Apple's new iPhone security setting keeps thieves out of your digital accounts
theverge.com
theverge.com
My phone was snatched from my hands in the street. I was able to wipe it via 'Find Devices' within a few minutes; I was able to track its location for the rest of the day, until I requested that my carrier irrevocably disable its network service. There was no evidence of any accesses of my information or accounts linked on the phone, then or since.
In the following days, it was still visible in my Apple device lists as mine, with reference information like its model and serial number – as it should have remained, indefinitely, to prevent anyone else from associating it with their accounts. (Until recently, I still had an iPhone 4 listed there that hasn't been turned on for many years.)
But sometime since then, it was removed from my Apple account – without my permission, and with no notification to me. This step would also apparently allow someone else to use the device with Apple services.
Apple Support insists only a person who authenticated to them as me could have done that, and that they have no records of when/how that happened – a policy that seems designed to help criminals cover their tracks, with no help to customers other than: "you should change your password".
Further, even if I provide the serial-number/IMEI with a police report, Apple says they can't determine if they've activated Apple services to that stolen property for someone else or provide me with any further help.
I thus suspect theft networks have figured a way around Apple's breezy assurances about locking-out stolen devices, perhaps similar to how they've often deeply pierced major telecom providers in order to carry out SIM-swap attacks.
But: if anyone on HN knows more about how the smartphone theft/fencing (chop shop?) operations typically work, or how Apple's systems do or don't protect against post-theft hijacking of registered Apple devices, I'd love to hear perspectives that either flesh-out, or refute, my impressions that Apple's related systems involve some false bluster & "security theater".
That's my best guess as to what happened here.
The alternative, that the thieves fully compromised my account via obtaining my Apple password and circumventing the various secondary checks via my other devices, seems very unlikely to me.
There's been no evidence of unintended account accesses – like the confirmation challenges that pop-up on other devices. Unfortunately, Apple seems to lack the user-reviewable log of all authentication events that others like Google offer.
The sorts of compromises that would have revealed my password – like a keylogger on one of my primary Apple devices – should've shown up as other attacks on targets of more value than a single street-snatched several-years-old iPhone.
Also sounds like something doable by compromised Apple insiders. :/
Show that to the right Apple employee, you should be good to go.
The key thing is to protect your data first and that means wiping it remotely. Leave it attached to your iCloud account device list though because that'll leave the provisioning / device lock in place. I'm sure they have a way around that now but it'll make it more difficult and devalue it for the thief at least.
But yes - it looks to me like dishonest actors managed to get the device out of my "iCloud account device list" without my permission, and thus evade the "provisioning / device lock".
What's more surprising is if they have no audit logs that would let them discover the compromised employee in these cases.
I got an iPhone from a relative, the relative had forgotten the passcode and the Apple ID password.
I did a factory reset of it via iTunes and of course when it started up and I started with the setup it said it was locked to *@*.com.
I contacted Apple support and they said I needed proof of purchase for them to unlock it.
I did not have any proof of purchase and neither did my relative.
But I refused to let that stop me. So I made a proof of purchase, printed it and went to an Apple store.
I told the Apple Genius about the iPhone and that it was locked but factory reset and presented the "proof of purchase".
The Apple Genius went to get a manager or something and the manager checked the "proof of purchase" and then connected the iPhone to the store Wi-Fi and did some stuff on their iPad and rebooted the iPhone. The iPhone did a reset and then it was unlocked and ready to be setup without any hurdles.
So I am guessing some thieves have figured this out.
When I managed a hospital's iPhone deployment I made it a point to always back up our receipts electronically because I have... had to make quite a few emails to AppleCare Security to release a few Activation Locked devices. It's not a terribly difficult process once you've done it a couple times, and I reasonably think I could release as many phones as I wanted these days with enough fake receipts.
... My personal stuff is enrolled into my own personal Jamf instance and because I went through a bunch of motions with Apple Business my personal phones and Macs are all DEP locked ;)
It's mind-bogglingly easy to bypass MDM/DEP on even a T2-enabled/Apple Silicon MacBook.
Like three minutes, and not overly complex. Without spelling it out here, null route three DNS entries, install macOS Monterey, edit /etc/hosts similarly, and then upgrade to Sonoma. You can even remove the null routing after (it's only needed to bypass network calls in the installer).
Nothing broken, no errors, 100% DEP-escaped.
I suspect that the only thing you can't do at that point is reset to the OOB experience for selling it.
Imagine the false docs are often accepted, rather than triggering a criminal prosecution. The practical maximum downside may be mere impoundment of the device, rather than a conviction/jailing.
(And, even that would require Apple's policy to be to assertive & confrontational: "you presented us suspicious documentation, we're holding this device – that you carried here, in your possession – until police sort it out." Does Apple want to take the risk of that backfiring on them? Or would store staff, in practice, simply say: "we can't accept that documentation, you and your device should leave.")
Then Apple's lenience here will support a positive resale value of stolen devices, enough for the weakness in their systems to be exploited.
The thieves figured out you just need to know (or be) an employee of any of the 500+ Apple stores. I assume that some theft rings have this process quite streamlined.
It was reported in T-Mobile's systems as my personal visit, with supporting documentation/ID, to one of their retail locations in Oklahoma – thousands of miles from anywhere I'd recently been. So, while remotely possible that their employee gullibily-reviewed credible false documents, it seemed far more likely to be:…
- an insider abuse by a corrupt employee;
- a deep hack of T-Mobile's systems, allowing such admin actions with forged audit-trails; or…
- compromise of an authorized employee's credentials plus access to capable internal-system front-ends.
The Apple Support person I spoke to insisted that an analogous compromise here was impossible - that no Apple employee had the power take such an action without my Apple ID password. Based on other reports in this thread, I highly suspect she was lying to me, probably in conformance with Apple policy.
"If you need help removing Activation Lock and have proof of purchase documentation, you can start an Activation Lock support request."
Hopefully this works well, I assume third party apps such as banking will be able to opt in to the additional protection (not sure if this is strictly required actually, I checked my banking app and if Face ID fails you have to enter the banking PIN, you can’t enter the device PIN).
Is there a way to lock individual apps so they require Face ID even if they weren’t designed to? A smart thief having access to the Gmail app for example, if the phone was unlocked when stolen, could wreak havoc.
Something like one passcode for ordinary phone use, one that would immediately and covertly send an emergency text to your family with your current location, one that would instantly wipe the device and one that would give you access to the hidden gay dating app you don't want people to know about.
It would be a real boon if Apple themselves did it, incorporating not just codes or biometrics even but also arbitrary information from phones sensors if advanced users wanted. So for example you could explicitly set a few geofences and say that certain actions could only be done within them (and only at certain times of day even), or certain apps viewed at all (by literally keeping the encryption keys for them locked away unless all conditions were met). If it's not even possible for you to comply when traveling in the first place and that's widely known and transparent it reduces the value in trying to coerce you.
Such a system could also be useful outside of security fwiw, just in ordering our lives. Someone finding distraction hard could lock all their games and social media apps in a view accessible only at home and forbid any app store purchases as an aid in avoiding temptation. Anti-engagement instead of trying to get more engagement.
I understand, and they are not wrong for not thinking through all the brutal scenarios that real life likes to play out. But I believe that engineering teams that have a security focus should have at least some consultant from areas where violence is normal.
So, effectively, all scenarios they think about is normal theft: forgetting the phone someone, or someone snatching the phone from you. They never think about someone sticking a gun to your face and forcing you to unlock the phone so they can run away in a motorcycle, while depleting your accounts. A distress code could be extremely helpful for bank institutions to flag every transaction post-distress. And locking your digital accounts (iCloud, DropBox, etc)
https://news.ycombinator.com/item?id=34936015
Now it seems like thieves would not be able to immediately unlink a phone from Find My if they have the passcode, because of the security delay
In screentime you can set a different code, so when anyone else can access your phone, they can’t change the code and lock you out of your phone.
If you get the screen time password wrong a few times it will let you put the device passcode in.
Keep in mind afaict this is the situation with 2nd account having Rescue Code enabled. Things might be different if it’s not.
Email me for how to actually restrict yourself with iOS Screen Time (without 3rd party apps) in a way which you really-really can’t bypass when you feel down. Disclaimer: Not an Apple employee, but a former smartphone addict, ahem, I’m sorry, user.[1]
1: I believe all smartphone users are addicts as much as rest of their lives allows it, without the use of hard restrictions.
However they got the passcode, it was enough to immediately change the 'trusted phone number' with Apple and lock me out of my account. Even after hours on the phone with Apple Support explaining the situation and offering to provide a police report and any documentation they wanted to verify my identity, the weren't able/willing to help me without that phone number. There have been numerous hassles to moving to a new Apple ID, including having to provide proof-of-purchase for all my other Apple devices to get them unlinked from the stolen account. But the worst by far was losing years worth of photos, which I foolishly trusted to be stored safe in iCloud and are now locked away from me and available to criminals.
This is a step in the right direction but I'd love for Apple to improve their policies around proving ownership of a stolen account. Even with this new protection, if you're ever robbed at gunpoint or coerced while drugged, your Apple ID can be taken and there's no path (that I've been able to find) to recover it.
I'm thankful to be alive, since I don't know what drug I was given and how much. And fortunately she left my passport so I was able to get home. But what a mess, I really can't recommend it.
Like ok I get it, there should be a fall back to biometrics not working for whatever reason. But for getting into your phone, but for apps that use biometrics since generally those have their own fall back of just using your password to login.
Unless I am missing it, I don't see this being a change here? I hope that is coming if not.
It forces an hour delay for people using the device passcode to reset the Apple ID password EXCEPT if its in a known location like home (also blocks changing the device passcode and turning off FindMy), and forces FaceID for these, even if the phone has been forced to forget the FaceID keys and require the device passcode.
And it requires FaceID without a passcode ID fallback for certain categories of authentication.
Judging by how often finger print readers get false negatives, this seems like an incredibly bad and frustrating idea.
Still though, why don't iPhone owners use face unlock? Is it not good?
But also the phone locks back to requiring a passcode with enough failed attempts, so presumably people stealing them know how to induce recognition failure.
Guess what I receive on this iPhone? Right, email & text.
On my PC it prompts for my YubiKey, but I cannot use it on iOS.
Just like the horseshit that once an iPhone is stolen it’s bricked for a thief. A friend’s iPhone got stolen and after a week it was removed from his device list in iCloud account. Apple Support refused to even acknowledge it and then didn’t respond anymore. They shut him off.