iPhones and iPads Now Require a Passcode on Every Backup/Sync
tidbits.com
tidbits.com
I believe this may be an intentional change to temporarily avoid a security issue, which otherwise hadn't been fixed yet: https://theevilbit.github.io/posts/cve-2022-32929/ (as shown in the blog post and embedded Twitter thread linked earlier)
> The issue is that an attacker can invoke the `AppleMobileBackup` utility and make a backup to a custom location. Thus completely bypassing the protected backup location.
The issue was "fixed" on the macOS side by updating the binary to not support this behavior, but the problem is that you can still swap in a binary from an older version of macOS to get around this.
So, presumably, the problem is blocked from the iOS side now until the issue is resolved from the iOS side to make the older macOS binaries not work with newer iOS. I think it's safe to assume there wasn't time to fix this fully (since it needs to behave differently depending on the version of macOS making the request to avoid making older Macs entirely incompatible despite the prompt) and therefore the fix is temporary, but it would be a shame if it was permanent.
I’m not holding my breath though for Apple to fix this.
In any case, requiring passcode might be a good permanent solution after all.
What I think is far more likely: it's a dark pattern to discourage people from doing their own backups.
One of selling points of iCloud is scaring people into the possibility of their stuff being lost from their phone getting destroyed/lost/stolen.
Up until this change was implemented, it was painless and transparent to do backups of your phone. You just needed to have your Mac or Windows computer turned on and your phone on WiFi with power. It Just Happens.
This is also a convenient way for law enforcement to get people's iMessage history, because iMessage backs up by default to iCloud, unencrypted, including the user's iCloud encryption keys. Without this, if LEOs wanted a criminal's messages they'd have to pound sand.
We know that the FBI has at least a somewhat sympathetic ear at Apple, probably because keeping the FBI happy means Congress doesn't start applying levers on the company.
Given the timing which is right after they deployed the enhanced iCloud security that supposedly E2EE's everything in a (again, supposedly) very secure way, I suspect this was a tradeoff they made to keep the FBI/Congress happy, while also boosting revenue.
'Hey, we'll nerf the local backups, and don't worry too much about enhanced security, most people won't turn it on because it's a pain and we'll put scary warnings on it.'
What is the point of that? I recently upgraded my phone and I didn't have this happen before?
What's annoying for me is I use a very strong password, which is stored in my password safe, which isn't compatible with this prompt, so I basically just stopped buying things from the App store, problem solved?
Authy get it, they prompt you to enter your backup password, just to check you know it, but you can skip so it doesn't get in your way when you're in a hurry.
I have one bank that never re-prompts for their passcode, and I've been locked out of the app since I got a new phone and put the wrong code in; because they name everything differently from all the other banks too. N.B. I can see the same accounts via my business login and phoning them is pain, so...
I have an account with an Italian bank that is also one of the biggest European banks, when I switched phone they asked me for (iirc) 3 different codes plus an additional sms otp, after that they first disconnected my old phone from the account and then they asked for my debit card PIN which I didn't remember because my card was replaced less than a month ago. I was then locked out from my account and I still didn't manage to get back in. To be fair I didn't even try to call their customer support, I just drained the account using Apple Pay which luckily was still working.
Revealing a card PIN to anything other than ATM/POS hardware seems fundamentally wrong too.
Hence, even free, apps are associated with an account in a particular region. Also, it’d be easy to ruin someone’s life by downloading a free app like Tinder or Grinder to their phone.
Maybe I'm being unnecessarily stubborn, but I don't with to sign in with Apple ID on it.
I don't think Chrome would be region locked.
> Also, it’d be easy to ruin someone’s life by downloading
That could be restricted by requiring the user sign in with their device unlock credentials. I don't see how requiring the device be associated with online Apple ID helps protect you. After all, if someone malicious got their hands on the phone and wished to install something contraversial they could create and sign into a throw away Apple ID.
I've never looked into how you reskin a web engine, but I think there must be enough settings and hooks that not everything works exactly the same between iOS web browsers.
Yes, they could probably create a throwaway account (I don't think you need a credit card to "purchase" free apps) but it's a barrier to entry that is likely too high for a lot of kids at the age of having a managed cell phone.
My password is long, unlocking with another Apple device usually means finding my iPad somewhere in the house (the only device I have on my person is an Android phone - Apple don't seem to consider this case).
End result - it's too much bother usually.
As far as I know, it's always been a requirement, though after entering once, you can install more apps without entering a password for a temporary period. It's a good idea, too, since your AppleID is tied to your debit card or credit card, so if someone got a hold of your unlocked iDevice, if the AppleID password wasn't required, they could install as many apps as your debit card or credit card will allow. That's no good. Getting a refund for an AppStore App is near impossible.
You can disable the requirement for a password for free apps via the Settings > (your name) > Media & Purchases > Password Settings menu.
Don't know what you're talking about -- I've done it several times when an app turned out not to work or not have a feature I needed. The refund was processed every time.
Obviously if you needed to refund 100 apps in a week you'd probably have an issue, but normal occasional refunds seem to present no problem whatsoever.
Apple's response was to lock me out of the app store entirely. They'd never let me use that credit card again for anything Apple related.
Generally speaking, expect to not be able to use the card if not the whole account when you charge back. It's intended to be a last resort option.
It sucks because sometimes the company is wrong and the customer is right, and a chargeback is the only way for the customer to win. But from the company’s perspective those are a small minority of cases; most chargebacks are abusive customers trying to get something for nothing, and it’s best just to cut them off.
Imagine you had a small dispute at a local bar, maybe they gave you $10 less in change than they should. And you see the till open on your way out, and there’s only a $100 bill in it. We can debate the morality of taking it, but I don’t think anyone would expect to be welcomed back after taking it.
Make no mistake, Apple has no compunctions whatsoever to use incessant nagging and degraded user experience to push you where they want you.
Now it nags me every day to enter my passcode on my devices. :-(
Call it a profit theory instead. Could be wrong, could be right, but it’s no more a conspiracy than planning a Friday party.
Naïve, I know.
If the CEO can make more profit for his shareholders then that his fiduciary responsibility.
At the end of the day, this might desensitize the 5 power users who still use local backups, and they are probably harder to desensitize than most.
> iCloud backups don’t suffer from this requirement
Regardless, I hope Apple come up with a better solution.
I’m in the process of moving to better purpose built products. System76 for general compute, and Garmin for health and activity tracking. I’m hoping for the Fairphone to land in USA soon so I can transition to it.
Also, spending time on a solid home server setup and leaning on Home Assistant community to provide an ideal smart home. HomeKit is just another walled garden that will harm IoT advancement.
And now I am stuck. Either I shell out $ for their backup, or I need to enter my pin at random moments...
And when I don't wish to spend money, I am stuck with a bug(?) where my iCloud backup is > 5GB even when I uncheck _ALL_ things.
It's a ruse to make me spend money.
A simple method is to make the backup encrypted, where it leaves your device encrypted.
This is once again Apple forcing people to pay for more Apple products under the guise of security.
That's non-trivial because the computer that you've trusted identifies itself to the iphone cryptographically.
This past month I migrated from iphone 12 to 13 and it involved manually reloading/resetting virtually everything, despite making a local backup of the old phone. It would seem that the apple builtin apps specifically just don't restore without icloud - it's almost as if there's a product manager somewhere that's using icloud utilization in GB as their OKR benchmark, and that's one way to hit it.
Apple discontinuing TimeCapsule and disbanding the team couple years back isn't lost on me either.
I don't know the nuances of U.S. antitrust law.
Would this likely qualify as illegal anticompetitive / monopolistic behavior?
And not to mention the complete opaque “System Data” usage of iPhone Storage. One day it’s 1GB and next day it’s 20GB. Without any way of knowing what exactly is taking that space. Of course you can’t clear those up since you are on an Apple device.
The cynic in me says that this is exactly why they're doing it. And that's why I tend to boycott services from device manufacturers - the incentives are all wrong.
If someone has physical access to my Mac, I've got more things to worry about than them swiping my phone data.