What Lockdown Mode is for
Lockdown Mode is Apple's extreme protection for people who may be targeted by sophisticated, well-resourced attacks — the mercenary spyware threat model, not the everyday one.
It works by reducing attack surface: limiting certain message attachment types, restricting some web technologies, blocking particular wired connections, and constraining features that have historically been exploitation paths.
Why that does not make it a photo vault
Reducing remote attack surface and separating your photo library from someone holding your unlocked phone are unrelated problems.
Lockdown Mode does not encrypt the Photos library, does not require a distinct credential to view images, and does not hide anything from a person who is authenticated on the device. Someone with the passcode sees exactly what they would have seen otherwise.
It is not a general recommendation
Apple is explicit that Lockdown Mode is for a small number of people at specific risk, and that it meaningfully reduces functionality. Enabling it broadly trades away capability for protection against a threat most users do not face.
Recommending it as a general privacy measure is a common error in security writing, and it usually indicates the recommendation was not matched to a threat model.
Using it correctly, if it applies to you
- Enable it for its documented threat model, not as general hardening.
- Apply it consistently across supported connected devices, since inconsistency reintroduces the gap.
- Continue applying ordinary photo, account and device privacy controls separately.
- Expect and plan for the feature limitations rather than disabling it situationally.
Misstatements to avoid
- Recommending it to everyone as a privacy improvement.
- Describing it as photo encryption or a vault feature.
- Assuming it protects against someone who has your device and passcode.
A fictional example
Eli starts with a non-sensitive test: “Use Lockdown Mode only for its documented threat model.” Next, Eli follows the second check: “Apply ordinary photo, account, and device privacy controls separately.” This fictional scenario demonstrates the decision process; it is not a report of product testing.
Common mistakes
- Recommending it to everyone
- Calling it photo encryption
What this workflow does not change
- Recommending it to everyone
- Calling it photo encryption
Questions people ask
Who should use it?
Apple says most people are never targeted by the sophisticated attacks it is designed to address.