Apple's iCloud Policy Creates Security Loophole Exposing Employee Data, Setting Stage for OpenAI Lawsuit

Deep News08-04 18:41

Apple has filed a lawsuit against OpenAI and former Apple employees, accusing them of stealing trade secrets. For years, departing Apple staff have inadvertently taken confidential internal materials with them.

In early August, Apple initiated legal proceedings, alleging that several former employees now working at OpenAI had stolen a significant amount of trade secrets. This includes unauthorized access to Apple's confidential documents after their departure. Insiders revealed that before the formal lawsuit, over 400 former Apple employees who had moved to OpenAI received stern letters from Apple's legal department, informing them that confidential Apple materials were still on their devices. However, these sources claim that the root cause of this issue lies in Apple's own system design, not a deliberate attempt by former employees to steal secrets. The core problem is that while Apple revokes most corporate system access after an employee resigns, they can still access internal files shared with them during their tenure.

This predicament is not limited to former Apple employees now at OpenAI. Over the past decade, more than a dozen former Apple employees who moved to other companies told The Information that they could still access confidential documents after leaving, and had never actively tried to retain them. These former employees stated that a large number of Apple documents shared during their employment, including plans for new product launches, continued to sync to their personal devices via iCloud after they left. Some even received updates to these documents. Some departing employees admitted they were afraid to delete these files, worried it might attract Apple's attention.

This apparent security flaw creates a stark contrast with Apple's famously secretive culture. Apple has always aggressively pursued leakers and sued departing employees who take technical secrets to competitors. In its recent lawsuit against two former employees, Liu Chang and Tan Tan, and OpenAI, Apple stated: "The trade secrets related to Apple's hardware business collectively constitute one of the most valuable intangible assets in American business."

Apple's case against OpenAI still has strong legal merit. The complaint alleges that Liu Chang and Tan Tan took multiple proactive and unauthorized steps to steal trade secrets, aiming to help OpenAI compete with Apple in the hardware space. For example, Apple claims Liu used a "rare, previously undiscovered" security vulnerability to log into corporate shared folders after his departure, downloading dozens of confidential files and bragging about it to colleagues. Tan Tan is alleged to have sent Apple's confidential materials to her personal email before leaving and, after joining OpenAI, continued to lobby current Apple employees to leak trade secrets.

OpenAI denies that it or its employees engaged in trade secret theft. Shortly after the lawsuit was filed, an OpenAI spokesperson stated: "We have no intention of acquiring the trade secrets of other companies. While we take the allegations seriously, we have not seen substantive evidence that supports this complaint."

Apple's official response was: "The core of this case is that OpenAI employees illegally obtained confidential information about Apple's unreleased technology, processes, and products. The content of the complaint has nothing to do with documents shared or stored via iCloud." Apple also stated that it would not file a lawsuit simply because a departing employee's personal iCloud account accidentally retained confidential materials.

Multiple former Apple employees explain that a company policy encouraging the use of personal devices for work creates the situation where departing staff inadvertently retain access to confidential files. When new employees join Apple, they are typically issued an iPhone and a Mac and provided with a large, paid iCloud storage plan. The key step is that during onboarding, Apple encourages employees to use their existing personal Apple ID for this work iCloud, allowing colleagues to share internal files with them through this account. The practical reason behind this policy is that an iPhone can only be logged into one primary Apple ID for full iCloud functionality at a time. For employees to separate work and personal accounts, they would need to carry two phones. Many former employees say this is why the vast majority choose to use their personal Apple ID for work iCloud.

When an employee leaves, Apple reclaims access to the dedicated work iCloud directory and authentication for internal systems like Slack. However, the exit process does not fully check for scattered confidential files. Because the employee continues to use the same personal Apple ID, any Apple internal documents stored outside the dedicated work directory remain accessible.

The security mechanism's flaw creates a sharp contrast with Apple's traditionally strict confidentiality stance, leading to speculation that Apple might intentionally allow departing employees to take confidential materials. In 2023, chip startup Rivos, after being sued by Apple, raised this point in a countersuit. Rivos claimed that Apple deliberately created this situation to intimidate current and former employees. "Whether through negligence or by creating a pretext to sue departing employees and their new employers for stealing materials, Apple has a system where employees, simply by using the company-mandated tools (iCloud, iMessage), can unknowingly 'retain' confidential files and take them when they leave," Rivos wrote in its countersuit.

It is difficult to find another tech company more obsessed with secrecy than Apple. Apple is accustomed to maintaining an air of mystery, doing its utmost to prevent information leaks before product launches. In its lawsuit against OpenAI, Apple stated that trade secrets "support Apple's ability to quickly and at scale deliver new products with unique features to consumers." Apple places particular importance on supply chain secrecy. From the 2000s to the early 2010s, leaks from iPhone assembly plants and component suppliers greatly angered management. The Information previously reported that in 2013, a warehouse employee at Apple's core supplier, Jabil, stole a prototype iPhone 5c shell, and photos of it were leaked online, disrupting Apple's product launch plans.

In the United States, Apple employees must adhere to strict security protocols. Many teams operate in silos, unaware of each other's research and development projects. The company constantly reinforces employees' confidentiality obligations through training, non-disclosure agreements, and product project code names. This is why the risk from encouraging employees to use their personal Apple IDs for work is particularly prominent. Apple promotes the use of its own consumer-grade software to support internal operations. Employees use Pages and Keynote for collaborative editing; besides email, iMessage is a common channel for internal communication and file transfer. iCloud Drive is a core tool for project collaboration. Former employees reveal that new hires are given 2TB of iCloud storage for free, and employees can choose to merge it with their existing personal plan or use it separately.

Other large enterprises have more stringent IT controls, allowing them to completely cut off access to work files after an employee leaves. Even if they allow employees to log into their personal iCloud on work computers, they standardize file sharing methods to facilitate unified control upon departure. In the late 2010s, Apple introduced a managed 'Apple Work' folder within an employee's iCloud, designed to allow for the remote wiping of confidential materials when an employee leaves. This folder would automatically disappear after the employee left. However, former employees say the biggest drawback is that during employment, a large number of internal documents are not automatically stored in this work folder. Many shared files are scattered outside the folder, mixed with personal photos and documents in the same iCloud Drive.

For a long time, Apple teams have commonly relied on iMessage groups to communicate and transfer confidential files. In some cases, employees could still access chat histories and attachments after leaving. Around 2019, Apple introduced Slack to mitigate this issue; once an employee leaves, they immediately lose access to their Slack account.

Exit review standards vary significantly by employee level. Former employees explain that for senior executives, someone will check their devices to ensure no confidential files remain; the exit process for regular lower-level employees is relatively simpler. In its July lawsuit, Apple mentioned that a large number of employees moving to OpenAI even skipped the complete exit process. "Apple has recently noted a trend: employees preparing to move to OpenAI are deliberately avoiding security procedures, ignoring security personnel invitations, and refusing to schedule exit security checks."

Previously, the mechanism of merging work and personal accounts has appeared multiple times in Apple's lawsuits against startups. In 2019, chip company Nuvia, which was developing server processors, aggressively recruited from Apple's semiconductor team. Apple then sued former employee and Nuvia co-founder Gerard Williams III, accusing him of planning to found Nuvia and poach Apple employees while still employed, violating his employment contract. Apple's complaint listed a large amount of communication records between Williams and external parties, including non-Apple employees. Before formal discovery, Apple had amassed a massive amount of call and text message records, reconstructing his communications with Nuvia's founding team and outside investors. The document precisely counted that between October and December 2018, he had "at least 88 calls with his two co-founders, totaling 2,361 minutes." Williams subsequently filed a countersuit, accusing Apple of accessing his call and text records to intimidate employees interested in joining Nuvia. His lawyer called this a "shocking and disturbing invasion of privacy." Apple settled with Nuvia in 2023.

In 2021, chip startup Rivos was founded, also recruiting Apple semiconductor engineers. Learning from the Nuvia case, these employees tried to minimize legal risks: they used the encrypted communication app Signal to discuss joining plans, avoiding iMessage; they also stored Apple's confidential materials on their devices in the 'Apple Work' folder or Box enterprise cloud, ensuring they would lose access after leaving. Even with these precautions, after Rivos hired over 40 Apple chip engineers, Apple still filed a lawsuit in 2022. Apple accused several Rivos employees of taking gigabytes of sensitive Apple self-developed chip data when they left. The complaint alleged that some employees used USB drives to download data, while others saved unreleased chip presentations to their personal iCloud. Court documents stated that one employee, even after moving thousands of files into the work folder, still had copies in their personal iCloud; another employee used their Mac's Time Machine feature to fully back up their work laptop and copy terabytes of data to an external storage device, though sources said this person never accessed those files again.

Apple and Rivos settled in 2024. However, the negative impact had already occurred: after the lawsuit, it became very difficult for Rivos to continue recruiting Apple engineers. Meta Platforms, Inc. was reported to be acquiring Rivos for around $2 billion late last year.

Disclaimer: Investing carries risk. This is not financial advice. The above content should not be regarded as an offer, recommendation, or solicitation on acquiring or disposing of any financial products, any associated discussions, comments, or posts by author or other users should not be considered as such either. It is solely for general information purpose only, which does not consider your own investment objectives, financial situations or needs. TTM assumes no responsibility or warranty for the accuracy and completeness of the information, investors should do their own research and may seek professional advice before investing.

Comments

We need your insight to fill this gap
Leave a comment