iCloud Uploads Local Data Outside of iCloud Drive
datavibe.net
datavibe.net
Have TextEdit enabled in the iCloud System Preferences panel. Open TextEdit, create a new document, type stuff in it. Now press cmd + O to display the iCloud document picker, and you'll see your new document got uploaded to iCloud, without you ever hitting Save or explicitly agreeing to save it on iCloud.
The only way on Mavericks to have 100% local data was to:
a) disable Documents in the Cloud for all apps or a specific app, or:
b) save documents to the local drive immediately after creating them, before typing anything.
I'm surprised this isn't more commonly known, and that everyone seemed totally fine with it. Doesn't seem like intuitive or expected behavior for an average user IMO.
And anyone working with data under HIPAA had better know this already!
Though if this is actually a thing that many people want to do, perhaps the new Blackberry OS actually does something that people need...
[Full disclosure: I work on vCloud Air]
[1] http://vcloud.vmware.com/service-offering/security-complianc...
That's true of small services, but less so of big enterprise vendor (and, given the size of the health IT market and the big enterprises to serve in that space, that shouldn't be surprising.)
(Not a lawyer, but I have to care about this, for professional reasons.)
[+] Say, emailing in the clear about PHI. This is extraordinarily common even among people who theoretically know better.
When individuals work around these policies, there tends to be some level of legal shielding for the larger business entity when it is investigated.
Odds of an enforcement action are minimal (940 complaints for Security Rule violations in 5 years divided by one sixth the economy), given that enforcement is complaint-driven and CSV files rarely complain. If you're big enough you budget for fines like retail budgets for employee theft -- sure, don't seek it out, but you won't be heartbroken when it happens.
There are two kinds of users in this scenario. Those who don't care (99%) and those who do.
If you count yourself among the latter group, as I do, then it's always solid advice to choose actions which clarify your intentions.
In this case:
- don't use iCloud
- don't use iCloud sync for the app you use for private data
- do explicitly choose to save the file locally
- don't enable new features like Continuity that clearly change the file
persistence and availability model without considering your old patterns
The author is rightly sore that his bits got pushed to Apple due to his oversight. He's wrong to place the blame fully on Apple, but it's hard to be fair when you're angry. And I'm glad he wrote it up because it should encourage people to think carefully about where and to whom they trust their data. Though most people I know sync their private data to Dropbox, Ffs, so...thinking != thinking, I guess.My secure notes strategy is vim with encrypted files on an encrypted partition. It could still leak, and I'd be angry, but there are at least three vendors involved that would have to alter their products behaviours before I was hugely surprised. TextEdit on HFS+ on OSX with iCloud enabled is just one vendor, who can't always cater to my 1% of 1% expectations.
I opted in to iCloud Drive to synchronize files - files I chose to store in iCloud.
I did not opt in to synchronize my unsaved files in apps not currently supported by Continuity, nor was there any warning or indication that that would occur.
How would you feel if the OS, without warning, started syncing your vim temporary files (including your pre-encrypted versions) to the cloud? This is the same thing. Don't hate because it's TextEdit and iA Writer.
My only hesitation is that you and I have to recognize that we are on the fringes of the fringe, and be hyper-vigilant.
This behaviour is only surprising if you get lax (as I was, too) about evolving functionality.
My point about vim is that for me, it's a purposeful simplification. I do sometimes wish for a more flexible note taking app, but I know that it would take an earthquake of change for vim to sprout a file sync feature that tied into iCloud. And I value that, a lot.
This is why this is worth sounding the alarm over - it's an OS-level change that affects all apps, not just Apple's.
Obviously, it's completely possible that mdsworker or any of the other dozens of Apple daemons is slowly leaking my unencrypted RAM or swap files out to 17.x.x.x or somewhere else I've allowed in my packet filter configuration.
But that is the line between enhancement for the majority and malice for the targeted. As long as I force Apple to cross that line before causing me any damage, I feel comfortable trusting them (their corporate policy, their auditing, their hiring, their systems administration, etc).
Well, you may know that, but don't worry, when it happens and surprises you and you post about it, there will definitely be someone here on Hacker News to scold you that you should have known better and that it's all your fault for not anticipating the unexpected and unannounced changes.
How would you feel if your unsaved files suddenly disappear? Would you blame apple for deleting files you explicitly chose to not save?
You were relying on a feature in an unusual and unintended way. Sooner or later, that may stop working.
The "unsaved files" being not synced to iCloud was never something that was meant to be guaranteed, it was just how it was.
What I'm suggesting is that by opting to explicitly save a file locally, you're giving more of a signal that you don't want it available remotely, compared to not saving a file at all.
Does it shift the danger of the world squarely onto those who couldn't ever possibly be you, as your internal narrative has you as perfectly informed at all times?
I'm a security-conscious engineer that's been using Apple hardware and software for two decades. Today, my computer took a bunch of private text and uploaded it without my knowledge or consent, completely contrary to my expectations.
Does it threaten your worldview to consider that perhaps I didn't do anything wrong?
(To answer your question directly: I would be annoyed but it wouldn't be the end of the world; I'd simply restore those files from backup as I knew where they were being autosaved previously. That's an entirely different ballgame than silently uploading them.)
Because you presented it as a personal violation and unconscionable shock, many people are reacting with incredulity.
I don't think you did anything wrong, tactically, and I think this is an important discovery. I do think you need to rethink your strategy around private data though, because the course of user experience is at odds with your desires.
You might be trying to argue that people also want privacy or security in their document sync, but that has nothing to do with the matter at hand. iCloud is at least as secure as any other consumer sync service.
This attitude is completely unhelpful. It throws those who are otherwise ignorant under the bus simply because they don't (can't?) understand how modern tech works. Is that really fair? Must we really divide the world up this way? Most of the public hasn't caught up to how modern systems work and what the trade-offs really are, and they certainly won't if this is the approach we choose to take.
It's almost reminiscent of Morlocks and Eloi from HG Well's Time Machine.
If you look at the reaction of those 99% to Apple planting a U2 album on their phone, you see an angry response when people are made aware...
What users care about as revealed by buying behavior is: user experience, user experience, user experience, user experience, cost, user experience, and user experience.
That's not an entirely healthy example but it does show it is possible to make consumers take topics like security and privacy seriously.
The issue right now is there aren't enough voices telling them how serious these topics are.
It also might be helpful to drop "privacy." It's security. These are vulnerabilities. Apple could have encrypted this stuff with keys the customer controls, but that takes more engineering to make it friendly and usable. They won't until people care.
When I know that I value a product or service for different reasons than the majority of other customers, I recognize that the product might change in a way that eliminates or reverses the value I derive.
When I think about the privacy of my personal information, I know that I would be greatly irritated to learn that a single shred of "my stuff" went anywhere outside of my control.
I care. I care a lot. The cloud is not made for me. Social technology is not made for me. The extent that social and cloud creeps into my operating system of choice is a clearly tense relationship that I have to think about and plan defensively around.
I don't think everyone should have to do that -- but they don't. They want universal sync and autotweeting, and I am not one to begrudge them.
When I say "most people don't care", I mean that they have decided that the benefits are greater than the risks, and on the whole would rather trust Apple than Google or some syncerrific.io sort of operation. Maybe they care that their friends, neighbors, and coworkers can't read MyFavoriteHentai.docx, but they do not care much about strangers.
So they get the product that they want. And I (and some of the rest of us, but really quite few) do not. And this is the way it should be.
So I'm not throwing anyone under the bus. I wish there was a way to make the product that people want without making it harder for me (and the OP) to get what I want out of it, but it's impossible to serve all cases. That becomes my problem, and I bear it willingly.
My point is that they're not even aware of how things work and therefore are not at all in a position to comprehend what the risks really are, let alone make sensible decisions.
The flaw in your reasoning is linking behaviour to knowledge. Just because people are behaving in a certain way doesn't mean that they are fully aware of the consequences of those actions. When it's only a small part of your life, it has little impact but when you suddenly realise a large chunk of your life depends on those choices it can be a bit of a shock (consider all the celebrities who had private images leaked recently).
Jennifer Lawrence has a different problem. Apple can't really help her either.
I said there are two kinds of people. This is superficially true of any binary criterion.
I was only discussing the kind of which the OP is a member.
The existence of that other, much larger, group is a very different problem to solve. Important, but not relevant for OP.
Correct, and those of us that do should act on behalf of those who don't, because a good many of them are not technically inclined enough to know if they should care.
Apple is averse to asking users lots of questions in general, but especially difficult questions that most won't understand or know how to answer -- or the implications of their choice. Pretending for a sec that Apple will change their default setting here, to the detriment of 99% of their users but to satisfy the noisy us... I'd love to see suggestions on how to word this checkbox option.
iCloud has a lot of options already. It's a complicated concept for most people. I agree that this is borderline surprising behaviour, but I don't see how to avoid surprising someone.
- Those who don't care and will never care
- Those who don't care but will care in the future
- Those who care now and will care in the future
- Those who care now and will not care in the future.
The first one is common. The second one does happen. The third one is more common than the fourth.
I think the amount of users this will affect is greater than you expect.
most of the time, the default is to enable the new privacy invasive features unfortunately... (it should be opt-in, always)
Another gotcha I noticed around the same time - Notes from iPhone are automatically stored to the primary email account. So I had my private scratchpad phone notes stored on my corp account's Notes folder with no easy and obvious way to re-associate them to the correct account.
It's easy to disable, but as the writer notes, that's not the point - if you don't know it's happening, there's not much you can do, just feel your stomach drop, disable it, then get to work figuring out how much damage was caused (i.e., get to swapping keys, ugh...).
I expect that files I edit are saved at some point, somewhere, iCloud makes perfect sense in that it allows me to pick up where I left off on any device. Not only that, but Mavericks had the same behaviour for unsaved files as far as I remember.
This is exactly the behavior I want and expect from Apple as a user, it would surprise me if they DIDN'T do this.
And I'm baffled by yours, and others' in the thread. With the PRISM/Snowden revelations, Apple still refusing to encrypt their data center links, not using perfect forward secrecy, etc, the cloud simply doesn't seem like a good default.
They could make this opt-in, as it's supposedly linked to Continuity, but it's very clearly unintuitive, as evidenced by others in this thread (https://news.ycombinator.com/item?id=8511115 for one). If even HN people (probably at least the 95th percentile in tech literacy compared to the general pop) didn't know this, then what about your typical PEBKAC user?
And, sorry to be incendiary, but I'm sure the NSA isn't displeased by Apple's UX choice here.
I (and I believe most people) honestly could care less about the NSA. If they want to get at you, they will. Period. There is no technical solution to what is fundamentally a political problem. Most Americans WANT to be spied on, because terror. I don't like it, don't support it, but I'm not losing sleep over it.
I personally don't mind using iCloud, but I understand the authors reservations. But feel the root problem is the NSA, not apple. It's too bad that America has lost control of its government and is unable to fix this.
It would appear that iCloud is synchronizing all of the email addresses of people you correspond with, even for non-iCloud accounts, to their recent addresses service. This means that names and email addresss that are not in iCloud contacts, not synchronized to your device, and only available in an IMAP-accessed inbox are now being sent to Apple, silently.
Welcome to HN, where blaming the user isn't just our profession, it's our hobby!
Big boys in market, sooner or later, will move all software and hardware power to their side leaving you with a screen, mouse and keyboard to interact with everything.
As soon as companies do not have control over whatever you are doing, they are losing benefit on it.
Get ready to this big move already, every big company will try to do this to my opinion which is sad.
One may not like this, because Snowden, but I don't think most people really are worried about that.
http://chrome.blogspot.com/2014/09/adobe-joins-chromebook-pa...
I guess if you don't opt in to iCloud Drive you're safe?
Number two, there is an easy way to prevent data from ever even touching the cloud. Just immediately save the new document to a local non-iCloud folder before you populate it.
In terms of whether defaulting unsaved docs to iCloud is a good/bad design decision:
Defaulting unsaved documents to the cloud means if someone steals your account login and you don't have 2-factor auth enabled, they can access your unsaved docs.
Defaulting unsaved documents to local storage means continuity doesn't work and kills a lot of value of iCloud.
I think it's a good decision.
Red herring.
Can't say for sure whether a p2p wifi connection would really be an good substitute but I'm skeptical and I bet Apple's thought it through. I know AirDrop works that way but it seems to take a few seconds to set up the connection. Handoff is super fast, in my experience. So since AirDrop is designed to connect with unknown devices that p2p setup performance hit makes sense, but since handoff is for trusted devices, going through iCloud might be faster.
https://developer.apple.com/library/ios/documentation/UserEx...
It was not necessary to do it that way and the exact same user experience could be achieved without the data leaving the room. Continuity only needs to work within bluetooth (and therefore wifi) range.
If Continuity didn't require bluetooth (e.g. for picking up a document on your mac that was started on your phone left in the car in the parking garage) then this design decision could be defended, at least a little bit - but it doesn't work that way.
But you ignored what I noted about the performance of setting up p2p wifi vs. iCloud. Given that Apple does implement p2p wifi for AirDrop, it lends support to the theory that they had good reason to pass on it for Continuity.
So, what is it? On the drive or outside of it?
Does it matter? I googled a bit, but couldn't determine whether Apple can decrypt that data. It is encrypted both in transit and in the cloud, but do they hold the keys?
I know I have to trust them to do what they say they do, anyways, but if they do not have the keys, they cannot change their mind (say in response to a visit from the NSA)
Apple absolutely holds the keys to everything stored on iCloud. See their iOS security whitepaper [1], in the iCloud section:
> iCloud
> iCloud stores music, photos, apps, calendars, documents, and more, and automatically pushes them to all of a user’s devices. iCloud can also be used by third-party apps to store and sync documents as well as key values for app data as defined by the developer. An iCloud account is configured via the Settings app by the user. iCloud features, including Photo Stream, Documents & Data, and Backup, can be disabled by IT administrators via a configuration profile.
>The service is agnostic about what is being stored and handles all files the same way. There are two components for each file. The first is the file’s metadata, which consists of its name, extension, and filesystem permission settings. The second component is the file’s contents, which are treated by iCloud simply as a collection of bytes.
> Each file is broken into chunks and encrypted by iCloud using AES-128 and a key derived from each chunk’s contents that utilizes SHA-256. The keys, and the file’s metadata, are stored by Apple in the user’s iCloud account. The encrypted chunks of the file are stored, without any user-identifying information, using third-party storage services, such as Amazon S3 and Windows Azure.
[1]: https://www.apple.com/ipad/business/docs/iOS_Security_Feb14....
"iCloud Keychain allows users to securely sync their passwords between iOS devices and Mac computers without exposing that information to Apple."
So, I guess somebody should write a 'notepad' for iOS and Mac OS X that stores its data as secure notes in the KeyChain (assuming that secure notes get synced, too)
It all makes perfect sense and is perfectly logical. How is it even possible to be surprised by this?! I’m mystified. It’s also not data outside iCloud. It is very much inside iCloud. Obviously. Newly created documents have to be saved somewhere, and if iCloud is your default location that’s exactly where. Where else?!
According to Apple's KB, just signing into iCloud makes iCloud the default location for all unsaved docs (for iCloud-enabled apps).[1] So even if you've just turned on iCloud for photo streams or syncing contacts or whatever, iCloud becomes the default location for all unsaved docs.
What IP addresses?
http://www.washingtonpost.com/wp-srv/special/politics/prism-...
It is really quite likely that the access to Apple and Google and other large providers' systems is done at an operations level, without knowledge of their management and providing for complete plausible deniability. How many network admins and ops people at Apple have physical access to the machines where keys are generated, stored, and used?
https://en.wikipedia.org/wiki/Tailored_Access_Operations
The #1 realtime end-to-end encrypted messaging service on the planet (where the software development and cyphertext transmission are both physically present inside the legal jurisdiction of the US) would be your first choice, no?
AFAICT that was xenadu02's point - that data from Apple et al are being collect by PRISM, but Apple is not a "partner" in the sense that "partner" implies cooperation. If intelligence agencies have to steer clear of management, that's not a partnership, that's espionage.
[0]: https://finance.yahoo.com/news/how-the-government-could-have...
[1]: see iOS security white paper from Feb 2014, iCloud was the same back in 2012.
All of these things are just normal. It's not like an evil mastermind decided that there was the need to access your unsaved documents.
I mean, you can still get angry about it but it seems pointless since you (probably) already use all of the google services that are available.
Also, a "security researcher" should know better :)
Presumably they actually did have permission through some ToS you have to agree to if you want to use OSX - which begs the question of what insane amount of permission they actually have here. Seems that it probably boils down to that they can make an argument for literally anything on the mac being useful for continuity, so they can probably upload anything they like by default using that claim?
It appears that the only new functionality in this case is increased visibility via iCloud Drive. Presumably these documents were always saved on iCloud, which has been default behavior when you don't save to the local file system for a while.
As usual, there's an unfounded insinuation that this is intentionally nefarious activity on Apple's part. Documents and Data sync is easily disabled -- what did anyone think it was doing previously?
"Intentionally nefarious" implies bad faith - I think it's just wickedly reckless and violates the huge amount of trust that end users place in their OS vendor.
The synchronization of the email recents list across iCloud via recentsd is the big problem. If I add a third-party email account that I access via IMAP, it is not the job of my phone or workstation to send the metadata (sender list) to my OS vendor's servers, even if it does enable the feature of easy address autocomplete on my other devices.