Live data from Hacker News

Apple update looks like Czech mate for locked-out iPhone user

theregister.com

201–210 of 237 posts

Re: Apple update looks like Czech mate for locked-out iPhone user

#201

Earlier quoted context omitted.

You say locking oneself out, but I decline to consider any situation where a password can be set but not later entered as one where the user bears even a modicum of fault.

I remember a website that silently removed everything but the first 8 characters from the "password" field upon registration but somehow didn't do the same on the login page. It took me several hours and several password resets to actually log in after registration, since for some reason the trimming happened client-side and only when typing the password manually (and I was pasting my password from a password manager…

In a similar vein, I remember encountering a site where the frontend enforced basic complexity requirements ala “use at least one number and one symbol” but the system would silently drop all non-alphanumerics when it saved (presumably in some kind of failed conversion on the way into the backend DB). So setting a password like “foo_bar4!” would become “foobar4” which was surprising. What blew my mind though was when I figured out the stripped password worked to log in, which was how I eventually figured out what was happening, escaped the reset flow, and generated a compliant password.

Re: Apple update looks like Czech mate for locked-out iPhone user

#202
post #197

Earlier quoted context omitted.

iPhones are currently the primary target of thieves by an overwhelmingly wide margin. There are many ways to wipe them and its an industry in its own right. One of the most common, as always, is simple social engineering. They contact the victim posing as Apple, convince them to reveal their credentials in this way or that, wipe the device and away they go. If that fails they're stripped down and sold for parts, whic…

That’s all true, but it is also true that iPhone theft is relatively rare. My assertion is that there would be way, way more theft if you could just downgrade and wipe.

Is it? Do you have any data to back this up?

Because a quick search for UK statistic shows that even though iPhones are minority of phones over here they are the overwhelmingly majority of all phone theft:

https://www.loveitcoverit.com/news/changing-world/mobile-pho...

"In terms of smartphone models, the data also indicates who might be most at risk. Looking at the entirety of the UK, 68.6% of stolen phones are iPhones."

Re: Apple update looks like Czech mate for locked-out iPhone user

#203

Since the beginning, iPhone keyboard is wrong in entering a character first, háček second. It has been the other way around on typewriters and then computers for decades. Then some smart guy at apple thought he knows better. One of those never-fixed-bugs.

> It has been the other way around on typewriters and then computers for decades.

On a typewriter, I would expect one to type the latin character, hit backspace, and then add the mark? Or if using a typewriter without the necessary mark, just type the latin characters, then add the marks with a pen to the full sheet.

Re: Apple update looks like Czech mate for locked-out iPhone user

#204
post #138

Earlier quoted context omitted.

Weirdly I care more about my rights as the owner of the device than the rights of a theoretical attacker.

I’m all for a system that allows you to wipe the device to do a downgrade or upgrade (just like any PC with an unset bios password allows) but the idea that it’s a good design for someone without my OS password to be able to downgrade my OS or perform any operation on my OS is insane. What’s even the point of setting a password if anyone can manipulate the system without entering it in? The entire iPhone OS is on an…

Yeah I agree that a downgrade that always results in a full wipe is a good compromise.

Re: Apple update looks like Czech mate for locked-out iPhone user

#205

Earlier quoted context omitted.

Doesn't this mean that no matter how securely your phone is locked, Apple (and probably the three-letter agencies) can always unlock it by installing an appropriate update?

If the data you care about is encrypted with a token locked behind your passcode input, and it's not theoretically brute forceable by being a 4 character numeric only thing, then not easily, no. Could they produce an update that is bespoke and stops encrypting the next time you unlock, push it to your phone before seizing it, wait for some phone home to tell them it worked, and then grab it? Perhaps, but the barrier…

> Perhaps, but the barrier to making Apple do that is much higher than "give us the key you already have", and only works if it's a long planned thing, not a "we got this random phone, unlock it for us".

The attack situation would be e.g. at the airport security check, where you have to part with your device for a moment. That's a common way for law enforcement and intelligence to get a backdoor onto a device. Happens all the time. You wouldn't be able to attribute it to Apple collaborating with agencies or them using some zero-day exploit. For starters, you likely wouldn't be aware of the attack at all. If you came home to a shut-down phone, would you send your 1000$ device to some security researcher thinking it's conceivably compromised, or just connect it to a charger?

If you can manually install anything on a locked phone, that's increasing the attack surface, significantly. You wouldn't have to get around the individual key to unlock the device, but mess with the code verification process. The latter is an attractive target, since any exploit or leaked/stolen/shared key will be potentially usable on many devices.

Re: Apple update looks like Czech mate for locked-out iPhone user

#206
post #91

Earlier quoted context omitted.

So could they finally fix their quotations marks in Czech? Probably no, they never cared, so why should they start caring now.

No but they might be able to fix authentication problems, which is what this is.

Guess what, they’ll do nothing. If Czech market is small enough for them to fix quotation marks, they’re not fixing Czech keyboard.

OTOH, if an American will whine enough on Internet, they may fix it for him. Maybe some other American should use standard Czech quotes as password to get it fixed also.

Re: Apple update looks like Czech mate for locked-out iPhone user

#207
post #167

Earlier quoted context omitted.

Doesn't this mean that no matter how securely your phone is locked, Apple (and probably the three-letter agencies) can always unlock it by installing an appropriate update?

Not necessarily. If the secret is protected in the secure element against something only you can provide (physical presence of RFID, password, biometric etc) then it is ok. BUT you must trust the entire Apple trusted chain to protect you. That is a rather big BUT.

> If the secret is protected in the secure element against something only you can provide (physical presence of RFID, password, biometric etc) then it is ok.

But we already established unlocking is not possible, so going with the argument it's implied there is a side-channel. Nothing, but a secret in your brain is something only you can (willingly) provide. Especially not biometric data, which you distribute freely at any moment. RFID can be relayed, see carjacking.

If you can side-step the password, to potentially install malware/backdoor, that's inherently compromising security.

Re: Apple update looks like Czech mate for locked-out iPhone user

#208

I think the biggest lesson here is to back up. The reason for losing access to the phone is amazingly dumb but it could have fallen down the stairs for basically the same effect. And do your could backups cross-provider. You never know what the "big players" are going to pull, and your lifetime customer value is less than the cost of a single support call.

> your lifetime customer value is less than the cost of a single support call

yes that is the pattern, pioneered by Google here in California

Re: Apple update looks like Czech mate for locked-out iPhone user

#209
post #197

Earlier quoted context omitted.

iPhones are currently the primary target of thieves by an overwhelmingly wide margin. There are many ways to wipe them and its an industry in its own right. One of the most common, as always, is simple social engineering. They contact the victim posing as Apple, convince them to reveal their credentials in this way or that, wipe the device and away they go. If that fails they're stripped down and sold for parts, whic…

That’s all true, but it is also true that iPhone theft is relatively rare. My assertion is that there would be way, way more theft if you could just downgrade and wipe.

It’s rare in the US and very common in London

Re: Apple update looks like Czech mate for locked-out iPhone user

#210
post #57

Earlier quoted context omitted.

Probably the only hope is jailbreaking.

Jailbreaking a locked, inaccessible iphone?

Keep in mind that everyone else is usually unaware (by design) of what all the intelligence agencies can do, but I doubt they would help in this scenario even if they could.

On the other hand, if this happens to a far more important person...

Post reply on HN