{"id":43353,"date":"2024-05-21T14:48:39","date_gmt":"2024-05-21T18:48:39","guid":{"rendered":"https:\/\/mjtsai.com\/blog\/?p=43353"},"modified":"2024-11-01T16:07:14","modified_gmt":"2024-11-01T20:07:14","slug":"apple-updates-silently-enable-icloud-keychain","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2024\/05\/21\/apple-updates-silently-enable-icloud-keychain\/","title":{"rendered":"Apple Updates Silently Enable iCloud Keychain"},"content":{"rendered":"<p><a href=\"https:\/\/lapcatsoftware.com\/articles\/2024\/5\/3.html\">Jeff Johnson<\/a>:<\/p>\n<blockquote cite=\"https:\/\/lapcatsoftware.com\/articles\/2024\/5\/3.html\"><p>I&rsquo;ve discovered today that unfortunately this issue&mdash;this bug, I would call it, though who knows whether Apple considers it a bug or &ldquo;expected behavior&rdquo;&mdash;still exists with the latest versions of macOS Ventura and Sonoma, 13.6.7 and 14.5 respectively.<\/p><p>[&#8230;]<\/p><p>The external drive had a macOS Ventura 13.6.7 boot volume with iCloud enabled but iCloud Keychain disabled. After updating the volume to macOS Sonoma 14.5, iCloud Keychain was enabled. (I then disabled iCloud Keychain, which actually caused System Settings to hang and eventually crash, but afterward iCloud Keychain did seem to be disabled.)<\/p><p>[&#8230;]<\/p><p>What I&rsquo;d like to do is update from Ventura to Sonoma without an internet connection, giving Sonoma no chance to upload my passwords or other data to iCloud before I can disable iCloud Keychain.<\/p><p>[&#8230;]<\/p><p>You might wonder why I don&rsquo;t sign out of iCloud <em>before<\/em> I update from Ventura to Sonoma. It turns out that there&rsquo;s no point in that, due to <em>another<\/em> bug, &ldquo;Signing out of iCloud and signing back in again forgets all of your previous iCloud settings&rdquo; (FB12168173), which I also discovered last year.<\/p><\/blockquote>\n<p>Because installing macOS <em>also<\/em> re-enables Wi-Fi, his workaround was to turn off Wi-Fi after downloading the installer, delete his Wi-Fi password, and then install the update.<\/p>\n\n<p><a href=\"https:\/\/lapcatsoftware.com\/articles\/2024\/5\/4.html\">Jeff Johnson<\/a>:<\/p>\n<blockquote cite=\"https:\/\/lapcatsoftware.com\/articles\/2024\/5\/4.html\">\n<p>The success of the trial run gave me the confidence to update my main development machine, an M1 MacBook Pro, from Ventura to Sonoma. Unfortunately, for unknown reasons, I experienced a different result the second time. As before, the workaround did successfully prevent Sonoma from connecting to my WiFi network. And as before, I confirmed in System Settings that iCloud Keychain was still disabled after the Sonoma update. However, after I finally connected to my WiFi network again, I discovered to my horror that Sonoma <em>did<\/em> then silently enable iCloud Keychain. My workaround was ultimately futile.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/defcon.social\/@mysk\/111167154833155521\">Mysk<\/a>:<\/p>\n<blockquote cite=\"https:\/\/defcon.social\/@mysk\/111167154833155521\"><p>If you&rsquo;ve never enabled iCloud Keychain and recently upgraded to iOS 17, chances are good that your passwords are now stored on Apple servers. As confirmed by many users, iOS 17 secretly turns iCloud Keychain on. This video shows the entire process step by step[&#8230;]<\/p><\/blockquote>\n\n<p>Previously:<\/p>\n<ul>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2022\/07\/22\/apple-re-enables-bluetooth-on-every-update\/\">Apple Re-enables Bluetooth on Every Update<\/a><\/li>\n<\/ul>\n\n<p id=\"apple-updates-silently-enable-icloud-keychain-update-2024-05-28\">Update (2024-05-28): See also: <a href=\"https:\/\/news.ycombinator.com\/item?id=40485053\">Hacker<\/a> <a href=\"https:\/\/news.ycombinator.com\/item?id=40409290\">News<\/a>.<\/p>\n\n<p id=\"apple-updates-silently-enable-icloud-keychain-update-2024-05-29\">Update (2024-05-29): <a href=\"https:\/\/mastodon.social\/@krzyzanowskim\/112507591783734612\">Marcin Krzyzanowski<\/a>:<\/p>\n<blockquote cite=\"https:\/\/mastodon.social\/@krzyzanowskim\/112507591783734612\"><p>I noticed my disk storage went drastically low and I started to check system, then I realized something ( #macos update???) enabled iCloud Photos synchronization to my Mac (that can take all the storage it get, and for that very reason I didn&rsquo;t enable it on my mac)<\/p><\/blockquote>\n\n<p id=\"apple-updates-silently-enable-icloud-keychain-update-2024-05-31\">Update (2024-05-31): See also: <a href=\"https:\/\/talk.tidbits.com\/t\/apple-keychain-privacy-fail\/27921\">TidBITS-Talk<\/a>.<\/p>\n\n<p id=\"apple-updates-silently-enable-icloud-keychain-update-2024-06-03\">Update (2024-06-03): <a href=\"https:\/\/mastodon.scot\/@callme_jc\/112546586832694287\">Johann Campbell<\/a>:<\/p>\n<blockquote cite=\"https:\/\/mastodon.scot\/@callme_jc\/112546586832694287\">\n<p>Really wish Apple could stop toggling iCloud Photos on without my permission, when it KNOWS I won&rsquo;t pay for more than the base 5 GB of iCloud storage.<\/p>\n<\/blockquote>\n\n<p id=\"apple-updates-silently-enable-icloud-keychain-update-2024-06-05\">Update (2024-06-05): <a href=\"https:\/\/lapcatsoftware.com\/articles\/2024\/6\/4.html\">Jeff Johnson<\/a>:<\/p>\n<blockquote cite=\"https:\/\/lapcatsoftware.com\/articles\/2024\/6\/4.html\">\n<p>A follower on Mastodon <a href=\"https:\/\/hachyderm.io\/@ranvel\/112510102208190380\">gave me a nice tip<\/a> on how to prevent this in the future: <a href=\"https:\/\/support.apple.com\/guide\/apple-configurator-mac\/create-and-edit-configuration-profiles-pmd85719196\/mac\">create a configuration profile<\/a>.<\/p>\n<p>First, download the <a href=\"https:\/\/apps.apple.com\/app\/apple-configurator\/id1037126344\">Apple Configurator app<\/a> from the Mac App Store. Then open Apple Configurator, select New Profile from the File menu, uncheck Allow iCloud Keychain in Restrictions, and save the <code>.mobileconfig<\/code> file.<\/p>\n<\/blockquote>\n\n<p id=\"apple-updates-silently-enable-icloud-keychain-update-2024-11-01\">Update (2024-11-01): <a href=\"https:\/\/lapcatsoftware.com\/articles\/2024\/10\/4.html\">Jeff Johnson<\/a> (<a href=\"https:\/\/mastodon.social\/@lapcatsoftware\/113403519071201392\">Mastodon<\/a>, <a href=\"https:\/\/news.ycombinator.com\/item?id=42014588\">Hacker News<\/a>):<\/p>\n<blockquote cite=\"https:\/\/lapcatsoftware.com\/articles\/2024\/10\/4.html\"><p>What I didn&rsquo;t realize at the time, indeed didn&rsquo;t realize until now, is that iCloud Keychain already uploaded all of my passwords and kept them in iCloud even after I disabled iCloud Keychain.<\/p><p>[&#8230;]<\/p><p>Today I was shocked to discover a bunch of my website passwords in Safari while booted into Sequoia on the Mac mini. There shouldn&rsquo;t be any personal data on the mini, and iCloud Keychain is disabled in its Sequoia volume.<\/p><p>[&#8230;]<\/p><p>The question is, how do you delete all data from iCloud Keychain?<\/p><\/blockquote><p>An old Apple support document suggests that there&rsquo;s an option to delete the data from the cloud when you turn it off, but that no longer seems to be the case.<\/p><blockquote cite=\"https:\/\/lapcatsoftware.com\/articles\/2024\/10\/4.html\"><p>As a workaround, I manually deleted all of my passwords in the Passwords app in Sequoia, enabled iCloud Keychain, and then disabled iCloud Keychain again. To verify the password deletion, I booted into Sonoma on the Mac mini and enabled iCloud Keychain there. Fortunately, no passwords were downloaded from iCloud.<\/p><p>[&#8230;]<\/p><p>I&rsquo;m still concerned about other data that may still be in iCloud Keychain. For example, what about wifi passwords? I can&rsquo;t very well delete my wifi password on the Mac mini and then sync the deletion to iCloud Keychain, because of course I can&rsquo;t sync anything without wifi! And what else does iCloud Keychain store that I can&rsquo;t necessarily see in the user interface?<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/news.ycombinator.com\/item?id=42016770\">Jeff Johnson<\/a>:<\/p>\n<blockquote cite=\"https:\/\/news.ycombinator.com\/item?id=42016770\"><p>A crucial point to understand: unbeknownst to me, my passwords ended up on a device that I didn&rsquo;t specifically authorize to download them.<\/p><p>The good news is that the device is owned by me and under my control. However, since it&rsquo;s just a test machine with no personal data&mdash;or so I believed&mdash;it&rsquo;s less protected than my other devices. For example, it has a weak login password, no Filevault, and no biometrics (Mac mini).<\/p><\/blockquote>","protected":false},"excerpt":{"rendered":"<p>Jeff Johnson: I&rsquo;ve discovered today that unfortunately this issue&mdash;this bug, I would call it, though who knows whether Apple considers it a bug or &ldquo;expected behavior&rdquo;&mdash;still exists with the latest versions of macOS Ventura and Sonoma, 13.6.7 and 14.5 respectively.[&#8230;]The external drive had a macOS Ventura 13.6.7 boot volume with iCloud enabled but iCloud Keychain [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2024-05-21T18:48:41Z","apple_news_api_id":"efe7a629-5d53-4920-a916-efe97e5d0a61","apple_news_api_modified_at":"2024-11-01T20:07:18Z","apple_news_api_revision":"AAAAAAAAAAAAAAAAAAAABQ==","apple_news_api_share_url":"https:\/\/apple.news\/A7-emKV1TSSCpFu_pfl0KYQ","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[1850,131,16,1417,1142,31,2321,30,2223,2385,2222,355,2087,187],"class_list":["post-43353","post","type-post","status-publish","format-standard","hentry","category-technology","tag-apple-configurator","tag-bug","tag-icloud","tag-icloud-keychain","tag-icloud-photo-library","tag-ios","tag-ios-17","tag-mac","tag-macos-13-ventura","tag-macos-14-sonoma","tag-passkeys","tag-privacy","tag-software-update","tag-wifi"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/43353","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=43353"}],"version-history":[{"count":7,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/43353\/revisions"}],"predecessor-version":[{"id":45630,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/43353\/revisions\/45630"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=43353"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=43353"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=43353"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}