macOS Sonoma silently enabled iCloud Keychain despite my precautions
lapcatsoftware.com
lapcatsoftware.com
There is no sensible explanation that a flagship device can be full of bugs and inferior quality to its 3-year older non-flagship counterparts.
Apple's quality control has been getting worse every year. This is something we say every year; that's because its true every year. They started the highest coming out of the 2000s, plenty big laurels to rest on. But their (and Microsoft's) software has gotten so bad nowadays that linux desktops are starting to look stable (and don't interpret that as an endorsement of the improvements in stability of the linux desktop experience, not even close, year of the linux desktop might happen but only because everything is so shit that you might as well at least use the shit that isn't taking screenshots of your desktop or resurfacing photos you deleted five years ago).
Yikes. That seems so wrong.I havent had this happen. For me the final straw was Windows Defender sending files to be analyzed, without letting you audit which files have been sent over.
There has been an unknown bug for a few years where, sometimes, the process that is supposed to tag the photo for deletion removes it from the list but doesn’t add the right tag for deletion and the schedule process never noticed them and never told the OS to delete the files. They just sat there in the photos library folder, sometimes for years.
The files were never actually deleted, just removed from the photos list. Later another process was deployed that saw unreferenced photos and added them into the photos index. That freaked some people out, particularly if they really had wanted to get rid of those photos.
This all happened as a higher level than the OS. The OS file deletion process was never invoked for these photos.
Big-tech sees no value in QA thee days when they already have monopolies over huge markets, so these jobs get cut. And even when they don't get cut, since such jobs are dead-end for your career there anyway ... you get what happens.
So a lot of QA is actually outsourced to third party body shops where employees don't care beyond shoveling some tests out the door to get home quick and get paid.
One of my favorite features is on the mickey/minnie watch face, they verbally tell you the time if you tap them..... except when they don't. Sometimes they just stop working until you power cycle the watch lol.
Also phone calls to/from the watch seem to go through fits of random failure. Like at least once a week it'll inexplicably fail to get notifications or fail to answer phone calls. And then once a month I'll have to power cycle both the watch and the phone because they fall into a trap where any call in/out fails.
I first noticed these bugs on my s4 and iphone xs. I'm currently using an s8 and iphone 13. Still got those bugs lol.
Oh I thought of one more. Any iOS device with a home button and an alphanumeric password won't show you the keyboard when it first starts up. You have to hit the power button and then wake it with the home button to see the keyboard lol.
The funny part is I use the sleep app and the alarms. When I'm really worried about missing an alarm I set my android phone too, or the alarm clock by my bed lol. That rarely is needed.
Thanks for explaining iPhone SE2/SE3 behavior.
iOS Magnifier (for blind people!) will randomly stop speaking "image descriptions", continuing onscreen, invisible to the blind user.
First I had Keychain taking a full core on _all_ my devices and had to go through a rabbit hole to fix it [0], then I had “fileproviderd “ do the same (again, across all devices) and had to delete iCloud DB to fix it.
I wonder how less tech-savvy users are supposed to notice the issue (and maybe fix them).
Of course, this is just one of the thousands of bugs.
I'm thinking of changing brands when I upgrade. Guess I shouldn't look too closely at getting an iPhone either...
Five min install,
Play Store works great,
difficult to find apps that intentionally break themselves due to not being Google Android.
Then Apple made some annoying decisions with watchOS 10, and I stopped using it altogether.
To the point where I want to include some sort of caveat or flaw in my reply, lest I be accused of the dreaded fanboyism. Problem with that is that I don't have one. I can't think of a single bug or glitch in the 18 months I've had it.
I guess I have one kvetch: there was a major OS version bump during which they disabled swiping between faces. They added it back as an option, which I promptly turned on, and that was that.
There was significant backlash about the removal of swiping faces. I'm also glad they brought it back. I used that feature professionally to swipe to an ugly watch face that showed seconds.
If you yourself is not a primate ape I would be surprised and call every news agency available to tell them a new species is using written language and the internet.
Apple is shipping broken software left and right ever since the ARM transition and it's become noticeable.
http://feedbackassistant.apple.com is where you file such requests. Just keep in mind that the wall they have between public and internal systems means you may not get updates unless you periodically ask for them.
What other species/order than primate apes do you think would be suitable for apple QA?
But based on your comment, unfortunatelly I can't say the same for you.
The "yourself" might feel awkward but is required to ensure that I am talking about the specific poster instead of something like "if you are not a X" in which case it would read like a general you.
If you understood what I was expressing and have a better and more succinct way to express it let me know.
I've had an Ultra since it launched and it's been no different to any other Apple Watch.
I had NONE of these problems with older watches despite doing the exact same things.
The rich customer does not buy Apple because of the quality, but because of the price. /s
I don't like the "on principle" response since a lot of people will end up thinking, "oh, so it doesn't really matter." Even the author's elaboration could lead to responses like: "they are control freaks," or "they are paranoid."
In my case, the answer is simple: I have access to systems that contain confidential information about other people. Protecting their data is my responsibility. While I have little doubt that Apple (and other vendors that provide similar services) do their best to guarantee the security of these products, their centralized nature and potential value of the data it leads to make them very juicy targets.
For the record, there's plenty of data I wouldn't want to give either company (especially Google) but the answer there is also fairly straightforward: I don't put my passwords into my iCloud Keychain. Or, for that matter, into Google's password manager.
I am your doctor.
I am your lawyer.
I don't trust any company, let alone a foreign controlled one to have authorised access to my accounts as me. I would be held accountable if they were exposed and they sufficiently covered their tracks (and they are incentivised to try).
Why should I brazenly permit this?
(for the record, as a private individual I am using iCloud keychain, and for work I use 1password with its online storage: however I just make video games, I don’t have the power to destroy lives, nor do I have a responsibility to avoid it; I am merely pointing out that perfect being the enemy of good is not always good enough for everyone.)
The biggest problem with Keychain here isn't that it is able to share with iCloud, it's that it claims to have the ability not to (but it seems to not work) and will "upgrade" to sharing without prompting. This is a bad thing. But now we know it's happening, we can choose to avoid the product.
On the other hand, Apple do write the OS and all its updates so they can steal all your passwords whenever they feel like it. And one might be inclined to assert that they just did.
Someone said "Apple re-activated a password sharing system and that's bad because I intentionally turned it off"- I agree.
To-wit someone responded: "Well, actually I think Apple are going to do a better job of handling passwords" - which, I do not agree with given the context of reactivating the feature silently.
It does not have to be a matter of trust. People make mistakes. The wrong mistake can lead to a vulnerability. Technology advances. What was considered secure 20 years ago is not considered secure today. Companies change hands and have changes in leadership. Then there is the question of: what does trusting a company mean? Their actions are the result of a multitude of minds, not a singular one.
- avoid storing anything on iCloud
- disable iCloud via MDM / Apple Configurator policy profile
- router block Apple network (17.0.0.0/8) connections
- router block Apple CDNs via dnsmasq wildcard domains
- router allow Apple servers for notifications and app/OS updates
- login via App Store only, not Settings/iCloud
Apple list by service: https://support.apple.com/en-us/101555 - never take your precious Apple laptop outside
- somehow make sure there is no other open WLAN nearbyIf using a travel router, Apple Configurator can limit Wi-Fi SSIDs. There are claims that some Apple traffic can bypass on-device iOS VPNs.
The list above is not about distrusting the vendor or OS, it's about leveraging the vendor's officially published statements of behavior (e.g. HTTPS network traffic identified by PKI certificates tied to vendor's legal identity), used in contracts with enterprise customers that have competent lawyers, for the benefit of smaller customers.
MDM policy can be configured to narrow the vendor's documented claims of software+hardware behavior. Narrowed claims are cheaper to verify empirically. If evidence can be found that MDM policy is not being enforced, then the pool of affected parties grows from powerless individuals to a class action (Apple has paid millions in the past) and/or large enterprises who use MDM to protect confidential enterprise data.
> How do you ensure that the OS does not by itself connect to a random open WLAN
In the case of Wi-Fi, MDM and Apple Configurator can configure device policy to connect only to approved SSIDs + a null list of approved SSIDs. To validate enforcement of this WiFi policy, the device can be placed in a small faraday box (commercial < $1000, DIY < $100) that blocks external RF, with an SDR that records all internal RF traffic for analysis. For a device with a null list of approved SSIDs, there should be zero Wi-Fi traffic from the baseband radio.
Another option for MDM policy enforcement validation is to use a virtual iOS/macOS instance, where a hypervisor can perform live behavioral analysis of OS execution paths. Any unexpected behavior can be further investigated by reverse engineering of non-encrypted OS firmware binaries. Corellium offers a hosted service for virtualized iOS analysis, https://www.corellium.com. They won their legal conflict with Apple.
Finally, a third option is to modify the hardware device to disable unwanted radios, using only a wired network connection via USB. Past news articles have covered expensive modifications of commercial Apple hardware, for use by governments and companies in facilities where wireless networks were not allowed.
If it's not here already - I dont really follow the space :-)
If Apple allows VMs on iPad Pro in iOS 18, it might take some wind out of Oryon sails, but with Nvidia, Mediatek and maybe AMD joining the Arm train in the coming year, real competition lies ahead.
A repairable Arm laptop from Framework would be great.
Seems similar to how Windows settings “accidentally” revert to the less private ones.
With Microsoft, every update I get this wizard that tries to trick me to put OneDrive, trial Office and other things. and... one in a few update a new dark pattern is being added. So it's not a bug... it's a feature from their perspective.
It's not perfect, but it monitors what process on your system wants to make what network connection.
What appalled me was that even when adding a LOCAL email account, accountsd tries to phone home to apple. Apple is phoning home in ways it never should.
Though for that specific feature, Apple operates a lookup service that Mail uses to attempt to automatically configure your SMTP and IMAP/POP settings. It would be nice if it asked permission first.
My System Settings > Passwords says "Turn on iCloud Keychain" with two buttons "Not Now" and "Enable". (No idea what why there's a button "Not Now"?)
But I don't use Keychain at all, I use a third-party password manager. At some points I'm sure Keychain has asked me if I wanted to save various passwords in Keychain and I've always said no. And it hasn't bugged me about it in a long time.
I wonder why OP's systems are turning it on when mine didn't?
Their present day approach makes it seems very plausible that it's just marketing and weasel words, nothing more. :(
"I've always managed my data myself, taking personal responsibility for protecting it and backing it up. I don't want or need Apple to insert itself into this process as a remote nanny."
But do this to sync to iCloud at all, you'd have to log into an Apple account in the first place on the machine. Surely that is counter to the requirement?
It's usually possible to login via the App Store, without logging into iCloud.
- no subscription
- open-source encryption (SQLCipher)
- device-to-device encrypted sync via ethernet/wifi, dropbox, google drive
- indie US developer, lineage to 1998 STRIP on PalmPilot
- TOTP 2FA authenticator
- sync encrypted notes/images
1999, http://www.cnn.com/TECH/computing/9911/30/palm.tools.idg/> Secure Tool for Recalling Important Passwords (STRIP). STRIP uses heavy-duty, 128-bit triple-Data Encryption Standard to store information, and that means any information -- credit-card numbers, Web site accounts and voice-mail access codes. STRIP (Zetetic Enterprises, free) is also a great tool for IT managers who administer distributed environments. It can random-generate complex passwords and allows account information to be beamed between Palms, so the IT staff can stay up-to-date.
This company has shown multiple times in the past that they can and will change their closed source software's behavior to the detriment of user privacy (remember Apple's on-device image scanning?). Why are you or OP surprised when these things continue to happen on the closed source walled garden?
In theory 1Password has the superior product, as they use MFA for accessing your vault, and your account password only allows access to the encrypted vault (unlike Bitwarden where your account password unlocks everything).
But that is all theory, and you don't really know what really goes on behind the scenes, and it could all just be "theater". It probably isn't, but that's where the trust part comes in.
Personally i doubt that Apple has any nefarious intent, and i believe their intention is to make stuff better and more secure, and that they protect/respect privacy. Again, this is a matter of trust, and i trust Apple.
I don't base my assumptions on blind trust, but actually review their documentation on their services, like iCloud Data Security [^1]. They're pretty open about how they encrypt stuff, and also mention stuff like when using standard iCloud encryption, your backup of messages includes a key that can be used to decrypt the messages in the backup.
I enabled Advanced Data Protection as soon as it became available, and stopped worrying about it. For stuff that i want to keep secret at all costs i use GPG or Cryptomator.
As for Keychain i use a mix of Keychain and 1Password. Keychain for everything "simple" that i don't care about, i.e. websites that requires a login. It plays well with Hide my Email, and offers the path of least resistance. My 1Password usage is mostly stuff that doesn't fit easily into Keychain.
Besides, in this case.. it does not help that you'd also have to exchange hardware
If you’re this distrustful of Apple, your logic should say to not use local Keychain at all. You either trust Apple’s hardware backed E2EE or you don’t trust anything from Apple at all, there’s no picking and choosing when it comes to this sort of thing.
I bet privacy researchers at Apple are facepalming reading these threads thinking people can run their own crypto better than they can.
> thinking people can run their own crypto better than they can
Running or developing ?
You can probably run something like Password Store [1] fairly secure, though you still have to trust the operating system not to leak your secrets, and it turns out that today, regardless of your choice, all major operating systems more or less synchronize your data to the cloud.
I know Linux doesn't do it (Ubuntu tried some Amazon partnership once), but Linux is a poor match for many workplaces where Windows or MacOS are kings. Yes, you can run VSCode (or Vim/Emacs or whatever) on Linux, but running Photoshop, Fusion365 or various other business tools is not as "easy" as on Windows/MacOS, and in the end a company only has so many IT support staffers.