5 ms·
I don't really understand the folks that use the platform and then talk about how completely untrustworthy it is.
by upon_drumhead 2y ago
I don't really understand the folks that use the platform and then talk about how completely untrustworthy it is.
- ben_w 2y agoPick your poison, everything else is also broken.
- upon_drumhead 2y agoSure, but if you fully believe that the platform is untrustworthy, that seems like the ultimate dealbreaker for someone who is concerned about their data privacy. It's the juxtaposition of "I don't trust this platform at all" and "I put my data that must remain private on it" that I don't understand.
- dkarras 2y agoTrusthworthy has two meanings here. I trust that Apple does have no intention to look into my private data. I think they'd rather have no way of getting into it while providing the services as that minimizes their liability. In that sense they are trustworthy. But you might not trust them to be secure enough to store that data. Or maybe it has nothing to do with Apple, maybe you don't want your keychain in the "cloud" ever. I trust Apple does not intend to be nefarious, I don't trust (the security of) any "cloud" to store sensitive data. Those are not conflicting positions to be in.
- deleted 2y ago[deleted]
- ric129 2y agoThere's an inherent trade-off in everything Besides, in this case.. it does not help that you'd also have to exchange hardware
- asadotzler 2y agoBecause this particular untrustworthiness manifested after the user adopted the platform. I don't really understand corporate bootlicking either, but I can at least take a minute to think about it before posting nonsense.
- lordofgibbons 2y ago> Because this particular untrustworthiness manifested after the user adopted the platform. This company has shown multiple times in the past that they can and will change their closed source software's behavior to the detriment of user privacy (remember Apple's on-device image scanning?). Why are you or OP surprised when these things continue to happen on the closed source walled garden?
- revscat 2y agoNo one is fully trustworthy.
- fsflover 2y agoFree software operating systems which do not call home are. Example: Qubes OS.
- Apocryphon 2y agoIt's kind of funny- I find myself to be on the critical side when it comes to Apple, especially on HN, but when it comes to iCloud Keychain I use it pretty unquestioning. Probably because I don't trust 1Password or other password managers to be any better, and it's a feature that's baked into the OS so adoption is frictionless.
- 8fingerlouie 2y agoWhen it comes to trust it doesn't really matter what you use. In theory 1Password has the superior product, as they use MFA for accessing your vault, and your account password only allows access to the encrypted vault (unlike Bitwarden where your account password unlocks everything). But that is all theory, and you don't really know what really goes on behind the scenes, and it could all just be "theater". It probably isn't, but that's where the trust part comes in. Personally i doubt that Apple has any nefarious intent, and i believe their intention is to make stuff better and more secure, and that they protect/respect privacy. Again, this is a matter of trust, and i trust Apple. I don't base my assumptions on blind trust, but actually review their documentation on their services, like iCloud Data Security [^1]. They're pretty open about how they encrypt stuff, and also mention stuff like when using standard iCloud encryption, your backup of messages includes a key that can be used to decrypt the messages in the backup. I enabled Advanced Data Protection as soon as it became available, and stopped worrying about it. For stuff that i want to keep secret at all costs i use GPG or Cryptomator. As for Keychain i use a mix of Keychain and 1Password. Keychain for everything "simple" that i don't care about, i.e. websites that requires a login. It plays well with Hide my Email, and offers the path of least resistance. My 1Password usage is mostly stuff that doesn't fit easily into Keychain. [^1] : https://support.apple.com/en-us/102651 https://support.apple.com/en-us/102651
- overstay8930 2y agoSeriously, you have to be so detached from reality to think iCloud Keychain sync is an issue at all, you just have to believe Apple put a backdoor their own TPM chip so they could decrypt your Keychain with a software update without human interaction. If you’re this distrustful of Apple, your logic should say to not use local Keychain at all. You either trust Apple’s hardware backed E2EE or you don’t trust anything from Apple at all, there’s no picking and choosing when it comes to this sort of thing. I bet privacy researchers at Apple are facepalming reading these threads thinking people can run their own crypto better than they can.
- 8fingerlouie 2y agoI fully agree. > thinking people can run their own crypto better than they can Running or developing ? You can probably run something like Password Store [1] fairly secure, though you still have to trust the operating system not to leak your secrets, and it turns out that today, regardless of your choice, all major operating systems more or less synchronize your data to the cloud. I know Linux doesn't do it (Ubuntu tried some Amazon partnership once), but Linux is a poor match for many workplaces where Windows or MacOS are kings. Yes, you can run VSCode (or Vim/Emacs or whatever) on Linux, but running Photoshop, Fusion365 or various other business tools is not as "easy" as on Windows/MacOS, and in the end a company only has so many IT support staffers. [1]: https://www.passwordstore.org/ https://www.passwordstore.org/
- RedComet 2y agoPlenty of "privacy researchers" thought it was suspicious that they chose P-256 for iCloud keychain while using it nowhere else.