How Hackers and Scammers Break into iCloud-Locked iPhones
vice.com
vice.com
As always, the important thing here is for criminals to know this: even if they force you to unlock the phone, they are not off the hook.
Asking these people to wait two days before they can get their phone fixed or to sell it wouldn't be a nice user experience. Can you imagine the amount of pissed off people in the Apple store waiting to get their screen fixed only to be told to come back in 2 days?
1-2 hours would be the ideal candidate I think without being a inconvenience.
Another idea would be a 24-48 hour window to 'revoke' the disabling of the activation lock. Perhaps they can login to Apple ID website to reinstate activation lock remotely.
Maybe Apple can also provide a duress password.
When I was setting up my new phone I restored my latest backup from iCloud and upon doing so, my old stolen phone was no longer trackable since iCloud recognises the new one as being the old one.
Although I am far from an Apple fanboy, I feel that their phones are the least-bad choice at the moment but I am really starting to question that after this experience. Not very happy about that, Apple. I am interested to know if by doing that the phone is now unlocked, or what the deal is, but I can't, since it's no longer trackable.
That said, it is a pet peeve of mine that the new phone from old backup workflow doesn’t prompt for a new device name or to rename the old device. Reusing the name can be confusing if/when you still have both devices.
I suspect that the user above fell victim to something similar to what was mentioned in the article and had the device removed from their account that way.
That's not interesting IMO, that's asking for trouble. You go with a device worth 1000 USD or so to a poor country. You use the device on the streets. You're basically putting a bullseye on yourself saying "rob me!" Get a dumbphone/tourist phone instead.
https://krebsonsecurity.com/2017/02/iphone-robbers-try-to-ip...
https://krebsonsecurity.com/2017/03/if-your-iphone-is-stolen...
Personally, i lost my iPhone 3 yrs ago, since then I have got many phishing emails, which leads to an Apple-like website. I always type something like, "betterlucknexttime" for password, just for fun.
Why give further information to the scammer, even if it's just my IP address?
Water tends to kill the PCB (due to corrosion), but all the individual chips will usually survive.
https://www.vice.com/en_us/article/gyakgw/the-prototype-dev-...
If usable, couldn't a thief just steal your iPhone and wait for you to wipe it?
This is why resellers want it removed from iCloud and will visually confirm it. You can get halfway through the setup process before realizing it’s still locked to another account.
We learned the hard way, once, when returning a company phone.
Activation lock effects the ability for the phone to be set up (e.g. activated).
Actual data on the phone is encrypted to a set of keys, that are themselves protected by the SEP, which checks the passcode, does the timer enforcement, and increments counters, etc.
The moment the device is reset/wiped the keys are gone forever and the data cannot be recovered (even if your took it apart and read the flash directly)
I don't care much about the repair industry, they can sell every part of a phone, both legit or stolen, except the display and the logic board. The display can't be resold anyway as it will have been extensively scratched anyway and the logic board rarely breaks.
I'm a bit fucked if I get mugged!
If so, this could lead to an additional sentence, for cybercrime.
As a robber, you probably also do not really want to spend time “negotiating” with your victim over their password, thus giving them more time to see your face, spot your accent, etc.
I think you're giving criminals too much credit here. Risking a few years in jail to get $200 when you can get that risk free working a minimum wage job means they either don't care about the punishment, or they don't think they're going to be caught.