Android's theft protection features
blog.google
blog.google
"Theft Detection Lock is a powerful new feature that uses Google AI to sense if someone snatches your phone from your hand and tries to run, bike or drive away"
How much data could it have to look at in the time that someone "snatches" a phone?
> If a common motion associated with theft is detected, your phone screen quickly locks – which helps keep thieves from easily accessing your data.
So it's probably a machine learning model that was trained on motion data of snatches, but it's likely not AI in the sense of LLMs.
But I wonder how many false positives this could yield. For example you are in a hurry and you snatch your phone from a table. How precicesly can this model decide with just motion data, if this was theft or not.
Edit: To clarify, I was thinking of horizontally, in the direction that corresponds to the top of the screen, as if you were bent over using the phone--probably holding the bottom-of-screen--and then someone grabbed the top-of-screen to pull it away.
Good heuristics. Also that must not be a mainly downward rapid movement, which probably only means you just dropped your phone.
I mean, most people dropping their phone will be too glad/devastated that the device did/didn't escape harm to bother being annoyed that they have to unlock the screen again.
There's a saying that when something becomes mainstream it is no longer considered AI. Fun to see that being reversed.
If I snatch a phone from the table (probably already locked?) or drop it, I will suck up the additional login.
I have long thought about the utility of a little locking-beacon. If phone suddenly gets out of range, should auto lock. If only Bluetooth were not so unreliable.
These are two different things, since I do not want my phone to have no lock screen just because my headphones are sitting near it, but if it is unlocked and suddenly my headphones disappear, that would be a useful precaution, even if it doesn't eliminate the risk on its own.
I remember that I used the last option many years ago, as that was really convenient and worked very well. Basically as long as the phone was in your hand or pocket it kept unlocked, but as soon as you laid it on a table it got locked.
But now that fingerprint unlock is a thing, I don't even mind unlocking my phone as it is one fluid motion and happens unconsciously.
- Private Lock (source): https://github.com/wesaphzt/privatelock
- Private Lock (F-Droid): https://f-droid.org/en/packages/com.wesaphzt.privatelock/
Gotta admit first thing I would do is stage a theft scenario to see how it works.
If you're trying to call 911, or you're trying to video an assault... and someone tries to stop you, such as by jostling you or your phone... what's the likelihood that this Private Lock will get in the way of that?
Especially location data. If something like Find My Phone is activated, my immediate bias is to assume Google is taking advantage of this data collection to monitize my data without my consent.
Even on graphene OS, location without GMS is almost unusable.
I never spend more than 200 euros on a phone and consider them disposable. If I lost my (locked) phone, I'd merely get my (identical) backup phone from home and continue as if nothing happened.
The other downside is false positives or other occasional failure modes. Many such "auto-magic" features choose not to expose any granularity to the user, perhaps because they think it'll make it less "magic" or that a few entirely optional scaling settings in an "advanced" tab will hopelessly confuse users. Too often such "all or nothing" reliance on the infallibility of their magic 'do-the-right-thing' code forces me to entirely turn off what would otherwise have been a useful feature.
For example, we have the greatest opportunity in a generation for someone to build "photoshop for text" i.e. a proper GenAI based LLM tool with similar design choices. LMstudio is the only even close example of this, and they're not getting it in the way that blender does.
For me its car's lane assistant, interfering with driving is big no for me. Asked my father to turn it off on their new mazda 3 too, 99% ok behavior is simply too low, even 99.9% would be.
Otherwise, in city driving, it's like some paranoid front seat passenger grabs the wheel every 30 seconds.
Of course, I always turn these stupid features off but, inexplicably, my wife likes them and keeps turning them back on. So when I happen to drive that car it continues to be a nasty surprise until I remember to turn it off. This also makes a separate UX failure even worse. Settings like seat position, enter/exit behavior, navigation and even entertainment options are stored and recalled in per-driver settings. These per driver settings can also be linked to each key fob. She has her fob and I have mine. Very nice - except these damn driver "assist" features are NOT stored in per-driver settings like they obviously should be!
Damn it, car UX designers - all user options should be stored per driver. It's a few KB for bit flags and single-byte values, it's not like we don't have the storage these days.
Is this going to be a significant deterrent to mugging in practice, or are muggers still going to approach for your wallet, and take the phone in any case (to prevent calling, and to flip it for parts)? Is there data?
For muggers that want the phone not to be tied to a Google account, is a mugging going to turn in a more intense and lengthy encounter, while they make you deactivate your account on it? (And they're getting nervous about how long it's taking, and take it out on you.)
Personally, my first choice is not to be mugged. But, if/when I do get mugged again, my second choice is that it be a quick and smooth transaction, in which everyone remains calm, and I don't get physically hurt nor develop PTSD.
In my experience, they're lifted from people's hands while walking, taken out of back pockets, out of lockers, from the window sill at bars/restaurants, etc.
this would certainly deter that sort of activity.
On Android, it's called FRP and has been part of the Android CTS since ~2015.
This is already happening.
"Police said the gunmen forced one of the victims to reset his phone password while threatening him with a pistol. They made another victim log into their banking apps." (https://cwbchicago.com/2024/05/chicago-bucktown-robbery-spre...)
It's a deterrent because instead of getting a working phone that you might be able to sell for $500+ second hand, you get a brick that's only usable for parts. It might not stop all muggings, but it does make it much less lucrative. Given how many countries are going cashless, a phone is basically the highest value item a person has on them, so being able to cut the value of that is certainly going to deter the marginal criminal.
>For muggers that want the phone not to be tied to a Google account, is a mugging going to turn in a more intense and lengthy encounter, while they make you deactivate your account on it?
Adding a 1-2 hour probably makes the "force you to unlock the phone" strategy from being viable.
>(And they're getting nervous about how long it's taking, and take it out on you.)
It might suck for the first few people who get mugged, but after the first few the thieves would realize it's not caused by the victim and there's nothing they can do about it. Granted, a person who decides to mug people probably isn't the most rational, but this strategy seems to be used elsewhere (eg. time delayed bank/narcotic safes).
I know this wouldn't happen in USA or any serious country (because these people were prosecuted), but in 3rd world countries (where phone theft is super common) this will still be a problem.
Upon pick-up, I gave him a hefty reward and we both went our merry ways.
First the phone shows up the other side of the globe, then someone either tries to trick you or threaten you to remove it from your account.
How did they get that info?
I got texts from “Apple Support” at first then it graduated to a threat of some hitman from Miami who was going to kill me if I didn’t release the phone.
Of course, the whole time I just imagined some small lanky dude sitting in a basement wrote these texts trying to act tough and I just laughed.
The catfishing/blackmail scam of getting you to send nudes to a stranger who then turns around and threatens to release them is a different matter as the added charge of "revenge porn" relative to the blackmail charge is not as significant as the added charge of "murder" in the phone theft scenario.
Depends on how much untraceable, no-takeseys-backsies crypto you have access to on your phone.
Can I turn this off ?
I don't know why they're touting it as a new feature.
> Expect to unlock your screen or enter Google Account information [after reset]
https://support.google.com/android/answer/9459346?hl=en#veri...
This is powered by AI! /s
Factory reset should be exactly that; FRP needs to die in a fire.
It sounds like this new thing is going in the opposite direction.
Theft protection is a friction to deter "script kiddies" equivalent of phone thieves.
If that second pin code is entered the phone will go in anti-theft mode and e.g. hide specific apps, automatically erase it self or whatever you can think of.
At an old job, I was on a project at an international airport and was given one of those cards to get you through all the doors. Bypass security, get down to poke the planes, etc. Slide the card and key in a code to get through.
They gave us two codes: one to open the door, and another that opened the door and set off the silent alarm.
Settings -> Chats -> Chat backups
Someone put "prevent backups" on banks security audit checklist and that's that.
Had they provided a second form of access, independently of a single phone, I would be more than fine with it.
As far as I understand, this whole Find My/Remote Lock stuff will stop working when the thief pulls the bar down and activates the Airplane mode. Then all the data is one vulnerability away from being accessed.
This is the case on Google Pixel 8 Pro and it's been there for ages; I assume it's the same for other vendors.
I'm surprised this isn't a feature on android yet.
I think the only quick action that doesn't require you to unlock the device is the flashlight.
Of course the thief can still forcibly shutdown the phone or open it and remove the battery.
Having just changed out the battery on my trusty Note 20 Ultra yesterday, this made me smile as I imagined a thief evenly applying heat to the back edges of the phone, carefully prying the phone open with suction cups and a series of plastic picks, gently dislodging six fragile micro-connectors, removing 11 different nano-sized screws, removing the wireless charging antenna, peeling back layers of ribbon connectors, removing the speaker module, dripping solvent into the battery compartment and then waiting ten minutes for it to soften the battery glue so they can start prying the battery out.
Maybe somewhere during that painstakingly onerous process, they'll pause and ponder their life choices. I know I certainly did! :-).
The magic combo still (thankfully / sadly) works though.
Finding that "one vulnerability" is going to be pretty hard. The device is still going to be locked, you're very limited in what your exploit has access to. The common EoP used for rooting/jailbreaks are going to be out, because you won't be able to run arbitrary code on the phone. True, there are occasionally exploits in the bootchain itself (eg. checkra1n for iOS), but you could be waiting years/decades for it. By then the phone would be useless, and any juicy credentials already rotated. Best case scenario, you get some nudes.
On iOS, if the device is stolen, after a reset, you can't set the phone up (and it's been like that for over a decade).
Google says that's exactly what FRP does.
> Activation Lock is an Apple feature designed to prevent the unauthorized transfer or use of Apple devices. Built into Apple’s Find My system, it’s Apple’s implementation of factory reset protection, which manufacturers are legally required to include in order to sell smartphones in the US.
Given that it's been legally required since 2015 to sell smartphones, this must be something else.
[1] https://www.kandji.io/definitions/what-is-activation-lock
EDIT: Looking at the actual announcement.
> Factory reset upgrade prevents a reset by a thief. For some criminals, the goal is to quickly reset your stolen device and resell it. We’re making it more difficult to do that with an upgrade to Android’s factory reset protection. With this upgrade, if a thief forces a reset of the stolen device, they’re not able to set it up again without knowing your device or Google account credentials. This renders a stolen device unsellable, reducing incentives for phone theft.
> More steps for changing sensitive device settings to protect your data. Disabling Find My Device or extending screen timeout now requires your PIN, password or biometric authentication, adding an extra layer of security preventing criminals who got a hold of your device from keeping it unlocked or untrackable online.
> When enabled, our new enhanced authentication will require biometrics for accessing and changing critical Google account and device settings, like changing your PIN, disabling theft protection or accessing Passkeys, from an untrusted location.
AFAIK this has always been true for iOS, or true for as long as I can remember at least.
The rest is pretty neat & unique to Android though (e.g. a separate PIN-required space for certain apps like bank or health data, automatic protection on snatch, fast-lock using very low-overhead authentication mechanism).
Android and ios boot mechanism are pretty identical: secure boot -> unlock modem -> unlock user area. There are some differences in where in the CPU this happes and how it is protected but Pixel phones are pretty close to iPhone even if we look at such details.
The article says nothing about it but I hope people realize that there has to be a feature to securely wipe and reset the device.
The thief becomes so annoyed and frustrated that they end up returning the phone the next day.
Source: daily driving a Linux phone.
Has this not been the case in the past?
Instead the phones are stripped for parts and distributed globally.
The optimism in Apple threads is interesting. The pessimism in Google threads is interesting. Everyone thinks google sucks and wants Google to do more. Fans/ads/astroturfing make Apple out to be an angel.
I don't like either, its just interesting to watch how each company has different customer personalities and perceptions.
People here are so quick to be skeptical. Good.
The double standard is not good.
I have seen this and managed to do it to our own device from that manufacturer :')
1.iPhone detects I’m in an unusual location (I’m not, vpn). It just decided this all of a sudden, and I’ve used vpns in the past without issue.
2. Goes into lockdown mode
3. You need Face ID to disable lockdown mode
4. Face ID cannot be used in lockdown mode. Go back to step 3
Step wtf: We’re now trapped out.
5. I have to reset my phone. I forgot that I have eSIM, so resetting deletes my phone number too.
Step holy shit: Apple let me delete my entire sim card in about a one click warning lol.
——-
These people don’t dog food their own shit at all. Had to disable Face ID after an event like that.
VPN literally moves your phone to an unusual location, for all intents and purposes.
Apple needs to revisit that feature because that lockout could have happened at a critical time.
iOS Lockdown Mode does not usually constrain the method of unlocking the phone.
Tell me how you get out of lockdown mode.
The behavior being described sounds a bit like malware. If it happens again, the best option is to Force Restart (VolUp, VolDown, hold side button until the device reboots), which cannot be intercepted by any apps which might be trying to simulate iOS system prompts.
It's impossible to use the apple ID password or lockscreen password/PIN for this?
Maybe I’m just crazy because it seems like a ridiculous oversight.
Never heard of this behavior, but it's not associated with the Apple feature called "Lockdown Mode", which does not constrain use of secure enclaves for Touch ID or Face ID authentication, https://support.apple.com/en-us/105120
There's an option during reset to keep the eSIM, https://allthings.how/how-to-factory-reset-iphone-without-er...
I recently had a similar debacle with my Google account when I was travelling out of state and lost my phone. I needed to access my account quickly and fortunately knew my password and had added my partner's phone number as a 2fa method for exactly this kind of scenario.
Well when I went to log in Google took it upon themselves to disable that 2fa method, because it thought there were more secure options available. Except there weren't because I was far from home and all of my other devices!
I was pretty shocked that Google would change my security settings without any notice to me and confirmation on my part.
Quite frankly I need to make a stronger commitment to memorizing three passwords for life.
But to your point, yes I have critical apps where the main threat vector is being accidentally locked out.
I'm of the same mind that providers can be underrated risks, because it doesn't always cross people's minds that the provider could be that seemingly incompetent. It's certainly a potential situation to consider when dealing with companies that have poor support. And unfortunately, not all of them have great support or self-service tools like account recovery codes.
Thanks asshats! Hard nope on any "AI" here.
There have been multiple thefts in Chicago where "Police said the gunmen forced one of the victims to reset his phone password while threatening him with a pistol. They made another victim log into their banking apps." (https://cwbchicago.com/2024/05/chicago-bucktown-robbery-spre...)
Despite some popular fantasies, buying a handgun and shooting some targets (or live pigs?!?!) does not turn one into an action hero. That kind of escalation is likely to get the phone owner or another innocent person killed. It's a stupid risk, especially given that there are much better ways to protect your phone data.