Updating from macOS Ventura to Sonoma Silently Enables iCloud Keychain
lapcatsoftware.com
lapcatsoftware.com
Pretty egregious behaviour.
It would be amazing the victims of this kind of egregious privacy violating behavior would receive a cut of the fine that the offender is charged.
That would give people an incentive to report this kind of shit.
This is precisely the problem. Apple treats its users as dumb cattle. "We know better. Shut up and be happy with what we force down your throat."
Of course, Apple can do no wrong. Forced lock-in? "Don't you feel so much more secure now that you're firmly in our garden? Our walled garden that you cannot escape from?"
I remember when Microsoft uploaded people’s personal wifi creds in Windows 10. It’s all highly suspect.
Stop it. This over sharing by default will doom us all.
Because automatically sharing credentials between devices by default is what most people want, especially younger customers for whom this has always been the normal state of affairs.
In my case, I liked that, and so will my users.
But I do think that it could be problematic, if this means that authorities could now get ahold of your keychain, when having it restricted to a single device, avoids that.
Ref also [1]: > In Big Sur Apple decided to exempt many of its apps from being routed thru the frameworks they now require 3rd-party firewalls to use (LuLu, Little Snitch, etc.) > Q: Could this be (ab)used by malware to also bypass such firewalls? > A: Apparently yes, and trivially so
[0] https://x.com/patrickwardle/status/1318437929497235457 [1] https://x.com/patrickwardle/status/1327726496203476992
Now if only they'd stop trying to get me to enable iCloud Drive just because I use an iPhone for work.
But another way around is the way VMWare Fusion let you set up networking in Bridged mode. Any traffic from the VM went through without a peep from Little Snitch running on the host. No reason malware couldn't be designed in the same way.
AFAIK, XProtect is the only remaining line of defense against malware installed in this way.
Long term I suspect the actual answer will be that if you don't want to use iCloud Keychain then you just can't use the keychain at all, which is a shame as it once was one of the good parts of macOS.
Disabling SIP wasn't an issue, because I had already done it to eliminate slow app launches: https://lapcatsoftware.com/articles/2024/2/3.html
On my second attempt, I managed to update without an internet connection. See the new addendum to the article.
I'd be a bit careful here by the way. Disabling SIP results in other weird differences too, that may cause programs to run for you but not most of your users.
For example, LD_ and DYLD_ environment variables are no longer sanitized [1] for system processes.
Fun fact: the GitHub Actions Mac environment also disables SIP. So it might run for you and in CI, but not for your users.
[1] https://briandfoy.github.io/macos-s-system-integrity-protect...
I probably could have done something fancy where the VMs were left running a day or two before being frozen and deployed, but disabling SIP was the much simpler solution to the problem.
The latest 'national security' bill signed into law this April grants the US govt access to any and all commercial hardware. This as I understand it, am I wrong?
Doesnt this imply that every cloud service should be assumed insecure?
iCloud and App Store are independent. You can sign in to the App Store but not iCloud. In fact I've never used iCloud on my iPhone.
Don't do that. You can sign in within the App Store app, but don't sign in anywhere else.
• It shows my previous accounts even after I delete the app.
• Clearing Safari's cache does not work.
• Disabling iCloud Drive and iCloud Keychain does not work.
• Even completely signing out of iCloud does not work!
----
WHY can't the user see this data?
WHY can't the user delete this data without going through the app?
WHAT ELSE do apps store on our devices that we aren't even aware of? (This is just what we can see: The list of saved accounts for "quick login")
HOW MANY other apps are secretly doing this?
WHY does Apple even allow this in the first place??
Worst of all, WHY aren't more people raising more of a ruckus about this extremely appalling practice?!
But I agree. The user should be asked if they want to clear it on app delete
The iOS keychain isn't visible to the user which is the problem.
It has the SSID in plaintext in current-network and preferred-network, not the passphrase. I’m not sure how it’s obfuscated or encrypted but it is not plaintext
The other commenter is correct - the last (few?) Wi-Fi passwords are stored in NVRAM so that the recovery environment can connect to the network more conveniently.
that said, apple did add the option for end-to-end encrypted “advanced data protection” for the majority of icloud data a year or so ago.
perhaps they also enabled it by default in sonoma?
"For additional privacy and security, 15 data categories — including Health and passwords in iCloud Keychain — are end-to-end encrypted. Apple doesn't have the encryption keys for these categories, and we can't help you recover this data if you lose access to your account."
How do you know this?
My friend, I'm afraid I have no idea what you mean. What do you believe Apple claims they can't do that conflicts with this? (If your answer is "end-to-end encryption", Apple has supported this for at least a decade.)
"How do we validate claims of end-to-end encryption?"
It is a lot of trust to place in a company. I would be curious if there are ways to test Apple's claims?
I'm not a security expert, and you can't prove a negative, so AFAIK the only evidence is the lack of reported incidents where Apple's iCloud Keychain data has been directly hacked or compromised. Given that iOS and iDevices are among the highest-value targets for hackers and nation-states, that seems like reasonably solid evidence.
From a business perspective, lying about such a thing would have virtually zero upside but unimaginably massive downside. It's a great Apple-hater fantasy, though.
Thank you. That's exactly what I wanted to hear from you. The link you provided is in no way, shape or form actual evidence of what you're suggesting.
> From a business perspective, lying about such a thing would have virtually zero upside but unimaginably massive downside.
What are users going to do? Buy a Surface tablet and a Samsung phone?
> It's a great Apple-hater fantasy, though.
I just dipped my toe into the Apple waters again and bought an m1 air a year or so go. I'm currently shopping for a used iPhone.
I don't have brand loyalty and I use what works, and it just so happens that Apple has been making stuff that works pretty well in my opinion recently. But I'm under no illusion that I can trust them.
And we have plenty of historical examples, including recent ones, that big companies are simply lying through their teeth almost every time they open their mouths. Companies that rely heavily upon marketing are lying more so than others.
"Macs don't get viruses" claim made while several Mac viruses existed at the time. It's been lies for decades.
No, they didn't.
Anyway, iCloud Keychain has always been end to end encrypted.
iCloud Keychain is fine, just use a good password. There's no particular harm in letting Apple store an encrypted blob for you on its servers.