Live data from Hacker News

Apple update looks like Czech mate for locked-out iPhone user

theregister.com

221–230 of 237 posts

Re: Apple update looks like Czech mate for locked-out iPhone user

#221
post #142
post #134

Earlier quoted context omitted.

There is a list of valid characters accepted for a passcode. That list was created, the characters debated, and a consensus reached by Apple engineers (I hope, for all our sakes. I don't want to imagine a world where this bare minimum level of engineering diligence wasn't done by a trillion dollar company) Just have an automated keyboard test for every new release to ensure those characters aren't broken.

Agreed, but just to be clear; I was asking how would you test that assuming you still wanted to remove a character that was previously present.

That's the thing: you don't! The charset for passwords should be always inputable even if no one is using it.

If you wanted to reduce the size of the charset, you'd basically create a transition plan, and ask everyone in the world with a passcode to set a new passcode and validate that against the new charset/rules. A company that can perfectly transition the world from x86 to ARM can surely manage that.

Re: Apple update looks like Czech mate for locked-out iPhone user

#222
post #217

Earlier quoted context omitted.

Sorry, I mean for this part of your post " but it is also true that iPhone theft is relatively rare.".

I would say that phone theft is relatively rare. I didn’t mean to single out iPhone really - AFAIK the major manufacturers of Android phones provide similar protection, and if feel the same about them removing it. To me the surprising claim would be that phone theft is common - I don’t think I know of anyone who’s had their phone stolen - but if you want stats, sticking with the UK, here’s the official statistics on…

In the US millions are stolen per year. Nobody knows the exact number because I suspect many may not even realize they've been stolen from and simply think they lost their phone somewhere. Thieves tend to target touristy areas where this is even more likely.

It's also going to make the targets even less likely to report the crime to police as well. 'Hi, I don't live in this country and I think my phone might have been stolen somewhere at some point in time over the past several hours, maybe.' is not even going to be investigated by the police, even if somebody does decide to file a report.

Come to think of it, this may all be yet another reason why thieves don't tend to abuse personal information. That sort of stuff is going to get reported and can be viably investigated by the police.

Re: Apple update looks like Czech mate for locked-out iPhone user

#223
post #217

Earlier quoted context omitted.

I would say that phone theft is relatively rare. I didn’t mean to single out iPhone really - AFAIK the major manufacturers of Android phones provide similar protection, and if feel the same about them removing it. To me the surprising claim would be that phone theft is common - I don’t think I know of anyone who’s had their phone stolen - but if you want stats, sticking with the UK, here’s the official statistics on…

In the US millions are stolen per year. Nobody knows the exact number because I suspect many may not even realize they've been stolen from and simply think they lost their phone somewhere. Thieves tend to target touristy areas where this is even more likely. It's also going to make the targets even less likely to report the crime to police as well. 'Hi, I don't live in this country and I think my phone might have bee…

[dead]

Re: Apple update looks like Czech mate for locked-out iPhone user

#224
post #203

Since the beginning, iPhone keyboard is wrong in entering a character first, háček second. It has been the other way around on typewriters and then computers for decades. Then some smart guy at apple thought he knows better. One of those never-fixed-bugs.

> It has been the other way around on typewriters and then computers for decades. On a typewriter, I would expect one to type the latin character, hit backspace, and then add the mark? Or if using a typewriter without the necessary mark, just type the latin characters, then add the marks with a pen to the full sheet.

Diacritics usually did not advance paper on typewriters, hence their name "dead keys".

[0] https://en.wikipedia.org/wiki/Dead_key

Re: Apple update looks like Czech mate for locked-out iPhone user

#225

Earlier quoted context omitted.

If the data you care about is encrypted with a token locked behind your passcode input, and it's not theoretically brute forceable by being a 4 character numeric only thing, then not easily, no. Could they produce an update that is bespoke and stops encrypting the next time you unlock, push it to your phone before seizing it, wait for some phone home to tell them it worked, and then grab it? Perhaps, but the barrier…

> Perhaps, but the barrier to making Apple do that is much higher than "give us the key you already have", and only works if it's a long planned thing, not a "we got this random phone, unlock it for us". The attack situation would be e.g. at the airport security check, where you have to part with your device for a moment. That's a common way for law enforcement and intelligence to get a backdoor onto a device. Happen…

Sure, but that'd be a waste.

Part of the reason e.g. Cellebrite is obsessive about not telling people many specifics about their product capabilities outside of NDA is that Apple is quite serious about trying to fix these things, and "we can crack every iPhone before the 14" probably tells them a fair bit about what might have a flaw.

Tools like that lose a lot of value if anyone paying enough attention can infer they exist, even indirectly, like if all the TSA agents you know suddenly switch to Android phones, or some of them tell you not to bring iPhones through security and won't tell you why, or a thousand other vectors for rumors to start.

All it takes is enough rumors for people to say it's enough to not trust any more, and suddenly you've lost a lot of the value of a secret information source.

So if you have a tool like that, where most people don't think it's readily available, the way you probably use it is very sparingly, to keep it that way.

Re: Apple update looks like Czech mate for locked-out iPhone user

#226

I think the biggest lesson here is to back up. The reason for losing access to the phone is amazingly dumb but it could have fallen down the stairs for basically the same effect. And do your could backups cross-provider. You never know what the "big players" are going to pull, and your lifetime customer value is less than the cost of a single support call.

> You never know what the "big players" are going to pull,

When one pays 1000 Euros for a product, one expects a basic level of quality.

Re: Apple update looks like Czech mate for locked-out iPhone user

#227

Earlier quoted context omitted.

This is exactly the reason why I keep all my shit on an SD card despite Google deliberately making the external storage experience as painful as possible: slow access, broken writes, failed unmounts, no filesystem repair. Literally every time I restart my phone I need to put the card to my PC and repair the filesystem. Also, same card works extremely well when plugged into PC via random cheap USB card reader. On PCs…

GNU/Linux exists on mobile, too. Sent from my Librem 5.

Tell me more about this

Re: Apple update looks like Czech mate for locked-out iPhone user

#230

Earlier quoted context omitted.

> Perhaps, but the barrier to making Apple do that is much higher than "give us the key you already have", and only works if it's a long planned thing, not a "we got this random phone, unlock it for us". The attack situation would be e.g. at the airport security check, where you have to part with your device for a moment. That's a common way for law enforcement and intelligence to get a backdoor onto a device. Happen…

Sure, but that'd be a waste. Part of the reason e.g. Cellebrite is obsessive about not telling people many specifics about their product capabilities outside of NDA is that Apple is quite serious about trying to fix these things, and "we can crack every iPhone before the 14" probably tells them a fair bit about what might have a flaw. Tools like that lose a lot of value if anyone paying enough attention can infer the…

There is a difference in targeted software supply attacks vs. weakening encryption for everyone by introducing a master key. Apple would be required to cooperate by US law, it may never become public either. But as I said, Apple doesn't have to know, or "know". This feature inherently compromises security. Contrary to device encryption, OS update security depends on a single key held by Apple (rather several devOps guys...), which could be stolen, leaked or shared.

Would you bet, the NSA can't sign iOS updates?

> So if you have a tool like that, where most people don't think it's readily available, the way you probably use it is very sparingly, to keep it that way.

Of course. This is reserved for targeted attacks against journalists and other enemies of the state.

> All it takes is enough rumors for people to say it's enough to not trust any more, and suddenly you've lost a lot of the value of a secret information source.

As if Apple users would care...

https://www.apple.com/legal/transparency/us.html

https://gizmodo.com/apple-iphone-privacy-analytics-class-act...

https://thenextweb.com/news/apple-apps-on-big-sur-bypass-fir...

https://www.theguardian.com/us-news/2025/oct/23/trump-white-...

https://www.404media.co/iceblock-owner-after-apple-removes-a...

https://www.404media.co/apple-gave-governments-data-on-thous...

https://www.404media.co/fbi-extracts-suspects-deleted-signal...

Post reply on HN