Live data from Hacker News

Apple silently uploads your passwords and keeps them

lapcatsoftware.com

61–70 of 130 posts

Re: Apple silently uploads your passwords and keeps them

#61
post #51
post #46

Earlier quoted context omitted.

The only person guaranteeing this is the case and will stay the case is the person keeping your passwords. That seems to me to be a pretty wild thing to have faith in.

Companies aren’t people. Compare the benefits to a multi trillion dollar company to maintain security vs the minimal benefits from using your passwords for anything. They really want to avoid the risk from anyone inside the company having access to your passwords and then doing anything with them.

Indeed, companies are not people.

Compare the consequences for a large company vs an individual.

For the individual, if caught, a debilitating fine and, depending upon damages, jail time. Probable end of career, if related.

In short, life changing.

For the company, possible fine almost certainly less than the revenue made. Small chance of larger civil suits, with legal costs and possible judgments. Depending upon visibility, perhaps some additional PR spend. Even if the sum total cost is greater than the associated revenue, those costs can be used to offset tax liability.

In short, low risk of existential threat, or even actual financial loss -- just reduced profits.

Re: Apple silently uploads your passwords and keeps them

#62
post #55

Earlier quoted context omitted.

> You just open Keychain/Passwords and delete the passwords. This also deletes the local copy of the passwords.

There is a separate iCloud Keychain so you can just copy to your local one. Or use the Export All Passwords feature in the Passwords app.

> There is a separate iCloud Keychain

No, there is not. If there was a separate iCloud Keychain, then my passwords never would have gotten uploaded in the first place. Most of these passwords were Safari web form logins. Safari stores them where it wants.

> Or use the Export All Passwords feature in the Passwords app.

Export them to where? I want to use the operating system to store my passwords locally. I just don't want them in iCloud.

Re: Apple silently uploads your passwords and keeps them

#63
post #58

Earlier quoted context omitted.

Of course. Apple has to decrypt the passwords when it pre-fills the browser. And the decryption keys are stored on your devices in the Secure Enclave. Apple doesn’t have the keys on their servers.

Either way the passwords are being uploaded, which is the comment I was replying to.

The ciphertext is not the plaintext (obviously). So an encrypted password is not a password. An encrypted password is a string resulting from the application of an encryption algorithm and a key to a password. Uploading that string is not uploading the password.

The fact that Apple's software can access the keys stored on the device to decrypt the password after you securely authenticate is neither here nor there.

Re: Apple silently uploads your passwords and keeps them

#64
post #54

Earlier quoted context omitted.

I understand that Apple claims that this is the case. But given their history of incompetence in the past, that claim affords me little confidence that their closed source software does not contain critical bugs that might lead to recording or exposing the users’ plaintext passwords.

“History of incompetence” really needs some citations, especially for the belief that open source tools are better - they had Gotofail but OpenSSL had Heartbleed, etc. One of the better questions to ask is not how the source code is managed but how it’s audited: there’s a long history of problems in both open and closed software but well audited codebases tend to have them patched before exploits are publicly availab…

> “History of incompetence” really needs some citations

Here’s a big one: https://arstechnica.com/gadgets/2007/11/be-cautious-of-that-...

The article contains few details. More insight is at the discussion on https://www.cableforum.uk/board/showthread.php?p=34430700

Briefly, when implementing file moving in (closed source) Finder code, someone at Apple who was apparently a beginner programmer or student intern made an elementary error that reliably destroyed files. The system already had a battle-tested mv command in its BSD subsystem, but they didn’t use that code. The point of this story (and, yes, there is a large handful of similar stories) is what it tells you about Apple’s culture and practices around testing, care, and concern for real soundness and quality (as opposed to appearance).

Re: Apple silently uploads your passwords and keeps them

#65
post #36
post #5

Earlier quoted context omitted.

They silently enable the option to store in the Cloud on OS update? They offer no option to delete your passwords from the Cloud once there? If that's indeed how they all/always work, we shouldn't just Stockholm-syndrome accept it!

> They offer no option to delete your passwords from the Cloud once there? Does it matter tho. Like in general internet, once something is posted, it will not disappear with certainty. We can never be certain that there is a copy of the encrypted password on some log file when we have no visibility into that sytem. Since it is encrypted, it passes the regulation checks. That is just a UI bug if passwords keep coming…

Sorry, this is false.

You can absolutely to a high degree protect and store data, including the safe removal.

An organisation like Apple should absolutely be forced to delete the data, especially data collected using deceptive tactics

Re: Apple silently uploads your passwords and keeps them

#66
A crucial point to understand: unbeknownst to me, my passwords ended up on a device that I didn't specifically authorize to download them.

The good news is that the device is owned by me and under my control. However, since it's just a test machine with no personal data—or so I believed—it's less protected than my other devices. For example, it has a weak login password, no Filevault, and no biometrics (Mac mini).

In general, the presence of my passwords in the cloud is an unwanted and unnecessary liability for me. I understand that for other people, cloud storage is a benefit, and I don't wish to deprive them of that choice. Nonethless, Apple deprived me of a choice in this case.

Re: Apple silently uploads your passwords and keeps them

#67
post #51

Earlier quoted context omitted.

Companies aren’t people. Compare the benefits to a multi trillion dollar company to maintain security vs the minimal benefits from using your passwords for anything. They really want to avoid the risk from anyone inside the company having access to your passwords and then doing anything with them.

Indeed, companies are not people. Compare the consequences for a large company vs an individual. For the individual, if caught, a debilitating fine and, depending upon damages, jail time. Probable end of career, if related. In short, life changing. For the company, possible fine almost certainly less than the revenue made. Small chance of larger civil suits, with legal costs and possible judgments. Depending upon vis…

The company will also consider the benefits of cooperating with Spook Agency Inc.

Maybe a plunge protection stock-price guarantee.

Or NOT.

Re: Apple silently uploads your passwords and keeps them

#68
post #65
post #36

Earlier quoted context omitted.

> They offer no option to delete your passwords from the Cloud once there? Does it matter tho. Like in general internet, once something is posted, it will not disappear with certainty. We can never be certain that there is a copy of the encrypted password on some log file when we have no visibility into that sytem. Since it is encrypted, it passes the regulation checks. That is just a UI bug if passwords keep coming…

Sorry, this is false. You can absolutely to a high degree protect and store data, including the safe removal. An organisation like Apple should absolutely be forced to delete the data, especially data collected using deceptive tactics

> You can absolutely to a high degree protect and store data, including the safe removal.

> An organisation like Apple should absolutely be forced to delete the data, especially data collected using deceptive tactics

As long as there are no consequences (regulation checks with fines) of not doing it correctly and/or if there is no observability and enforceability, it is just talk and does not matter in practice. Essentially, until the previous applies, it is just exchanging trust with words.

Re: Apple silently uploads your passwords and keeps them

#69
post #66

A crucial point to understand: unbeknownst to me, my passwords ended up on a device that I didn't specifically authorize to download them. The good news is that the device is owned by me and under my control. However, since it's just a test machine with no personal data—or so I believed—it's less protected than my other devices. For example, it has a weak login password, no Filevault, and no biometrics (Mac mini). In…

> Apple deprived me of a choice in this case.

Settings -> Apple ID -> iCloud -> iCloud Passwords & Keychain -> Sync this Mac

In general though having a weak password on a device logged in to iCloud is a bad idea.

Re: Apple silently uploads your passwords and keeps them

#70
post #19

Earlier quoted context omitted.

I'm considered switching to Mac from linux and I came across your blog which has been very informative. What made you chose mac over linux?

I didn't choose Mac over Linux. I chose Mac over Windows in the year 2002, and I became a Mac developer in 2006. Things were a lot different back then. Now it's too late for me, because my entire livelihood depends on Mac.

Not throwing shade here on your decision, but that's still choosing Mac over Linux and every day you continue to make that choice.

It's a perfectly fine decision, but Linux was, and still is, an option for plenty of people who develop for Apple hardware/software without daily driving it, myself included.

Post reply on HN