Live data from Hacker News

Updating from macOS Ventura to Sonoma Silently Enables iCloud Keychain

lapcatsoftware.com

51–60 of 69 posts

Re: Updating from macOS Ventura to Sonoma Silently Enables iCloud Keychain

#51

Earlier quoted context omitted.

> If it did turn out that Apple was actually able to do what they claim they can't… My friend, I'm afraid I have no idea what you mean. What do you believe Apple claims they can't do that conflicts with this? (If your answer is "end-to-end encryption", Apple has supported this for at least a decade.)

I think what the poster is getting at is: "How do we validate claims of end-to-end encryption?" It is a lot of trust to place in a company. I would be curious if there are ways to test Apple's claims?

> "How do we validate claims of end-to-end encryption?"

I'm not a security expert, and you can't prove a negative, so AFAIK the only evidence is the lack of reported incidents where Apple's iCloud Keychain data has been directly hacked or compromised. Given that iOS and iDevices are among the highest-value targets for hackers and nation-states, that seems like reasonably solid evidence.

From a business perspective, lying about such a thing would have virtually zero upside but unimaginably massive downside. It's a great Apple-hater fantasy, though.

Re: Updating from macOS Ventura to Sonoma Silently Enables iCloud Keychain

#52
post #47

An example of "Keychain" abuse is how Facebook so disgustingly tracks you even after you delete all apps, and can track you even after you restore an iCloud Backup ON A NEW PHONE! • It shows my previous accounts even after I delete the app. • Clearing Safari's cache does not work. • Disabling iCloud Drive and iCloud Keychain does not work. • Even completely signing out of iCloud does not work! ---- WHY can't the user…

Could be stored in keychain. But I agree. The user should be asked if they want to clear it on app delete

Not "could be", it's absolutely stored in the keychain.

The iOS keychain isn't visible to the user which is the problem.

Re: Updating from macOS Ventura to Sonoma Silently Enables iCloud Keychain

#53
post #32

Earlier quoted context omitted.

macOS yes, though it breaks a lot of the “just works” style integration. On iOS I don’t know how you’d install anything beyond the apps included out of the box so it would be very limited.

> On iOS I don’t know how you’d install anything beyond the apps included out of the box so it would be very limited. iCloud and App Store are independent. You can sign in to the App Store but not iCloud. In fact I've never used iCloud on my iPhone.

Honest question: how? It seems to me that when I sign in to Apple ID, it automatically signs me in to iCloud. I've found this quite annoying.

Re: Updating from macOS Ventura to Sonoma Silently Enables iCloud Keychain

#54
post #32

Earlier quoted context omitted.

> On iOS I don’t know how you’d install anything beyond the apps included out of the box so it would be very limited. iCloud and App Store are independent. You can sign in to the App Store but not iCloud. In fact I've never used iCloud on my iPhone.

Honest question: how? It seems to me that when I sign in to Apple ID, it automatically signs me in to iCloud. I've found this quite annoying.

> when I sign in to Apple ID, it automatically signs me in to iCloud

Don't do that. You can sign in within the App Store app, but don't sign in anywhere else.

Re: Updating from macOS Ventura to Sonoma Silently Enables iCloud Keychain

#55

Earlier quoted context omitted.

Your laptop storing a Wifi credential locally is terrifying?

I think it’s plain text? Unless recovery environment has a symmetrical encryption scheme and it can decrypt the cypher text stored in nvram?

I just checked nvram -p

It has the SSID in plaintext in current-network and preferred-network, not the passphrase. I’m not sure how it’s obfuscated or encrypted but it is not plaintext

Re: Updating from macOS Ventura to Sonoma Silently Enables iCloud Keychain

#56
post #6

Earlier quoted context omitted.

> perhaps they also enabled it by default in sonoma? No, they didn't. Anyway, iCloud Keychain has always been end to end encrypted.

And only enabled if 2FA is enabled. It won't work without (as won't many Apple services).

Thank you, this was the missing piece of the puzzle for me.

Re: Updating from macOS Ventura to Sonoma Silently Enables iCloud Keychain

#57
post #2

This isn't the first time, nor will it be the last: the only reason I'm actually using iCloud Keychain is because, despite always turning it off and feeling like I needed to keep doing it over and over again every time I got a new device, one day I was in a discussion with someone about it and I went to show them how I turn off most of the iCloud features, and I discovered I had actually failed and now had already be…

Don’t you feel so much more secure now?

Can't tell if sarcasm, but if not:

This is precisely the problem. Apple treats its users as dumb cattle. "We know better. Shut up and be happy with what we force down your throat."

Of course, Apple can do no wrong. Forced lock-in? "Don't you feel so much more secure now that you're firmly in our garden? Our walled garden that you cannot escape from?"

Re: Updating from macOS Ventura to Sonoma Silently Enables iCloud Keychain

#58

Earlier quoted context omitted.

I think what the poster is getting at is: "How do we validate claims of end-to-end encryption?" It is a lot of trust to place in a company. I would be curious if there are ways to test Apple's claims?

> "How do we validate claims of end-to-end encryption?" I'm not a security expert, and you can't prove a negative, so AFAIK the only evidence is the lack of reported incidents where Apple's iCloud Keychain data has been directly hacked or compromised. Given that iOS and iDevices are among the highest-value targets for hackers and nation-states, that seems like reasonably solid evidence. From a business perspective, l…

> so AFAIK the only evidence is the lack of reported incidents

Thank you. That's exactly what I wanted to hear from you. The link you provided is in no way, shape or form actual evidence of what you're suggesting.

> From a business perspective, lying about such a thing would have virtually zero upside but unimaginably massive downside.

What are users going to do? Buy a Surface tablet and a Samsung phone?

> It's a great Apple-hater fantasy, though.

I just dipped my toe into the Apple waters again and bought an m1 air a year or so go. I'm currently shopping for a used iPhone.

I don't have brand loyalty and I use what works, and it just so happens that Apple has been making stuff that works pretty well in my opinion recently. But I'm under no illusion that I can trust them.

Re: Updating from macOS Ventura to Sonoma Silently Enables iCloud Keychain

#60

Earlier quoted context omitted.

One thing I learned from using Little Snitch is that a lot of Apple apps are seemingly immune from these types of firewalls, due to Apple shenanigans around k-ext signing etc [0]. Ref also [1]: > In Big Sur Apple decided to exempt many of its apps from being routed thru the frameworks they now require 3rd-party firewalls to use (LuLu, Little Snitch, etc.) > Q: Could this be (ab)used by malware to also bypass such fir…

This is not longer the case. But another way around is the way VMWare Fusion let you set up networking in Bridged mode. Any traffic from the VM went through without a peep from Little Snitch running on the host. No reason malware couldn't be designed in the same way.

VMware Fusion isn't sandboxed and installs daemons running as root (which requires Gatekeeper approval or bypass to run, followed by an admin password to install the daemons).

AFAIK, XProtect is the only remaining line of defense against malware installed in this way.

Post reply on HN