Earlier quoted context omitted.
Either way the passwords are being uploaded, which is the comment I was replying to.
The ciphertext is not the plaintext (obviously). So an encrypted password is not a password. An encrypted password is a string resulting from the application of an encryption algorithm and a key to a password. Uploading that string is not uploading the password. The fact that Apple's software can access the keys stored on the device to decrypt the password after you securely authenticate is neither here nor there.
Apple silently uploads your passwords and keeps them
91–100 of 130 posts
Re: Apple silently uploads your passwords and keeps them
#92A crucial point to understand: unbeknownst to me, my passwords ended up on a device that I didn't specifically authorize to download them. The good news is that the device is owned by me and under my control. However, since it's just a test machine with no personal data—or so I believed—it's less protected than my other devices. For example, it has a weak login password, no Filevault, and no biometrics (Mac mini). In…
>[manufacturer] deprived me of a choice in this case This seems to be the industry trend with these remotely managed machines, like Apple or Windows PCs. The update mechanism, for better or worse, takes power from the user and assigns it back to the manufacturer / service provider. It's something that the software world would have considered a Trojan horse some 20 years ago, an extension of control to the end users m…
Re: Apple silently uploads your passwords and keeps them
#93A crucial point to understand: unbeknownst to me, my passwords ended up on a device that I didn't specifically authorize to download them. The good news is that the device is owned by me and under my control. However, since it's just a test machine with no personal data—or so I believed—it's less protected than my other devices. For example, it has a weak login password, no Filevault, and no biometrics (Mac mini). In…
>[manufacturer] deprived me of a choice in this case This seems to be the industry trend with these remotely managed machines, like Apple or Windows PCs. The update mechanism, for better or worse, takes power from the user and assigns it back to the manufacturer / service provider. It's something that the software world would have considered a Trojan horse some 20 years ago, an extension of control to the end users m…
Pray they don’t finish the job.
Re: Apple silently uploads your passwords and keeps them
#94Earlier quoted context omitted.
You'd be more in control over having your passwords silently uploaded to a third party without your knowledge or consent, for starters. Again, full respect for your decisions, but there are consequences to them and as your blog and experience shows, they are numerous and have serious impacts.
Me: work-related activities are mostly what I use a computer for, so I'm not sure what I would even do with Linux. You: You'd be more in control over having your passwords silently uploaded to a third party without your knowledge or consent If I mostly use a computer for work purposes, what do you think my passwords are for? Also, I've been using a Mac since 2002, and iCloud Keychain got toggled on in 2024. It's kind…
Do your thing buddy, but I'm not the one who had their (work) passwords were silently uploaded to iCloud without permission.
Re: Apple silently uploads your passwords and keeps them
#95Earlier quoted context omitted.
“History of incompetence” really needs some citations, especially for the belief that open source tools are better - they had Gotofail but OpenSSL had Heartbleed, etc. One of the better questions to ask is not how the source code is managed but how it’s audited: there’s a long history of problems in both open and closed software but well audited codebases tend to have them patched before exploits are publicly availab…
> “History of incompetence” really needs some citations Here’s a big one: https://arstechnica.com/gadgets/2007/11/be-cautious-of-that-... The article contains few details. More insight is at the discussion on https://www.cableforum.uk/board/showthread.php?p=34430700 Briefly, when implementing file moving in (closed source) Finder code, someone at Apple who was apparently a beginner programmer or student intern made a…
Apple does take this stuff seriously. Implying otherwise is just absurd.
Re: Apple silently uploads your passwords and keeps them
#96For example, although I laboriously went through a ton of settings to make it less privacy-invading, I knew, for example, that I was still only one fumbled touch to a piece of glass away from Apple saying, "Oh, hey! I just grabbed all of your photos! Forever!" (Then Apple would say "Thanks!" in a sunny Californian way that normally is not every meaningful, but accidentally takes on meaning in the era of surveillance capitalism and AI training data.)
Re: Apple silently uploads your passwords and keeps them
#97Earlier quoted context omitted.
Of course. Apple has to decrypt the passwords when it pre-fills the browser. And the decryption keys are stored on your devices in the Secure Enclave. Apple doesn’t have the keys on their servers.
Either way the passwords are being uploaded, which is the comment I was replying to.
Re: Apple silently uploads your passwords and keeps them
#98A crucial point to understand: unbeknownst to me, my passwords ended up on a device that I didn't specifically authorize to download them. The good news is that the device is owned by me and under my control. However, since it's just a test machine with no personal data—or so I believed—it's less protected than my other devices. For example, it has a weak login password, no Filevault, and no biometrics (Mac mini). In…
Re: Apple silently uploads your passwords and keeps them
#99Re: Apple silently uploads your passwords and keeps them
#100A crucial point to understand: unbeknownst to me, my passwords ended up on a device that I didn't specifically authorize to download them. The good news is that the device is owned by me and under my control. However, since it's just a test machine with no personal data—or so I believed—it's less protected than my other devices. For example, it has a weak login password, no Filevault, and no biometrics (Mac mini). In…
The device isn't "owned by you and under your control" if your passwords were synced without your doing or permission.
Why are you being repeatedly, needlessly pedantic? Everyone knows what I meant (including you, who chose to misinterpret). Your other comment was also pointless: "that's still choosing Mac over Linux and every day you continue to make that choice." https://news.ycombinator.com/item?id=42016888
You can play with your own ultra-strict definitions of "own" and "choose", but please do it in your own mind, and don't pester us with them in these comments. It adds absolutely nothing to the conversation.