Live data from Hacker News

Apple silently uploads your passwords and keeps them

lapcatsoftware.com

101–110 of 130 posts

Re: Apple silently uploads your passwords and keeps them

#101
post #68
post #65

Earlier quoted context omitted.

Sorry, this is false. You can absolutely to a high degree protect and store data, including the safe removal. An organisation like Apple should absolutely be forced to delete the data, especially data collected using deceptive tactics

> You can absolutely to a high degree protect and store data, including the safe removal. > An organisation like Apple should absolutely be forced to delete the data, especially data collected using deceptive tactics As long as there are no consequences (regulation checks with fines) of not doing it correctly and/or if there is no observability and enforceability, it is just talk and does not matter in practice. Esse…

Why? Why can’t the default state be that I can trust my vendors of software not to gobble up my most private information?

OpenBSD has never sent my passwords to Theo’s basement. I trust them without regulations. But more importantly, there’s a crew of capable hackers dissecting the code.

Re: Apple silently uploads your passwords and keeps them

#102
post #96

All the trust-us data-grabby pushes by Apple products creeped me out, until I finally got rid of their products. For example, although I laboriously went through a ton of settings to make it less privacy-invading, I knew, for example, that I was still only one fumbled touch to a piece of glass away from Apple saying, "Oh, hey! I just grabbed all of your photos! Forever!" (Then Apple would say "Thanks!" in a sunny Cal…

What do you use now instead?

Re: Apple silently uploads your passwords and keeps them

#103
post #94
post #80

Earlier quoted context omitted.

Me: work-related activities are mostly what I use a computer for, so I'm not sure what I would even do with Linux. You: You'd be more in control over having your passwords silently uploaded to a third party without your knowledge or consent If I mostly use a computer for work purposes, what do you think my passwords are for? Also, I've been using a Mac since 2002, and iCloud Keychain got toggled on in 2024. It's kind…

Not sure where or what "work passwords" has to do with it, passwords are passwords especially if you're running your own business, which it seems you are. Do your thing buddy, but I'm not the one who had their (work) passwords were silently uploaded to iCloud without permission.

> Not sure where or what "work passwords" has to do with it

How many times do I have to explain that I use a computer mostly to do work, which is development of Apple software, requiring a Mac, and therefore most of my computer usage is necessarily on a Mac. Consequently, switching to a Linux machine as a "daily driver" is pointless, because I have nothing much to "drive" daily except my work.

Re: Apple silently uploads your passwords and keeps them

#105
post #75

Earlier quoted context omitted.

> Settings -> Apple ID -> iCloud -> iCloud Passwords & Keychain -> Sync this Mac You clearly didn't even read the article. The whole point was that Apple silently toggled this on without my knowledge or consent.

So do Chrome and Firefox. If you sign into them, they download your saved passwords which were uploaded to their clouds.

I think firefox asked me what I want to sync

Re: Apple silently uploads your passwords and keeps them

#106

The blurring distinction between local and cloud has gotten so bad that not even a nerd can tell if their device is respecting the privacy border.

It begins with the choice of operating system. Getting Windows/OSX to not phone home is one thing, ensuring it stays that way as the updates come in is another can of worms entirely.

Re: Apple silently uploads your passwords and keeps them

#107
post #54

Earlier quoted context omitted.

“History of incompetence” really needs some citations, especially for the belief that open source tools are better - they had Gotofail but OpenSSL had Heartbleed, etc. One of the better questions to ask is not how the source code is managed but how it’s audited: there’s a long history of problems in both open and closed software but well audited codebases tend to have them patched before exploits are publicly availab…

> “History of incompetence” really needs some citations Here’s a big one: https://arstechnica.com/gadgets/2007/11/be-cautious-of-that-... The article contains few details. More insight is at the discussion on https://www.cableforum.uk/board/showthread.php?p=34430700 Briefly, when implementing file moving in (closed source) Finder code, someone at Apple who was apparently a beginner programmer or student intern made a…

So you’re saying that having a data loss condition 17 years ago which only affected a subset of users who lost their storage connection in the middle of a move operation tells us something about their products today? Does that also mean that I shouldn’t use Linux because ReiserFS lost data on local storage in some cases back then, or btrfs did so more recently?

What policy are you saying we should use to evaluate software? In particular, what’s left if we’re saying it’s no longer good enough to have learned from mistakes? I supported a lab full of computational scientists who heavily used their Macs with external storage at that time and this caused no problems for anyone, so I also am looking for something more quantitative like whether a bug which only affected handful of users disqualifies usage for everyone.

Re: Apple silently uploads your passwords and keeps them

#108
post #101
post #68

Earlier quoted context omitted.

> You can absolutely to a high degree protect and store data, including the safe removal. > An organisation like Apple should absolutely be forced to delete the data, especially data collected using deceptive tactics As long as there are no consequences (regulation checks with fines) of not doing it correctly and/or if there is no observability and enforceability, it is just talk and does not matter in practice. Esse…

Why? Why can’t the default state be that I can trust my vendors of software not to gobble up my most private information? OpenBSD has never sent my passwords to Theo’s basement. I trust them without regulations. But more importantly, there’s a crew of capable hackers dissecting the code.

I would like that default, but otherwise it is a bit silly assumption.

1. You can't demand something that cannot be enforced/monitored

2. You can't enforce/ push monitoring if there is no regulation in place, and systems are not transparent.

3. Enforcement/monitoring does not matter if there is no stick (fines) present

In the case of OpenBSD, you are using open system that you can verify your self. That alone makes them less likely to do something malicious (since they might get caught more likely!) and changes the trust. There is no financial carrot to make Apple products visible, as most of the users don't understand a thing about the technology and marketing might be more efficient than opening technology, which might result in intellectual property theft and lose of market position.

Since everything cannot be transparent in a competitive and commercial world, I think it would be okay to put at least 10 times bigger fines for those who do not have transparent systems and get caught on not following the regulations to get some balance.

Re: Apple silently uploads your passwords and keeps them

#109
post #96

All the trust-us data-grabby pushes by Apple products creeped me out, until I finally got rid of their products. For example, although I laboriously went through a ton of settings to make it less privacy-invading, I knew, for example, that I was still only one fumbled touch to a piece of glass away from Apple saying, "Oh, hey! I just grabbed all of your photos! Forever!" (Then Apple would say "Thanks!" in a sunny Cal…

What do you use now instead?

For smartphone, GrapheneOS.

For tablet, I was using a PocketBook ereader (which works fine airgapped, and is friendly towards DRM-free ebooks, and doesn't need jailbreaking).

For most purposes, Debian Stable on my laptop, and on my GPU server.

Re: Apple silently uploads your passwords and keeps them

#110
post #66

A crucial point to understand: unbeknownst to me, my passwords ended up on a device that I didn't specifically authorize to download them. The good news is that the device is owned by me and under my control. However, since it's just a test machine with no personal data—or so I believed—it's less protected than my other devices. For example, it has a weak login password, no Filevault, and no biometrics (Mac mini). In…

I had a similar but more concerning experience. I enabled family sharing (years ago when it was newer) and suddenly my spouse had access to many (all?) of MY passwords in HER keychain. I never knowingly granted access or put any passwords in a non-personal group — it just happened like magic.
Post reply on HN