Live data from Hacker News

Updating from macOS Ventura to Sonoma Silently Enables iCloud Keychain

lapcatsoftware.com

11–20 of 69 posts

Re: Updating from macOS Ventura to Sonoma Silently Enables iCloud Keychain

#12
I had to blink twice last time when I installed Sonoma on a new partition that I did not have to provide a wifi password. This appears to confirm that. While I can understand that some people would appreciate this, I'm not exactly chuffed by a fresh install silently grabbing passwords from an old install.

Re: Updating from macOS Ventura to Sonoma Silently Enables iCloud Keychain

#13
post #6
post #5

i understand and agree that this should at the very least have an opt-in dialog box. that said, apple did add the option for end-to-end encrypted “advanced data protection” for the majority of icloud data a year or so ago. perhaps they also enabled it by default in sonoma? https://support.apple.com/en-us/108756

> perhaps they also enabled it by default in sonoma? No, they didn't. Anyway, iCloud Keychain has always been end to end encrypted.

Right, it's obviously end-to-end encrypted because if it weren't, everyone would have been screaming for years about how horrendously insecure it was.

iCloud Keychain is fine, just use a good password. There's no particular harm in letting Apple store an encrypted blob for you on its servers.

Re: Updating from macOS Ventura to Sonoma Silently Enables iCloud Keychain

#14
post #12

I had to blink twice last time when I installed Sonoma on a new partition that I did not have to provide a wifi password. This appears to confirm that. While I can understand that some people would appreciate this, I'm not exactly chuffed by a fresh install silently grabbing passwords from an old install.

That is not related. Mac computers store the last successful wifi credentials in in the EFI, and use them to give macOS Recovery internet access.

Re: Updating from macOS Ventura to Sonoma Silently Enables iCloud Keychain

#15
post #6
post #5

i understand and agree that this should at the very least have an opt-in dialog box. that said, apple did add the option for end-to-end encrypted “advanced data protection” for the majority of icloud data a year or so ago. perhaps they also enabled it by default in sonoma? https://support.apple.com/en-us/108756

> perhaps they also enabled it by default in sonoma? No, they didn't. Anyway, iCloud Keychain has always been end to end encrypted.

And only enabled if 2FA is enabled. It won't work without (as won't many Apple services).

Re: Updating from macOS Ventura to Sonoma Silently Enables iCloud Keychain

#16
post #12

I had to blink twice last time when I installed Sonoma on a new partition that I did not have to provide a wifi password. This appears to confirm that. While I can understand that some people would appreciate this, I'm not exactly chuffed by a fresh install silently grabbing passwords from an old install.

if you have an iPhone, iPad or any other logged in device with the wifi password it will auto grab it from that device without you doing anything.

Re: Updating from macOS Ventura to Sonoma Silently Enables iCloud Keychain

#18
post #2

This isn't the first time, nor will it be the last: the only reason I'm actually using iCloud Keychain is because, despite always turning it off and feeling like I needed to keep doing it over and over again every time I got a new device, one day I was in a discussion with someone about it and I went to show them how I turn off most of the iCloud features, and I discovered I had actually failed and now had already be…

I had the exact same experience with iCloud Drive (or whatever it is/was called) years ago. I kept turning it off and never agreed to use it and one day discovered it was on anyway and a bunch of my stuff was already in the cloud. Pretty egregious behaviour.

Yeah this is the kind of behaviour that I'm hoping the EU will step in and regulate.

It would be amazing the victims of this kind of egregious privacy violating behavior would receive a cut of the fine that the offender is charged.

That would give people an incentive to report this kind of shit.

Re: Updating from macOS Ventura to Sonoma Silently Enables iCloud Keychain

#19
post #8
post #5

i understand and agree that this should at the very least have an opt-in dialog box. that said, apple did add the option for end-to-end encrypted “advanced data protection” for the majority of icloud data a year or so ago. perhaps they also enabled it by default in sonoma? https://support.apple.com/en-us/108756

Even with so-called standard data protection, iCloud Keychain passwords are always end-to-end encrypted, and Apple cannot decrypt them. "For additional privacy and security, 15 data categories — including Health and passwords in iCloud Keychain — are end-to-end encrypted. Apple doesn't have the encryption keys for these categories, and we can't help you recover this data if you lose access to your account." https://s…

> Apple cannot decrypt them.

How do you know this?

Re: Updating from macOS Ventura to Sonoma Silently Enables iCloud Keychain

#20
post #12

I had to blink twice last time when I installed Sonoma on a new partition that I did not have to provide a wifi password. This appears to confirm that. While I can understand that some people would appreciate this, I'm not exactly chuffed by a fresh install silently grabbing passwords from an old install.

That is not related. Mac computers store the last successful wifi credentials in in the EFI, and use them to give macOS Recovery internet access.

That is fucking terrifying.
Post reply on HN