How my brother's iCloud account was stolen
7c0h.com
7c0h.com
AFAIK my brother didn't hand over his iCloud password. That's what the phishing messages were for. Had he not fallen for that (as the article in Spanish explains) the thieves could have only sold the phone for parts. As for how they changed the recovery number, lstamour [1] has what I consider a good guess.
My brother did have a screen lock, but it was a 4-digit numeric code. My guess is that the smudges on the screen revealed quite easily what the code was as AFAIK the thieves didn't ask for it. He chose that code because he often shares the phone with his wife and having to show his face every time was annoying. He didn't know you can have two registered faces, and I don't have the heart to tell him now.
And finally, many of you correctly pointed out that there are steps that could have mitigated this attack. I wanted to share this story mostly [2] because I think it's an interesting example of what iPhone security is like for the type of user who would never set foot in HN. I could have easily followed the steps delineated in this comment [3] from the other thread, but my brother is not that type of user.
[1] https://news.ycombinator.com/item?id=34407683
[2] Okay, the main reason I published this story was to find someone who can help (wink wink). But the other reason was definitely in the top 3.
I think the information you added makes the majority of the discussion in this thread irrelevant. If the thieves phished the password in a separate attack and then used that to perform iCloud account hijacking - then that's a fairly expected outcome that is not unusual in the industry. Having both the password and the phone basically proves full ownership.
I empathize with your frustration, but realistically speaking, the outcome very likely would have been the same if he used any other phone from a major tech company.
The thieves changed the phone number immediately while they only obtained the password around 5 days after stealing the phone. Had Apple support been more... well, supportive, we would have been able to recover the account long before the thieves got the second factor. There was a big window of time in which Apple could have helped, but they chose to send us in circles instead.
As for "proving full ownership", those factors cannot prove full ownership because the thieves are not the legal owners of the account. There are multiple ways in which we can prove ownership (legal documents, access to the iCloud email, photos of us inside the account, etc) but Apple doesn't want to provide real tech support (as this commenter [1] pointed out).
Also, related: had this happened in Europe, the GDPR would force Apple to provide my brother his data (as I've written before regarding Google and a locked account [2]). So it's not like they can't, but rather that they don't want to, and I think it's perfectly fair to criticize them for that.
Saying that, I can see how by limiting their involvement they are reducing the risk surface. To address issues like that (and there is, of course, a huge spectrum of account hijacking situations) they would need to train an army of international support representatives who would have the authority to overwrite iCloud ownership - an incredibly questionable power. They would need to be able to validate various documents (e.g. US military ID or some obscure residence permit in Japan), be able to verify photos (which with recent ML advancements is becoming increasingly difficult), make phone and video calls to verify identify, and so much more. In turn, these representatives would become vulnerable to social engineering attacks themselves. If they overwrite ownership for a very sensitive account - who would ever trust Apple again?
It’s basically one of the major principles of cryptographic products: it’s safer for them (and, to be honest, for everyone) to deny giving access to one account, then jeopardize trust in the entire company.
I hope Apple will be able to help you through some process - maybe it takes longer than it should have. Good luck!
I'm sorry this happened to you.
Did not know that. Then again, not sure how we can do that ... in iOS.
https://discussions.apple.com/thread/7647773?answerId=305700...
- what you have, and
- what you know
Also, after reading this I'm going to have to think about what would happen if someone stole my phone. I take it everywhere with me. It's not an iPhone, but it's still worth a few hundred dollars and it has all kinds of data and logged-in accounts on it. I assume if it was stolen at gunpoint, I wouldn't be in a position to refuse to unlock it and unlock some apps/accounts.
Please if you aren't backing up your cloud storage photos/important files, stop reading HN and go and set it up now.
I can recommend backblaze for cheap reliable storage and the restic backup client which is brilliant (a single, small binary). There's also rclone, or even the backblaze cli client. [Sorry I sound like a Backblaze shill!]
I run it as a cron on my NAS, and the only intereaction I need to have with it is to give it a new 2FA code every ~2-3 months. Highly recommend it
[1]: https://github.com/icloud-photos-downloader/icloud_photos_do...
The way I do it is slightly roundabout but works well — I sync to iCloud, which in turn syncs to my desktop, which I backup to my NAS from there.
(Important note: You'll need to turn on "Download Originals to this Mac" in Photo's Settings, otherwise you'll get hi-res proxies rather than bit-for-bit source images.)
https://apps.apple.com/us/app/photobackup-backup-photos-and-...
I recommend everyone who hasn't done it before, to hit the above url while logged in and firing off an export. It will respond back after some time with URLs you can download. Great for downloading your Youtube playlists and history.
I haven't seen any alternatives to Google Photos either. Ente might be most promising, but their iOS app is not great at actually automatically uploading photos.
There are some situations where you may have entered geolocation data on the app/website and this will end up in the json file rather than embedded in the image file metadata. It's up to you to work out how you want to merge this back in.
It is interesting that Apple has no way of viewing phone number histories.
Feels like there’s a missing password prompt there. And maybe confirmation on a second device, if you have one.
The fact that "I'm going to change my phone number, which is an important credential to this account" has less security than "I want to buy an app for $0.99" just goes to show you that sometimes, particular emergent properties of a system are not what any logical person would come up with deliberately.
That or someone just needs to make a big enough stink and try to get the liability shifted to Apple for negligence here on account takeovers, and they'll figure out how to change.
Don’t know how it is implemented exactly, but on the OS level they can do a lot of clever tricks. From their servers they can literally send a challenge-response protocol to the secure enclave of your computer, thus verifying that on the other end of the encrypted connection they are trully talking with a computer manufactured by them, and that computer is the one which is registered to your account.
If they implement this correctly they can make an attack against this chain of trust very costly.
On the other hand on the web they get a http querry with some cookie attached. Maybe. Lot harder to gain the same level of assurances there. And a simple cross site scripting attack, or a compromised browser extension can steal said cookie.
Known to belong to me, yes. Known to be in my possession, no.
You'd still need one further thing to go on as far as I can figure - I'd need the password to type into my browser first - but treating "browser session" and "machine the browser is running on" as separate levels of trust seems naive in terms of what someone who steals the machine can do.
The real question here, IMO, is how do you prevent against this. Because to the Apple engineers in the US of A, having your phone stolen at gunpoint is almost unheard of, and getting it swiped from your hand is also barely a problem anymore since thieves in the US typically don't go through all this effort to phish the Apple ID password from you (at most they sell it to a 3p service that ships it overseas to China for teardowns and parts salvaging).
0: https://apple.stackexchange.com/q/382190 (note that it prompts for local user account password because the long-lived token that performs a new grant for the Safari session is stored in local Keychain; so if you have touch ID or watch unlock on your Mac, it'll use that first)
> https://apple.iforgot-ip.info and https://apple.located-maps.info
Hell, I'll even go to them and send some fake stuff. Thanks for the idea.
Edit: they're down. Too bad, I'll have to send junk elsewhere.
0: https://safebrowsing.google.com/safebrowsing/report_phish/?h...
I think you have to activate the Apple 2-factor authentication so that your key Apple ID info cannot be changed without corroboration or that 28 character code.
If Apple were to let this situation be reversed, who is to say a hacker wouldn't be using this exploit to take over someone else's account?
The problem boils down to one of the most profitable companies in the world becoming that way by cheaping out on support for their users.
How would this work? You provide a certain number of photos to corroborate who you are? How would that not be vulnerable to hacking as well?
The interesting bit is theives ability to disable FindMy, it's effects, and following sequence of events.
I have to push back on this. It's not stupidity to not realize you need another Apple device to have any reasonable chance of navigating their support channels. It's not something they go out of their way to teach you about, until you learn the hard way. Indeed it's an infuriating (IMO) dark pattern.
Don't blame yourself or others - this is on Apple!
EDIT
My personal brush with this was when my wife's phone was lost/stolen/etc and she forgot her iCloud password. Even though she had not one but two active macbooks, the fact that the credit card she'd registered with iCloud caused weeks of delay from Apple. They wouldn't budge unless we entered the original CC number, but their system rejected it due to the expiration. Madness! I'm glad that I had an internal contact - most people would have been locked out for good. These days I use a thinkpad...
Except the bloody thing wouldn't work on my Android phone. The page was just telling me to download the iCloud app from an Apple device.
I didn't get the iPad back and haven't purchased anything from Apple since.
Regaining access to a single device that has been robbed and unlocked at gunpoint is a tough scenario. But I agree that there must be better support patterns to recognize and deal with such a scenario… the rather unfortunate thing I see here is his brother falling for a phishing scam, which yes ultimately will lose the device for good (physical access + password). That is harder to deal with from the support end, I’d imagine.
"An iPhone is not cheap in general, and in Argentina less so. The current price for an iPhone 13 is ca. 400.000 ARS, which roughly translates to 2200 USD or 1300 USD at the unofficial rate (it's complicated). With an average monthly salary of 427 USD (according to Numbeo) you can see that getting a new iPhone is not a choice to take lightly."
More countries have Rupees than I thought: https://en.wikipedia.org/wiki/Rupee
"You don't have to worry about anything, we've got you covered. But there's a 0.05% chance on any given day that you lose access to everything and we won't bring it back unless you personally know someone at our company."
That's not true at all. There were entire businesses before "the cloud" that did very little more than service people who had lost their data and help them recover it.
I used to get billed out at near-lawyerly rates for recovering data in the mid 1990s. While I was in high school. Businesses like DriveSavers were even more lucrative.
You're right that the safest option will be to have backups of your own, but at that point the cloud is only adding convenience for backing up your device for restoring, or for synchronizing files between cell and pc. To be sure you still have your data five years from now, you still need to do it yourself. I believe a lot of people understand the cloud to mean "I give you money, you make sure everything works and I don't have to get into the details".
What are they supposed to do? Believe everyone that calls up with "I got locked out?"
I kind of wish that they had a way to lock possibly stolen accounts and allow people to verify their ID at an Apple Store or something, though.
Perhaps they could prompt users to keep local backups of their icloud data rather than pretending it's impossible to lose info in the cloud.
The article doesn't say that happened, though. It just says "My brother got his iPhone stolen at gunpoint." If the victim had been made to hand over his password, that's a very very huge detail the blogger did not include.
I had my phone stolen from me at Pride in SF and went through a lot of the same steps. The thieves yanked the SIM immediately. I was able to follow the phone as it hopped onto public wifi networks (mostly at stores) that I had joined before. it finally wound up in Shenzhen, China.
In general, it's expected that you should be able to update your own phone number in your iCloud account.
Also, trivia for iPhone users: my brother used to have Face ID set up, but he disabled it because he couldn't figure out how to set up a second face and it was annoying when he needed to share the phone with his wife. So don't do that!
To add some context, Argentina has a history of robbers asking people to do complex tasks at gun point, like withdrawing money, and other things during “secuestro express”.
Lots of people keep talking about password codes, etc. You should be able to hand over your phone to an attacker and walk away knowing you and your data is safe.
At least don't use biometrics, they will cut off your thumb AND steal your iphone.
There is a lot of disappointment expressed in the comments here but we need level-headed solutions, not just rage against things that are actually useful in 99.9999……% situations.
This is essentially the famous xkcd "5 dollar wrench" problem https://xkcd.com/538/
Unfortunately I don't have an iPhone to check, but another comment [1] suggests that this may happen if you physically change SIMs. My brother said they didn't ask for his iCloud password, which makes sense: if they had the password then they wouldn't have needed the phishing step afterwards.
At this point I will just stop commenting on this post as it seems like either Apple already fixed this or some of the most critical information has been omitted by the author. So we are just guessing and raging for no reason.
Some of the economics of the underworld are remarkably sophisticated. Everyone has a role and there are some parts of the supply chain that require different kinds of risk. Sometimes it’s risking cash, physical safety or personal-criminal repercussions.
This was just in the news in Philadelphia recently where a whole house was forced at gunpoint one by one to unlock and sign out of their iphones. https://www.cbsnews.com/amp/philadelphia/news/how-philadelph...
Id be in trouble since my work iPhone has some password manager generated random nonsense that i would never be able to remember. All i know is it uas the second single tick on the keyboard, not the first, and they look visually identical on ios.
And you can put your phone into Lost Mode with Find My turned on, right away by signing into https://icloud.com/find from any web-enabled device.
Another, cheaper but potentially more risky option, is to use a Google Voice number as your 2FA SMS line.
If the OP's brother had either of those options in place, I'm pretty sure he could have recovered his account and removed the stolen iPhone from the list of authorized devices.
https://support.apple.com/guide/icloud/erase-a-device-mmfc0e...
It sounds like this might not have worked in the author's situation, where the thieves changed the phone number immediately. It sounds like at that point it was pretty much game over.
Even without changing the number, phone numbers are easy to hijack. The security of the scheme depends on how gullible a cell phone company customer service rep is, or how corrupt a phone shop employee is who is willing to do a "SIM swap" for the crooks. See Brian Krebs' website for a description of the process and how it was used to empty crypto wallets.
Furthermore, telecom standards were designed by committee and rely mostly on security by obscurity. The SS.7 system used to carry text messages has no encryption or authentication and no security whatsoever, which is how Russia or Saudi Arabia have been using it to track dissidents in the US through their phones. Even if you don't have access to the SS7 network, you can also intercept them over the radio waves using about $1000's worth of PC and electronics because spy agencies have gimped the encryption standards to make them easy to tap.
I may be wrong and I have multiple devices with 2FA activated, so my mileage may vary because of this. I’d always expect 2 factors to be necessary to make changes to my account. If changing the phone number with activated 2FA is possible without one of these elements present I’d consider it an oversight. I consider the SMS mostly a tool to make sure the user has access to the new phone number while setting it up and does not misstype.
Since OP mentions a 4-digit smear code I am not convinced that Apples security is the weakest link.
Another idea, what about Legacy contact? I’d not be ashamed to “use it in any way possible” to re-gain access to something that was stolen from me.
As the author found, support is useless . It took me close to 2 weeks after emailing Tim Cook about the situation, since I was seriously considering an iPhone. Executive liason had it reset for me.
I was able to change the password, login, and the VERY next day the password was changed (presumably from whomever is using it on THIER phone). I've given up. My time is not worth chasing this down.
I may eventually just start harassing the douchebag who thinks they have my email address, but there are like 3 or 4 people whom i get email for. AFAICT every single one is a boomer.
Their support did nothing. Their privacy department did nothing. What finally set things into motion was complaining to their regulatory authority. Wouldn't you know it, within two days, I had a personal email saying they'd remove my email from the account, and they haven't emailed me since.
So I changed the email address on the account to Tesco support's email address, now they can deal with it.
sev.erian@gmail and severian@gmail are the same to gmail but many places treat them as different. (I don’t know what iCloud does.)
This is straight out of Office Space, except In Real Life.