Live data from Hacker News

Apple silently uploads your passwords and keeps them

lapcatsoftware.com

91–100 of 130 posts

Re: Apple silently uploads your passwords and keeps them

#91
post #63
post #58

Earlier quoted context omitted.

Either way the passwords are being uploaded, which is the comment I was replying to.

The ciphertext is not the plaintext (obviously). So an encrypted password is not a password. An encrypted password is a string resulting from the application of an encryption algorithm and a key to a password. Uploading that string is not uploading the password. The fact that Apple's software can access the keys stored on the device to decrypt the password after you securely authenticate is neither here nor there.

[deleted]

Re: Apple silently uploads your passwords and keeps them

#92
post #66

A crucial point to understand: unbeknownst to me, my passwords ended up on a device that I didn't specifically authorize to download them. The good news is that the device is owned by me and under my control. However, since it's just a test machine with no personal data—or so I believed—it's less protected than my other devices. For example, it has a weak login password, no Filevault, and no biometrics (Mac mini). In…

>[manufacturer] deprived me of a choice in this case This seems to be the industry trend with these remotely managed machines, like Apple or Windows PCs. The update mechanism, for better or worse, takes power from the user and assigns it back to the manufacturer / service provider. It's something that the software world would have considered a Trojan horse some 20 years ago, an extension of control to the end users m…

Might be good for some "average" user but strikes me as bad for software developers or other folks with particular need for tight control.

Re: Apple silently uploads your passwords and keeps them

#93
post #66

A crucial point to understand: unbeknownst to me, my passwords ended up on a device that I didn't specifically authorize to download them. The good news is that the device is owned by me and under my control. However, since it's just a test machine with no personal data—or so I believed—it's less protected than my other devices. For example, it has a weak login password, no Filevault, and no biometrics (Mac mini). In…

>[manufacturer] deprived me of a choice in this case This seems to be the industry trend with these remotely managed machines, like Apple or Windows PCs. The update mechanism, for better or worse, takes power from the user and assigns it back to the manufacturer / service provider. It's something that the software world would have considered a Trojan horse some 20 years ago, an extension of control to the end users m…

The war on general purpose computing has already been won, over the average consumer.

Pray they don’t finish the job.

Re: Apple silently uploads your passwords and keeps them

#94
post #80
post #78

Earlier quoted context omitted.

You'd be more in control over having your passwords silently uploaded to a third party without your knowledge or consent, for starters. Again, full respect for your decisions, but there are consequences to them and as your blog and experience shows, they are numerous and have serious impacts.

Me: work-related activities are mostly what I use a computer for, so I'm not sure what I would even do with Linux. You: You'd be more in control over having your passwords silently uploaded to a third party without your knowledge or consent If I mostly use a computer for work purposes, what do you think my passwords are for? Also, I've been using a Mac since 2002, and iCloud Keychain got toggled on in 2024. It's kind…

Not sure where or what "work passwords" has to do with it, passwords are passwords especially if you're running your own business, which it seems you are.

Do your thing buddy, but I'm not the one who had their (work) passwords were silently uploaded to iCloud without permission.

Re: Apple silently uploads your passwords and keeps them

#95
post #54

Earlier quoted context omitted.

“History of incompetence” really needs some citations, especially for the belief that open source tools are better - they had Gotofail but OpenSSL had Heartbleed, etc. One of the better questions to ask is not how the source code is managed but how it’s audited: there’s a long history of problems in both open and closed software but well audited codebases tend to have them patched before exploits are publicly availab…

> “History of incompetence” really needs some citations Here’s a big one: https://arstechnica.com/gadgets/2007/11/be-cautious-of-that-... The article contains few details. More insight is at the discussion on https://www.cableforum.uk/board/showthread.php?p=34430700 Briefly, when implementing file moving in (closed source) Finder code, someone at Apple who was apparently a beginner programmer or student intern made a…

Something from almost 20 years ago doesn’t quite work the way you think it does.

Apple does take this stuff seriously. Implying otherwise is just absurd.

Re: Apple silently uploads your passwords and keeps them

#96
All the trust-us data-grabby pushes by Apple products creeped me out, until I finally got rid of their products.

For example, although I laboriously went through a ton of settings to make it less privacy-invading, I knew, for example, that I was still only one fumbled touch to a piece of glass away from Apple saying, "Oh, hey! I just grabbed all of your photos! Forever!" (Then Apple would say "Thanks!" in a sunny Californian way that normally is not every meaningful, but accidentally takes on meaning in the era of surveillance capitalism and AI training data.)

Re: Apple silently uploads your passwords and keeps them

#97
post #58

Earlier quoted context omitted.

Of course. Apple has to decrypt the passwords when it pre-fills the browser. And the decryption keys are stored on your devices in the Secure Enclave. Apple doesn’t have the keys on their servers.

Either way the passwords are being uploaded, which is the comment I was replying to.

Your response implied something that is outright incorrect, which is what is at issue here.

Re: Apple silently uploads your passwords and keeps them

#98
post #66

A crucial point to understand: unbeknownst to me, my passwords ended up on a device that I didn't specifically authorize to download them. The good news is that the device is owned by me and under my control. However, since it's just a test machine with no personal data—or so I believed—it's less protected than my other devices. For example, it has a weak login password, no Filevault, and no biometrics (Mac mini). In…

The device isn't "owned by you and under your control" if your passwords were synced without your doing or permission.

Re: Apple silently uploads your passwords and keeps them

#99
The most obnxious aspect of owning an iphone for me. Apple turns icloud syncing on by default for everything, not just password management. Photos, browsing history etc. there should be an account setting that lets you turn this off completely no matter what device you sign into with your icloud account. Completely obnoxious, my icloud photos is a total mess of triple and double copies of photos going back decades i recently had no idea it was even syncing. All from signing in then having stop automatic syncing. I now only sign in when the device has fresh reset so i can immediately turn all the syncing off. This should be an account wide option that applies to any all current and future device sign ins.

Re: Apple silently uploads your passwords and keeps them

#100
post #98
post #66

A crucial point to understand: unbeknownst to me, my passwords ended up on a device that I didn't specifically authorize to download them. The good news is that the device is owned by me and under my control. However, since it's just a test machine with no personal data—or so I believed—it's less protected than my other devices. For example, it has a weak login password, no Filevault, and no biometrics (Mac mini). In…

The device isn't "owned by you and under your control" if your passwords were synced without your doing or permission.

> The device isn't "owned by you and under your control" if your passwords were synced without your doing or permission.

Why are you being repeatedly, needlessly pedantic? Everyone knows what I meant (including you, who chose to misinterpret). Your other comment was also pointless: "that's still choosing Mac over Linux and every day you continue to make that choice." https://news.ycombinator.com/item?id=42016888

You can play with your own ultra-strict definitions of "own" and "choose", but please do it in your own mind, and don't pester us with them in these comments. It adds absolutely nothing to the conversation.

Post reply on HN