possess active security clearances, often lack the expertise needed to supervise engineers with far more advanced technical skills. Microsoft has told ProPublica that escorts “are provided specific training on protecting sensitive data” and preventing harm.

Microsoft’s reference to the escort model comes two-thirds of the way into the 125-page document, known as a “System Security Plan,” in several paragraphs under the heading “Escorted Access.” Government officials are supposed to evaluate these plans to determine whether the security measures disclosed in them are acceptable.

In interviews with ProPublica, Microsoft has maintained that it disclosed the digital escorting arrangement in the plan, and that the government approved it. But Defense Secretary Pete Hegseth and other government officials have expressed shock and outrage over the model, raising questions about what, exactly, the company disclosed as it sought to win and keep government cloud computing contracts.

Keep reading

Scientists propose putting nanobots in our bodies to create ‘global superbrain’

A team has proposed using nanobots to create the ‘internet of thoughts’, where instant knowledge could be downloaded just by thinking it.

An international team of scientists led by members of UC Berkeley and the US Institute for Molecular Manufacturing predicts that exponential progress in nanotechnology, nanomedicine, artificial intelligence (AI) and computation will lead this century to the development of a human ‘brain-cloud interface’ (B-CI).

Writing in Frontiers in Neuroscience, the team said that a B-CI would connect neurons and synapses in the brain to vast cloud computing networks in real time.

Such a concept isn’t new with writers of science fiction, including Ray Kurzweil, who proposed it decades ago. In fact, Facebook has even admitted it is working on a B-CI.

However, Kurzweil’s fantasy about neural nanobots capable of hooking us directly into the web is now being turned into reality by the senior author of this latest study, Robert Freitas Jr.

Keep reading