Report: Apple’s secrecy efforts partly undermined by lax work iCloud policy

A new report from The Information details how Apple’s policy of encouraging employees to mix personal and work iCloud accounts has allowed some former staffers to retain access to confidential company files long after leaving. Here are the details.

Report could weaken Apple’s arguments against OpenAI

Last month, Apple filed a trade secrets theft lawsuit against two former employees, OpenAI, and Jony Ive’s io Products.

In the complaint, Apple outlines several steps it takes to protect confidential information and trade secrets, including contractual, technical, physical, and procedural safeguards. These range from recurring confidentiality training and the signing of multiple agreements, to requirements that departing employees return company devices and complete offboarding interviews designed to ensure they no longer retain access to confidential materials.

Apple’s efforts to safeguard its secrets will likely be central to both its case and OpenAI’s defense. As The Verge editor-in-chief Nilay Patel recently noted on The Vergecast, trade secret law (and lawsuits built around it) often hinge on whether a company can show that it took reasonable measures to keep the information in question confidential.

Which brings us to The Information’s report, and its account of several cases where “Apple employees who left for other companies over the past decade told The Information they, too, continued to have access to confidential documents after leaving the company, even though they made no effort to do so.”

From the report:

The reason behind this, The Information notes, is the fact that iPhone users “can only log into a single primary Apple ID that unlocks all iCloud capabilities at a time.” So to avoid carrying two different sets of devices, one for personal and another for work (which is not uncommon by any means), “most Apple employees opt to use their personal Apple IDs to access their iCloud accounts.”

The report explains that, since the late 2010s, Apple employees have had access to a company-managed folder within iCloud that is automatically removed when they leave.

However, many internal documents are reportedly not automatically saved there, allowing files shared outside the folder to remain mixed with employees’ personal data and accessible after their departure.

The Information also says that Apple has been accused of blurring the lines between personal and work devices as a deliberate tactic to create grounds for legal action against former employees and their new employers:

Finally, The Information’s report notes that Apple’s lawsuit against OpenAI contains several allegations of deliberate trade secret theft, which are very different from the circumstances in which former employees inadvertently retained access to files through iCloud. Still, the report could complicate Apple’s efforts to show that it took reasonable measures to keep its confidential information secure.

In a statement to The Information, Apple said:

Apple added that “it doesn’t pursue legal claims against former employees who accidentally hold on to Apple documents in their personal iCloud accounts.”

To read The Information’s full report, follow this link.

Leave a Reply

Your email address will not be published. Required fields are marked *