They uploaded new software and downloaded data they were not authorized to download without getting permission first.
I'm sure there is some cover your ass clause in the EULA that tries to protect them when they (accidentally or on purpose) violate the CFAA, but, in this case, they pretty clearly did things that exceeded their authorization.
The relevant part of the CFAA is a.1 (I removed the bits that are irrelevant):
> (a) Whoever—
> (1) having knowingly accessed a computer without authorization or exceeding authorized access, and by means of such conduct having obtained ... restricted data, as defined in ... causes to be communicated, delivered, or transmitted, or attempts to communicate, deliver, transmit or cause to be communicated, delivered, or transmitted the same to any person not entitled to receive it ...
1. I thought implied consent was out of fashion these days
2. What if it's something like an IDE that reads the surrounding directories? VS code does that and I certainly didn't know that feature even existed before I first opened it, so how could have given authorization? Is Microsoft in breach of the CFAA?
Reading the directory in a software running on your computer is not the problem. The question is, is data from the surrounding directories transmitted to somebody else's computer, a.k.a. The Cloud?
The service isn’t capable of delivering the keychain to anything other than the user’s own devices.
It’s Apple. They are the other end where the traffic is decrypted.
And yes they can see your stuff. We know this because law enforcement gets access to it all the time.
The keychain is just another keystore.
> They are the other end where the traffic is decrypted
Only for certain types of data, with certain settings. That does not include the keychain.
https://support.apple.com/en-us/102651
> And yes they can see your stuff. We know this because law enforcement gets access to it all the time.
What law enforcement typically gets access to is iCloud Backups, which is not end-to-end encrypted by default (but can be) and is not a mandatory feature. iCloud backups do not contain your keychain.
> The keychain is just another keystore
Nobody has said anything else? But Apple does not hold the key to decrypt it.
https://support.apple.com/guide/security/secure-icloud-keych...
Did they announce this change? It's a pretty major UI departure. In particular, if you have one Apple device and loose it, the 2022 article implies you can recover your keychain, but the 2023 article says you're completely screwed.
A lot of people rely on iCloud backup. It seems like there should be a device-wide toggle that lets you choose between the two behaviors for things like passwords, health data, and all the other E2E apps.
The escrow is only an additional layer of security - your device still has to decrypt the downloaded keychain contents using your password AFTER proving to escrow that you're allowed to download the encrypted keychain using device or SMS 2FA or an iCloud security code.