Live data from Hacker News

Apple users are being locked out of their Apple IDs with no explanation

9to5mac.com

271–280 of 548 posts

Re: Apple users are being locked out of their Apple IDs with no explanation

#271

One frustrating thing about Apple is that if you try to get help, there isn’t really any way to do it. There isn’t any way to open a real support ticket that will be seen by an engineering team there. The store staff can only do basic things. And if you go to their forums, you will get bot-like responses telling you to follow some useless generic steps that do nothing for your specific problem, or weird replies justi…

Not trying to excuse their behavior, but my best friend and roommate was a part time phone support in college so I learned a few tricks… 1. They get a lot of dumb questions. If you want a “talk to an engineer” bug report, you really need to prove competency to the support staff. Obviously be nice because they’re not the source of your problems they’re just trying to do their job. 2. Chat staff aren’t able to do much,…

>4. If you make any reference to the TOS/Laws/etc they will mark your account as troubled and you will never get service again. You get legal canned responses only. They seem you not a valuable customer anymore. Don’t reference warranty law, definitely don’t threaten to sue, etc.

This is problematic. They'll be happy to parrot out whatever TOS section you violated if you get banned under TOS, but completely stonewall you if you bring it up?

In situations like these, I draw analogy to a hypothetical legal system that does the same thing. Imagine that you are defending yourself in a court of law, and you bring up a specific legal code in your defense. The court then brickwalls you and assumes you are a bad actor, and you get thrown in jail. I know the analogy isn't perfect, but none are.

Re: Apple users are being locked out of their Apple IDs with no explanation

#272
post #86

Earlier quoted context omitted.

This also spooked me. I’m a former security professional—there are few good reasons Apple should be doing this, and it smells of a targeted attack. If I had a zero-day exploit to steal your data, this is what it would look like. In the other hand, if Apple suddenly found out that a good chunk of encrypted volumes weren’t actually encrypted / the key was recoverable by an offline attacker, this would also explain the…

Yeah, I’m one of the people affected by this and it has happened to me on multiple machines on multiple updates and I have no idea what’s happening. Of course the keys do not actually work like for everyone else, which is even worse from a consumer UX standpoint (if I didn’t knew better I’d just throw away the old key…)

It's on my todo list to backup and wipe that machine at some point. It's a desktop machine, not a laptop, and I don't save the recovery key to my iCloud, so I don't see how this could be a security threat. But something smells fishy.

Re: Apple users are being locked out of their Apple IDs with no explanation

#273
post #230

Earlier quoted context omitted.

>IT "Security" is reaching new heights of being bullshit. You can't win, and asking people to buy multiple devices and keep them continuously in sync is a bit much You likely don't need to buy multiple devices. I log in from random countries/VPNs all the time and never have issues, but I do have 2fa enabled. If your account only has a password and there was a suspicious sign in attempt, it's reasonable for them to as…

I would agree with you if there actually was anything different in a suspicious way about those logins. There weren't. Same devices, same ISP, same browsers, not even an OS update in between. Just one day, few days ago, out of the blue, Facebook decided to pop up a conformation request, offering no alternative to confirming from "another device", and that's with them knowing (or at least having that information avail…

> and that's with them knowing (or at least having that information available) that there are no live sessions of that account (the whole browser in private mode thing).

Unless you explicitly logged out, they likely to see the opposite picture, i.e. numerous "valid" sessions (as opposed to active) that haven't been used for varying lengths of time because you logged in, but from their perspective, you never logged out. You just cleared your cookies which means the session is still "valid", even if it's inaccessible to you because the session cookies have been cleared from your device.

I don't know if they take any of this into account but as you've pointed out, assuming that the rightful owner of the account must have access to a different session is a huge assumption to make.

Re: Apple users are being locked out of their Apple IDs with no explanation

#274
post #238
post #226

Earlier quoted context omitted.

> It recognized the email and the pswd but then wanted verification from the original device! Did you have 2fa enabled by any chance? I have 2fa via TOTP on my accounts and while they offer using a signed in phone as a verification option, using TOTP was always an option, and I was never locked out of my account. >Despite having the original sim in the new phone. That would only help if google had some way of tying t…

Yes I had 2fa + OTP, however being a new phone they still ask you to tap on the old phone.

Are you talking about a prompt like this[1]? If so, there should be a poorly named "more options" or "don't have your phone?" link that gives you the option to enter your TOTP code instead.

[1] https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh...

Re: Apple users are being locked out of their Apple IDs with no explanation

#275
post #230

Earlier quoted context omitted.

>IT "Security" is reaching new heights of being bullshit. You can't win, and asking people to buy multiple devices and keep them continuously in sync is a bit much You likely don't need to buy multiple devices. I log in from random countries/VPNs all the time and never have issues, but I do have 2fa enabled. If your account only has a password and there was a suspicious sign in attempt, it's reasonable for them to as…

I would agree with you if there actually was anything different in a suspicious way about those logins. There weren't. Same devices, same ISP, same browsers, not even an OS update in between. Just one day, few days ago, out of the blue, Facebook decided to pop up a conformation request, offering no alternative to confirming from "another device", and that's with them knowing (or at least having that information avail…

My experience with Meta is it is just a PII fishing expedition masquerading as a security check.

I abandoned my facebook account when they asked for my driver's license scan, a few weeks later suddenly they didn't need it after all. My BIL recently wanted me to check sout omething he had setup on facebook and I found I could "login" by clicking one of the "what are people doing" spam emails they send. I've never used it on this PC before and have no idea what the password even is anymore. Super secure.

Re: Apple users are being locked out of their Apple IDs with no explanation

#276
post #8

Happened to me today. First got the message on my computer that my location was unknown and needed to enter a code from the phone. By the end of it, I had to reset my Apple password. No idea why it happened.

Didn't someone discover the unpachable NSA backdoors in the M series processors recently? Could be related.

Yeah, LOL. They're trying to memory hole that one.

Re: Apple users are being locked out of their Apple IDs with no explanation

#277
post #230

Earlier quoted context omitted.

>IT "Security" is reaching new heights of being bullshit. You can't win, and asking people to buy multiple devices and keep them continuously in sync is a bit much You likely don't need to buy multiple devices. I log in from random countries/VPNs all the time and never have issues, but I do have 2fa enabled. If your account only has a password and there was a suspicious sign in attempt, it's reasonable for them to as…

I would agree with you if there actually was anything different in a suspicious way about those logins. There weren't. Same devices, same ISP, same browsers, not even an OS update in between. Just one day, few days ago, out of the blue, Facebook decided to pop up a conformation request, offering no alternative to confirming from "another device", and that's with them knowing (or at least having that information avail…

That's the reason to setup 2fa, because otherwise monopolies can legally kick you. Well, they can kick you anyway, because they are monopolies.

Re: Apple users are being locked out of their Apple IDs with no explanation

#278
post #248

Earlier quoted context omitted.

And unlike, say, Samsung Ultrabooks or even Microsoft Surfaces, Macs last a really long time. My kids are using my 2011 MacBook Air and 2009 iMac and they still work, even the battery still kinda hangs in. They've had a few rough years 2016-2019 with the butterfly keyboards but I don't know many current manufacturers with products as solid long term.

In my experience laptops from the competition are as durable when you pick up the professionnal line instead of the general consumers one. That will be Lenovo thinkpads, Dell latitude, HP elitebook, etc.

I'll admit the support for my Dell was pretty good. They sent someone on-site to fix a known defect in their product line.

Re: Apple users are being locked out of their Apple IDs with no explanation

#279
It happened to me last night! At that moment, I froze, thinking that somehow my password had leaked and someone was trying to brute-force my MFA. At the time, I was at a restaurant celebrating my son's birthday and couldn't change the password on my phone... So I just ignored it and when I got home, I changed the password on my MacBook without any trouble.

This morning, as a precaution, I changed all my important passwords.

Good to know it wasn't just me.

Re: Apple users are being locked out of their Apple IDs with no explanation

#280
post #42

The thing that scared me recently was two updates that gave me new encryption keys. At first I trusted apple and wrote down the new key. But I became suspicious after the second update and checked online. It seems like it's happening to others, so I used the recommended command-line tool to verify my new encryption key and it didn't verify. Apparently it works after disabling and enabling encryption, but I'm just kee…

> updates that gave me new encryption keys On iOS or macOS? Was a consent dialog presented before the update was installed?

I'm not him, but for me it was MacOS. After the update was installed and the system rebooted it presented a dialog asking if I wanted to be able to use iCloud for recovery if I forgot my Mac login password. I let it set that up.

Afterwards I wondered if it was just storing the recovery key I already had in iCloud or if it had generated a new recovery key and my saved one was invalid.

I checked my recovery key ("sudo fdesetup validaterecovery") and it was no longer valid. A bit of Googling failed to turn up a way to get a copy of the recovery key that was in iCloud, and I decided I'd rather have a recovery key I store myself in case I need to recover when I cannot get online so I switched it back.

Switching back is easy. You just turn off FileVault, then turn it back on and choose to manage the new recovery key yourself.

Post reply on HN