Tech Tip – Turn On End-to-End Encrypted Backups in WhatsApp

Backing up your chats? Make sure your backups are also encrypted. Otherwise, they could be accessed if your cloud account is compromised.

How to:

– Open WhatsApp and tap ‘Settings’.
– Go to ‘Chats > Chat Backup > End-to-End Encrypted Backup’.
– Tap ‘Turn On’ and create a password or use a 64-digit encryption key.
– Save your password safely. If you lose it, you won’t be able to restore your backup.

Pro-Tip: Encrypting backups ensures your messages stay private even if someone breaches your cloud storage.

Tech News : UK Government Not Allowed To Hide Apple Encryption Battle

A judge has ruled that the UK government’s legal dispute with Apple over encrypted data access must be heard in public, rejecting claims that secrecy was needed for national security reasons.

The Encryption Battle That Spilled Into the Open

At the heart of this case is Apple’s Advanced Data Protection (ADP) system, a tool designed to give users enhanced privacy by encrypting their iCloud data so only they, and not even Apple, can access it. However, that level of security put the tech giant on a collision course with the UK Home Office.

Earlier this year, the government issued a Technical Capability Notice under the Investigatory Powers Act (IPA), demanding that Apple give law enforcement access to data protected by ADP. The move, described by campaigners as a call for a “backdoor,” would have allowed the government to access not just British users’ files, but potentially data from global users as well.

Apple responded by pulling ADP from the UK entirely in February and launching a legal challenge in March, but not before a flurry of criticism from privacy groups and US lawmakers.

The UK government then attempted to have the case heard in secret, claiming even acknowledging the existence of the proceedings could harm national security. However, in the latest development in this matter, the Investigatory Powers Tribunal has issued a sharp rebuttal.

Open Justice Wins (For Now)

In its published ruling, the tribunal said it would be “a truly extraordinary step” to conduct a hearing in total secrecy without even acknowledging that a hearing was happening at all.

“For the reasons that are set out in our private judgement, we do not accept that the revelation of the bare details of the case would be damaging to the public interest or prejudicial to national security,” the tribunal added.

While it’s still possible that parts of future hearings could be held behind closed doors, the decision sets a clear precedent, i.e. that legal disputes with wide-ranging implications for the public shouldn’t be kept out of sight.

Why Does This Matter So Much?

Far from being just a symbolic move, Apple’s decision to withdraw ADP from the UK had real-world consequences for businesses, particularly those relying on Apple’s ecosystem to handle sensitive information. For example, Apple’s ADP offers end-to-end encryption for iCloud data, meaning that not even Apple can decrypt the contents. That includes files like:

– Business documents stored in iCloud Drive.

– Notes containing intellectual property.

– Photos, messages, and device backups.

For firms that operate internationally, ADP is, therefore, a vital part of their data security posture. Without it, UK-based businesses are now left with fewer tools to protect critical data, a point that hasn’t gone unnoticed in the cybersecurity industry.

Worse still, the idea of a government demanding backdoor access could push other vendors to either reduce their own security standards to comply, or retreat from UK markets altogether.

A Chilling Message to the Tech Sector?

Apple has consistently maintained a firm stance against building any form of backdoor or master key into its products or services. The company has long argued that such mechanisms would undermine user trust and pose unacceptable security risks, not just to individuals but to broader digital infrastructure. Apple has been keen to stress that, despite pressure, such as from the UK government, it remains committed to offering its customers the highest level of data protection. Also, while the ADP feature has been removed from the UK for now, Apple has signalled that it hopes to reintroduce it in the future, but only if it can do so without compromising on its encryption standards.

For now, therefore, it seems clear that Apple will not alter ADP to satisfy the UK government’s demands, even though other tech firms, particularly smaller vendors, might struggle to resist such orders or afford lengthy legal battles.

If the Home Office ultimately prevails in its attempt to force Apple’s hand, it could pave the way for future notices targeting other encrypted services. That’s caused alarm among privacy experts, who warn that the UK could become a test bed for surveillance-friendly legislation.

Privacy Advocates Applaud the Ruling

Groups like Open Rights Group, Big Brother Watch, and Index on Censorship, who intervened to oppose secret proceedings, have welcomed the tribunal’s stance.

“This is bigger than the UK and Apple,” said Jim Killock, executive director of Open Rights Group. “The Court’s judgment will have implications for the privacy and security of millions of people around the world.”

Big Brother Watch’s interim director Rebecca Vincent was even more direct, saying: “The Home Office’s order to break encryption represents a massive attack on the privacy rights of millions of British Apple users, which is a matter of significant public interest and must not be considered behind closed doors.”

Also, Privacy International has added that decisions “affecting the privacy and security of billions of people globally should be open to legal challenge in the most transparent way possible”.

National Security and Civil Liberties

As for the UK Home Office, it maintains that its priority is to “keep people safe” and insists the powers in question are tightly targeted and subject to judicial oversight, i.e. that it is not seeking blanket access to user data.

For example, as a Home Office spokesperson was recently quoted as saying: “There are longstanding and targeted investigatory powers that allow the authorities to investigate terrorists, paedophiles and the most serious criminals,” and they “are subject to robust safeguards including judicial authorisations and oversight to protect people’s privacy.”

Not Just Governments To Worry About

However, critics argue that demanding access to encrypted systems, especially those which don’t even allow the vendor to unlock data, could weaken security for everyone. Once a backdoor exists, they warn, it’s not just governments who might exploit it. Cybercriminals, hostile nation-states, and rogue insiders could all potentially discover or gain access to such vulnerabilities, thereby turning a tool meant for law enforcement into a global security risk. History has shown that even tightly controlled security features can leak or be reverse-engineered, making backdoors an attractive target for attackers looking to access sensitive personal, corporate, or state-level data.

Ripple Effects for Tech, Trust and Trade

This dispute has already triggered broader conversations about how democratic governments balance national security with digital rights. It has also raised fresh concerns about the UK’s post-Brexit regulatory environment, especially for tech companies deciding whether to invest or offer full services in the country. For example:

– Messaging services like WhatsApp and Signal, which also use end-to-end encryption, have previously threatened to exit the UK market if forced to compromise security.

– International businesses may reassess how they handle data belonging to UK users if privacy protections appear weaker.

– Cybersecurity vendors could find themselves caught between compliance obligations and user trust.

In short, the ruling that this case must be public is just one chapter in a much bigger battle, and one that could shape the future of encrypted technology, digital trade, and civil liberties in the UK and beyond.

What Does This Mean For Your Business?

The tribunal’s decision to reject secrecy in the Apple case upholds the principle of open justice in matters where both privacy and state power are at stake. Many may say that’s not just a win for transparency, but it also sets a precedent that future legal efforts to reshape the digital privacy landscape must be exposed to public scrutiny.

For UK businesses, the implications are immediate and practical. Many rely on Apple’s secure ecosystem to manage client data, protect sensitive communications, and comply with international privacy standards. Without access to features like ADP, these organisations may now face greater exposure to cyber risks, along with legal and reputational complications when dealing with overseas clients or partners. The uncertainty surrounding encryption standards could also force some firms to rethink their digital strategies altogether, particularly those in regulated sectors like law, finance, or healthcare.

There are also broader questions around competitiveness. If the UK is perceived as an outlier in how it treats encryption, global tech firms may respond by limiting product availability, delaying security updates, or withdrawing features altogether, steps we’ve already seen with Apple. Smaller tech providers may lack the resources to fight back, thereby making them more likely to comply or exit the market, potentially skewing the playing field and reducing the range of secure digital services available to UK consumers and businesses alike.

Also, privacy and civil liberties groups see the ruling as a crucial moment in defending end-to-end encryption, not just as a technical measure, but as a fundamental right. Their argument is that breaking encryption doesn’t just weaken the security of criminals, it weakens it for everyone. As governments around the world watch this case unfold, the UK risks becoming a proving ground for policies that could reshape how digital rights are protected (or compromised) for decades to come.

While this ruling keeps the spotlight on the Apple-Home Office standoff, the underlying conflict is far from resolved. As the case continues through the courts, the balance between public safety, privacy, and corporate responsibility will remain under intense scrutiny. For now, what’s clear is that encryption has become more than just a technical debate, i.e., it’s essentially a litmus test for how the UK defines trust, accountability, and digital sovereignty in a rapidly evolving world.

Featured Article : Public Hearing Demanded For Apple’s UK Encryption

Privacy advocates are calling for Apple’s legal challenge against a secret UK government order to be heard in public, arguing that millions of users’ privacy rights are at stake.

Could Set Precedent

The case, currently set to be conducted behind closed doors, could set a major precedent for the future of encryption and government surveillance.

Why Apple is Fighting the UK Government

At the heart of the issue is Apple’s Advanced Data Protection (ADP) feature, which the company recently withdrew from the UK market after refusing to comply with a government order to provide access (back doors) to encrypted user data. The feature, launched in 2022, offered end-to-end encryption (E2EE) for iCloud backups, photos, and notes, ensuring that only users could access their stored data. Even Apple itself could not decrypt this information, a security measure the company insists is critical to protecting user privacy.

However, the UK government issued a Technical Capability Notice (TCN) under the Investigatory Powers Act 2016 (IPA), compelling Apple to create a mechanism (the ‘back door’ idea) that would allow law enforcement agencies to access encrypted user data when required. Apple refused and instead removed the feature entirely for UK users. While the company has not publicly detailed the exact reasoning, it is widely understood that Apple believes complying with the order would create a security back door, compromising user privacy not just in the UK but globally.

Legal Challenge

Consequently, Apple has now launched a legal challenge against the order, arguing that it is unlawful. But the proceedings are set to take place behind closed doors, prompting major privacy rights groups to intervene and call for transparency.

Why Rights Groups Are Demanding a Public Hearing

Three major privacy advocacy organisations, Open Rights Group, Big Brother Watch, and Index on Censorship, have now written a joint letter to the Investigatory Powers Tribunal (IPT), urging it to open the hearing to public scrutiny rather than conducting it behind closed doors. Their main argument is that millions of users in the UK, as well as international Apple customers, are affected by the case, and they have a right to know how their data security might be compromised.

For example, the letter, addressed to Lord Justice Singh, President of the IPT, states:

“This case implicates the privacy rights of millions of British citizens who use Apple’s technology, as well as Apple’s international users. There is significant public interest in knowing when and on what basis the UK government believes that it can compel a private company to undermine the privacy and security of its customers.”

The rights groups argue that the Investigatory Powers Tribunal has a duty to hold hearings in public unless there is a compelling reason not to, such as a direct threat to national security. In this case, they say, there is no justification for secrecy, as the existence of the TCN has already been widely reported, and Apple has already reacted by withdrawing its encryption service in the UK.

The Legal Battle Over Encryption

The case has sparked fresh debate about encryption and its role in privacy versus law enforcement. Apple has consistently maintained that any back door created for law enforcement could be exploited by hackers and authoritarian regimes, ultimately making data less secure for everyone.

This argument is actually supported by many cybersecurity experts, who warn that once encryption is weakened for one purpose, it cannot be limited to just government use. Criminals, rogue states, and malicious actors could also exploit the vulnerability.

The UK government, however, insists that access to encrypted data is necessary in cases involving national security threats, terrorism, and child abuse investigations. Under the Investigatory Powers Act, companies can be compelled to provide access to data when law enforcement agencies make a valid request. The government claims that Apple’s refusal to comply could hinder criminal investigations.

Could Other Governments Follow the UK’s Lead?

One of the most concerning aspects of the UK’s demand is its potential global impact. For example, if Apple is forced to create a back door for UK law enforcement, this would set a precedent for other countries to demand similar access. This could include authoritarian regimes that might use such powers to suppress political dissidents, journalists, or activists.

Privacy advocates, therefore, argue that weakening encryption in one country may fundamentally undermine encryption everywhere. Once a vulnerability exists, it can be exploited by malicious actors globally. This is why Apple, and other tech companies, have resisted such demands in the past.

For example, in 2016, Apple famously refused to help the FBI unlock an iPhone used by a terrorist in the San Bernardino attack, arguing that doing so would compromise the security of all iPhone users. The FBI eventually paid a third party to crack the device, but the case set an important precedent for tech companies standing firm against government pressure.

Pressure from the US and Other Stakeholders

The UK is not the only place where the case has raised alarms. A group of US politicians, including Senators Ron Wyden and Alex Padilla, has also called on the IPT to hold the hearing in public. In a separate letter, they warned that the UK’s actions could have major security implications for users globally and could lead to a wider erosion of privacy rights.

The BBC has also weighed in, arguing that it should be allowed to report on the hearing given its widespread implications. As media and privacy groups continue to demand openness, the IPT will now have to decide whether to stick with a closed-door approach or allow public scrutiny.

What Does This Mean For Your Business?

The outcome of this case could have significant implications not only for Apple but for the wider technology industry and UK businesses that rely on secure communications. If the Investigatory Powers Tribunal rules in favour of the UK government, it may force tech firms to reconsider their encryption policies, making it more difficult to guarantee data privacy. This could erode trust in cloud storage and digital services, potentially impacting businesses that rely on these technologies to store sensitive corporate information securely.

On the other hand, if Apple prevails, it would send a strong message in defence of encryption, reinforcing the argument that companies should not be required to create vulnerabilities in their own security measures. Such a ruling could also influence similar debates worldwide, particularly as other governments look at introducing legislation that could force tech firms to weaken encryption.

For UK businesses, this legal battle highlights the growing tension between regulatory compliance and cybersecurity. Many companies depend on strong encryption to safeguard intellectual property, financial transactions, and customer data. If the UK government’s position on encryption tightens, firms may need to rethink how they handle data protection and cybersecurity risks.

More broadly, this case highlights deeper concerns about the balance between privacy and national security. For example, governments argue that access to encrypted data is essential for law enforcement, but privacy advocates warn that weakening encryption could expose users to greater risks. The push for transparency in Apple’s legal battle reflects a wider demand for accountability in government surveillance and policymaking.

As the tribunal prepares to make its decision, attention will remain fixed on the potential ramifications for digital privacy. Whether the hearing remains private or is opened to public scrutiny, the ruling will set an important precedent, shaping how governments and tech companies navigate encryption debates in the future. For now, UK users of Apple’s iCloud storage remain without Advanced Data Protection, and the outcome of this case will determine whether they ever get it back.

Security Stop Press : Encryption Risks : New Quantum Chip

Start-up Oxford Ionics (founded 2019) recently reported that its new quantum chip breaks global quantum performance records, providing over twice the performance of previous world records, and without using error correction. What’s more, the company reports that the new quantum chip can be built at scale in existing semiconductor factories.

Dr Michael Cuthbert, Director of the UK’s National Quantum Computing Centre, said: “The new results mark a pivotal step forward in ion trap quantum computing and validates the scalability of the technology.” 

However, although advances in quantum computing and its scalability offer many advantages, they may also increase risks to current encryption methods. For example, algorithms like RSA and ECC, which rely on difficult mathematical problems, could be easily broken by quantum computers using Shor’s algorithm. This makes the development and implementation of quantum-resistant encryption, such as lattice-based cryptography or quantum key distribution, urgently necessary. Immediate action is required to safeguard sensitive data against future quantum threats.

Security Stop Press : Microsoft’s RSA Key Policy Change

Microsoft is making a security-focused policy change that will see RSA keys with lengths shorter than 2048 bits deprecated. RSA keys are algorithms used for secure data encryption and decryption in digital communications, i.e. to encrypt data for secure communications over an enterprise network.

However, with RSA encryption keys becoming vulnerable to advancing cryptographic techniques (driven by advancements in compute power) the decision by Microsoft to depreciate them is being seen as a way to stop organisations from using what is now seen as a weaker method of authentication.

Also, the move by Microsoft will help bring the industry in line with recommendations from the internet standards and regulatory bodies who banned the use of 1024-bit keys in 2013 and recommended that RSA keys should have a key length of 2048 bits or longer.

An Apple Byte : Quantum-Proof iMessage Update

Apple says it’s rolling out an update to its iMessage texting platform that can defend against future encryption-breaking technologies such as decryption by quantum computers.

Apple says its PQ3 “groundbreaking post-quantum cryptographic protocol” offers Level 3 security, i.e. it provides protocol protections that surpass those in all other widely deployed messaging apps. Apple says PQ3 (post-quantum cryptography 3) has the strongest security properties of any at-scale messaging protocol in the world and that it has “rebuilt the iMessage cryptographic protocol from the ground up to advance the state of the art in end-to-end encryption”. 

Although Apple acknowledges that quantum computers with the capability to crack classical public key cryptography algorithms don’t exist yet, it says its PQ3 update offers “the strongest protection against quantum attacks” in the future and is “the only widely available messaging service to reach Level 3 security”.