Confidential Apple Files in iCloud
The way Apple combines work and personal iCloud accounts left some employees able to access confidential documents after departing the company, reports The Information. The site spoke to more than half a dozen former Apple employees who were unknowingly left with access to sensitive content.
[…]
Apple told The Information that the OpenAI lawsuit is unrelated to any files left available on iCloud and that it does not pursue legal claims against former employees who accidentally have Apple documents in their personal iCloud accounts.
[…]
In a now-settled legal dispute, chip company Rivos claimed Apple intentionally lets former employees retain access to files “as part of a planned effort to generate a pretextual basis to sue the employees and their new employer for ‘stealing’ Apple material.” In the Rivos case, an employee was targeted for keeping work files in his personal iCloud account.
The documents included confidential material such as plans for product launch events. The former employees said they made no effort to retain access and unexpectedly found the files mixed with their personal iCloud data.
The problem reportedly grew from Apple’s practice of encouraging employees to connect their personal Apple IDs to company-funded iCloud storage.
[…]
Apple also relied heavily on iMessage for workplace conversations and file sharing before rolling out Slack around 2019. Former employees could retain old iMessage conversations and attachments, while Apple could terminate their Slack access when they left.
If you use your personal Apple ID, you get a magic “Apple Work” folder in iCloud Drive. When you leave Apple, that “Apple Work” folder disappears. But any other files or folders that were shared with you that were outside that magic folder are still in your iCloud Drive, because it’s still your personal iCloud account.
[…]
You still have the same Apple ID account, even though you no longer have an employee @apple.com email account. Overall, this is a humane way of dealing with digital identity. Your Apple ID account is you, the person, not “example@icloud.com”, one specific unique email address. And you, the person, may well have multiple email addresses — all of which can be associated with your one Apple ID account. That makes Apple IDs more nuanced and complicated than a simple mapping of one email address = one account. And it obviously makes access restrictions more complicated.
Yesterday, OpenAI released messages to show that Apple employees (with permission) retained access to the departing employee’s personal iCloud account so that they could access work files that were stored there. It’s just a mess that both the software and corporate policy encourage mixing everything in one account.
As many things I know about Apple, this whole thing both makes perfect sense and feels absolutely bonkers.
Previously:
- OpenAI Open Letter Responds to Apple Lawsuit
- Apple Sues OpenAI Over Trade Secrets
- Privacy for Apple Employees