What Apple should tell you when you lose your iPhone
medium.com
medium.com
This would be ideal, even if it doesn't really contribute to returning stolen phones. It makes the whole idea of stealing an iPhone so much more difficult for thieves.
A strong deterrent in my opinion is much better than a solution which returns your phone. I'd rather have it not stolen in the first place.
(Though a sophisticated thief might have a lightweight faraday cage on them - sleeve lined with aluminium foil might sufficiently dampen Wifi/GPS/cell signals.)
I would personally prefer to just lose my phone and have robust measures to stop thieves from accessing my data than increase the possibility of bad actors/govt using it as yet another surveillance tool (or at least more than it already is).
Prey (preyproject.com) does this. It'll take pics and screenshots and send them to you along with GPS coordinates at regular intervals.
Edit: Uhh, repetition it seems. God damn I need to not leave HN windows open for a couple hours then replying without refresh.
Obviously if your day-to-day as a police officer involves the cartels or something you won't care about an iPhone. But if you live someplace where a murder would make the news regardless of the circumstances, someone will probably look into it if you can prove you know where the thief is (or that the phone was in a given house/apartment).
The people who are really going to be in a bind are the totally unprepared legitimate owners who've been hacked.
Anything iCloud-initiated does not benefit from the protection of the secure enclave on the device--so with your idea, you'd be opening a denial-of-privacy attack vector
Not being able to remove the battery could be an advantage in this case :)
1) in situations where phones are not meant to be switched on (e.g. some flights)
2) from a privacy perspective not being able to ensure your phone is actually off is not great.
Nice try, but that's a long way from a (long running, secret, and still hidden) vast government/corporate conspiracy to remotely power on any smartphone to spy on the owner.
It was quite discussed at that time. for example: http://www.tomsguide.com/us/nsa-remotely-turn-on-phones,news...
OTOH: This opens up a whole new avenue of pranks to pull on iPhone users.
Why not have Siri yell 'Im a stolen iPhone' full volume with the volume switch disabled.
On a serious note, none of these options seem desirable if the Apple account is compromised.
I'd've been _extremely_ unimpressed if the device suddenly started proclaiming it was stolen.
Why not make the iPhone blow in the face of the stealer?
/s
aggressively look for open access points and attempt to associate with them and phone home [...] location info
put the phone into a power conservation mode to keep it alive and phoning home as long as possible.
Isn't there an inherent conflict here? I doubt that you can aggressively scan and phone home, and conserve battery life.Personally I've never had issues with iPhones for the battery, I've had three- but then I also spring for AppleCare.
I used to have the same idea [1], having been a victim of theft and robbery myself, but as others in that thread pointed out, it would be trivial for thieves to take out the SIM, or to wrap it up in something that blocks all signals.
I think a better way might be to introduce a PANIC MODE; a special state that could be activated with a predefined fingerprint or PIN, different from the ones you use for unlocking. Say your left pinky.
In Panic Mode, the device would present a "fake" environment, which allows most operations but:
* Keeps the device secretly powered on even after being powered off.
* Regularly connects to open networks AND also transmits an SOS to all nearby Apple devices, to use THEIR network and transmit its location to Find My Phone.
* If not powered off, defaults to an easy passcode, like 0000 or 1234, and disables lockout protection for invalid retries.
* When unlocked, presents a home screen that looks identical to a freshly installed OS, with empty or random Notes, Contacts, Calendar etc.
* Allows calls to any local number, but for a duration of one minute only, so the networks can aid law enforcement in tracking it as well.
----
TL;DR: Make the device appear unsecured to the thieves, so they don't have to force the owner to remove all protections, and entice them to keep using it normally for as long as possible while secretly and aggressively tracking them.
iPhone thefts will decrease when thieves know that the iPhone that they just stole is going to get them caught.
I understand that some don't like the privacy implications of a phone that can be forced into spy mode with Apple ID credentials. Fine. Give the user the option to disable this functionality on the device (and only on the physical device). Users that don't want it can disable it in their settings and the phone will act just like the phones do today when stolen, regardless of what happens on the iCloud side.
However, many don't know about iCloud/Find My Phone yet, and it requires an internet connection to disable anyway, which most people don't have outdoors, here.
Some kind of "fake mode," filled with random data, would also help with government coercion in, ahem, the more civilized countries.
Works for thieves of opportunity, not necessarily others.
I received a variety of phishing attempts over email, but most surprisingly - I received phishing iMessages too. They were all eerily good.
My assumption was that police reports were being scraped. I wonder if this data is available unencrypted on the phone or sim card
Edit: Here are some of the messages I received - I forgot that they had my name too: http://imgur.com/a/NmIt4
I feel like we've gone backwards in UX with Inbox app and mobile email clients that hide the email by default.
> I keep my file extensions hidden because if that's all between me and a virus I'm already fucked. It's also a sign I need to move operating systems.
Showing extensions doesn't just guard against viruses, it also allows you to know what file type a file is, without having to memorize every icon on your system. You can also rename files to a different extension if you need to.
Somehow you found the comment more interesting than I.
That being said we are starting to create fairly good systems to prevent spoofed addresses.
As for sender, you can make it show the actual email address at all times (disable "use smart addresses").
also, the fact that it won't show an auto-complete list on a domain, is aggravating.
How does phishing like this scale? I would think the vast majority of the time the thief is going to have no idea what the email or phone number of the victim is. Seems like a pretty elaborate scam for something that relies on stealing phones where Medical ID is enabled.
Is there some other way that the thief would be able to easily contact the victim by email or text?
Even with Medical ID enabled, that only shows name, DOB, medications.. I would think for most people that still isn't going to be enough info to get an email and phone number from by googling.
Not saying it isn't possible, I just think that it seems odd that the difficulty of making the scam work seems out of balance with the polish of it.
I assume that the thief which actually steals the phone isn't the same guy which puts this kind of scam on. And if you're the one which buys the stolen phones at larger scale (e.g. by running a used-phone-shop) this kind of scam scales very well I would think.
The free market at it's finest.
I think this is the wrong question. You only need "scale" when your response rate or "take per device" is relatively low.
In this case, I suspect the success rate is incredibly high and/or if it lets you unlock and disassociate the the device from the account, the device itself becomes more valuable.
It's a win-win for the bad guys.
I'm the orig post author, and I did think of that too. But no - it was far from home on a holiday trip in a rental car. If someone really wanted my phone, there are many simpler ways. Also, it wasn't the only car with a broken window on the same parking lot when we came back to the car.
In addition, we're a really open company and not that great a target for espionage. We have very few secrets worth significant money.
I just got unlucky.
If you're not cool with that, you can configure Siri to only function when unlocked. I used to operate that way, but especially controlling music in the car and fumbling with Touch ID when fingers aren't cooperating, I grew tired of it and went back.
Also, "send email to YOUR NAME HERE" will present a list of email addresses if you have more than one.
I saw in another long blog post how something like 80% of all stolen phones in the world end up in about a half dozen locations in Asia that act as bulk resellers. (I think the article was about the guy in SF who lost his phone at a bar and it ended being used by an orange farmer in Shanghai?!? - it was a cool story).
I daresay these bulk 'processing' plants for lost/stolen phones may have a team in place that try and identify the previous owners and send out bulk scam emails to try and hook them?
For those interested: https://www.buzzfeed.com/mjs538/i-followed-my-stolen-iphone-...
That said I've had an iPad stolen from the seat pocket when I was asleep on a long haul flight so I can sympathise and this scam particularly hits home.
A few days later I got an email "Cesar's Macbook Pro Has Been Found." My name isn't Cesar -- that must be the thief or the guy who bought it from him. I assume he re-formatted the disk and re-installed the OS and changed the computer name before connecting to WiFi whereupon the call-home feature told the machine to wipe itself.
It's a weird user experience to tell me the name of the new owner but nothing else.
A few years ago I was on holiday in Italy and someone broke in to my car and stole a suitcase which contained my laptop, passport and camera. Earlier this year I was living in Rome for a few months and the amount of cars with smashed windows I saw (to grab whatever was left on the seat) was staggering.
Even if you have insurance, it may not cover theft from an unattended motor vehicle (at least mine didn't).
I've changed my PIN to something quite long, so hopefully an attacker cannot just pop the SIM card out of my iPhone and use it on another device.
Operators in Finland always give you PIN cards with a preset code like 0000 or 1234, and tell you to switch it in their quick start instructions. I'm sure many people leave it as it is, though. Almost no-one seems to know you can actually set it to be more than 4 digits.
This looks like an area that phone operating systems could fix – by making it easy to change your PIN, and encourage using more than 4 digits for it.
Ah, http://www.techrepublic.com/article/pro-tip-protect-your-and... suggests that you have 3 attempts, then there's a separate system (PIN Unlock Key, PUK) which a comment notes gives 10 attempts.
I'm wondering if you can read the data straight off the card via some physical means, attack that to get the PIN?
If your phone is stolen call your carrier and have them disable the number or invalidate the sim.
Of course, being Apple, the other device must also be an Apple device.
Edit: And it seems you can't remove the phone number: http://i.imgur.com/p6myEqx.png
The existence of the feature would hopefully act as one more trivial inconvenience to deter more thieves.
[1]: https://www.theguardian.com/technology/2015/aug/10/htc-finge...
[2]: http://betanews.com/2015/08/11/htc-and-samsung-phones-storin...
Imagine you press it but for whatever reason it doesn't register. Now your "incorrect" fingerprint is flying over the internet. With a bit of retouching or guessing your original fingerprint can now be recovered.
...not that your fingerprints aren't all over your phone anyways...
Excellent bit of social engineering by the scammers, shame they cause so much harm.
That always looks incredibly dodgy to me, not sure why they don't use a visa.com subdomain so it doesn't look like a phishing scam.
Bear in mind that it's also used for Mastercard's SecureCode and possibly other credit card providers as well.
To answer your root cause question: I think it's a hook back to the issuing bank, and Visa themselves are only tangentially involved, AIUI. So things like securesuite are the vendors for the bank. (Am I wrong? That's how it was explained to me once.)
Not even joking.
So, I'd say a server is "just a computer somewhere", The Cloud is necessarily more than that.
I reported most of it to Apple but (unsurprisingly I guess) it took forever to actually convince the support representative that no, it was not actually Apple trying to contact me. Finally they gave me an email address to forward the evidence to, and I never heard about it again.
For example...
- Lock screen notifications..
- Medical info feature.
- Emergency numbers feature.
- Lock screen wallpapers that might give something away.
- Email clients with poor security and where they do have security each one works differently.
All this increases the attack surface giving attackers a few more opportunities to exploit.Fifteen years ago, if my phone was stolen, that sucked, but that was basically the end of that. I buy a new phone, and move on with my life.
Nowadays if a phone is stolen, they have to have access to my email, passwords, and effectively my entire identity, and it appears that that is exactly what's happening.
Phones are awesome, but I think I'd rather lose an eight-hundred-dollar phone than have someone get access to my email.
Not if you use the simple passcode or TouchID.
Regardless, I'm not disagreeing with you, I was just stating that the problem stated in the article wouldn't have happened fifteen years ago
None of that necessarily applies. Plenty of people choose to opt-out of the madness that is the smartphone life.
FWIW, I've also received these phishy "Find My iPhone" notifications that my phone was found, via SMS [1], and nearly fell for it (as I had lost a phone months ago).
Apple Support did not seem to be surprised, and just explained how to report spam.
Agree that these are potentially very effective, as users will be eager to log in to retrieve their phones. As such, it is arguably incumbent on Apple to explicit warn about them.
URL was www.apple.com.in1.at (Austria?), redirecting to iCloud.com.sign-inc1.pw (Palau??).
[1] https://twitter.com/FabianLischka/status/758543021130457088
Finally from a precaution avoid inputting your email address in the lock message. Also register an iCloud email. There is a better chance of apples servers detecting this as a fraud email than any other email sever thus (hoping) it will trash the bait like this.
Hardly. The remote wipe will clear all of your private data. Seems like the purpose is well met to me.
Activation Lock is there to prevent resale of stolen devices, which simultaneously increases odds of return to you, and decreases odds of iOS theft overall.
From the article