Live data from Hacker News

Updating from macOS Ventura to Sonoma Silently Enables iCloud Keychain

lapcatsoftware.com

41–50 of 69 posts

Re: Updating from macOS Ventura to Sonoma Silently Enables iCloud Keychain

#41
post #23

Earlier quoted context omitted.

I provided both a citation and the relevant quote from it.

If it did turn out that Apple was actually able to do what they claim they can't, how would you explain the source that you linked to?

Posing a hypothetical without any evidence of that being true is not a valid rebuttal.

Re: Updating from macOS Ventura to Sonoma Silently Enables iCloud Keychain

#42

Earlier quoted context omitted.

> If it did turn out that Apple was actually able to do what they claim they can't… My friend, I'm afraid I have no idea what you mean. What do you believe Apple claims they can't do that conflicts with this? (If your answer is "end-to-end encryption", Apple has supported this for at least a decade.)

Apple claims they cannot decrypt. What will you do if that claim turns out false? That is what the person you are talking with means, and it is very clear throughout the conversation.

Great, so what does he mean by "how would you explain the source that you linked to?", since no part of that conflicts with what I've said or anything else? (I really appreciate the parsing help!)

Re: Updating from macOS Ventura to Sonoma Silently Enables iCloud Keychain

#43
post #28

If people wonder about things, they should install Little Snitch and see how often apple apps phone home. It's amazing. Not only after install, but hours and days later will apps start quietly phoning home.

One thing I learned from using Little Snitch is that a lot of Apple apps are seemingly immune from these types of firewalls, due to Apple shenanigans around k-ext signing etc [0].

Ref also [1]: > In Big Sur Apple decided to exempt many of its apps from being routed thru the frameworks they now require 3rd-party firewalls to use (LuLu, Little Snitch, etc.) > Q: Could this be (ab)used by malware to also bypass such firewalls? > A: Apparently yes, and trivially so

[0] https://x.com/patrickwardle/status/1318437929497235457 [1] https://x.com/patrickwardle/status/1327726496203476992

Re: Updating from macOS Ventura to Sonoma Silently Enables iCloud Keychain

#44
post #28

If people wonder about things, they should install Little Snitch and see how often apple apps phone home. It's amazing. Not only after install, but hours and days later will apps start quietly phoning home.

One thing I learned from using Little Snitch is that a lot of Apple apps are seemingly immune from these types of firewalls, due to Apple shenanigans around k-ext signing etc [0]. Ref also [1]: > In Big Sur Apple decided to exempt many of its apps from being routed thru the frameworks they now require 3rd-party firewalls to use (LuLu, Little Snitch, etc.) > Q: Could this be (ab)used by malware to also bypass such fir…

Apple removed the exclusion list: https://obdev.at/blog/a-wall-without-a-hole/

Re: Updating from macOS Ventura to Sonoma Silently Enables iCloud Keychain

#45

Earlier quoted context omitted.

> If it did turn out that Apple was actually able to do what they claim they can't… My friend, I'm afraid I have no idea what you mean. What do you believe Apple claims they can't do that conflicts with this? (If your answer is "end-to-end encryption", Apple has supported this for at least a decade.)

I think what the poster is getting at is: "How do we validate claims of end-to-end encryption?" It is a lot of trust to place in a company. I would be curious if there are ways to test Apple's claims?

It's not just trust in a company. Matthew Green was geeking out about iCloud Keychain privacy a few years ago. He sometimes speaks of contacts in Apple security who are really committed and competent engineers. Their professional reputations are on the line too. Nothing would damage their careers like a backdoor that conspiracy types love to speculate on.

Re: Updating from macOS Ventura to Sonoma Silently Enables iCloud Keychain

#46
post #44

Earlier quoted context omitted.

One thing I learned from using Little Snitch is that a lot of Apple apps are seemingly immune from these types of firewalls, due to Apple shenanigans around k-ext signing etc [0]. Ref also [1]: > In Big Sur Apple decided to exempt many of its apps from being routed thru the frameworks they now require 3rd-party firewalls to use (LuLu, Little Snitch, etc.) > Q: Could this be (ab)used by malware to also bypass such fir…

Apple removed the exclusion list: https://obdev.at/blog/a-wall-without-a-hole/

Huh, that was a pretty quick turn around for Apple, glad to know.

Now if only they'd stop trying to get me to enable iCloud Drive just because I use an iPhone for work.

Re: Updating from macOS Ventura to Sonoma Silently Enables iCloud Keychain

#47

An example of "Keychain" abuse is how Facebook so disgustingly tracks you even after you delete all apps, and can track you even after you restore an iCloud Backup ON A NEW PHONE! • It shows my previous accounts even after I delete the app. • Clearing Safari's cache does not work. • Disabling iCloud Drive and iCloud Keychain does not work. • Even completely signing out of iCloud does not work! ---- WHY can't the user…

Could be stored in keychain.

But I agree. The user should be asked if they want to clear it on app delete

Re: Updating from macOS Ventura to Sonoma Silently Enables iCloud Keychain

#48
post #28

If people wonder about things, they should install Little Snitch and see how often apple apps phone home. It's amazing. Not only after install, but hours and days later will apps start quietly phoning home.

One thing I learned from using Little Snitch is that a lot of Apple apps are seemingly immune from these types of firewalls, due to Apple shenanigans around k-ext signing etc [0]. Ref also [1]: > In Big Sur Apple decided to exempt many of its apps from being routed thru the frameworks they now require 3rd-party firewalls to use (LuLu, Little Snitch, etc.) > Q: Could this be (ab)used by malware to also bypass such fir…

This is not longer the case.

But another way around is the way VMWare Fusion let you set up networking in Bridged mode. Any traffic from the VM went through without a peep from Little Snitch running on the host. No reason malware couldn't be designed in the same way.

Re: Updating from macOS Ventura to Sonoma Silently Enables iCloud Keychain

#49
post #12

I had to blink twice last time when I installed Sonoma on a new partition that I did not have to provide a wifi password. This appears to confirm that. While I can understand that some people would appreciate this, I'm not exactly chuffed by a fresh install silently grabbing passwords from an old install.

How would it have synced the wifi password from iCloud without the wifi password one wonders?

Re: Updating from macOS Ventura to Sonoma Silently Enables iCloud Keychain

#50
post #12

I had to blink twice last time when I installed Sonoma on a new partition that I did not have to provide a wifi password. This appears to confirm that. While I can understand that some people would appreciate this, I'm not exactly chuffed by a fresh install silently grabbing passwords from an old install.

if you have an iPhone, iPad or any other logged in device with the wifi password it will auto grab it from that device without you doing anything.

I believe this is just iCloud Keychain in action.

The other commenter is correct - the last (few?) Wi-Fi passwords are stored in NVRAM so that the recovery environment can connect to the network more conveniently.

Post reply on HN