Unreliable warnings from Apple about Password data leaks
So I’ve read other questions with concerns over this new feature and I can’t find answers to explain my 423 warnings my data security recommendations just gave to me.
First, I have been a system designer/programmer since 1983. I probably was the first person to use all different passwords for every site visited since the internet became so readily available to everyone. I’ve also known all along to make my passwords difficult to hack.
With my new iPhone 12 mini this feature has alerted me to 423 compromised passwords. Many I know are valid warnings because most are silly bogus sites that I don’t care about where I used a junk email account and a bogus easy password since I don’t care. It has never been used for any site or account that would compromise me. So there are many reused matching logins. For instance, when I have to create a user account just to read an article, receive a newsletter, or reply to comments, but I dont have to provide my real name nor any other identifiable info about me and I never buy anything on the site, I used my standard bogus email and one of my passwords for junk. Makes it quick and easy to get on with what I’m doing and easy to log in next time. While none are close to the following, they are similar to a password like Crackers379. I have six junk passwords over the years that I rotate depending which one enters my head first. So ya, lotsa duplicate passwords in my keychain.
However, the first warning is for iCloud.com.
First, that means iCloud had a data leak. Holy yikes. Not feeling secure or good about that ... at all. I actually switched to Apple devices because they are so secure.
Second, my iCloud password was carefully crafted and all password checking sites estimate that it would take 3 quadrillion years to hack with the best bits and hardware.
Third, the email it listed for my iCloud account was correct, but when I click on the warning the password it shows me that is leaked is one of my six junk passwords, of which I have never, ever, ever used in conjunction with my iCloud email. Ever.
My iPhone obviously has the correct password stored because when I came to log in here to post, it used it to sign me in. The bogus one wouldn’t have worked.
So my questions are:
1) why does it have multiple passwords for my iCloud email stored? How did Apple pair my Apple email address with a wrong password that I have never used on their site? Why is it in my keychain?
2) If this first warning for such a sensitive site is untrustworthy and cattywhompus, why would I be able to trust any of the other 423 warnings? My time is valuable and I need to trust this new feature before spending time doing what it tells me to do.
iPhone 12 mini, iOS 14