Live data from Hacker News

Ask HN: Why does Apple want me to expose my iPhone password to repair my screen?

news.ycombinator.com

41–50 of 77 posts

Re: Ask HN: Why does Apple want me to expose my iPhone password to repair my screen?

#41

One of the main reasons I pay for AppleCare is to use the Express Replacement Service[0]. They will overnight a new iPhone to you while you keep the old one, then you can transfer your data to the new one and safely wipe the old one before mailing it back. This avoids a lot of hassle with the store’s repair team and is the same price as most repairs. (The front glass only repair is slightly cheaper than ERS but would…

FYI, if you do this option they’ll likely still ask you to disable find my iirc

Re: Ask HN: Why does Apple want me to expose my iPhone password to repair my screen?

#42

One of the main reasons I pay for AppleCare is to use the Express Replacement Service[0]. They will overnight a new iPhone to you while you keep the old one, then you can transfer your data to the new one and safely wipe the old one before mailing it back. This avoids a lot of hassle with the store’s repair team and is the same price as most repairs. (The front glass only repair is slightly cheaper than ERS but would…

How would the transfer work with a completely dead screen on the old phone?

[deleted]

Re: Ask HN: Why does Apple want me to expose my iPhone password to repair my screen?

#44

Earlier quoted context omitted.

That cannot work for all the payment cards etc you have right? That data never leaves the secure chip on your phone, I hope?

The iPhone transfers card details to Apple Watch automatically, so no, that data is not stored in a non-exportable fashion. The data-storage capacity of things like a TPM or Apple's secure enclave is absolutely tiny (e.g. the TPM specification[1] only requires ~7KiB) - which makes sense considering it only needs to store a handful of encryption keys and other stored-secrets. [1] https://trustedcomputinggroup.org/reso…

Payment cards aren’t transferred to Apple Watch automatically. The enrollment process occurs again and the watch receives its own unique card number.

The iPhone does allow you to initiate the enrollment for your Apple Watch without entering the card number again, you just need to re-enter the CVV.

Re: Ask HN: Why does Apple want me to expose my iPhone password to repair my screen?

#45

Earlier quoted context omitted.

That cannot work for all the payment cards etc you have right? That data never leaves the secure chip on your phone, I hope?

The iPhone transfers card details to Apple Watch automatically, so no, that data is not stored in a non-exportable fashion. The data-storage capacity of things like a TPM or Apple's secure enclave is absolutely tiny (e.g. the TPM specification[1] only requires ~7KiB) - which makes sense considering it only needs to store a handful of encryption keys and other stored-secrets. [1] https://trustedcomputinggroup.org/reso…

The actual TPM storage may be tiny, but you can use it to encrypt and decrypt arbitrary amounts of data. All the TPM needs to hold is the key.

That you can actively ask it to transfer data to the Watch or Cloud doesn't automatically mean that it is not using the TPM for storing that data at rest, requiring the phone to be unlocked for any such transfer.

Re: Ask HN: Why does Apple want me to expose my iPhone password to repair my screen?

#46

You are needlessly paranoid. It's common to ask for the password and I don't think they'd touch your private files. After the screen is fixed they'd need to do QA that it works correctly. Some things you just have to trust in life, too much paranoia won't lead you to good places. Trust me, I've been there.

It's common to normalisation or deviance is how you blow up space planes.

Re: Ask HN: Why does Apple want me to expose my iPhone password to repair my screen?

#47

Earlier quoted context omitted.

That cannot work for all the payment cards etc you have right? That data never leaves the secure chip on your phone, I hope?

The iPhone transfers card details to Apple Watch automatically, so no, that data is not stored in a non-exportable fashion. The data-storage capacity of things like a TPM or Apple's secure enclave is absolutely tiny (e.g. the TPM specification[1] only requires ~7KiB) - which makes sense considering it only needs to store a handful of encryption keys and other stored-secrets. [1] https://trustedcomputinggroup.org/reso…

Cards on an Apple Watch are provisioned separately from those on a paired phone. They have different card numbers, and are provisioned as two separate passes, each with its own fraud control. Once a pass has been added to one Apple device, a reference token to that physical card is added to your iCloud account, which can be used to initiate the provisioning flow on other devices. Usually that token requires at least a CVV to prove possession, but may also require bank-issued OTP or phone call verification as well.

The Secure Enclave is small, but supported between 8 and 16 cards, depending on hardware. As of iOS 17, the atorage is based on actual space available and can store upwards of 30 cards on an iPhone 14.

Re: Ask HN: Why does Apple want me to expose my iPhone password to repair my screen?

#49

FWIW, I've had the unofficial repair shops try to insist I needed to tell them my PIN ahead of a screen repair so they could "test everything works." I'm sure plenty fall for it. All those nudes don't leak themselves. Doesn't answer your question, but be careful that your distrust doesn't lead you into worse trouble.

> All those nudes don't leak themselves.

No need to hack devices, anymore: https://www.cnn.com/2023/09/20/europe/spain-deepfake-images-...

Re: Ask HN: Why does Apple want me to expose my iPhone password to repair my screen?

#50

Samsung phones have a feature for this specific scenario. Maintenance Mode creates a temporary user account, allowing a service technician to test all of the functionality of your device without exposing any user data. Given Apple's stated commitment to privacy and security, I'm surprised that there's no equivalent feature. https://www.samsung.com/uk/support/mobile-devices/what-is-ma...

It is double-edged sword. Adds new attack vector to compromise the whole phone. Is the user data encrypted when the maintenance mode is on? Can thiefs access it and make phone usable?
Post reply on HN