← Back to Feed

The serpent’s tongue: Luring the Python out of its den

July 14, 2026 · Malwarebytes · Severity: MEDIUM

The UK Home Office has issued a Technical Capability Notice to Apple, demanding access to encrypted iCloud data specifically for British users. This formal order requires Apple to build or maintain technical functions that allow law enforcement to intercept communications or remove encryption protections. Previously, the UK had secretly ordered Apple to provide global access to protected iCloud backups. Apple’s Advanced Data Protection (ADP) offers end-to-end encryption for iCloud backups, which even Apple cannot access. Faced with the Home Office’s demand, Apple chose to withdraw ADP for UK customers starting January 2025 rather than create a backdoor, leaving the feature available elsewhere. This decision has sparked concerns about user privacy and security, as weakening encryption could expose data to breaches and criminal exploitation. Apple has lodged a complaint with the Investigatory Powers Tribunal (IPT), challenging the legality and scope of the Home Office’s powers under the Investigatory Powers Act. Privacy International and Liberty have also filed parallel complaints, questioning the necessity and secrecy of Technical Capability Notices. They advocate for Apple’s case to be heard publicly due to its significant public interest implications. The debate highlights the tension between privacy rights and law enforcement needs, particularly in cases involving terrorism and child exploitation. Critics argue that creating a backdoor could inadvertently aid criminals, who might shift to other platforms beyond legislative reach. This ongoing conflict underscores the broader global struggle over encryption, privacy, and government surveillance.

The UK Home Office has once again demanded Apple allows it access to encrypted iCloud data.

The Guardian reports that the Home Office issued a Technical Capability Notice to Apple, this time targeting only British users. A Technical Capability Notice is a formal government order that compels tech and telecommunications companies to build or maintain specific technical functions—such as intercepting data or removing encryption protections—so law enforcement can access communications.

In the last round of this ongoing battle, the UK secretly ordered Apple to provide blanket access to protected iCloud backups around the world. Advanced Data Protection (ADP) is Apple’s opt‑in end‑to‑end encryption for iCloud backups, which even Apple itself cannot read. Apple argued that weakening or removing ADP would expose users to data breaches and other threats, and instead chose in January 2025 to withdraw ADP for UK customers rather than build a backdoor, while leaving it available elsewhere.

So, instead of working to keep citizens safe and secure, the Home Office just ended up removing an option for them.

Apple has responded by lodging a complaint with the Investigatory Powers Tribunal (IPT), seeking to challenge the scope and lawfulness of the government’s powers to issue such notices under the Investigatory Powers Act. The Tribunal is an independent court that has the power to investigate claims that the UK intelligence services have acted unlawfully.

Privacy International and Liberty have parallel complaints at the IPT challenging Technical Capability Notices more broadly, including their secrecy and necessity, and have asked for Apple’s claim to be heard in public given its wide public-interest implications.

I feel the fear of leaving an intentional backdoor is justified. If it exists, there is a chance that (AI-assisted) criminals will find and exploit it.

Weighing the importance of the right to privacy and the ability to investigate cases including terrorism and child sexual abuse is not easy. Apple’s ADP is used by many and as soon as criminals would know it’s no longer safe for them to use, they’d move to other platforms. Platforms where no legislative power will be able to gain access.

Reddit r/privacy users have been discussing alternatives for a year.

But, given the danger of a backdoor becoming available for criminals, we think in this case privacy should prevail. Let us know how you feel in the comments.


Browse like no one’s watching. 

Malwarebytes Privacy VPN encrypts your connection and never logs what you do, so the next story you read doesn’t have to feel personal. Try it free → 

Key Takeaways

  • Python's popularity, readable syntax, and extensive third-party library ecosystem make it an attractive target for threat actors seeking to compr. Due to the friendly nature of its syntax, extensive capabilities, and wide range of libraries, Python’s adoption by the developer community has.
  • Each technique is assessed for persistence, supported build methods, and distribution compatibility. We conclude with practical defensive.
☕ Buy a Coffee