Live data from Hacker News

Apple update looks like Czech mate for locked-out iPhone user

theregister.com

61–70 of 237 posts

Re: Apple update looks like Czech mate for locked-out iPhone user

#61
post #41
post #36

Earlier quoted context omitted.

I agree with you and don't really get what Apple gets from removing a valid Czech character, but how would you test if all existing passcodes remain inputable without knowing the passcodes of all iPhone users? The one way to do this that I could see is to include both the new keyboard and the old one and if someone fails to unlock with the new one auto report that to Apple (not the code, just that the unlock failed a…

Phased roll-out. You first introduce a version that still accepts all extant inputs but will actively warn that there are characters that will be removed in a future release. Then you wait. Then you roll out a version where the new functionality is flipped on by default, but where you still allow to explicitly toggle to the old one. Then you wait some more. And then - only then - you roll out a release where the old…

It might be tricky when user upgrades while jumping the “headups” version.

There should be migration taken into consideration that is kept to any previous version allowed to be upgraded from.

Re: Apple update looks like Czech mate for locked-out iPhone user

#62
post #27

Earlier quoted context omitted.

The "real mistake" is changing things that used to work.

You can use emojis as passwords, do you think that's a good idea? They work now, there's a good chance that they won't be the same forever. See what happened to the family emojis

In my password, I have the Collectivity of Saint Martin flag emoji and United States Minor Outlying Islands flag emoji next to the French flag emoji and US flag emoji. For good measure, also the flag of Chad next to the flag of Romania. I am sure it's not going to cause any issues.

Re: Apple update looks like Czech mate for locked-out iPhone user

#63

I think the biggest lesson here is to back up. The reason for losing access to the phone is amazingly dumb but it could have fallen down the stairs for basically the same effect. And do your could backups cross-provider. You never know what the "big players" are going to pull, and your lifetime customer value is less than the cost of a single support call.

This is exactly the reason why I keep all my shit on an SD card despite Google deliberately making the external storage experience as painful as possible: slow access, broken writes, failed unmounts, no filesystem repair. Literally every time I restart my phone I need to put the card to my PC and repair the filesystem. Also, same card works extremely well when plugged into PC via random cheap USB card reader.

On PCs you still have Linux that resists enshittification and you can pick your own hardware, but it's a really sad state of affairs that there is literally no meaningful mobile system that isn't actively hostile to the user.

Re: Apple update looks like Czech mate for locked-out iPhone user

#64
post #36
post #15

Earlier quoted context omitted.

[flagged]

I agree with you and don't really get what Apple gets from removing a valid Czech character, but how would you test if all existing passcodes remain inputable without knowing the passcodes of all iPhone users? The one way to do this that I could see is to include both the new keyboard and the old one and if someone fails to unlock with the new one auto report that to Apple (not the code, just that the unlock failed a…

If passwords are Unicode then you need a way to input arbitrary Unicode (e.g. a Character Map dialog).

Re: Apple update looks like Czech mate for locked-out iPhone user

#65
post #41
post #36

Earlier quoted context omitted.

I agree with you and don't really get what Apple gets from removing a valid Czech character, but how would you test if all existing passcodes remain inputable without knowing the passcodes of all iPhone users? The one way to do this that I could see is to include both the new keyboard and the old one and if someone fails to unlock with the new one auto report that to Apple (not the code, just that the unlock failed a…

Phased roll-out. You first introduce a version that still accepts all extant inputs but will actively warn that there are characters that will be removed in a future release. Then you wait. Then you roll out a version where the new functionality is flipped on by default, but where you still allow to explicitly toggle to the old one. Then you wait some more. And then - only then - you roll out a release where the old…

For other features, yes, but not this. Of course people will work around the warnings and then suddenly they're locked out of their whole phone?

Re: Apple update looks like Czech mate for locked-out iPhone user

#66
Majority of California based companies employee English only or English and Spanish speakers possibly with some Indian language as well. This leads to lots of problems when you are bilingual or bilingual in other languages such as German in French. Neither Apple nor Microsoft under this sort of language swapping well. Never mind rarer languages like Czech or Greek.

Re: Apple update looks like Czech mate for locked-out iPhone user

#68
post #55

Earlier quoted context omitted.

That's not really true in any country these days.

Regardless, why should a Vietnamese person be forced to restrict their password to ASCII? If you want to sell your devices in a country, the least you can do is to adopt to the local market. I get that Western cultural dominance makes this hard for some, but I think it should be the bare minimum.

because it is common sense

Re: Apple update looks like Czech mate for locked-out iPhone user

#69

The side of my brain that manages organizational changes wonders: how does Apple, a 50 year old company of tens of thousands of engineers and over a trillion USD market cap, manage to keep feature velocity high while not making more of these types of errors? The bug seems low likelihood but high severity for the few affected users. Other than simply never changing the login keyboard (or any of the keyboard code) or h…

They do. Companies mess things up all the time. But only a fraction of bugs get discovered and then reported, so it appears that their quality is ok.

I have recently discovered several bugs in different products created by different companies. And none has been reported so far in my research despite the products' popularity. I am not surprised, since those bugs require specific combination of conditions to be triggered, which most people have never run into, like in this article.

And I don't even blame them -- the engineers probably could never think of such use cases and don't have those workflows themselves. You'd have to really go out of your way to use obscure workflows to discover them.

Although in this case Apple dropped the ball by locking user out and not providing any alternatives.

Re: Apple update looks like Czech mate for locked-out iPhone user

#70
post #67

Seems like a front-end bug? So just access the API directly, or ask someone who knows how to do that? Plenty of iOS-focused reverse engineers out there.

How? The article states:

> For the same reason, plugging in an external keyboard is also a no-go since freshly updated iPhones are placed in what's known as a Before First Unlock state, which prevents wired accessories from working until the passcode is entered.

The user can't even enter their passcode, how do you expect them to perform code execution?

Post reply on HN