"according to law-enforcement officials" - they are clearly not experts in tech and are unaware of the crucial difference between Apple and Android in this scenario.
The most significant difference is that Google explicitly stated their system includes "reasonable time-limited protections against hijackers changing passwords or recovery factors" - but only if users have properly configured recovery options beforehand.
According to Google's official statement: "Google Account Recovery flows also have reasonable time-limited protections against hijackers changing passwords or recovery factors set up by the legitimate users - provided users have set up a recovery phone and/or recovery email."
In contrast, the WSJ article describes how on iPhone:
- Thieves could immediately change the Apple ID password using just the device passcode
- there was no waiting period or time-limited protection mentioned
- Once changed, victims were instantly locked out with no grace period
- Apple's Recovery Key feature could be enabled by thieves to permanently lock victims out
Android users on the other hand could proactively:
- Set up recovery email and phone numbers that would be retained for 7 days after changes
- Enable Google's Advanced Protection Program, which specifically blocks PIN-based password resets entirely
- Configure multiple recovery options that created additional barriers
Apple users had limited options, the article mentions security keys could be added, but testing showed "security keys didn't prevent account changes using only the passcode, and the passcode could even be used to remove security keys from the account". This made Android's vulnerability more preventable and recoverable for users who had properly configured their security settings in advance, whereas Apple users were stuck and vulnerable to the pin-hijack until fixed, because iOS did not offer any similar protections such as time-based safeguards.