iCloud was storing cleared browsing histories
theverge.com
theverge.com
This is solved by knowing what is stored is private browsing data, which should be marked anyways. Safari just isn't that well thought out of a browser.
Safari is just a browser that has made a different set of tradeoffs.
Who defined it that way? And how do you define 'exit', 'data' and 'exist'?
Leveraging native APIs means less code (fewer bugs), less disk usage, less RAM usage, etc.
>> The point of private browsing is to make it so when that window exits, that data doesn't exist anymore.
When defining what private browsing is supposed to do we should keep in mind Safari was the first major browser to introduce the feature.
(You can go back to the old behavior via a system setting: "Close windows when quitting an app")
Given that, it is logical that it reopens private windows, just as, for example, TextEdit or Numbers reopen windows with content you never explicitly saved (even across reboots)
Nope!
This is vestigial thinking from the MacOS perspective. The concept of "saving" is gone. The concept of "memory state" versus "disk" is gone, from the user perspective. Those are all implementation details now. For the user it's simply, your windows stay open until you close them. Quitting does not close windows, so it's not unusual to see them when you return to an app.
By the way, Safari in iOS does exactly the same thing. And given that iOS kills apps on its own, there would be no question that randomly killing private sessions would be a bug.
I mean maybe you could distinguish between a force quit and an OS quit, but why? Just close the windows if you want to clear them. The private window guarantee is there will be no trace after you close the window. It's just vestigial thinking that quitting apps also closes windows.
If anyone has any pointers to documentation on the forensics aspects of this I'd appreciate a link.
It doesn't look like there's that much open source available for the new-ish Windows 8+ hibernation file: https://github.com/volatilityfoundation/volatility/issues/25
To be clear to anyone else reading this, that's not what I said nor close to what I meant. I think I understand where you're coming from though.
Apple doesn't rely on advertising revenue like Google or Facebook so in the past they've been much more likely to avoid collecting data whenever it could get in the way of their self-professed privacy narrative.
Storing your data on a cloud service that isn't competent is a privacy risk.
And a reliability risk, as I found out last year when my albums on iCloud Photos disappeared. Not the photos themselves, just the albums in which I organised them, but organising data can take a lot of time, and any data loss is unacceptable. They weren't in trash.
Apple's "self-professed privacy narrative" is partly right, but partly marketing, and partly disingenous, as if collecting data has no other purpose than advertising: https://dcurt.is/privacy-vs-user-experience To be clear, I'm not taking a black-and-white view; it's partly right, partly wrong.
BTW, The Verge wasn't clear — was the forensics firm getting data from an iDevice or Mac's local storage, or across the Internet from iCloud servers?
a "trusted device" is only an Apple device, phone calls are for backup when you lose them. Even after that it's significant inconvenience in comparison to any other vendor using a standardized OTP approach working with any application that implements the standard. It's one of the little ways how Apple makes not owning an iOS device inconvenient for mac users.
The 'legacy' (my phrasing, only because it was the first implemented) MFA is SMS-based, and thus has not dependency on iPhones.
There's a newer (about a year or two old by this point) solution which has a 'richer user experience' and depends on having other Macs or iPhones to receive the MFA authentication dialogs.
What if I don’t have access to a trusted device or didn't receive a verification code?
If you're signing in and don’t have a trusted device handy that can display verification codes, you can have a code sent to your trusted phone number via text or a phone call instead. Click Didn't Get a Code on the sign in screen and choose to send a code to your trusted phone number. You can also get a code directly from Settings on a trusted device.
iCloud has offered 2 step authentication since 2013 [0]. From what I can tell, the celeb hack happened a few weeks before the public release in mid-2014.
[0] https://9to5mac.com/2013/03/21/apple-beefs-up-icloud-apple-i...
sqlite3 $HOME/Library/Preferences/com.apple.LaunchServices.QuarantineEventsV2 'select LSQuarantineDataURLString from LSQuarantineEvent'
sqlite3 $HOME/Library/Preferences/com.apple.LaunchServices.QuarantineEventsV2 'delete from LSQuarantineEvent'
Here is a SQL to view timestamps:
SELECT datetime(LSQuarantineTimeStamp + 978307200, "unixepoch", "localtime") as LSQuarantineTimeStamp from LSQuarantineEvent
(Based on http://www.forensicswiki.org/wiki/Mac_OS_X with modification.)
In my testing, only downloads from Safari are logged here, not those from Firefox (haven't tested Chrome). If you don't use Safari as your primary browser, that might explain not seeing many downloads.
And yeah, it had all kinds of interesting stuff I've downloaded over the years in mine. Now cleared. ;)
Self hosted sync server https://docs.services.mozilla.com/howtos/run-sync-1.5.html
Self hosted accounts server https://docs.services.mozilla.com/howtos/run-fxa.html#howto-...
The latter includes instructions about how to add the accounts server url to about:config
> Unlike most iCloud data, the records don’t seem to have been accessible to law enforcement requests. Apple declined to comment when reached by The Verge.
Nobody knew it was even available?
As people have pointed out, yes, Apple is a trusted part of the system and could release a new iOS/macOS update that captures these keys but short of that, neither Apple nor law enforcement have any access to your iCloud data.
"iCloud uses a minimum of 128-bit AES encryption and never provides encryption keys to any third parties."
If I interpret this correctly I am first party, Apple is second and third is everyone else.