Comment by basisword

6 hours ago

They removed a specific (non-default) feature which provided end to end encryption rather than build a backdoor. They continue to offer encrypted backups etc. although they hold the keys. So not great but also not a backdoor that breaks encryption for everyone and can potential be accessed without legal oversight.

To be a bit more clear:

They offer standard encryption by default, where they hold a copy of your encryption key and can assist you if you lose access to your key.

They also allow you to opt into advanced data protection, where they do not have a copy of your encryption key, so you need to be sure you protect it yourself.

If a company has a copy of the customer's encryption key on their server, you have no choice but to hand it over in response to a warrant, as we recently saw with Microsoft handing over the bitlocker key for a customer's computer.