Live data from Hacker News

Apple's new iPhone security setting keeps thieves out of your digital accounts

theverge.com

1–10 of 74 posts

Re: Apple's new iPhone security setting keeps thieves out of your digital accounts

#2
Related article and thread from Feb: https://www.wsj.com/articles/apple-iphone-security-theft-pas...

https://news.ycombinator.com/item?id=34936015

Now it seems like thieves would not be able to immediately unlink a phone from Find My if they have the passcode, because of the security delay

Re: Apple's new iPhone security setting keeps thieves out of your digital accounts

#3
This is a good development. Making phone theft less appealing is a good thing, and locking away precious personal data and accounts if it does still happen is great. It’s an ordeal to face against thieves to change any login information they could find looking through the data on a phone. I hope this will be secure and work as advertised.

Re: Apple's new iPhone security setting keeps thieves out of your digital accounts

#4
This is basically a branding and broader application of the existing Keychain access control presence requirement, whose documentation specifically calls out these scenarios. All finance apps should be using presence verification post login and preceding an outgoing transaction or possible takeover action.

Re: Apple's new iPhone security setting keeps thieves out of your digital accounts

#5
Great news, I was pretty shocked that the original flaw still existed. Getting your phone stolen is annoying but the worst case is you buy a new phone, but thieves being able to take over your digital life is potentially catastrophic.

Hopefully this works well, I assume third party apps such as banking will be able to opt in to the additional protection (not sure if this is strictly required actually, I checked my banking app and if Face ID fails you have to enter the banking PIN, you can’t enter the device PIN).

Is there a way to lock individual apps so they require Face ID even if they weren’t designed to? A smart thief having access to the Gmail app for example, if the phone was unlocked when stolen, could wreak havoc.

Re: Apple's new iPhone security setting keeps thieves out of your digital accounts

#6
post #4

This is basically a branding and broader application of the existing Keychain access control presence requirement, whose documentation specifically calls out these scenarios. All finance apps should be using presence verification post login and preceding an outgoing transaction or possible takeover action.

[deleted]

Re: Apple's new iPhone security setting keeps thieves out of your digital accounts

#8

It's a welcome change, especially the time-lock is something that I always thought about. SMS and EMail as 2FA are dead when someone can unlock your phone. Still though, why don't iPhone owners use face unlock? Is it not good?

masks? sunglasses? etc

But also the phone locks back to requiring a passcode with enough failed attempts, so presumably people stealing them know how to induce recognition failure.

Re: Apple's new iPhone security setting keeps thieves out of your digital accounts

#9
Finally. For current iOS versions, there is a workaround: use the “screentime” feature to disallow pincode changes.

In screentime you can set a different code, so when anyone else can access your phone, they can’t change the code and lock you out of your phone.

Re: Apple's new iPhone security setting keeps thieves out of your digital accounts

#10

It's a welcome change, especially the time-lock is something that I always thought about. SMS and EMail as 2FA are dead when someone can unlock your phone. Still though, why don't iPhone owners use face unlock? Is it not good?

They do use it but you can force passcode requirement by holding down the power button until 'slide to power off' appears. From daringfireball: '(One way the scam would run: Chat up the victim in a bar, and offer to use the target’s phone to snap a photo of the victim and their friends. Surreptitiously lock the phone out of Face ID when handing it back to the victim. Then, when next the victim wants to do anything on their phone, they need to enter their passcode. Either the thief or a partner in a team gleans the passcode. Then they steal the phone, knowing the device passcode.)'
Post reply on HN