Live data from Hacker News

Apple has locked my Apple ID, and I have no recourse. A plea for help

hey.paris

311–320 of 1001 posts

Re: Apple has locked my Apple ID, and I have no recourse. A plea for help

#311
post #195

I treat apple ID and google ID like throwaway accounts. I would never trust anything valuable to either. The problem is that it is very hard for "usual people" to do that. I will also never have an electronic ID. We (Switzerland) were dumb enough to vote yes for it but we are giving away our freedoms eventually. We need regulations to ensure vendor cannot lock in users and cannot threaten them. Everything should work…

> I will also never have an electronic ID. We (Switzerland) were dumb enough to vote yes for it but we are giving away our freedoms eventually. What's the link with the rest though? Your government already knows you, whether your id has your information printed with ink or stored on a chip. Belgium has had electronic id for decades now and I fail to see how it has taken away any freedom, but it has enabled people to…

I think the fear many people have is that digital ID will be required for non-government services as well. I can easily see that happen in the USA and Switzerland is the kind of weird that may also let that sort of thing happen.

With things like age verification becoming mandatory just about everywhere and actual privacy-conscious digital age verification being very difficult, there's definitely a risk towards abuse and badly designed authorization mechanisms (although the EU's open source backend and frontends should make it easy for other countries if they do actually care about privacy).

Re: Apple has locked my Apple ID, and I have no recourse. A plea for help

#312
post #279

Here is how the gift card scam works (in Australia) [Quote] Yes they do still get activated at the checkout. But when you go to redeem, the code is missing the last digit or two so it doesn't work. People take the unactivated gift card, tamper with it to get inside carefully so it's not detectable, scratch and get the code, remove the last digit or two, replace the scratch off layer, put the unactivated gift card bac…

This is why Target doesn't have the activation code on their gift cards anymore, you have to have it added with a sticker when it is being activated now, and then scratch it off.

Re: Apple has locked my Apple ID, and I have no recourse. A plea for help

#313

Earlier quoted context omitted.

> The laws against that are very strict, incentivizing companies to overshoot and block false positives. Yes, in many countries they are, but I don't think the laws are dictating Apple to completely turn off the accounts, but instead dictate that Apple should take measures against it. They could disable those gift card features + Apple wallet/pay if they suspect fraud, and if no one complains within a month, then dis…

All this costs money for little return of invest. As long as the collateral damage is below a threshold that causes reputational damage, there is no business incentive to solve this.

Yes, I agree, the companies don't actually care about consumers, only what's cheaper for them. But this is a choice companies do, not because laws somehow require them to block the entire account vs individual features. I was just adding that because the original comment made it seem like the companies are somehow forced to act like they do because of laws, but it isn't, it's an intentional cost-measured choice they make by themselves.

Re: Apple has locked my Apple ID, and I have no recourse. A plea for help

#314

Earlier quoted context omitted.

I don’t mean to defend this, but I know from experience that gift cards are frequently used for money laundring. The laws against that are very strict, incentivizing companies to overshoot and block false positives. At the same time, AML solutions tend to be a closely guarded black box which simply tells you to block a customer, finding out why is pretty difficult. To add more to the problem, some anti money Landry s…

> The laws against that are very strict, incentivizing companies to overshoot and block false positives. Yes, in many countries they are, but I don't think the laws are dictating Apple to completely turn off the accounts, but instead dictate that Apple should take measures against it. They could disable those gift card features + Apple wallet/pay if they suspect fraud, and if no one complains within a month, then dis…

> I don't think the laws are dictating Apple to completely turn off the accounts, but instead dictate that Apple should take measures against it.

You misunderstand the nature of financial regulation. The laws on things like money laundering are intentionally vague, they say things like "Apple should take measures against it". And financial regulators will not come out and say (especially in writing) that you MUST do any particular thing (like ban customers entirely on suspicion).

What they WILL do is ask probing questions, frown a lot, and make suggestions. Which the company had better take seriously. Because the financial regulators have the ability to simply close down your business, and if you cross enough of the unclear lines they will do so.

Re: Apple has locked my Apple ID, and I have no recourse. A plea for help

#315
post #289

Earlier quoted context omitted.

- Don't use Apple. Or Google.

If it was be that simple. In that case I would have to go to the bank for every transaction/payment I want to initiate online. Banking app doesn't work for jailbroken devices. Using PC to access banks website works, but transactions still require 2FA and they don't support any other 2FA flow except the one in the app.

You don't have to go to the bank for every transaction, you can just go there once to close out your account and open one somewhere that doesn't require that.

Re: Apple has locked my Apple ID, and I have no recourse. A plea for help

#316

Earlier quoted context omitted.

Not only local copies but also at least own and use one device where you have your important data that is not on the same OS ecosystem as the other device(s) - also helps with things like 2FA, password manager, etc., if shit has hit the ceiling fan on the other device. In addition, I always suggest people to: - Not use big tech's cloud services - ever - But if you must, do not use many cloud services from just one pr…

How much free time do you think the average person has to learn and set all this up? “You’re giving these companies your data and then dare to be angry when you lose it? Just get a degree in computer science and host it yourself!!1! I am very smart”

I think you’re taking the message the wrong way.

Those are the steps the commenter suggests you take to use these services safely.

It’s not that these steps are reasonable.

Re: Apple has locked my Apple ID, and I have no recourse. A plea for help

#317
post #298

I imagine that every "should have known better" respondent on this thread has internalized their abuse. Why in the world do we let tech companies adjudicate our service relations?

It's more of an 'is' thing rather than an 'ought'

Re: Apple has locked my Apple ID, and I have no recourse. A plea for help

#319
While I understand the attraction of doing so, I’m not sure I like the implication in the post that the reason this needs to be reviewed is because of how loyal of a customer this person is, or the fact that they have written books on developing for Apple devices.

Re: Apple has locked my Apple ID, and I have no recourse. A plea for help

#320

I'm not the biggest advocate of the EU DMA, but account and device access is one item we should actually be regulating very heavily, where potential penalties for (suspected) abuse or incompliance must be much more granular than full-on account bans. It's hard to believe EU governments are actually considering mandating iOS and Android as gateways to access government services. It's a level of ignorance that's unfath…

> It's hard to believe EU governments are actually considering mandating iOS and Android as gateways to access government services. It's a level of ignorance that's unfathomable.

There's a good reason behind this approach, even though I don't think the benefits outweigh the downsides. These apps are supposed to be the phone equivalent of the NFC chips inside of passports and ID cards, which have all kinds of encryption and verification inside of them. They have to be protected against malicious data extraction, manipulation, and other fakery.

Phones do have the ability to do that, even free ones, and even regular desktops and laptops. How they do it kind of depends on the implementation (whether you call it a "secure element", a "TPM", or a "trusted execution environment"), but they all come down to "hardware proof shows that this digital signature is not extractable or alterable". The data isn't supposed to be something you can access, like a password, but something you can only do signed reads from, like the physical ID chips.

In iOS, that part runs entirely on dedicated hardware which will refuse to run non-Apple code, which is probably the best approach. On Android, there are more options and many phones run a software version of that concept in a dedicated separate virtual machine to save cost on physical hardware. The security of that virtual mechanism relies squarely on the early boot process having been verified not to be altered by malware. That's what the Google verification library is for in this case.

This approach can work just as well on other hardware with dedicated TPMs (although a lot of free software enthusiasts will tell you those are evil contraptions designed by Microsoft to turn your unborn children into little versions of Clippy) or dedicated encryption modules. However, you'd need a common enough, accessible API for those to function. That's actually quite easy on Windows and macOS, but Linux TPM support is rather woeful at the moment, especially with how uncommon things like secure boot (even self-signed secure boot) are.

In practice, nobody is going to buy a special sort of yubikey to log into their government's tax portal. Dragging people into basic multi-factor security has been a challenge that lasted decades.

However, pretty much all citizens already have phones capable of top-of-the-line security verification. Developing a free app is a lot easier than implementing cross-platform HSM support for a novel authentication mechanism.

All of this comes at the cost of having to run vendor-approved software. That's a huge problem for a lot of HN visitors, but those people form a sliver of a fraction of the population. I'm willing to bet the EU's digital access is inhibited more by the amount of old people without cell phones than the number of people who care about free software.

I personally feel like outsourcing this kind of trust to closed source implementations of vendor blobs is a terrible idea, but it's hard to find an accessible alternative that provides even the lax security properties those blobs provide.

Something I do find lacking in discussions about these technologies is how much the EU is relying specifically on American vendors here. America has been shown to be an unreliable ally that will gladly force the EU's hand with whatever mechanism comes to mind for extremely arbitrary reasons. There is a distinct lack of European alternatives when it comes to accessible secure computing, and I'd rather see the EU invest in local alternatives than go all-in on the security promises from Apple and Google.

Post reply on HN