The original implementation of iCloud included Apple's ability to recover the data. You can view this as a backdoor, and that might be fair, but the reality is that it's also a feature in the eyes of many customers - because people will lose devices and passwords, and when Apple doesn't have the keys that means they also lose data. Many customers would rather be able to get their data back.
Apple has moved more things into the bucket of "we do not have the keys for this" over time, but pretending that this isn't a tradeoff for the common customer is disingenuous. That's why ADP exists, so that those who want to make a different tradeoff can do so.
Commenters on HN tend to be technically savvy and tend to want the defaults to be tailored to a technically savvy customer base. That's fine, but that's not a real representation of all of the smartphone users out there, and in this case Apple is directly offering the choice that they usually get knocked for taking away.
Except they don't really. If you're in a convo there only needs to be one user who doesn't have ADP turned on and uses iCloud. And all your data is leaked.
It should be possible to force your messages to be excluded from backup even by recipients. Otherwise it's just for show when it comes to real life.
> And all your data is leaked.
Not all your data, just the data exchanged with that person.
But how could you force this? They could always copy it or whatever. Yes, I know, defaults.
But this would then need to be somehow enforced on the other side, right? Like preventing copying, or screenshotting, etc. And in that case, see the HN thread the other day about applications messing with these functions and how people want their devices to be theirs and not controlled by some third party.
> Yes, I know, defaults.
You gave the answer yourself. If the person you are writing with has E2EE enabled for message backups then just exclude that chat from backups on your end or enable E2EE for that chat. That means if you take the restore route without having access to the keys that conversation will not be restored.
You could even let people overwrite that setting. Preventing screenshots or copying has nothing to with this. Apple is claiming that message are end to end encrypted when in reality their defaults are set so that they are not. That is a lie and al they would need to do to change that is to change those defaults.