A Basic iPhone Feature Helps Criminals Steal Your Entire Digital Life
wsj.com
wsj.com
> Groups of two or three thieves would go to a bar and befriend victims, often asking them to open up Snapchat or some other social-media platform, said Sgt. Robert Illetschko, the lead investigator on the case. During that interaction they would try to observe the victim unlocking the iPhone with the passcode, he said. If they didn’t catch the passcode at first, they might have tried to get the victim to hand them the phone for a photo and then subtly turn it off before handing it back, he added. After an iPhone is restarted, a passcode is required to unlock it.
>“It’s just as simple as watching this person repeatedly punch their passcode into the phone,” said Sgt. Illetschko, adding that sometimes thieves would covertly film victims so they could be sure they caught the correct sequence. “There’s a lot of tricks to get the person to enter the code.”
Also, some comments on the article indicate that this only happens if you enable 2FA. If you don't enable 2FA, iOS demands your account password before making changes. That's a big deal, and something people should know.
Mine forces me to enter my password if I touch anything under iCloud.
The pin can be used to disable ”Find My” though.
> Mine forces me to enter my password if I touch anything under iCloud.
Do you have 2FA enabled? Like I said, I've seen suggestions that your iCloud pw is required when you don't enable 2FA, but not required if you do.
If this is true, it does seem like a vulnerability.
- enable Screen Time
- set a Screen Time password, make it different than the iPhone password
- use Screen Time to disable making changes to your account
With this the attacker would not be able to go to the step of changing the account password without entering the different Screen Time password.
I wonder why this is not mentioned or recommended, seems kind of obvious. Sure it is a bit inconvenient but you probably very rarely make changes to your account.
Here are some features and settings that you can allow changes for:
Passcode Changes: Prevent changes to your passcode
Account Changes: Prevent account changes in Accounts & Passwords
https://www.wsj.com/articles/stolen-iphone-passcode-security...
> • Enable additional protection. Some apps, such as Venmo, PayPal and Cash App, let you add a passcode. Just don’t use the same one as your iPhone.
> You can also set up a Screen Time passcode for yourself, then enable account restrictions to prevent an Apple ID password change, the way parents do with their kids’ devices. In Settings, go to Screen Time > Content & Privacy Restrictions, then toggle Content & Privacy Restrictions on. If you haven’t already set up Screen Time, you’ll need to choose a passcode. (Again, make it different from your iPhone’s.)
> Scroll down to the Allow Changes section, and where it says Account Changes, select Don’t Allow. Whenever you need to access your iCloud account settings, you’ll have to go to Screen Time and re-enable this.
My multiple banking apps all require me to authenticate again at least with FaceID every single time I use them, with very short timeouts. Which bank’s app can be looted with the phone passcode alone?
It is trivial to access all of someone’s passwords in keychain if you know their iOS passcode.
If I'm in any sort of situation, I disable facetime by pressing the power button 5 times quickly. This means the next unlock requires the full password. I also have the phone set to erase itself after 10 failed attempts at this password. I can also erase it remotely with findmy.
And I never, under any circumstances, let anyone other than myself touch my phone, or any of my computing devices, while they are unlocked. Ever. No exceptions. Even in an emergency situation the people I trust most have no reason to access one of my devices while unlocked. None.
Someone might steal my phone, but they won't get anything beyond the device itself.
Pressing the home button five times can be done in under a second.
1) observe victim entering passcode
2) steal victim's phone, which you now know the passcode for
3) use saved passwords on phone to access victim's email, online banking, etc
How exactly is this specific to the iPhone?
And once they enable "Recovery Key" on your iCloud account, Apple will never let you back in no matter what you do.
> A similar vulnerability exists in Google’s Android mobile operating system.
Anyway, iPhone is advertised and considered as a secure and privacy conscious compared to Android. It doesn't allow sideloading stating that security is compromised. Plus it's very expensive compared to other phones. So it's bigger news than being the same as Android phones.
But then I read the article yesterday about reprogramming the Yubikey to be able to output a static password instead of its normal behavior. I thought, maybe this is a good way to input a super long secure password to unlock a phone.
Is anyone using any unusual or exotic phone unlock security methods?
- Using a very long passcode? (Harder to shoulder surf)
- Using a third-party password manager instead of keychain (something with its own master password independent of Apple ID); in fact you could store intentionally wrong passwords in keychain as a decoy, heh.
- Configure financial apps to disable passcode authentication, requiring their own password/2FA on every login (this becomes inconvenient though... wonder if they can be configured for FaceID only without passcode auth)
- Some process (doesn't have to run on the phone) for rsyncing iCloud content to another service or NAS.
The article does a terrible job of burying this important detail.
[0]: https://play.google.com/store/apps/details?id=com.beemdevelo... [1]: https://play.google.com/store/apps/details?id=com.azure.auth...
But, I've done some shopping and am about to get a mobile computer. I don't want it. I will be reluctant ever to take it out of my office or home. And I don't want it in my car. I certainly don't want it in a restaurant. In a bar? Gads!!! Hopefully never. I'm pretty safe about a bar -- never been in one!
Yup, mobile computing has become wildly popular, but there are security problems.