The iPhone Setting Thieves Use to Lock You Out of Your Apple Account
wsj.com
wsj.com
So an attacker with the iPhone passcode can lock you out of your Apple account on all devices, even if they don't have your Apple ID password or your Recovery Key. Basically, the iPhone passcode is your only defense if you lose your iPhone. I had always assumed the Apple account password would be needed, and that the passcode is not as important as it is so common for it to be only four or six digits.
I'm going to go setup a stronger passcode now.
Just don't forget you turned this in and then get confused why it's greyed out in settings when you go to change something in there.
It suggests that one can use the unlocked stolen device to learn the appleID.
Then follow a series of steps on the device to turn off the screen time passcode by entering the appleID and the device passcode.
Namely "forgot passcode", "enter appleID", "forgot (appleID) password", "enter device passcode".
If correct, then the use of a screen time password can not defeat this attack.
Apple and Google both provide sensible security settings but you can only guess how recovery might work if you are locked out of your account from their docs. Even with their advanced security programs (requiring a hardware token) I’m not entirely sure that I’m not defeating the whole purpose of these measures by putting a mobile number in my account that can be sim swapped. On the other hand I’m also not entirely sure if I could recover access from what I think I’d need to provide to prove my identity (recovery codes, trusted contacts, …)
I get why they might not want to lay out the whole process and every heuristic they use, but it’s not really reassuring.
So, you can lose your google account, even with recovery set up.
https://apple.stackexchange.com/questions/217704/disable-dis...
> This transient display lasts 3 seconds to avoid too big a security problem. But this is still largely sufficient for anyone behind you to read it really easily. Moreover this transient display can be easily captured by any camera
[0] https://news.ycombinator.com/item?id=34936015
[1] https://www.karltarvas.com/2023/02/25/protecting-your-iphone...
All this for a security “flaw” that isn’t really a flaw. It’s functionality that is consistent with industry standards —(Google/Android) works the same way.
Your cellphone might as well be an extension of your brain. Secure it with a strong password, and try to be mindful of shoulder surfers.
Major phone OS makers (all, what, 2 of them?) need to allow you to have at least 2 authentication paths - one when you are in a physically secure location, and one when your phone could be snooped or stolen. It's a fundamental need for phones.
To mitigate the problem of muggers demanding both codes, they should also allow location-based locking, where you could tell the phone to only allow the trusted functions to be accessed at certain GPS coordinates.
But since it is also stupidly profitable, it's a problem without any solution.
In the US, phone numbers are now as important as social security numbers, in that you need one to access a bunch of online services. That so much else is attached to that phone number and that the phone is its own weakness is unforgivable. I worry, however, that the mitigation will come in the form of tying identity into the phone to an even greater degree.
I'm more concerned about how much a phone is expected in the first place, for more and more things. Last year I went on a trip with some friends, and half of the places we went required apps for tickets or even parking, and even a hotel we stayed at was strongly pushing an app. If I'm flying somewhere, I still get a printed boarding pass because I don't want my phone to be the single point of failure that prevents me from flying if a freak accident happens between check-in and the gate.
I feel like this is being done with the hierarchy of how biometric unlocks work on the phones. Your most common logins can be biometric and are generally considered things that cannot be snooped or stolen though they may be coerced.
At least on iOS, it is generally easily possible to make sure that you only ever use biometric unlocks in public spaces and spaces you are worried about being snooped (spaces outside of your home).
It's also possible to be afraid of coercion and temporarily disable biometrics with a quick button press.
Presuming of course that you trust the biometric unlocks in the first place. But if you trust them, then that definitely gives you two authentication paths, one of which is harder to snoop/steal than the other.
As someone whose brother lost years of his children's videos when thieves locked him out of his iCloud account [1] this part confirms two things. First, it gives me hope that we might one day recover the account, seeing as the data is not cryptographically locked. And second, it confirms that the reason we couldn't get the access back is not because Apple can't do it, but rather because they don't care.
If you have an iPhone, user gkiely shared this tip on how to further protect your account: https://news.ycombinator.com/item?id=33602627
I assume your account dates from the days before Advanced Data Protection[1]. Nowadays, you can configure it so that the majority of iCloud data is now encrypted with a key that only you control.
[1]https://support.apple.com/en-gb/guide/iphone/iph584ea27f5/io...
[1] https://github.com/icloud-photos-downloader/icloud_photos_do...
[3]
#!/bin/bash
mkdir "$(pwd)"/{photos,cookies} 2> /dev/null
if [[ -z "${ICLOUD_PASSWORD}" ]]; then
exit 1
fi
podman container run -it --rm --name icloud \
-v $(pwd)/photos:/data \
-v $(pwd)/cookies:/cookies \
-e TZ=America/Boise \
icloudpd/icloudpd:latest \
icloudpd --directory /data \
--cookie-directory /cookies \
--folder-structure {:%Y/%Y-%m-%d} \
--username mysuperduper@username.com \
--password "${ICLOUD_PASSWORD}" \
--size originalThat's the article.
I can't confirm bc the article is paywalled but if this trick works with any unlocked iPhone then I am very interested. Plenty of cases where it is snatched from your hands on the street and accessed while unlocked, and then it's a race of whether you can wipe it first. Don't have another device at hand... unlucky.
I also think Android has a similar issue.
No it doesn't. For any security sensitive stuff, you'll be asked to reconfirm your device password (and potentially also the password of another device on your account).
> Apple introduced the optional recovery key in 2020 to protect users from online hackers. […]
> iPhone thieves with your passcode can flip on the recovery key and lock you out. And if you already have the recovery key enabled, they can easily generate a new one, which also locks you out. […]
> So long as you can access your iPhone, you can add or reset a recovery key without any extra credentials. Apple says this is a convenience measure. However, it also gives thieves easier access.
Uff! Security vs convenience is a difficult problem, but only protecting against remote/online hacking is a massive oversight! One shouldn’t underestimate the incentives for thiefs stealing your passcode and device in real life.
Most of the time she still reaches for her old Android because it unlocks instantly (and properly, not to a stupid lock screen!) with a fingerprint.
My Samsung on the other hand always opens flawlessly with a fingerprint scanner.
What is Apple trying to avoid here by not including one?
The dark makes no sense. It’s not using visible spectrum, it uses IR laser dots and flood illuminator coupled with an IR camera to map and photograph your face in 3d.
Mask Auth only works afaik with iPhone 12 and greater.
Apple used to include Touch ID. Some devices still have it (iPads etc). They are trying to avoid something though - there’s no physical space on the devices for finger print scanner. The iPad integrates it into the on/off button which is large and exposed. But most phones have very small physical buttons that are typically covered by cases. The rest of the screen (sans notch) is edge to edge touch screen.
On my iPhone 14 the Face ID is basically flawless and very fast. I would suspect your “new” device that’s second gen Face ID is simply not as capable as the fifth gen on market today.
But, dude, if you like android, go for it.
> While there are mixed opinions from privacy experts on which is more secure, Apple claims that Face ID is 20 times more secure than Touch ID. While the chances of someone unlocking your iPhone using a spoofed fingerprint is one in 50,000, this number grows exponentially to a false positive of one in a million when it comes to Face ID.
This happened to me twice in the span of an hour while the phone was face up on my desk at work. I can only guess Face ID is being triggered repeatedly by some feature and is failing so it is disabled.
Perversely this means I’m not as willing to use a very long complex passcode because I don’t want to have to type all that if I’m in a rush and Face ID stops working suddenly.
Personally I would prefer they bring back Touch ID.
It's probably the notifications on your lock screen triggering a Face ID check in case you want to read what they say. You could reduce the number of notifications that you receive, or use a Focus Mode while at work, or keep the phone in a pocket or face down/in a dark place.
1. If you reboot your phone, you have to enter your passcode.
2. Some people prefer to use a passcode for legal reasons. Essentially the police can compel you to unlock your phone via faceID and touchID, but not passcode.
3. Some people might just like it and/or be used to it.
But sometimes you don't have the time. From what I recall, the police were able to apprehend Ross Ulbricht (of Silk Road fame) before he could log out of his computer.
But this sounds like a very clever way around the whole “Apple can’t be bothered to care” problem.
Companies circumvent this complexity by simply asking you to login before you can request anything. If someone has full access to your account, all information accessible should be considered as insufficient to validate you...
In the end such a GDPR-request without login would probably again be a case-by-case topic which needs to cross the desk of some legal department to approve the action. But yeah, at least there are strict guidelines for response-times and other obligations for the company.
As per usual process of Google, Amazon, Apple et al, the process for this GDPR Request is done online AFTER you've logged in with your ID.
In case of Apple this is done in the "Manage your Apple Account" area of your account settings, for which you need to be able to login first.
I'm not sure these companies have a process in place to provide you this data without you having access to your own account. Filing a GDPR Request like that might turn into a topic requiring support from a lawyer / consumer protection agency...