The UK’s National Cyber Security Council (NCSC) has – without any public notice or statement released at time of writing – removed guidance around encryption, following the removal of Apple’s encryption technology from the country after a controversal government request.
The Home Office allegedly issued a request to Apple to create a backdoor to its encrypted data for government access for national security reasons, which Apple has now appealed in a tribunal.
Before the appeal, however, Apple refused to comply with the request, instead opting to remove its encryption technology, Advanced Data Protection, from the UK rather than create a backdoor for the UK government.
Now, it has been revealed in a blog post that the NCSC has removed previously available guidance on using encryption to protect sensitive messages.
In the blog post, security expert Alex Muffet wrote that the NCSC has removed recommendations for using encryption to protect data for high-risk individuals.
Old guidance, which can be found archived on the WayBackMachine, provided information on encryption tools, incluidng Apple’s ADP technology.
ADP is Apple’s encryption tool for iCloud backups, which would encrypt any data stored on an indivuals’ iCloud, blocking anyone – from cyber-criminals, to Apple, law enforcement, and governments – from viewing stored data.
The same URL now leads to a completely different document produced by the NCSC, which makes no mention of encryption at all, including ADP.
Recommended
- Apple Launches Legal Challenge Over UK Encryption Access
- Encryption: The UK’s Stalemate Between Security and Surveillence
- UK Allegedly Demands ‘Backdoor’ to All Apple Encrypted Data
The new guidance advices high-risk individuals to secure their accounts and devices with multi-factor authentication, and even promotes Apple’s strict ‘Lockdown Mode’, yet neglects to mention encryption.
Prior to the Home Office’s request for backdoor to Apple’s ADP, the NCSC actually advised high-risk individuals to use the encryption tool to protect themsevles, their communication, and their data.
It remains unclear when exactly the NCSC made the change to the document, but Moffet’s screenshot of the previous, encryption-inclusive, guidance was dated to February 21, after the Home Office issued its secret request to Apple.
DIGIT has reached out to NCSC for comment, but has yet to recieve a response.





