Live data from Hacker News

Updating from macOS Ventura to Sonoma Silently Enables iCloud Keychain

lapcatsoftware.com

31–40 of 69 posts

Re: Updating from macOS Ventura to Sonoma Silently Enables iCloud Keychain

#31
An example of "Keychain" abuse is how Facebook so disgustingly tracks you even after you delete all apps, and can track you even after you restore an iCloud Backup ON A NEW PHONE!

• It shows my previous accounts even after I delete the app.

• Clearing Safari's cache does not work.

• Disabling iCloud Drive and iCloud Keychain does not work.

• Even completely signing out of iCloud does not work!

----

WHY can't the user see this data?

WHY can't the user delete this data without going through the app?

WHAT ELSE do apps store on our devices that we aren't even aware of? (This is just what we can see: The list of saved accounts for "quick login")

HOW MANY other apps are secretly doing this?

WHY does Apple even allow this in the first place??

Worst of all, WHY aren't more people raising more of a ruckus about this extremely appalling practice?!

Re: Updating from macOS Ventura to Sonoma Silently Enables iCloud Keychain

#32

Earlier quoted context omitted.

Is it possible to use macOS and iOS without iCloud? I never tried.

macOS yes, though it breaks a lot of the “just works” style integration. On iOS I don’t know how you’d install anything beyond the apps included out of the box so it would be very limited.

> On iOS I don’t know how you’d install anything beyond the apps included out of the box so it would be very limited.

iCloud and App Store are independent. You can sign in to the App Store but not iCloud. In fact I've never used iCloud on my iPhone.

Re: Updating from macOS Ventura to Sonoma Silently Enables iCloud Keychain

#33
post #23

Earlier quoted context omitted.

If it did turn out that Apple was actually able to do what they claim they can't, how would you explain the source that you linked to?

> If it did turn out that Apple was actually able to do what they claim they can't… My friend, I'm afraid I have no idea what you mean. What do you believe Apple claims they can't do that conflicts with this? (If your answer is "end-to-end encryption", Apple has supported this for at least a decade.)

I think what the poster is getting at is:

"How do we validate claims of end-to-end encryption?"

It is a lot of trust to place in a company. I would be curious if there are ways to test Apple's claims?

Re: Updating from macOS Ventura to Sonoma Silently Enables iCloud Keychain

#34
Nobody mentioned this so far, here goes:

The latest 'national security' bill signed into law this April grants the US govt access to any and all commercial hardware. This as I understand it, am I wrong?

Doesnt this imply that every cloud service should be assumed insecure?

Re: Updating from macOS Ventura to Sonoma Silently Enables iCloud Keychain

#35
post #23

Earlier quoted context omitted.

If it did turn out that Apple was actually able to do what they claim they can't, how would you explain the source that you linked to?

> If it did turn out that Apple was actually able to do what they claim they can't… My friend, I'm afraid I have no idea what you mean. What do you believe Apple claims they can't do that conflicts with this? (If your answer is "end-to-end encryption", Apple has supported this for at least a decade.)

Apple claims they cannot decrypt. What will you do if that claim turns out false? That is what the person you are talking with means, and it is very clear throughout the conversation.

Re: Updating from macOS Ventura to Sonoma Silently Enables iCloud Keychain

#36
post #2

This isn't the first time, nor will it be the last: the only reason I'm actually using iCloud Keychain is because, despite always turning it off and feeling like I needed to keep doing it over and over again every time I got a new device, one day I was in a discussion with someone about it and I went to show them how I turn off most of the iCloud features, and I discovered I had actually failed and now had already be…

Don’t you feel so much more secure now?

Re: Updating from macOS Ventura to Sonoma Silently Enables iCloud Keychain

#37
post #4

Earlier quoted context omitted.

> should be easier than the author's attempted workaround of disabling SIP and installing while offline Disabling SIP wasn't an issue, because I had already done it to eliminate slow app launches: https://lapcatsoftware.com/articles/2024/2/3.html On my second attempt, I managed to update without an internet connection. See the new addendum to the article.

> Perhaps disabling System Integrity Protection disables the malware scan too? I haven't checked this, but it's not really viable for me as a Mac software developer, because I need to test the same runtime environment as my users, otherwise I could write code that works for me but not for my users. I'd be a bit careful here by the way. Disabling SIP results in other weird differences too, that may cause programs to r…

Wait, why? Seems like a bad thing to do in CI?

Re: Updating from macOS Ventura to Sonoma Silently Enables iCloud Keychain

#38
post #20

Earlier quoted context omitted.

That is fucking terrifying.

Your laptop storing a Wifi credential locally is terrifying?

I think it’s plain text? Unless recovery environment has a symmetrical encryption scheme and it can decrypt the cypher text stored in nvram?

Re: Updating from macOS Ventura to Sonoma Silently Enables iCloud Keychain

#39
post #19
post #8

Earlier quoted context omitted.

Even with so-called standard data protection, iCloud Keychain passwords are always end-to-end encrypted, and Apple cannot decrypt them. "For additional privacy and security, 15 data categories — including Health and passwords in iCloud Keychain — are end-to-end encrypted. Apple doesn't have the encryption keys for these categories, and we can't help you recover this data if you lose access to your account." https://s…

> Apple cannot decrypt them. How do you know this?

How can you know anything, really?

Re: Updating from macOS Ventura to Sonoma Silently Enables iCloud Keychain

#40

Gah, I didn’t realize that iCloud Keychain was enabled automatically on ios17. I checked and it’s been on for months. Why would they do this? I remember when Microsoft uploaded people’s personal wifi creds in Windows 10. It’s all highly suspect. Stop it. This over sharing by default will doom us all.

> Why would they do this?

Because automatically sharing credentials between devices by default is what most people want, especially younger customers for whom this has always been the normal state of affairs.

Post reply on HN