Apple expands iCloud encryption, adds hardware key support

Apple cannot decrypt it. Neither can the FBI.
Advanced Data Protection encrypts data only on users' devices, making it inaccessible to Apple, law enforcement, or hackers.
Mark

So Apple is finally encrypting backups? That's been a long time coming.

Mimi

It is, and it's a real change. They're calling it Advanced Data Protection, and it covers 23 categories of data now instead of 14. The key thing is that once you turn it on, Apple literally cannot access your data—not even to help you recover it if something goes wrong.

Luke

Wait. If Apple can't access it, how does recovery work? That seems like a real trade-off users need to understand.

Mimi

That's the tension, yes. You have to keep your recovery key safe yourself. If you lose it and lose access to all your devices, Apple can't help you get back in. It's more secure, but it puts more responsibility on the user.

Mark

And this only applies to certain types of data, right? Not everything?

Mimi

Right. Mail, contacts, and calendar stay unencrypted because those systems have to talk to other services—Gmail, Outlook, whatever. You can't really do end-to-end encryption on something that needs to interoperate globally.

Luke

So the claim is that those three categories are technically impossible to encrypt, or just that Apple hasn't figured it out yet?

Mimi

Apple says it's the technical requirements of those systems. But that's Apple's assessment. Other companies might disagree.

Mark

When does this actually roll out?

Mimi

U.S. beta testers can use it now. Everyone in the U.S. gets it by the end of the year, and the rest of the world in 2023. Plus, early next year, you'll be able to use a physical hardware key to secure your account instead of just a password.

Luke

Has Apple said anything about why they're doing this now, after the FBI pushed back before?

Mimi

Not explicitly. But the pressure from privacy groups has been consistent, and encryption is becoming table stakes for security. Apple's positioning itself as the privacy company, so this fits that narrative.

Mark

Do other companies offer this level of encryption on cloud backups?

Luke

Not really at scale. This would put Apple ahead on that front, assuming the implementation is solid.

  • Apple is encrypting far more of what people store in the cloud — backups, photos, notes, and more — making that data unreachable even to Apple and law enforcement.
  • The FBI has historically pushed back against exactly this kind of protection, arguing it obstructs investigations, yet Apple is proceeding regardless.
  • Privacy groups who spent years demanding this expansion are now watching it materialize, though three data categories — mail, contacts, and calendar — remain outside the new protections due to technical constraints.
  • U.S. users in Apple's beta program can enable the feature now, with full domestic availability by year-end and a global rollout following in 2023.
  • Hardware security keys for iCloud accounts arrive in early 2024, layering physical authentication on top of the encryption overhaul and signaling that strong security is becoming the expected standard, not the exception.

In a moment that quietly reshapes the relationship between personal data and institutional access, Apple has moved to place the encryption keys for most iCloud data firmly in the hands of users themselves. The company's new Advanced Data Protection feature extends end-to-end encryption across 23 categories of stored information — a long-sought threshold that privacy advocates have pressed for, and that law enforcement has long resisted. What unfolds here is not merely a product update, but a philosophical statement about who ultimately owns the digital record of a life.

Apple announced a sweeping upgrade to iCloud security, centering on a new feature called Advanced Data Protection that extends end-to-end encryption from 14 to 23 categories of user data. The change is fundamental: where Apple previously held the encryption keys — enabling account recovery and, when compelled, cooperation with law enforcement — the new system places those keys exclusively on a user's trusted devices. Apple itself cannot decrypt the data. Neither can outside agencies.

The categories now protected include the ones people guard most closely: device backups, photos, messages, notes, reminders, Safari bookmarks, and voice memos. Mail, contacts, and calendar remain outside the new standard for now, as their need to interoperate with third-party services makes end-to-end encryption technically impractical at this stage.

The move carries real historical weight. Apple had reportedly explored similar protections before, only to abandon them following objections from the FBI, which has consistently argued that encryption without backdoors impedes criminal investigations. This time, Apple is proceeding. Privacy advocates who had publicly demanded backup encryption specifically — long considered the most sensitive store of personal data — are seeing that demand met.

The rollout begins with U.S. beta users immediately, expands to all American users by the end of 2022, and reaches global markets in 2023. A further layer arrives in early 2024, when Apple will allow users to secure iCloud accounts with physical hardware security keys — devices that add authentication beyond passwords and two-factor codes, and that have already become standard protection for high-value accounts elsewhere.

Apple announced a substantial overhaul of iCloud security on Wednesday, moving to encrypt far more of what users store in the cloud and making it harder for anyone—including Apple itself—to access that data. The centerpiece is a feature called Advanced Data Protection, which expands end-to-end encryption across iCloud from 14 categories of data to 23.

Under the current system, Apple holds the encryption keys to most iCloud data, which means the company can help you recover information if you lose access to your account. It also means Apple can, in theory, hand over that data to law enforcement if compelled. Advanced Data Protection changes this equation. Once enabled, data encrypted under the new standard lives only on your trusted devices—the phones, tablets, and computers where you're signed into your Apple ID. The encryption happens there, not on Apple's servers. Apple cannot decrypt it. Neither can the FBI, nor hackers attempting to break in through brute force.

The expansion covers the kinds of data people care most about protecting: device backups, messages, photos, notes, reminders, Safari bookmarks, Siri Shortcuts, voice memos, and wallet passes. Three categories remain unencrypted in this way—mail, contacts, and calendar—because those systems need to interoperate with email and calendar services across the internet. Apple says the technical requirements of those systems make end-to-end encryption impractical for now.

This move represents a significant shift for Apple, one that privacy advocates have been pushing for years. Multiple privacy groups have publicly demanded that Apple extend encryption to backups specifically, which are often the most sensitive repositories of personal data. The company had apparently considered doing this before but shelved the plans after the FBI objected. The bureau has long argued that encryption without backdoors hampers law enforcement investigations. Apple is proceeding anyway.

The rollout will be gradual. Users enrolled in Apple's beta testing program in the United States can enable Advanced Data Protection starting immediately. The feature will become available to all U.S. users by the end of 2022, with a global rollout beginning in 2023. Apple is also adding a second security layer: starting in early 2024, users will be able to secure their iCloud accounts with hardware security keys—physical devices that provide an additional authentication factor beyond passwords and two-factor codes. These keys have become standard tools for protecting high-value accounts, and their arrival on iCloud represents another step toward making strong security the default rather than the exception.

Data that's end-to-end encrypted can only be encrypted on your trusted devices where you're signed in with your Apple ID, meaning the tech company or law enforcement cannot access your data from Apple's databases.
— Apple
Vuoi la storia completa? Leggi l'originale su Firstpost ↗
Contattaci Domande frequenti