No, you're just wrong, even if your statements were right which they aren't either. Again, by your logic every single communication system on iOS is "backdoored" simply because iCloud Backup exists. Or for that matter any comms method on Linux or FreeBSD or macOS or Windows if someone makes unencrypted backups. That's horse shit, and it degrades the specificity and value of the term "backdoor" in the same way as "bricked" has become. Backdooring is a specific part of a given product/stack, a covert method of bypassing regular authentication. There is no convert status here, Apple clearly lays out exactly what components of iCloud are encrypted and how in their "iCloud security overview" [0]. And it's not as if E2EE backups have no downsides mass market, it means that users are fully responsible for their data with zero recovery possible. I still think Apple is wrong to not offer even the capability to do better wirelessly/networked and in fact that should be against the law, but it's not a "backdoor" and if there were options I'm sure lots of people would still pick the "recoverable in an emergency" one. Think, if it turns out there actually
is a backdoor in iMessage, like a secret second key that can be applied to any MITM'd data to decrypt it, how would you even describe that pray tell as different from "choosing to use a non-E2EE backup method"? Or do you not think any differentiation there would matter, that such a thing would be identical to you saying right now that "Signal has a backdoor"? All that said:
>a) on by default
I've never seen it on by default, it's a toggle. I can't find anything to support this assertion, and Apple's docs seem to indicate too it must be turned on [1]. How would it even be possible for this to work? Apple only gives you 5GB by default, and backups absolutely count against the quota.
>and b) isn’t clearly marked as being readable to Apple
As I linked they do clearly convey that. If you think it should be some extra warning dialog on enabling it, maybe that's a criticism, but there's certainly no standard around that across software industry-wide including on computers. Whether something is E2EE or not is usually something those that care need to look up. Maybe that should change. But no, it's not a "backdoor in practice".
>Let’s not even talk about Chinese users, as apparently Apple bending over to store all their data in CCP data centers doesn’t count.
No let's not, and no it doesn't here. That's a case with a lot more complexity then tends to come out on HN where instead people like you use it as a lazy bit of whataboutism. Apple is in the wrong there, and the US for allowing/encouraging it as well, but not for the same reasons as with the FBI and the path away from it is very different and harder as well. They deserve major blame in both cases, but why they deserve blame differs, and that matters.
----
0: https://support.apple.com/en-us/HT202303
1: https://support.apple.com/guide/iphone/back-up-iphone-iph3ec...