Live data from Hacker News

Thieves took their iPhones. Apple won't give their digital lives back

washingtonpost.com

31–40 of 117 posts

Re: Thieves took their iPhones. Apple won't give their digital lives back

#31
post #7

Earlier quoted context omitted.

A security model that the user does not understand and contains traps is not a good security model.

OK, but what model would you suggest? Apple has no adequate way to actually verify who anybody is without (a) forcing them to physically visit one of a small number of offices (it can't be every store), and (b) probably charging a significant fee to cover the cost of doing real verification. And even that demands assuming that the identifying information on the account is right.

I have a hard time believing this when they also have Apple Cash and Apple Pay.

Even with their strong privacy fundamentals they know more about their account holders than any single business should.

Re: Thieves took their iPhones. Apple won't give their digital lives back

#32
Apple’s encryption, is designed with end-to-end encryption for many types of data.

Some facts:

    Only the user's devices hold the keys to decrypt the data.

    Apple cannot decrypt it, even if served a subpoena.

Apple chose privacy over convenience. Sue all you want, you're going to lose.

Re: Thieves took their iPhones. Apple won't give their digital lives back

#34

Why should Apple open this can of worms and give users access to locked out data. How would this process even work on a larger scale? In the end if you dont backup your data locally, then its not your data and you risk losing it. If your business shuts down because you lost your phone its your own fault for not mitigating this type of risk enough.

The data isn't full E2E encrypted and unreachable in all these cases in the article. The iCloud default is not to encrypt things such that Apple can't decrypt the data; a user has to enable "Advanced Data Protection" for that to happen.

Apple could decrypt and return all the user data in all the cases in the article. They aren't doing that. Some folks are rightly pointing out "what is the point of storing all my stuff in your cloud if you're going to lock me out if I lose my phone?" That's not a backup, that's just paying a monthly fee to store more than what your phone alone can store.

Re: Thieves took their iPhones. Apple won't give their digital lives back

#35

My cousin’s phone was stolen in San Francisco. My mom’s phone was hooked up to the same account. Somehow the thief was able to change the account password and email account to something else. Now my mom cannot reset her phone because she doesn’t have access to the thieves account.

> Somehow the thief was able to change the account password and email account

That would be the fact that Apple lets anybody that knows the passcode reset the iCloud password as well, without any further authentication. And the passcode can be shoulder surfed by the thief...

"Stolen device protection" was developed as a response to a wave of such thefts: https://support.apple.com/en-us/120340

It seems like a good step forward but still not perfect, and I believe it's not on by default.

On the other side, with Advanced Data Protection, it seems shockingly easy to permanently lock oneself out of an iCloud account: As far as I understand, there is absolutely no way to recover an account protected that way if the recovery code is lost – not even by deleting all data currently stored on it and starting from scratch (e.g. from a local backup).

Given the fact that an iCloud account doesn't only contain a big pile of data, but access to some purchased products and services (subscriptions, app purchases, iTunes songs, the Apple Card etc.), that seems like a pretty big oversight.

Re: Thieves took their iPhones. Apple won't give their digital lives back

#36
post #32

Apple’s encryption, is designed with end-to-end encryption for many types of data. Some facts: Only the user's devices hold the keys to decrypt the data. Apple cannot decrypt it, even if served a subpoena. Apple chose privacy over convenience. Sue all you want, you're going to lose.

Read the article, that's not true by default, the only way you get that level of cryptographic protection is if you enable "Advanced Data Protection". None of the people in the article did that, all of them can trivially prove they are who they say they are via government documents, Apple could decrypt their data and return it, but Apple is refusing to do so.

Re: Thieves took their iPhones. Apple won't give their digital lives back

#37
post #32

Apple’s encryption, is designed with end-to-end encryption for many types of data. Some facts: Only the user's devices hold the keys to decrypt the data. Apple cannot decrypt it, even if served a subpoena. Apple chose privacy over convenience. Sue all you want, you're going to lose.

Then delete that data and let the user start over. How come Apple gets to hold iTunes purchases (apps, movies etc.) and somebody's email address hostage just because they also happen to store some end-to-end encrypted data on the same cloud account?

Just imagine Google letting people "brick" their accounts because they have a password protected PDF in their Google Drive they don't remember the password for...

And that's to say nothing about the not end-to-end encrypted data, which is still the default for most things in iCloud accounts (without ADP enabled).

Re: Thieves took their iPhones. Apple won't give their digital lives back

#38

I'm curious why Apple has let it get this far that court cases are underway and WaPo is writing an article about it. What's in it for Apple? Surely it's easy enough to define some kind of verification process based on various pieces -- phone number, credit card, purchase receipt, etc. -- and requiring a police report to be filed or something. And this isn't like Google or Facebook where accounts are free, preventing…

My gut tells me that they don't want to either set the precedent or let it be known that they can access your data and give/revoke access remotely, because it pokes a hole in their E2E encryption claims and opens the door to demands for backdoor access from governments.

It doesn't "poke a hole" in anything. The only way you get the full E2E encryption Apple talks about is if you enable "Advanced Data Protection", which none of the people in the article did, per the article. Apple could decrypt and return the data because Apple has the keys. Apple is refusing to do so.

Re: Thieves took their iPhones. Apple won't give their digital lives back

#39

It took me a minute to figure out how this works, but it must have something to do with using a "lost password" email reset on the iCloud account, and having the relevant email account logged in (or saved to the password manager) on the phone itself, so that all you need is the passcode to get into the iCloud account. Something like that?

Presumably they will need mail notifications enabled on the Lock Screen as well.

The described attack in TFA seems to involve learning the phone owner's passcode (for the phone), so no lock screen shenanigans needed.

Re: Thieves took their iPhones. Apple won't give their digital lives back

#40

I'm curious why Apple has let it get this far that court cases are underway and WaPo is writing an article about it. What's in it for Apple? Surely it's easy enough to define some kind of verification process based on various pieces -- phone number, credit card, purchase receipt, etc. -- and requiring a police report to be filed or something. And this isn't like Google or Facebook where accounts are free, preventing…

My gut tells me that they don't want to either set the precedent or let it be known that they can access your data and give/revoke access remotely, because it pokes a hole in their E2E encryption claims and opens the door to demands for backdoor access from governments.

Having access but pretending not to seems like the worst of both worlds.

Various entities will still be able to get to the data, while users might incorrectly assume that that's not the case.

Post reply on HN