Apple's iCloud File Sharing Left Ex-Employees With Access to Secret Documents (macrumors.com) 29
Apple's practice of mixing employees' work files with personal iCloud accounts reportedly left some former staff with continued access to confidential documents, messages, and even new updates after leaving the company. "The former employees said many Apple files they had been shared on over their careers at the company -- including planning documents for product launch events -- continued to sync to their personal devices through the iCloud storage service after they left Apple," reports The Information. "In some cases, they even received notifications about fresh updates to the documents. Some former employees said they were petrified to delete the files for fear that doing so would attract Apple's attention." MacRumors reports: Apple files get mixed in with employees' accounts because the company encourages them to use their personal Apple Accounts with their work iCloud account. Employees are given a 2TB iCloud plan and are able to merge the storage with their existing Apple Account or create a new account. Since only one primary account can be signed in at a time, most opt to use their existing account to avoid having to carry two iPhones. Apple has a managed folder for workplace files that it revokes access to when an employee leaves, but some internal documents aren't saved there automatically and shared files end up mixed in with personal content. Employees can also retain access to iMessage chats and files shared via the Messages app.
Lingering access to Apple systems is central to Apple's lawsuit against OpenAI. In its filing, Apple alleged that former employee Chang Liu breached Apple's systems using a "rare, previously unknown authentication bug" to download files while he was working at OpenAI. Apple told The Information that the OpenAI lawsuit is unrelated to any files left available on iCloud and that it does not pursue legal claims against former employees who accidentally have Apple documents in their personal iCloud accounts. "This case is about OpenAI employees wrongfully taking Apple's secret and confidential information regarding our unreleased technologies, processes, and products. Nothing in the filing relates to documents shared by, or stored in, iCloud."
Lingering access to Apple systems is central to Apple's lawsuit against OpenAI. In its filing, Apple alleged that former employee Chang Liu breached Apple's systems using a "rare, previously unknown authentication bug" to download files while he was working at OpenAI. Apple told The Information that the OpenAI lawsuit is unrelated to any files left available on iCloud and that it does not pursue legal claims against former employees who accidentally have Apple documents in their personal iCloud accounts. "This case is about OpenAI employees wrongfully taking Apple's secret and confidential information regarding our unreleased technologies, processes, and products. Nothing in the filing relates to documents shared by, or stored in, iCloud."
Defective by design (Score:5, Insightful)
The root cause comes from these twelve words:
Since only one primary account can be signed in at a time ...
Authentication systems that allow only a single signed-in account are defective by design. Approximately 100% of all people have more than one account that they need to be signed in with.
I have half a dozen Google accounts for specific purposes — one for work, one for personal, one for electronic music tablets to which multiple people share physical access, a couple of old domain-specific accounts that got converted from free work profiles, and I'm probably forgetting some. Not all of these are useful, but if I could not have continuous access to work and personal, it would be a tremendous pain in the backside.
And encouraging people to merge profiles like that is nuts. It all but guarantees leaks. A confidentiality agreement typically protects things you learned in the scope of your employment, but after you are employed, if they continue to send you confidential information, there's a decent chance that you aren't under any legal obligation to keep that secret.
This is just a really bad way to do things, driven by a fundamental flaw in their architecture. And it doesn't just cause problems for Apple. It causes problems for their customers as well. I can't have a separate iCloud account for my work. I have to use a Google account. And more than that, when I hit the maximum number of AirTag devices (which I'm about to reach), I can't add additional iCloud accounts. I'm hard-capped at a single account.
While we're at it, the limitation of a single user per iPad stems from the same defective design process. All of those sorts of 1:1 mapping decisions between accounts, users, and devices need to be fundamentally rethought, because they were always a mistake. Maybe now that Apple is being bitten by it, they'll finally do the things that users have been asking them to do for the last decade. Bonus points if they lose their lawsuit because of a lack of a modicum of care on their part, because that just might be enough to wake the sleeping giant and get them to fix this mess.
Re: (Score:2)
Apple's entire ecosystem is defective by design, not just their authentication system. Their security, software engineering, cloud engineering, and UI/UX are all defective by design.
Re: (Score:2)
I agree that it's a frustration to only have access to a single account at a time (in this case, an Apple ID), but I'll point out that this is the use case for probably 99.9% of their users. And there are some exceptions to this rule: Apple does have a mechanism in place that lets you use one Apple ID for music and a different one for their various App Stores, for example. However, this still doesn't let you use two Apple IDs for a single service at the same time.
I think the reasoning behind this is pretty
Re: (Score:3)
the UI problems involved in allowing multiple simultaneous logins to the same service are extremely complex
I mean, maybe if you're bad at software engineering, networking, and/or UX. Otherwise, it's relatively easy.
Re: (Score:3)
I agree that it's a frustration to only have access to a single account at a time (in this case, an Apple ID), but I'll point out that this is the use case for probably 99.9% of their users. And there are some exceptions to this rule: Apple does have a mechanism in place that lets you use one Apple ID for music and a different one for their various App Stores, for example. However, this still doesn't let you use two Apple IDs for a single service at the same time.
I think the reasoning behind this is pretty solid: the UI problems involved in allowing multiple simultaneous logins to the same service are extremely complex, and if you're only looking at a frustration for a vanishingly small percentage of your userbase, it doesn't make sense to make it more complex for everybody.
It really isn't complex. Google does it just fine. You have an account picker in the upper right corner, and you choose which account you're using to interact with that app. No big deal.
Having a mechanism to use one account for music and a different one for app stores? Now that's complex. That's adding special-casing for each app that needs to handle a separate account, instead of designing the auth system correctly to support multiple accounts to begin with. It's almost always easier to do it right t
Re: (Score:2)
I also disagree with the claim that 99.9% of users only have one iCloud account
Of course. If you had an iCloud account back when it was MobileMe, it didn't function as your iTunes account. Later on, when all accounts function as Apple IDs, you find out that new accounts are both but you can't merge yours - they are separate forever.
Re: (Score:2)
In my recent experience this is true. I tried to create a separate Apple ID for business so that I didn't need my personal Apple ID for it. Was weirdly complicated process. I even contacted apple business dev. people from local Apple Store. Their process begins with emailing forms that you fill out and send back in! Never got it to work properly and abandoned it.
Re: (Score:2)
Which doesn't really work as users routine confuse their accounts and upload files to the wrong account, and then confusion ensues when files are stored partially on a work account and on a personal account.
Microsoft makes it somewhat better because OneDrive ends up with different accounts show up multiple times. And YouTube
Re: (Score:3)
An iPhone is designed for personal use. It was never designed to have 1000's of these things (or more) 100% owned and 100% centrally managed by a company.
Companies supply "work phones" for a reason. You really don't want all your employees in key supplier or customer facing roles to be working on a privately controlled phone number and device (and sometimes private email addresses/messaging services). Don't even get into all the data retention legal issues when people discuss non-public information on de
Re: (Score:2)
Companies supply "work phones" for a reason.
I've never wanted to carry two phones, let alone two smart phones, and I imagine most people feel the same. If the company gives me a phone, it promptly goes into my desk, or equivalent, and stays there.
Re: (Score:2)
Employer created and managed Apple IDs (Score:2)
Isn’t the fix to let employer’s create and manage employee specific Apple IDs? Doesn’t Apple want organizations to buy into the Apple ecosystem?
I’d like to think an Apple work ID would require an Apple email address, but that might be true at creation time, and en employee could change the email to something else.
Re: (Score:2)
How is this not working as designed?
That's the point, it's an overwhelmingly bad design, like everything else Apple does.
Re: (Score:2)
Apple designs amazing hardware and great software. But when we get to online/networked/cloud... It's kinda shit, yeah. Which is notable because other companies have done extremely well in that space, to the point that Google's good-but-imperfect network services get more public complaints than Apple's dear-god-why network services. We just expect it now.
Re: (Score:2)
Apple designs amazing hardware and great software.
Visually, sometimes. Functionally, no.
Re: Employer created and managed Apple IDs (Score:1)
Which great software has Apple designed?
Re: (Score:2)
Mac OS seems good, from my minimal usage. Good enough that I bought a Neo to fill the netbook-shaped hole in my roster. First time buying an Apple product with my own money. (You can see my decades of disparaging posts on that website Slashdot.)
Is it *great*? Probably not, if I tried going too far off the beaten path. And I'm sure there's tracking and telemetry there hiding. Even a bit of cloud promo. But compared to Windows? My doctor's telehealth portal doesn't like Linux, so that was out too.
Re: (Score:2)
But compared to Windows? My doctor's telehealth portal doesn't like Linux, so that was out too.
Ouch. That's the rub indeed, people are getting fucked over by their "service" "providers". I'm able to use everything so far from Linux; the local hospital's telehealth and my bank's website will even work in Firefox, but I need to use Chromium (ungoogled is OK) to pay my bills. Otherwise I have to use the phone payment system, which of course is super duper easy actually but I'd still rather do it on the web.
Re: (Score:2)
Apple started as a hardware company, with network services coming MUCH later.
Google were always a network first company.
Re: (Score:2)
If they want to let employees use a personal ID for authentication, that's great. As long as the workspace area is partitioned off and they don't at all cross paths. There's a reason why Apple isn't competing with Microsoft or Google offering a unified online workspace.
Re: (Score:3)
Proof yet again that Apple does not design products and services for businesses. They focus is on a particular user experience which has allowed them to get enterprise customers through creatives and execs.
I have never signed into iCloud on my iPhone (Score:2)
I still get dunned you need to accept the iCloud terms,
You need to Sign into iCloud to finish the setup.
Your device has not been backed up to iCloud, Accept terms and Backup now.
I suspect Apple is doing backups to the cloud anyway. After all it is the customers data that is of value to Apple.
Re: (Score:2)
After all it is the customers data that is of value to Apple.
While I don't have any personal knowledge of what Apple does/doesn't do behind the scene, the main reason for the iCloud backup stuff is to keep you tied to their ecosystem and buying products. They want to make it easier for you to buy a new phone, or computer, and just have it pick up where the old one left off.
Someone at my company did this (Score:2)
Re: (Score:2)
since it's illegally preinstalled on all Win11 PCs
Nothing illegal about it.
You're example is more of a combination of employee and employer incompetence rather than Microsoft's design choices. Microsoft's design choices can be managed and "solved" by users, Apple's can only be fixed by Apple and only if they feel like it. Sharepoint and OneDrive can be used together very easily without accidentally doing what you just described.
BYOD DOA Without Provenance (Score:1)
The knight says... (Score:2)
Apple chose ... poorly.
Cleaning this up is not likely to be especially easy, and doing the forensics to determine what people had access to confidential data after they were no longer employed, and what damage that may have done to the company, is going to take a lot of time.
unprofessional (Score:2)