Jon Millican

@jonmillican.bsky.social

Applied privacy engineer in the UK. Currently at OpenAI. Previously helped to lead end-to-end encryption for Messenger at Meta. he/him

I've seen a lot of chatter today about Instagram ending support for optional End-to-End Encrypted DMs. I helped to lead on cryptography and privacy for E2EE in Messenger and Instagram for many years, until I left around 10 months ago, so it's disappointing to see it being removed from Instagram.

I've seen a lot of chatter today about Instagram ending support for optional End-to-End Encrypted DMs. I helped to lead on cryptography and privacy for E2EE in Messenger and Instagram for many years, until I left around 10 months ago, so it's disappointing to see it being removed from Instagram.

We at the Internet Society are deeply disappointed that Apple has had to stop offering end-to-end encryption in the UK. The following can be attributed to Dr. Joseph Lorenzo Hall, Distinguished Technologist at the Internet Society: 1/

The following can be attributed to Dr. Joseph Lorenzo Hall, Distinguished Technologist at the Internet Society:

The Internet Society is saddened at the news that Apple has removed access to its cloud end-to-end encryption, known as Advanced Data Protection, for its UK users as a result of pressure by the UK government. This move will make British Apple users less safe, and make their cloud data more susceptible to criminals and other attackers. It is clear that the UK government continued to pressure Apple to weaken the security of its service despite global outcry from cybersecurity experts, civil society, private industry, and foreign politicians. 

In choosing to remove the feature rather than building a backdoor into its Advanced Data Protection, Apple ensured that at least its global users would continue to benefit from the security and privacy of end-to-end encryption. However, for UK users, their government ensured that their security and privacy is worse than before.

"The British government’s undisclosed order, issued last month, requires blanket capability to view fully encrypted material, not merely assistance in cracking a specific account, and has no known precedent in major democracies."

U.K. orders Apple to let it spy on users’ encrypted accounts

Secret order requires blanket access to protected cloud backups around the world, which if implemented would undermine Apple’s privacy pledge to its users.

washingtonpost.com

Given that E2EE messaging is coming to Bluesky, now seems a good time to cross-post a thread of mine from Threads, briefly discussing one of the interesting non-obvious tradeoffs that we had to consider around message history.