Live data from Hacker News

Apple's new iPhone security setting keeps thieves out of your digital accounts

theverge.com

31–40 of 74 posts

Re: Apple's new iPhone security setting keeps thieves out of your digital accounts

#31
post #30
post #26

Earlier quoted context omitted.

Well I kind of did circumvent this hurdle. I got an iPhone from a relative, the relative had forgotten the passcode and the Apple ID password. I did a factory reset of it via iTunes and of course when it started up and I started with the setup it said it was locked to * @* .com. I contacted Apple support and they said I needed proof of purchase for them to unlock it. I did not have any proof of purchase and neither d…

Makes sense. No theft deterrence is perfect, and your solution required a lot of investment of time and would not scale to a substantially large theft ring.

Eh, fake receipts are fairly easy to knock out.

When I managed a hospital's iPhone deployment I made it a point to always back up our receipts electronically because I have... had to make quite a few emails to AppleCare Security to release a few Activation Locked devices. It's not a terribly difficult process once you've done it a couple times, and I reasonably think I could release as many phones as I wanted these days with enough fake receipts.

Re: Apple's new iPhone security setting keeps thieves out of your digital accounts

#32
post #16

After a iPhone theft in Europe earlier this year, I don't quite trust Apple's assurances with regard to stolen iPhones. My phone was snatched from my hands in the street. I was able to wipe it via 'Find Devices' within a few minutes; I was able to track its location for the rest of the day, until I requested that my carrier irrevocably disable its network service. There was no evidence of any accesses of my informati…

According to my friend at Apple, sometimes fairly low level employees have access to the internal system which can be used to dissociate devices from AppleIDs. I wouldn't be surprised if some of them were compromised, as the pay is not great. What's more surprising is if they have no audit logs that would let them discover the compromised employee in these cases.

Yup. The argument for end-to-end.

Re: Apple's new iPhone security setting keeps thieves out of your digital accounts

#33

Earlier quoted context omitted.

> And it requires FaceID without a passcode ID fallback for certain categories of authentication. Judging by how often finger print readers get false negatives, this seems like an incredibly bad and frustrating idea.

Good thing Apple hasn’t used TouchID on phones in a long time then?

Yeah, except for ones they currently sell: https://www.apple.com/iphone-se/

Re: Apple's new iPhone security setting keeps thieves out of your digital accounts

#34
post #16

After a iPhone theft in Europe earlier this year, I don't quite trust Apple's assurances with regard to stolen iPhones. My phone was snatched from my hands in the street. I was able to wipe it via 'Find Devices' within a few minutes; I was able to track its location for the rest of the day, until I requested that my carrier irrevocably disable its network service. There was no evidence of any accesses of my informati…

According to my friend at Apple, sometimes fairly low level employees have access to the internal system which can be used to dissociate devices from AppleIDs. I wouldn't be surprised if some of them were compromised, as the pay is not great. What's more surprising is if they have no audit logs that would let them discover the compromised employee in these cases.

Or they do have such logs, but don’t feel like taking the reputation hit of telling you what happened.

Re: Apple's new iPhone security setting keeps thieves out of your digital accounts

#35
post #11
post #9

Finally. For current iOS versions, there is a workaround: use the “screentime” feature to disallow pincode changes. In screentime you can set a different code, so when anyone else can access your phone, they can’t change the code and lock you out of your phone.

Doesn't work. If you get the screen time password wrong a few times it will let you put the device passcode in.

When the screen time settings are protected by a separate Apple ID with a separate phone number registered for 2FA (obviously the SIM card or eSIM shouldn’t be on the same phone), this works. In this situation you need access to that second account’s SIM card (which can be locked with a PIN) to remove the lock.

Keep in mind afaict this is the situation with 2nd account having Rescue Code enabled. Things might be different if it’s not.

Email me for how to actually restrict yourself with iOS Screen Time (without 3rd party apps) in a way which you really-really can’t bypass when you feel down. Disclaimer: Not an Apple employee, but a former smartphone addict, ahem, I’m sorry, user.[1]

1: I believe all smartphone users are addicts as much as rest of their lives allows it, without the use of hard restrictions.

Re: Apple's new iPhone security setting keeps thieves out of your digital accounts

#36

It's a welcome change, especially the time-lock is something that I always thought about. SMS and EMail as 2FA are dead when someone can unlock your phone. Still though, why don't iPhone owners use face unlock? Is it not good?

If anyone is interested, I wrote a small utility to time-lock data, to be able to self-restrict myself in terms of Screen Time etc. passwords: https://github.com/aerbil313/timelock

Re: Apple's new iPhone security setting keeps thieves out of your digital accounts

#37
Well, like most things Apple, we of course just have to take Apple’s word on it. And if ever you find out someone was able to access it, as usual, you’ll be told - “it’s not possible and we won’t be able to share audit logs” or “blah..long password..blah”.

Just like the horseshit that once an iPhone is stolen it’s bricked for a thief. A friend’s iPhone got stolen and after a week it was removed from his device list in iCloud account. Apple Support refused to even acknowledge it and then didn’t respond anymore. They shut him off.

Re: Apple's new iPhone security setting keeps thieves out of your digital accounts

#39
post #31
post #30

Earlier quoted context omitted.

Makes sense. No theft deterrence is perfect, and your solution required a lot of investment of time and would not scale to a substantially large theft ring.

Eh, fake receipts are fairly easy to knock out. When I managed a hospital's iPhone deployment I made it a point to always back up our receipts electronically because I have... had to make quite a few emails to AppleCare Security to release a few Activation Locked devices. It's not a terribly difficult process once you've done it a couple times, and I reasonably think I could release as many phones as I wanted these d…

with an MDM and Apple's Device Enrollment Program you don't even need to worry about this anymore[0]

[0]: https://www.apple.com/mx/business-docs/DEP_Guide.pdf

Re: Apple's new iPhone security setting keeps thieves out of your digital accounts

#40
post #34

Earlier quoted context omitted.

According to my friend at Apple, sometimes fairly low level employees have access to the internal system which can be used to dissociate devices from AppleIDs. I wouldn't be surprised if some of them were compromised, as the pay is not great. What's more surprising is if they have no audit logs that would let them discover the compromised employee in these cases.

Or they do have such logs, but don’t feel like taking the reputation hit of telling you what happened.

I worked on these systems when I worked there. I can tell you they have audit logs, but they're restricted to certain groups within Apple to see them
Post reply on HN