Apple suit highlights security issues

Apple has a name for the security ritual where a resigning employee is escorted straight out the door, access cut on the spot, no two weeks to linger: the “dreaded walk out.” According to the trade-secret lawsuit Apple filed against OpenAI in July, the way to beat it is almost mundane: don’t tell your employer where you’re going.

The suit alleges a senior electrical engineer left Apple in January, ignored the exit interview and confidentiality reminder, and never returned his work laptop. Weeks later, Apple says, he stumbled onto a rare authentication bug and found he could still reach Apple’s confidential file storage from outside the company. “LOL, I found out I can access the [network storage], so funny,” he wrote a former colleague, according to the complaint, before downloading dozens of engineering files. OpenAI denies wrongdoing, saying it has no interest in others’ trade secrets.

That is the part that should worry any employer. Collecting the badge and the laptop is the visible half of a goodbye. The invisible half — live passwords, cached credentials, network access that was supposed to be switched off — is what actually walks out. He never needed the Apple laptop for the bug; any browser would have done.

Which is why security teams say the first move when someone leaves isn’t chasing the hardware but killing the access — email, VPN, single sign-on — the same hour. Company laptops can be locked or erased remotely, but only if they are enrolled in management software and only when they next connect to the internet; a machine kept offline stays out of reach. Apple says it disables network access the day an employee departs. A bug it did not know about kept one door open anyway.