iPhone thief explains how he breaks into phones [video]
youtube.com
youtube.com
> "I'm here [in prison] because I got too carried away"
Arrested for getting passcodes through trickery and violence.
That said, this report makes a good point:
* Johnson would quickly replace the passcode and then replace FaceID with his face
* He could then get into PayPal, Venmo, etc via (his) FaceID
* He could make ApplePay transactions at physical stores, again using FaceID
So, device PIN = all you need to get into all finance apps (if FaceID was enabled for them)
> "Johnson made $20,000 per weekend from selling the stolen phones"
> "I wish I had not been so greedy and just got what I got and changed my life"
> "When you get out, will you forget about this trick?"
> "There's gonna be new tricks out"
> "...and I don't want nothing to do with it"
Changing the biometrics should automatically invalidate all FaceID tokens and block falling back to device PIN. It should effectively log the device out of all services, perhaps even delete browser cookies etc. since it should mean the person holding the phone is not the one who logged on to those.
Of course, this could have other implications so a lot of care has to be taken when designing and implementing this.
This means that if you enable log in with biometrics, you’re essentially enabling the fallback along even if the app has a separate PIN/passcode.
Wallet is still accessible with the device passcode as a fallback though, which means quite a lot of damage can still be done.
I always wondered if I should do it for convenience every time I open one of my banking apps, which always requires me to login again.
This has convinced me never to use such a thing, and I'm glad I've stood my ground.
if they can get the code from you, that is as good as having your face id and they can access everything..
I also don't use Apple's password manager so they would have to know another master password to access the passwords for my apps
1. When advanced data protection is turned on, it should not be possible to change the Apple ID password without the associated hardware tokens.
2. Again when advanced data protection is on, it should require the hardware tokens to add a Face ID appearance or change the device passcode.
What's the point of having an Apple ID password if you can change it with the phone pass code ? It just bother the regular users to have 2 passwords to remember, but adds no security whatsoever...
Maybe we shouldn’t take this article at face value.
1. you have a passcode set
2. you are logged into iCloud.
1 & 2 are true for nearly everyone so sounds like yes this is still a problem.