Remix.run Logo
prmoustache 3 hours ago

When I look at the imessage conversation, one thing strikes me: that guy looks to be using the same icloud account he used when working for Apple with OpenAI. Is he using his own personal account? Why do both Apple and OpenAI allow that in the first place, this look so amateur. I would have assumed each company would have opened a different account for him and locked him when leaving.

Is it standard practice at both Apple and OpenAI for employees to use their personal icloud account for work?

dannyw 3 hours ago | parent | next [-]

Apparently Apple encourages their employees to use their personal iCloud accounts for company information, because their own OS doesn't support one iPhone, multiple iCloud identities.

Source: https://appleinsider.com/articles/26/08/03/confidential-appl...

So yeah.

-0_0- 3 hours ago | parent | next [-]

Always found it odd that Apple don't let you have a second separate business profile to switch your phone to for work - especially when you don't necessarily want to be bringing browser history/personal apps into your workplace or wifi. Having your iphone locked to your personal account also hobbles their continuity features if you work on a business computer with its own work account (as most businesses do).

Facebook is equally bad on this front - requiring you to use your personal account to administrate business pages (don't even get me started on how they forced large businesses to use a custom 2FA method they then phased out - locking people out of their personal accounts forever).

tonyedgecombe 13 minutes ago | parent | next [-]

>Always found it odd that Apple don't let you have a second separate business profile to switch your phone to for work - especially when you don't necessarily want to be bringing browser history/personal apps into your workplace or wifi.

I'm guessing it's the same reason they don't offer multiple accounts on iPad. They would rather you bought more devices.

rickdeckard 2 hours ago | parent | prev [-]

however, it is quite neat for Apple if employees are "voluntarily" giving up their privacy by merging their accounts and indirectly allowing Apple to monitor their whole digital identity.

Apple is then "just" monitoring the corporate user account for security reasons, it was the employee who decided to use the same account for private purposes...

citrin_ru 2 hours ago | parent | prev | next [-]

Apple can give employees an iphone which will have an iCloud account in apples’s corp domain and can be used only for work. Many other companies do this.

EagnaIonat 3 hours ago | parent | prev | next [-]

Most companies give you a company phone with a company iCloud account.

dannyw an hour ago | parent [-]

According to more than a dozen former Apple employees, apparently not Apple though... despite the fact that they make iPhones.

fingerlocks 2 hours ago | parent | prev | next [-]

Even Microsoft lets you use your personal iCloud account on corp laptops. They can’t snoop your personal data without disabling SIP or showing system level privacy prompts or recording indicators.

zombot 3 hours ago | parent | prev [-]

So iOS is essentially unprofessional. A toy for those who have either no job or no private life. How does Android score in that respect?

happymellon 3 hours ago | parent | next [-]

You can have multiple users on a single device.

https://source.android.com/docs/devices/admin/multi-user

Either with a single local account that accesses multiple Google accounts, or multiple local accounts. Though this is device specific, it may be disabled by your manufacturer/provider.

As mentioned elsewhere though, an enrolled phone is an enrolled phone so corporate wiping will wipe the entire phone and not just the profile.

Melatonic 2 hours ago | parent [-]

Not true - you can do full MDM type enrolment or just the one where t can wipe the work part of the phone. On Android and iOS

stndef 3 hours ago | parent | prev | next [-]

It's been a while, but at a previous job (maybe 8 years ago) I was responsible for managing mobile devices and using Blackberry's MDM suite, you could have segregation of personal and private data, where you couldn't move data from one "container" to the other, including clipboard data.

I'm out of the loop now, though.

Android did have better support at the time, but if I remember correctly, devices that had a work managed profile on them could still be completely wiped, including the personal/private container.

A bit of a pain, but I've always preferred (where possible) to have separate work and personal devices.

frollogaston 3 hours ago | parent [-]

Yeah, I had an Android phone at work with separate personal/work profiles, but using the phone to begin with required one main account that had to be my personal. Might've been possible to remove after, but I was afraid to mess with it.

Wouldn't want one phone to be both personal and work though. They owned it, idk if I could've put my own sim in without unforeseen issues, it could've been wiped like you said, and it ofc got wiped when I quit.

frollogaston 3 hours ago | parent | prev [-]

Well, aint no way I'm working with a realtor over green bubbles, and they probably have two phones.

jzl 3 hours ago | parent | prev | next [-]

I've heard multiple times directly from Apple employees that there is no way to login to iCloud on your work machine using a company-controlled account. Many people create new Apple ID's which they only use while working there, but others just use their personal iCloud accounts. You are, of course, not supposed to store company data in iCloud. But thanks to Apple's own efforts, it's difficult to use a Mac without being logged into iCloud (for example if you want to use the App store), and some data can easily spill into the iCloud account.

If accurate, it is of course patently absurd that Apple has left this an unsolved problem.

putlake 3 hours ago | parent | next [-]

I have used a Macbook at work for 5 years without signing into any iCloud account ever.

tonyedgecombe 8 minutes ago | parent | next [-]

[delayed]

cvak 2 hours ago | parent | prev [-]

I suppose this is harder when the company hosts everything in icloud though...

trollbridge 2 hours ago | parent | prev | next [-]

Yes, that's correct - an Apple account is tied to a person. A person can have multiple Apple accounts, if they wish. But there is no such thing as an organizationally controlled Apple account.

prmoustache 3 hours ago | parent | prev | next [-]

Yes this seems incoherent and incompatible for a company that supposedly care about their trade secrets.

yreg an hour ago | parent | prev | next [-]

There is a solution though. I don't like it, but we use MDM to disable iCloud file sync, scan network communication and such.

fingerlocks 2 hours ago | parent | prev [-]

You can log into your personal account and have iCloud file sync disabled. I mean what does that prevent that you couldnt do by some other means? I could also just use a browser to drag and drop anything to my personal google drive. Or use a usb stick.

I don’t understand people that create separate Apple accounts for work.

I’ve always used my personal account on corp laptops, including MFAANG. It’s awesome being able to use side car on my personal machines, hand-off on my AirPods, or screen mirroring to my Apple TV during conference calls. What are you gaining from isolating your account? Why even bother making a fake account at all?

Brian_K_White a minute ago | parent | next [-]

This is simply bad hygene. It's such a basic thing that I can't even figure out how to back up far enough to start to explain why one should keep work and personal life seperate. I guess if I'd ever had kids I would have had to figure this out when they were like 5 or 6, and then I'd know how to explain what should be explained to every 5 or 6 year old.

aenis an hour ago | parent | prev | next [-]

If you are a decision maker, you might find your personal stuff subject to a subpoena for any number of reasons. Antitrust, insider trading, harassment suits, all sorts of legal fishing expeditions. Its convenient to be able to just give them the corporate burner, and get another. I know a few people who had to go through this with their personal phones and this is a horrible experience. For once, you lose your phone there and then and are explicitly forbidden for tampering with anything replicated to iCloud.

A friend of mine is a svp of something something and his corp was sued by antitrust regulators. One day police is at his doorstep - not even a legal letter - and they took his phone then and there. Super disruptive, considering one usually has a lot of MFA tied to the phone.

Melatonic 2 hours ago | parent | prev [-]

You aren't gaining or losing much - but they are gaining a huge risk. Just as you above show by being able to easily move files to any USB drive or Google Drive

fingerlocks an hour ago | parent [-]

Are you saying that your employers prevent you from accessing any potential data-leaking avenues? No usb ports, really? That’s an insane level of paranoia. Do you work for the mob or a drug cartel? How do you even compile and debug?

ihateolives 3 minutes ago | parent [-]

I've worked in strategically important sector and only USB devices that were allowed were keyboards and mice. The use of Bluetooth keyboard/mouse was discouraged.

aenis 3 hours ago | parent | prev | next [-]

This is what gets people subpoena'd and their entirely private messages scrutinised. Happened to a lot of people, including a friend of mine who's affair became a matter of public record after his company was investigated for anti-trust issues. Super unprofessional and legally dangerous.

I keep two phones, one for work, another for private life, and also two laptops for the same reason. The support for multi-identity is very inconvenient on apple[1], and very poor with whatsapp, signal and, really, most apps except for Google's. Shame, really, considering how well funded Apple and Meta are, and how little effort would be needed to implement the 80% of what people need: the ability to chat using different identities, without touching the rest of the OS wiring.

[1] on macos, its possible to create users with multiple apple id associations, but not on iphone

swiftcoder 3 hours ago | parent | prev | next [-]

> Is it standard practice at both Apple and OpenAI for employees to use their personal icloud account for work?

This doesn't seem out of line with common practices at other big tech firms. If you go work at Meta, your personal Facebook/Instagram/Whatsapp/Oculus accounts become intrinsically linked to your work login identity (though a few employees created a secondary account on of all those to prevent this).

Although there are better controls than there used to be, it's not all that uncommon for sensitive work data to leak through this linkage into the public products...

Barbing 2 hours ago | parent [-]

Did employees get official approval to create secondary accounts?

-

Someone went on Reddit to ask if they really had to use their personal Facebook account to manage the company page as they said their boss pushed back against the idea, saying, “Do you think when Disney manages their Facebook page that Disney marketing execs have to use their personal Facebook accounts?”

And it seemed like the answer may well have been yes. There must be some value to Zuckerberg in tying it all together.

swiftcoder 19 minutes ago | parent [-]

> Did employees get official approval to create secondary accounts?

Yeah, at orientation they told us it was an option. I don't recall more than a couple of people taking advantage - if you go to work for Meta you've probably made your peace with it already.

> “Do you think when Disney manages their Facebook page that Disney marketing execs have to use their personal Facebook accounts?”

There are various business portal things that separate a business page from just one user owning them, but you still login to a business page you manage via your personal account, regardless of size of business

plodman 3 hours ago | parent | prev | next [-]

Somewhat relevant from yesterday.

https://www.macrumors.com/2026/08/03/apple-icloud-sharing-ex...

frollogaston 3 hours ago | parent | prev | next [-]

Google allowed iMessage until a few years ago, when they banned all non-work messaging apps for exfiltration reasons. But you can still sign into a personal iCloud, which iirc you need to do for certain Mac App Store apps that are corp-approved.

klausa 3 hours ago | parent | prev | next [-]

>Is it standard practice at both Apple and OpenAI for employees to use their personal icloud account for work?

Yes.

h05sz487b 3 hours ago | parent | prev | next [-]

On the phone with some App Store support person I was told they don't like people having multiple Apple IDs. That's why I use my personal one for work as well.

wodenokoto 3 hours ago | parent | prev [-]

I have never worked at a place where they gave us corporate Apple accounts.

We’ve always been asked to use our personal Apple account to install apps used for work.

pjmlp 3 hours ago | parent | next [-]

Whereas I never worked in places where IT would not see that as a security violation.

simondotau 3 hours ago | parent | next [-]

Correct, because other companies are not in a position to certify the security of iCloud meeting their own standards. It shouldn’t surprise anyone that Apple trusts Apple more than other people trust Apple.

prmoustache 3 hours ago | parent | prev [-]

Same here

happymellon 3 hours ago | parent | prev [-]

Which is the point I've created a work Apple id unless they specifically set it up to prevent it.

Which has happened. Bonkers configuration.