Live data from Hacker News

Updating from macOS Ventura to Sonoma Silently Enables iCloud Keychain

lapcatsoftware.com

61–69 of 69 posts

Re: Updating from macOS Ventura to Sonoma Silently Enables iCloud Keychain

#61
post #54

Earlier quoted context omitted.

Honest question: how? It seems to me that when I sign in to Apple ID, it automatically signs me in to iCloud. I've found this quite annoying.

> when I sign in to Apple ID, it automatically signs me in to iCloud Don't do that. You can sign in within the App Store app, but don't sign in anywhere else.

TIL thank you!

Re: Updating from macOS Ventura to Sonoma Silently Enables iCloud Keychain

#62

Earlier quoted context omitted.

> Perhaps disabling System Integrity Protection disables the malware scan too? I haven't checked this, but it's not really viable for me as a Mac software developer, because I need to test the same runtime environment as my users, otherwise I could write code that works for me but not for my users. I'd be a bit careful here by the way. Disabling SIP results in other weird differences too, that may cause programs to r…

Wait, why? Seems like a bad thing to do in CI?

I disabled SIP in our CI environment because with ~5 Xcodes installed and VM images that were reset to a baseline every day or two the malware scanning often literally didn't finish before the VM was reset and it was forced to start over, and while it was running builds took 2-3 times as long.

I probably could have done something fancy where the VMs were left running a day or two before being frozen and deployed, but disabling SIP was the much simpler solution to the problem.

Re: Updating from macOS Ventura to Sonoma Silently Enables iCloud Keychain

#63

Nobody mentioned this so far, here goes: The latest 'national security' bill signed into law this April grants the US govt access to any and all commercial hardware. This as I understand it, am I wrong? Doesnt this imply that every cloud service should be assumed insecure?

Every cloud service should be assumed insecure, but not because of some new law.

Re: Updating from macOS Ventura to Sonoma Silently Enables iCloud Keychain

#67

Earlier quoted context omitted.

Apple claims they cannot decrypt. What will you do if that claim turns out false? That is what the person you are talking with means, and it is very clear throughout the conversation.

Great, so what does he mean by "how would you explain the source that you linked to?", since no part of that conflicts with what I've said or anything else? (I really appreciate the parsing help!)

The source you linked to makes one claim yet you can't verify that claim - that's what they mean.

And we have plenty of historical examples, including recent ones, that big companies are simply lying through their teeth almost every time they open their mouths. Companies that rely heavily upon marketing are lying more so than others.

"Macs don't get viruses" claim made while several Mac viruses existed at the time. It's been lies for decades.

Re: Updating from macOS Ventura to Sonoma Silently Enables iCloud Keychain

#68

Earlier quoted context omitted.

This is not longer the case. But another way around is the way VMWare Fusion let you set up networking in Bridged mode. Any traffic from the VM went through without a peep from Little Snitch running on the host. No reason malware couldn't be designed in the same way.

VMware Fusion isn't sandboxed and installs daemons running as root (which requires Gatekeeper approval or bypass to run, followed by an admin password to install the daemons). AFAIK, XProtect is the only remaining line of defense against malware installed in this way.

So, Little Snitch helps unless your adversary is either really good at what they do or really rich. Maybe nothing can be done in those cases, but I'd like to see the limitations of such software placed on the box.

Re: Updating from macOS Ventura to Sonoma Silently Enables iCloud Keychain

#69

Gah, I didn’t realize that iCloud Keychain was enabled automatically on ios17. I checked and it’s been on for months. Why would they do this? I remember when Microsoft uploaded people’s personal wifi creds in Windows 10. It’s all highly suspect. Stop it. This over sharing by default will doom us all.

> Why would they do this? Because automatically sharing credentials between devices by default is what most people want, especially younger customers for whom this has always been the normal state of affairs.

What you say makes sense for new installs, although even there an explicit and optional consent screen is warranted before doing something as privacy- and security-sensitive as syncing passwords to the cloud. But it's not definitely what's wanted by most people who previously had the feature disabled before the OS update.
Post reply on HN