They offer no option to delete your passwords from the Cloud once there?
If that's indeed how they all/always work, we shouldn't just Stockholm-syndrome accept it!
Seems pretty trivial to download the icloud windows client (which has password manager support), and modify/delete the passwords there?
Does it matter tho. Like in general internet, once something is posted, it will not disappear with certainty. We can never be certain that there is a copy of the encrypted password on some log file when we have no visibility into that sytem. Since it is encrypted, it passes the regulation checks.
That is just a UI bug if passwords keep coming back in the cloud/you still see them. Unless there is a system in place that can transparently verify that indeed, the passwords are deleted, does it matter?
This is a pretty lame windmill to tilt at.
They really want to avoid the risk from anyone inside the company having access to your passwords and then doing anything with them.
Compare the consequences for a large company vs an individual.
For the individual, if caught, a debilitating fine and, depending upon damages, jail time. Probable end of career, if related.
In short, life changing.
For the company, possible fine almost certainly less than the revenue made. Small chance of larger civil suits, with legal costs and possible judgments. Depending upon visibility, perhaps some additional PR spend. Even if the sum total cost is greater than the associated revenue, those costs can be used to offset tax liability.
In short, low risk of existential threat, or even actual financial loss -- just reduced profits.
Maybe a plunge protection stock-price guarantee.
Or NOT.
Apple on the other hand would see your bank balance as a rounding error to a rounding error, but could easily lose a billion dollar from bad publicity that’s what’s balancing vs any financial upsides. Further, doing it once doesn’t move the needle it needs massive scale and thus massive risks to be worth anything to them.
It is essentially about the trust. You either trust that they don't misuse the cloud-uploaded passwords or not. If you cannot trust that, you cannot trust the whole ecosystem as the same entity controls it and can misuse it in any imaginable way.
So essentially, the issue of deletion is just about the visibility in the UI, if we trust their claim about the end-to-end encryption.
You can absolutely to a high degree protect and store data, including the safe removal.
An organisation like Apple should absolutely be forced to delete the data, especially data collected using deceptive tactics
> An organisation like Apple should absolutely be forced to delete the data, especially data collected using deceptive tactics
As long as there are no consequences (regulation checks with fines) of not doing it correctly and/or if there is no observability and enforceability, it is just talk and does not matter in practice. Essentially, until the previous applies, it is just exchanging trust with words.
OpenBSD has never sent my passwords to Theo’s basement. I trust them without regulations. But more importantly, there’s a crew of capable hackers dissecting the code.
1. You can't demand something that cannot be enforced/monitored
2. You can't enforce/ push monitoring if there is no regulation in place, and systems are not transparent.
3. Enforcement/monitoring does not matter if there is no stick (fines) present
In the case of OpenBSD, you are using open system that you can verify your self. That alone makes them less likely to do something malicious (since they might get caught more likely!) and changes the trust. There is no financial carrot to make Apple products visible, as most of the users don't understand a thing about the technology and marketing might be more efficient than opening technology, which might result in intellectual property theft and lose of market position.
Since everything cannot be transparent in a competitive and commercial world, I think it would be okay to put at least 10 times bigger fines for those who do not have transparent systems and get caught on not following the regulations to get some balance.
We desperately need a free hard- & software (*nix) mobile platform, that is not exclusively owned by a for profit mega corporation and somewhat mainstream amongst the hacker community. Even better would be competing systems. I imagine these systems to have a high degree of modularity, incl. battery, and memory upgrades.
This is not an easy undertaking.
I don’t think regulating the megacorps is the answer. In a commercial world, they have the deeper pockets
Has been this way for at least a decade.
This also deletes the local copy of the passwords.
Or use the Export All Passwords feature in the Passwords app.
No, there is not. If there was a separate iCloud Keychain, then my passwords never would have gotten uploaded in the first place. Most of these passwords were Safari web form logins. Safari stores them where it wants.
> Or use the Export All Passwords feature in the Passwords app.
Export them to where? I want to use the operating system to store my passwords locally. I just don't want them in iCloud.
Settings -> Apple ID -> iCloud -> iCloud Passwords & Keychain -> Sync this Mac
iCloud only stores passwords when you're logged into iCloud. Logout and you're local only.
Would it be nice to have no configuration and customization? Sure. People have felt that way for as long as I can remember.
I've been using the Keychain app on the Mac for 20 years.
> you can clearly see the existence of multiple keychains and one explicitly labeled iCloud
There's no "iCloud" keychain if you don't use iCloud Keychain. There is a "Local Items" keychain. Let me emphasize LOCAL in the name. Unfortunately, what happens when iCloud Keychain is enabled (silently, without consent in my case), "Local Items" becomes "iCloud". macOS stores a lot of things in the Local Items keychain, including Safari web form passwords, which is why mine got silently uploaded to iCloud.
The big question here is whether there’s a reproducible way that the opt-in changes. iCloud Keychain has robust end to end encryption but it still needs to inform the user.
And you should also know...
Best practices for password storage use one-way hash functions (like bcrypt, Argon2, or PBKDF2).
I'm a happy Apple user, love the OS...just saying.
This is not true.
That is true if you are running a service that USES passwords. In that case you just need to confirm they match. That is not true if you are running a password manager where the user needs to be able to get their plain text password back out of the system.
https://support.apple.com/en-au/guide/security/secb0694df1a/...
It’s then stored in iCloud as a SQLite file and encrypted as it does for your other synced data.