News

There are hidden dangers in Apple’s iCloud sharing mechanism. Many resigned employees can still access confidential company documents. According to the latest investigation report, Apple has serious management omissions in its mechanism for mixing work and personal iCloud accounts, which has resulted in many resigned employees still being able to continue to access confidential internal documents after leaving the company.

3 min read
There are hidden dangers in Apple's iCloud sharing mechanism. Many resigned employees can still access confidential company documents. According to the latest investigation report, Apple has serious management omissions in its mechanism for mixing work and personal iCloud accounts. As a result, many resigned employees can still access confidential internal documents after leaving the company. According to several former employees interviewed, many internal Apple documents shared through iCloud during their tenure, including preparations for product launches, will still be synced to their personal devices after they leave, and they will even receive notifications of the latest updates to relevant documents. Some former employees admitted that they did not even dare to take the initiative to clean up these residual contents because they were worried that deleting files at will might attract the attention of Apple's legal team. The root cause of this problem lies in Apple's internal personnel management and account mechanism. Apple usually encourages employees to combine their personal Apple accounts with their work iCloud accounts, and provides employees with 2TB of iCloud storage space. Since a single iPhone and other devices can only log in to one main account at the same time, most employees choose to bind their work storage space directly to their personal accounts in order to avoid carrying two mobile phones. Although Apple has set up special enterprise management folders to uniformly revoke access permissions when employees leave, many internal files are not automatically stored in these controlled directories, and files shared through applications such as "Messages" are also mixed with personal data, resulting in loopholes in clearing permissions after departure. It is worth noting that residual system access rights have previously triggered litigation disputes. In previous legal proceedings against OpenAI and other companies and former employees, Apple accused former employees of illegally downloading or retaining company technical secrets; some defendant employees and related companies argued that Apple did not thoroughly clean up the files of the iCloud accounts of resigned employees, and even used this as an excuse to file subsequent lawsuits. However, Apple stated that the relevant lawsuits are for malicious theft of unreleased technologies and products and have nothing to do with iCloud's normal file sharing or storage mechanism. The company will not initiate lawsuits against resigned employees who inadvertently retained files in their personal accounts due to legacy problems in the system. Although there is currently no evidence that Apple intends to retain the file access rights of departed employees, industry analysts believe that this loophole in iCloud sharing and account erasure is obviously very different from the extremely high standards of data security and privacy protection that it has always emphasized. via cnBeta.COM - Chinese industry information station (author: source: cnBeta.COM)