5 ms·
i understand and agree that this should at the very least have an opt-in dialog box. that said, apple did add the option for end-to-end encrypted “advanced dat
by nhod 2y ago
i understand and agree that this should at the very least have an opt-in dialog box.
that said, apple did add the option for end-to-end encrypted “advanced data protection” for the majority of icloud data a year or so ago.
perhaps they also enabled it by default in sonoma?
https://support.apple.com/en-us/108756 https://support.apple.com/en-us/108756
- lapcat 2y ago> perhaps they also enabled it by default in sonoma? No, they didn't. Anyway, iCloud Keychain has always been end to end encrypted.
- TillE 2y agoRight, it's obviously end-to-end encrypted because if it weren't, everyone would have been screaming for years about how horrendously insecure it was. iCloud Keychain is fine, just use a good password. There's no particular harm in letting Apple store an encrypted blob for you on its servers.
- SpikeDad 2y agoAnd only enabled if 2FA is enabled. It won't work without (as won't many Apple services).
- adamomada 2y agoThank you, this was the missing piece of the puzzle for me.
- CharlesW 2y agoEven with so-called standard data protection, iCloud Keychain passwords are always end-to-end encrypted, and Apple cannot decrypt them. "For additional privacy and security, 15 data categories — including Health and passwords in iCloud Keychain — are end-to-end encrypted. Apple doesn't have the encryption keys for these categories, and we can't help you recover this data if you lose access to your account." https://support.apple.com/en-us/102651 https://support.apple.com/en-us/102651
- Teever 2y ago> Apple cannot decrypt them. How do you know this?
- CharlesW 2y agoI provided both a citation and the relevant quote from it.
- Teever 2y agoIf it did turn out that Apple was actually able to do what they claim they can't, how would you explain the source that you linked to?
- CharlesW 2y ago> If it did turn out that Apple was actually able to do what they claim they can't… My friend, I'm afraid I have no idea what you mean. What do you believe Apple claims they can't do that conflicts with this? (If your answer is "end-to-end encryption", Apple has supported this for at least a decade.)
- imwillofficial 2y agoI think what the poster is getting at is: "How do we validate claims of end-to-end encryption?" It is a lot of trust to place in a company. I would be curious if there are ways to test Apple's claims?
- Sporktacular 2y agoIt's not just trust in a company. Matthew Green was geeking out about iCloud Keychain privacy a few years ago. He sometimes speaks of contacts in Apple security who are really committed and competent engineers. Their professional reputations are on the line too. Nothing would damage their careers like a backdoor that conspiracy types love to speculate on.