Live data from Hacker News

Apple silently uploads your passwords and keeps them

lapcatsoftware.com

11–20 of 130 posts

Re: Apple silently uploads your passwords and keeps them

#11
post #3

This may be annoying, but it’s uploading encrypted versions of passwords, not passwords themselves. Keychain is end-to-end encrypted so no one else can read them.

End-to-end encrypted but Apple issues the keys when you log in and I don't think they offer any way to require explicit verification of new devices.

Re: Apple silently uploads your passwords and keeps them

#12
post #10
post #7

Earlier quoted context omitted.

They say they can’t, but it’s impossible to be certain. Although, if you distrust Apple enough to think they might lie about it, you probably wouldn’t want to use any Apple device or services. They already have privileged access to the software and hardware.

> Although, if you distrust Apple enough to think they might lie about it, you probably wouldn’t want to use any Apple device or services. It's not even about lies. It's about bugs and vulnerabilities, which every vendor has.

I'm considered switching to Mac from linux and I came across your blog which has been very informative. What made you chose mac over linux?

Re: Apple silently uploads your passwords and keeps them

#13
post #3

This may be annoying, but it’s uploading encrypted versions of passwords, not passwords themselves. Keychain is end-to-end encrypted so no one else can read them.

If they are uploading the PW and not the hash then… they are uploading the passwords themselves, encrypted or not.

And guess who has the decryption keys…?

Re: Apple silently uploads your passwords and keeps them

#14
post #7

Earlier quoted context omitted.

They say they can’t, but it’s impossible to be certain. Although, if you distrust Apple enough to think they might lie about it, you probably wouldn’t want to use any Apple device or services. They already have privileged access to the software and hardware.

> They already have privileged access to the software and hardware. The fact that the phone manufacturer has a more privileged access than the owner of the phone is absolute insanity.

That's pretty normal, isn't it? Do you have more privileged access to your phone than its kernel does?

Re: Apple silently uploads your passwords and keeps them

#15

Earlier quoted context omitted.

> They already have privileged access to the software and hardware. The fact that the phone manufacturer has a more privileged access than the owner of the phone is absolute insanity.

That's pretty normal, isn't it? Do you have more privileged access to your phone than its kernel does?

I'd prefer it to work like a normal computer where there's a separation of the OS and the hardware. But sure, other phones aren't better.

Re: Apple silently uploads your passwords and keeps them

#16

Earlier quoted context omitted.

That's pretty normal, isn't it? Do you have more privileged access to your phone than its kernel does?

I'd prefer it to work like a normal computer where there's a separation of the OS and the hardware. But sure, other phones aren't better.

I'm not sure I've used any operating system where I have more privilege than the kernel does.

Re: Apple silently uploads your passwords and keeps them

#17
post #3

This may be annoying, but it’s uploading encrypted versions of passwords, not passwords themselves. Keychain is end-to-end encrypted so no one else can read them.

End-to-end encrypted but Apple issues the keys when you log in and I don't think they offer any way to require explicit verification of new devices.

When importing the passwords into a new devices you’re required to enter the device password of whatever device created the password initially.

Still no proof that there’s no back door, but as far as the system on the surface goes, it does make sense.

Re: Apple silently uploads your passwords and keeps them

#18
post #6
post #3

This may be annoying, but it’s uploading encrypted versions of passwords, not passwords themselves. Keychain is end-to-end encrypted so no one else can read them.

Are you sure Apple can’t read them too?

Are you sure AES 256-bit hasn't been broken?

Re: Apple silently uploads your passwords and keeps them

#19
post #10

Earlier quoted context omitted.

> Although, if you distrust Apple enough to think they might lie about it, you probably wouldn’t want to use any Apple device or services. It's not even about lies. It's about bugs and vulnerabilities, which every vendor has.

I'm considered switching to Mac from linux and I came across your blog which has been very informative. What made you chose mac over linux?

I didn't choose Mac over Linux. I chose Mac over Windows in the year 2002, and I became a Mac developer in 2006. Things were a lot different back then. Now it's too late for me, because my entire livelihood depends on Mac.

Re: Apple silently uploads your passwords and keeps them

#20
post #17

Earlier quoted context omitted.

End-to-end encrypted but Apple issues the keys when you log in and I don't think they offer any way to require explicit verification of new devices.

When importing the passwords into a new devices you’re required to enter the device password of whatever device created the password initially. Still no proof that there’s no back door, but as far as the system on the surface goes, it does make sense.

Oh, I didn't notice that. I guess this is using their hosted HSMs to do the PIN check? Otherwise it would be trivial to brute force. But if they are using hosted then I think it can be considered a proper E2EE system.
Post reply on HN