Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

When I look at the imessage conversation, one thing strikes me: that guy looks to be using the same icloud account he used when working for Apple with OpenAI. Is he using his own personal account? Why do both Apple and OpenAI allow that in the first place, this look so amateur. I would have assumed each company would have opened a different account for him and locked him when leaving.

Is it standard practice at both Apple and OpenAI for employees to use their personal icloud account for work?



Apparently Apple encourages their employees to use their personal iCloud accounts for company information, because their own OS doesn't support one iPhone, multiple iCloud identities.

Source: https://appleinsider.com/articles/26/08/03/confidential-appl...

So yeah.


Always found it odd that Apple don't let you have a second separate business profile to switch your phone to for work - especially when you don't necessarily want to be bringing browser history/personal apps into your workplace or wifi. Having your iphone locked to your personal account also hobbles their continuity features if you work on a business computer with its own work account (as most businesses do).

Facebook is equally bad on this front - requiring you to use your personal account to administrate business pages (don't even get me started on how they forced large businesses to use a custom 2FA method they then phased out - locking people out of their personal accounts forever).


however, it is quite neat for Apple if employees are "voluntarily" giving up their privacy by merging their accounts and indirectly allowing Apple to monitor their whole digital identity.

Apple is then "just" monitoring the corporate user account for security reasons, it was the employee who decided to use the same account for private purposes...


>Always found it odd that Apple don't let you have a second separate business profile to switch your phone to for work - especially when you don't necessarily want to be bringing browser history/personal apps into your workplace or wifi.

I'm guessing it's the same reason they don't offer multiple accounts on iPad. They would rather you bought more devices.


As the maker of the iPhone, shouldn't Apple just give each employee a work phone running company's account?


Yes. But that doesn’t solve the problem for every other business or even families that want to share devices between roles or people.


I knew guys at Facebook who told me this and it deterred me from ever wanting to work there (among other things).


Apple can give employees an iphone which will have an iCloud account in apples’s corp domain and can be used only for work. Many other companies do this.


Most companies give you a company phone with a company iCloud account.


According to more than a dozen former Apple employees, apparently not Apple though... despite the fact that they make iPhones.


We created dummy accounts all the time when I was at Apple.

Testing/QA generate loads of them. I still remember one of mine: test_testerson@apple.com


Even Microsoft lets you use your personal iCloud account on corp laptops. They can’t snoop your personal data without disabling SIP or showing system level privacy prompts or recording indicators.


So iOS is essentially unprofessional. A toy for those who have either no job or no private life. How does Android score in that respect?


You can have multiple users on a single device.

https://source.android.com/docs/devices/admin/multi-user

Either with a single local account that accesses multiple Google accounts, or multiple local accounts. Though this is device specific, it may be disabled by your manufacturer/provider.

As mentioned elsewhere though, an enrolled phone is an enrolled phone so corporate wiping will wipe the entire phone and not just the profile.


Not true - you can do full MDM type enrolment or just the one where t can wipe the work part of the phone. On Android and iOS


> and iOS

I'm pretty sure this is a thread about how you can't do things like that on iOS.

Regardless, its been a long time since I've had to use a personal device for work purposes and at the time Android seemed to only want to lock the entire phone down. If that is now fixed them thats great.


It's been a while, but at a previous job (maybe 8 years ago) I was responsible for managing mobile devices and using Blackberry's MDM suite, you could have segregation of personal and private data, where you couldn't move data from one "container" to the other, including clipboard data.

I'm out of the loop now, though.

Android did have better support at the time, but if I remember correctly, devices that had a work managed profile on them could still be completely wiped, including the personal/private container.

A bit of a pain, but I've always preferred (where possible) to have separate work and personal devices.


> devices that had a work managed profile on them could still be completely wiped

No, personally-owned devices with a work profile cannot be wiped remotely using mdm. But company-owned with our without personal profile can be wiped by a mdm.


Yeah, I had an Android phone at work with separate personal/work profiles, but using the phone to begin with required one main account that had to be my personal. Might've been possible to remove after, but I was afraid to mess with it.

Wouldn't want one phone to be both personal and work though. They owned it, idk if I could've put my own sim in without unforeseen issues, it could've been wiped like you said, and it ofc got wiped when I quit.


Well, aint no way I'm working with a realtor over green bubbles, and they probably have two phones.


I've heard multiple times directly from Apple employees that there is no way to login to iCloud on your work machine using a company-controlled account. Many people create new Apple ID's which they only use while working there, but others just use their personal iCloud accounts. You are, of course, not supposed to store company data in iCloud. But thanks to Apple's own efforts, it's difficult to use a Mac without being logged into iCloud (for example if you want to use the App store), and some data can easily spill into the iCloud account.

If accurate, it is of course patently absurd that Apple has left this an unsolved problem.


I have used a Macbook at work for 5 years without signing into any iCloud account ever.


I have as well but if you want to use any software that is only on the App Store like Numbers or Pages then you are out of luck.

It is a sub-standard experience and it looks like it is only going to get worse as Apple pushes iCloud into more areas of macOS.


But I don’t have to use any apps from the store, in fact I’d say that at my company there aren’t any apps available on the store that we use. So the parent is right, it’s perfectly usable without ever touching iCloud. I don’t think I’ve ever even opened the settings for it on my work laptop


Apple certainly uses Numbers, Pages, etc. internally extensively, so you really do have to sign into an iCloud account as an employee.


That's rough. Not just the iCloud thing but, Numbers is so much worse than Excel or even Google Sheets.


Not anymore, it’s been slowly improving over the years and is pretty good now.


I'm saying it's bad because my new work laptop has Numbers instead of Excel ;_; There are CSVs I had to import into GSheets because Numbers was choking.


I suppose this is harder when the company hosts everything in icloud though...


macOS is generally good about not forcing an iCloud account, but the Mac App Store is the one piece of nonsense that needs it.


Yes, that's correct - an Apple account is tied to a person. A person can have multiple Apple accounts, if they wish. But there is no such thing as an organizationally controlled Apple account.


>A person can have multiple Apple accounts, if they wish.

I don't know if it's in the terms but Apple definitely discourages this. In particular it won't let you setup a new account on the same phone number as an existing account.


Yes this seems incoherent and incompatible for a company that supposedly care about their trade secrets.


This legal action will make anybody think twice before walking out of Cupertino with a stash of secrets.


Which is what OpenAI will argue - that Apple is negligent in protecting their trade secrets. Trade secrets are not protected in the USA if the company doesn't take reasonable effort in protecting them. I would feel quite confident as a lawyer arguing against a company that intentionally has their employees use personal accounts on their corporate devices, long after using separate work accounts and devices has become SOP for large companies with serious security concerns (almost certainly including OpenAI itself).

This is better explained in The Information article (which is paywalled): https://www.theinformation.com/articles/apple-icloud-policy-.... Emphasis mine:

> When new employees join Apple, the company often issues them an iPhone and Mac and pays for an iCloud account with a large amount of online storage capacity. Crucially, during the onboarding process, Apple encourages new hires to use their preexisting personal Apple IDs with this iCloud account, through which their co-workers can share internal Apple documents and other files with them.


There is a solution though. I don't like it, but we use MDM to disable iCloud file sync, scan network communication and such.


I have a company-managed Apple account on my work iPhone and Mac. So I beg to differ ¯\_(ツ)_/¯.

It is quite nerfed compared to a normal Apple account - for example the App store is effectively disabled and you need some MDM to be able to install or update apps. But otherwise, it allows me to not use my personal Apple account which was the main objective.

Edit for precision: I don't work at Apple. My point is that it is possible - I guess Apple doesn't want to manage these accounts, but it is not for lack of technical feasibility.


You can log into your personal account and have iCloud file sync disabled. I mean what does that prevent that you couldnt do by some other means? I could also just use a browser to drag and drop anything to my personal google drive. Or use a usb stick.

I don’t understand people that create separate Apple accounts for work.

I’ve always used my personal account on corp laptops, including MFAANG. It’s awesome being able to use side car on my personal machines, hand-off on my AirPods, or screen mirroring to my Apple TV during conference calls. What are you gaining from isolating your account? Why even bother making a fake account at all?


If you are a decision maker, you might find your personal stuff subject to a subpoena for any number of reasons. Antitrust, insider trading, harassment suits, all sorts of legal fishing expeditions. Its convenient to be able to just give them the corporate burner, and get another. I know a few people who had to go through this with their personal phones and this is a horrible experience. For once, you lose your phone there and then and are explicitly forbidden for tampering with anything replicated to iCloud.

A friend of mine is a svp of something something and his corp was sued by antitrust regulators. One day police is at his doorstep - not even a legal letter - and they took his phone then and there. Super disruptive, considering one usually has a lot of MFA tied to the phone.


This is simply bad hygene. It's such a basic thing that I can't even figure out how to back up far enough to start to explain why one should keep work and personal life seperate. I guess if I'd ever had kids I would have had to figure this out when they were like 5 or 6, and then I'd know how to explain what should be explained to every 5 or 6 year old.


You aren't gaining or losing much - but they are gaining a huge risk. Just as you above show by being able to easily move files to any USB drive or Google Drive


Are you saying that your employers prevent you from accessing any potential data-leaking avenues? No usb ports, really? That’s an insane level of paranoia. Do you work for the mob or a drug cartel? How do you even compile and debug?


My company locks down the USB ports on our macbooks so that only input devices are recognized. Flash drives and the like are not recognized. We’re a small private company in the telco space so definitely not the mob or a cartel.

Why would I need a USB drive to docker build or run a debugger?


Firmware development, IoT, basically anything embedded. Mobile devs that want a responsive debugger. Yubikey authentication. Smart card readers. Remoting into air-gapped machines.

Thats just stuff I do.I’m sure there are many other use cases.

For context, I work for a very large company in Redmond that has a renowned history of antitrust litigation.


Lot of places just lock down USB to read only. Exceptions could be made for specific machines and device IDs.

It's pretty common really - and if the internal disk is fully encrypted reasonably hard to easily exfiltrate a large amount of data.

Of course that doesn't stop taking screenshots with another device but that's a slow process


I've worked in strategically important sector and only USB devices that were allowed were keyboards and mice. The use of Bluetooth keyboard/mouse was discouraged.


This is what gets people subpoena'd and their entirely private messages scrutinised. Happened to a lot of people, including a friend of mine who's affair became a matter of public record after his company was investigated for anti-trust issues. Super unprofessional and legally dangerous.

I keep two phones, one for work, another for private life, and also two laptops for the same reason. The support for multi-identity is very inconvenient on apple[1], and very poor with whatsapp, signal and, really, most apps except for Google's. Shame, really, considering how well funded Apple and Meta are, and how little effort would be needed to implement the 80% of what people need: the ability to chat using different identities, without touching the rest of the OS wiring.

[1] on macos, its possible to create users with multiple apple id associations, but not on iphone



> Is it standard practice at both Apple and OpenAI for employees to use their personal icloud account for work?

This doesn't seem out of line with common practices at other big tech firms. If you go work at Meta, your personal Facebook/Instagram/Whatsapp/Oculus accounts become intrinsically linked to your work login identity (though a few employees created a secondary account on of all those to prevent this).

Although there are better controls than there used to be, it's not all that uncommon for sensitive work data to leak through this linkage into the public products...


Did employees get official approval to create secondary accounts?

-

Someone went on Reddit to ask if they really had to use their personal Facebook account to manage the company page as they said their boss pushed back against the idea, saying, “Do you think when Disney manages their Facebook page that Disney marketing execs have to use their personal Facebook accounts?”

And it seemed like the answer may well have been yes. There must be some value to Zuckerberg in tying it all together.


> Did employees get official approval to create secondary accounts?

Yeah, at orientation they told us it was an option. I don't recall more than a couple of people taking advantage - if you go to work for Meta you've probably made your peace with it already.

> “Do you think when Disney manages their Facebook page that Disney marketing execs have to use their personal Facebook accounts?”

There are various business portal things that separate a business page from just one user owning them, but you still login to a business page you manage via your personal account, regardless of size of business


Google allowed iMessage until a few years ago, when they banned all non-work messaging apps for exfiltration reasons. But you can still sign into a personal iCloud, which iirc you need to do for certain Mac App Store apps that are corp-approved.


>Is it standard practice at both Apple and OpenAI for employees to use their personal icloud account for work?

Yes.


On the phone with some App Store support person I was told they don't like people having multiple Apple IDs. That's why I use my personal one for work as well.


I have never worked at a place where they gave us corporate Apple accounts.

We’ve always been asked to use our personal Apple account to install apps used for work.


Whereas I never worked in places where IT would not see that as a security violation.


Correct, because other companies are not in a position to certify the security of iCloud meeting their own standards. It shouldn’t surprise anyone that Apple trusts Apple more than other people trust Apple.


Same here


I've always created a new Apple ID with my work email for every place I've been that's issued an iPhone. No chance in hell I'm signing on to a corporate managed device with my personal Apple ID.


Which is the point I've created a work Apple id unless they specifically set it up to prevent it.

Which has happened. Bonkers configuration.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: