Categories: MobilitySecurity

Apple Cranks iOS Encryption In Face Of FBI Flak

Apple is to require the use of secure communications for nearly all its iOS applications starting from the beginning of next year, the company announced at its developer conference.

The move extends Apple’s aggressive stance on encryption, which in recent months has seen it face off against the FBI in US court and publicly criticise draft UK legislation that would weaken such tools.

Surveillance fear

Apple, Google and others have placed more of an emphasis on encryption since revelations beginning in 2013 of the mass collection of communications data by the US government for surveillance purposes.

With iOS 9, released in March, Apple introduced a feature called App Transport Security (ATS) that, when in use, causes all unencrypted communications to fail. However, Apple initially gave developers the option of switching ATS off, acknowledging that in many cases the use of secure HTTP, or HTTPS, is not practical.

Now, however, the company has said it will require the use of ATS except in a few cases, with the change set to take place as of 1 January, 2017.

“By the end of 2016, when your apps communicate with your own server back ends, they must do so using a secure TLS channel using TLS 1.2, unless the data being communicated is bulk data such as media streaming and data that’s already encrypted,” Ivan Krstić, Apple’s head of security engineering and architecture, told an audience at the conference, which took place in San Francisco last week.

The change is a significant move for iOS developers, who will now be required to serve all data using HTTPS servers, which are considerably more expensive and complex to manage than those running standard HTTP, notably involving the purchase and administration of security certificates.

Encryption move

Google recently acknowledged this in providing code to developers that would switch ATS off in cases where advertisements using non-HTTPS networks would have failed to display.

“While Google remains committed to industry-wide adoption of HTTPS, there isn’t always full compliance on third party ad networks and custom creative code served via our systems,” Google stated at the time. “To ensure ads continue to serve on iOS9 devices for developers transitioning to HTTPS, the recommended short-term fix is to add an exception that allows HTTP requests to succeed and non-secure content to load successfully.”

Developers writing on Apple forums have questioned how the HTTPS requirement will affect low-cost, unencrypted servers and sites linked to hardware that can’t be made HTTPS-compliant or large public databases that are unlikely to meet the January deadline for encrypting their communications.

Computer security firm Sophos said even with exceptions in place, the move is likely to spur more encryption in applications for devices such as the iPad and the iPhone, increasing their security.

“A year from now, it seems highly likely that most modern mainstream iOS apps will be HTTPS-only,” wrote Sophos’ Bill Camarda in an advisory. “And that can only be good.”

Are you a security pro? Try our quiz!

Matthew Broersma

Matt Broersma is a long standing tech freelance, who has worked for Ziff-Davis, ZDnet and other leading publications

View Comments

  • Data security is a continuous arms race. I commend Apple's efforts at making communications safer.

Recent Posts

Raimondo Downplays Huawei Smartphone Chip

US Commerce Secretary Gina Raimondo says Huawei's flagship smartphone chip 'years behind' US technology, shows…

17 hours ago

Cloud Companies Reject Broadcom VMware Pricing Changes

Cloud companies, business user groups say Broadcom price changes do not address their concerns, as…

17 hours ago

UK Lawsuit Claims Grindr Shared HIV Status

Dating app Grindr sued over claims it shared sensitive user data, including HIV status, with…

18 hours ago

Meta Opens Quest VR OS To Third Party Gadget Makers

Meta Platforms opens operating system behind Quest virtual reality headsets to third parties amidst competition…

18 hours ago

EU Prepares Action Against ‘Addictive’ TikTok Lite Features

European Commission may ban rewards feature in recently launched TikTok Lite that it calls 'toxic…

19 hours ago

TikTok Says New US Ban Effort Would ‘Trample Free Speech’

US House of Representatives passes new bill combining TikTok measures with foreign aid, may face…

1 day ago