Signing in to iCloud on a Mac that is not yours
· 5 min read
The question comes up in three quite different situations, and the right answer differs: a family Mac you use occasionally, a colleague’s laptop for an hour, and a genuinely public machine.
The rule that covers most of it
Do not sign in to iCloud on a machine you do not control. Use icloud.com in a private browser window instead.
That gives you Drive, Photos, Mail, Notes, Reminders, Calendar and Find My, with nothing synced to the machine and nothing to clean up beyond closing the window.
For the great majority of “I just need a file” situations, this is the entire answer and it takes thirty seconds.
When signing in is reasonable
A family Mac you use regularly. Make yourself a proper user account on it and sign in there. Your account, your home folder, your iCloud. That is not “someone else’s Mac”; it is a shared machine on which you have a place. Setting up a Mac to share with a partner covers arranging that.
A work Mac issued to you, with the caveat that a personal Apple Account on a work machine is usually a bad idea for different reasons. What to do on day one with a work-issued Mac covers that.
What is never reasonable is signing in to the primary account of a machine belonging to someone else, even briefly.
Why not, concretely
Signing in starts syncing. Depending on that machine’s settings, your photo library, message history, files and saved passwords begin copying to a disk you will hand back.
Signing out removes most of it and not reliably all of it. Caches, thumbnails, search index entries and application-local copies can persist, and the machine’s owner has administrator access.
You may also become a trusted device for your Apple Account, which means that machine can show verification codes. Removing it from your device list afterwards is what undoes that, and it is the step people forget. What carries over when you sign in to a borrowed Mac covers the detail.
The genuinely public machine
A hotel business centre, a library, a shared terminal. Treat it as compromised, because you have no idea what is installed.
Do not sign in to anything you care about, including icloud.com, if you can avoid it. If you must, assume a keylogger and change the password afterwards from a machine you trust.
The practical answer for travel is to carry your own device, or to use your phone, which is a computer you control.
Getting a file without any of this
Worth listing, because people reach for sign-in when they do not need to.
Share links. Generate one from your own device before you need it. Right-click a file in iCloud Drive, Share, Copy Link. Anyone with the link opens it in a browser. No sign-in.
AirDrop, if both machines are Apple and nearby.
Email it to yourself, which is inelegant and requires nothing.
A USB drive. Still the fastest way to move a large file to a machine you do not control.
If you already signed in
The cleanup, in order.
- System Settings, your name, Sign Out, choosing not to keep a local copy.
- Sign out of Messages and FaceTime separately.
- Sign out of any browser profile.
- Empty Downloads and the Trash.
- From your own device, open Find My and remove that Mac from your device list.
- If the machine was genuinely untrusted, change your Apple Account password.
Step five matters more than it looks. Step six is only necessary if you have reason to distrust the machine.
Questions
Is icloud.com in a private window actually safe? On a machine you broadly trust, yes. On a machine that might be compromised, nothing typed into it is safe, including that.
Can I use a Guest account and sign in there? Better than signing in to their account, and everything is wiped at logout. Still not appropriate on a machine you suspect. It is a reasonable middle option on a friend’s Mac.
What if I need to use their Mac for a week? Ask for your own standard account on it. Five minutes to create, and it solves the whole problem. Getting a Mac ready to lend to someone covers it from the lender’s side.
Does signing in count against a device limit? Apple does not limit the number of Macs on an account in a way most people will hit. The practical limit is how many devices you want receiving your data.