Live data from Hacker News

Apple silently uploads your passwords and keeps them

lapcatsoftware.com

111–120 of 130 posts

Re: Apple silently uploads your passwords and keeps them

#111
post #66

A crucial point to understand: unbeknownst to me, my passwords ended up on a device that I didn't specifically authorize to download them. The good news is that the device is owned by me and under my control. However, since it's just a test machine with no personal data—or so I believed—it's less protected than my other devices. For example, it has a weak login password, no Filevault, and no biometrics (Mac mini). In…

@lapcat I noticed this part of your post:

>The only way to see the contents of iCloud Keychain is on an Apple device with iCloud Keychain enabled. You can't even see anything on the icloud.com website.

FYI this is because of all contents of iCloud Keychain are end-to-end encrypted, such that only your devices are able to decrypt the data. Apple’s servers do not have access to the contents of a user’s iCloud Keychain.

You might find this article interesting:

https://support.apple.com/guide/security/icloud-keychain-sec...

Also the second part of this Blackhat talk, titled “Synchronizing Secrets” is very interesting and details the design and security architecture of iCloud Keychain: https://youtu.be/BLGFriOKz6U

The relevant part of the talk starts at 22:40.

Re: Apple silently uploads your passwords and keeps them

#112
post #108
post #101

Earlier quoted context omitted.

Why? Why can’t the default state be that I can trust my vendors of software not to gobble up my most private information? OpenBSD has never sent my passwords to Theo’s basement. I trust them without regulations. But more importantly, there’s a crew of capable hackers dissecting the code.

I would like that default, but otherwise it is a bit silly assumption. 1. You can't demand something that cannot be enforced/monitored 2. You can't enforce/ push monitoring if there is no regulation in place, and systems are not transparent. 3. Enforcement/monitoring does not matter if there is no stick (fines) present In the case of OpenBSD, you are using open system that you can verify your self. That alone makes t…

That there isn’t an open, mobile hardware platform is a failure of the community, in my opinion.. although some have the right ideas, framework as an example of an open laptop platform.

We desperately need a free hard- & software (*nix) mobile platform, that is not exclusively owned by a for profit mega corporation and somewhat mainstream amongst the hacker community. Even better would be competing systems. I imagine these systems to have a high degree of modularity, incl. battery, and memory upgrades.

This is not an easy undertaking.

I don’t think regulating the megacorps is the answer. In a commercial world, they have the deeper pockets

Re: Apple silently uploads your passwords and keeps them

#113
post #51

Earlier quoted context omitted.

Companies aren’t people. Compare the benefits to a multi trillion dollar company to maintain security vs the minimal benefits from using your passwords for anything. They really want to avoid the risk from anyone inside the company having access to your passwords and then doing anything with them.

Indeed, companies are not people. Compare the consequences for a large company vs an individual. For the individual, if caught, a debilitating fine and, depending upon damages, jail time. Probable end of career, if related. In short, life changing. For the company, possible fine almost certainly less than the revenue made. Small chance of larger civil suits, with legal costs and possible judgments. Depending upon vis…

A person is likely not to be caught making their downside a fraction to their personal well-being and finances. 1/3 of the people on early would easily see more upside than downside from getting access to your banking info.

Apple on the other hand would see your bank balance as a rounding error to a rounding error, but could easily lose a billion dollar from bad publicity that’s what’s balancing vs any financial upsides. Further, doing it once doesn’t move the needle it needs massive scale and thus massive risks to be worth anything to them.

Re: Apple silently uploads your passwords and keeps them

#114
post #75

Earlier quoted context omitted.

> Apple deprived me of a choice in this case. Settings -> Apple ID -> iCloud -> iCloud Passwords & Keychain -> Sync this Mac In general though having a weak password on a device logged in to iCloud is a bad idea.

> Settings -> Apple ID -> iCloud -> iCloud Passwords & Keychain -> Sync this Mac You clearly didn't even read the article. The whole point was that Apple silently toggled this on without my knowledge or consent.

>You clearly didn't even read the article.

Of course not, I come here for the comments.

Re: Apple silently uploads your passwords and keeps them

#115
post #92

Earlier quoted context omitted.

>[manufacturer] deprived me of a choice in this case This seems to be the industry trend with these remotely managed machines, like Apple or Windows PCs. The update mechanism, for better or worse, takes power from the user and assigns it back to the manufacturer / service provider. It's something that the software world would have considered a Trojan horse some 20 years ago, an extension of control to the end users m…

Might be good for some "average" user but strikes me as bad for software developers or other folks with particular need for tight control.

At work, we discovered that our product doesn't work with Windows 11 because Microsoft forcibly installed W11 on our demo machine the night prior.

If you're curious, it's because the W11 Bluetooth stack is somehow even more broken than W10. Our entirely standard Bluetooth widget can't communicate with W11 PCs and there's really no good way to discover how or why. Bluetooth support is so bad in Windows that I've been assigned to start porting all our software over to Linux. I could go on for hours over this. Windows is so bad.

Re: Apple silently uploads your passwords and keeps them

#116
post #99

The most obnxious aspect of owning an iphone for me. Apple turns icloud syncing on by default for everything, not just password management. Photos, browsing history etc. there should be an account setting that lets you turn this off completely no matter what device you sign into with your icloud account. Completely obnoxious, my icloud photos is a total mess of triple and double copies of photos going back decades i…

I hate default on for cloud sync. It should be opt-in.

Re: Apple silently uploads your passwords and keeps them

#118
post #54

Earlier quoted context omitted.

I understand that Apple claims that this is the case. But given their history of incompetence in the past, that claim affords me little confidence that their closed source software does not contain critical bugs that might lead to recording or exposing the users’ plaintext passwords.

“History of incompetence” really needs some citations, especially for the belief that open source tools are better - they had Gotofail but OpenSSL had Heartbleed, etc. One of the better questions to ask is not how the source code is managed but how it’s audited: there’s a long history of problems in both open and closed software but well audited codebases tend to have them patched before exploits are publicly availab…

"“History of incompetence” really needs some citations"

Former Apple tech, G3/G4 iBook/PowerBook days. Crates of logic boards shipped in - most static-killed due to sand inside the crates. These were supposed to be used for repairing units that failed fresh from the manufacturing line.

NVRAM consistently killed itself.

Let me get out of my date of professional work in Apple repair - Trashcan Mac Pro - That one was very incompetently-designed given how badly people wanted to upgrade it and just could not due to space and thermal constraints.

One of my friends about 4 years ago bought an iMac, 24" model. FIVE RMAs due to hard drive failing. They kept replacing it with the same drive brand and type, and likely from the same manufacturing batch, because that's an INSANELY high RMA rate for a single unit for the same piece of hardware.

And that's just MY horror stories, and only from the HARDWARE perspective.

And Cashmere, Apple's diag software, was a total piece of crap that couldn't tell you half of what was truly wrong with the system. So there's a bit of software horror for ya. Most Apple techs were shooting blind unless it was a specific problem. And the poor OS imaging techs - it's fun having school system laptops that are LOCKED to a specific OSX version and can NOT be upgraded. Not for security, NOTHING. You have to install that specific image for that specific school district, and ship it out. The machines can not be upgraded on the OS side. What a security nightmare that must have been.

Shall I keep going? I'm sure if I thought hard enough I could find more incompetence which I hated while working as an Apple repair tech.

Re: Apple silently uploads your passwords and keeps them

#119

The blurring distinction between local and cloud has gotten so bad that not even a nerd can tell if their device is respecting the privacy border.

It’s pretty easy in macos, you turn off the features explicitly labeled as such in the nice icloud settings menu, or you never log into icloud in the first place

Re: Apple silently uploads your passwords and keeps them

#120
post #89
post #48

They probably encrypt the export with some kind of hash that is then securely transported to the new machine, decrypt it and import. Maybe someone can reverse engineer, attach a debugger and confirm, or analyze the traffic with a Transparent MITM Proxy on the new machine. Just grep for your password in the traffic captured, should be easy. And then write a blog post about that. Let's see what happens.

Or you could read their published security guide at https://help.apple.com/pdf/security/en_US/apple-platform-sec... For the May 2024 version the section on iCloud Keychain is on page 158.

I'm not in this field so I don't have time to read these documents. But I checked it out, and...from my understanding the document describes that they can't see your passwords because they do on device export+encrypt and new device decrypt+import.

Is it like that in reality? Should be easy to confirm with a MITM Transparent Proxy, someone should try to find out. Just out of curiosity.

It's exciting to find a company like Apple making a mistake, and they do make mistakes, but boy do they have quality software and it's getting better by the day. Just have a look at their SDK and interfaces: uniform and practical.

Post reply on HN