Live data from Hacker News

Apple's new iPhone security setting keeps thieves out of your digital accounts

theverge.com

41–50 of 74 posts

Re: Apple's new iPhone security setting keeps thieves out of your digital accounts

#41
post #31

Earlier quoted context omitted.

Eh, fake receipts are fairly easy to knock out. When I managed a hospital's iPhone deployment I made it a point to always back up our receipts electronically because I have... had to make quite a few emails to AppleCare Security to release a few Activation Locked devices. It's not a terribly difficult process once you've done it a couple times, and I reasonably think I could release as many phones as I wanted these d…

with an MDM and Apple's Device Enrollment Program you don't even need to worry about this anymore[0] [0]: https://www.apple.com/mx/business-docs/DEP_Guide.pdf

Hahahah when I worked at the hospital my director's answer to any of that was "Exchange is our MDM" despite me pushing for it, so I was stuck with the receipts regardless.

... My personal stuff is enrolled into my own personal Jamf instance and because I went through a bunch of motions with Apple Business my personal phones and Macs are all DEP locked ;)

Re: Apple's new iPhone security setting keeps thieves out of your digital accounts

#42
post #38

Related: Set up screen time, and disable password changes and account changes, and set a (different to your regular passcode) screen time passcode. Then you have a separate passcode that keeps sensitive account changes locked.

This is clever.

Re: Apple's new iPhone security setting keeps thieves out of your digital accounts

#43
post #26
post #16

After a iPhone theft in Europe earlier this year, I don't quite trust Apple's assurances with regard to stolen iPhones. My phone was snatched from my hands in the street. I was able to wipe it via 'Find Devices' within a few minutes; I was able to track its location for the rest of the day, until I requested that my carrier irrevocably disable its network service. There was no evidence of any accesses of my informati…

Well I kind of did circumvent this hurdle. I got an iPhone from a relative, the relative had forgotten the passcode and the Apple ID password. I did a factory reset of it via iTunes and of course when it started up and I started with the setup it said it was locked to * @* .com. I contacted Apple support and they said I needed proof of purchase for them to unlock it. I did not have any proof of purchase and neither d…

> The Apple Genius went to get a manager or something and the manager checked the "proof of purchase" and then connected the iPhone to the store Wi-Fi and did some stuff on their iPad and rebooted the iPhone. The iPhone did a reset and then it was unlocked and ready to be setup without any hurdles.

The thieves figured out you just need to know (or be) an employee of any of the 500+ Apple stores. I assume that some theft rings have this process quite streamlined.

Re: Apple's new iPhone security setting keeps thieves out of your digital accounts

#44
post #38

Related: Set up screen time, and disable password changes and account changes, and set a (different to your regular passcode) screen time passcode. Then you have a separate passcode that keeps sensitive account changes locked.

The last time this came up, it was pointed out this too can be bypassed.

Re: Apple's new iPhone security setting keeps thieves out of your digital accounts

#45

What I really wish apple had is the ability to have multiple passcodes with different behavior. Something like one passcode for ordinary phone use, one that would immediately and covertly send an emergency text to your family with your current location, one that would instantly wipe the device and one that would give you access to the hidden gay dating app you don't want people to know about.

Absolutely, the idea of "coercion codes"/"distress codes" or the like goes back a very long time, long before electronic devices even, it's a pretty natural idea that someone could use different canned expressions to code for different responses that attackers wouldn't be able to distinguish. All the core aspects are in place on iOS to do a system both user friendly and quite powerful around that, and years and years later it remains too bad that's hard. In fact in a touch of irony it was at one point quite feasible and pleasant to do with a jailbroken iPhone and Touch ID. The Touch ID system actually distinguished between the various registered fingers (up to five), which in turn meant you could use fingers themselves to trigger other behavior. So "unlock with either index finger" could be "normal", but "unlock with thumb" or middle finger could then run scripts of your choosing in the background.

It would be a real boon if Apple themselves did it, incorporating not just codes or biometrics even but also arbitrary information from phones sensors if advanced users wanted. So for example you could explicitly set a few geofences and say that certain actions could only be done within them (and only at certain times of day even), or certain apps viewed at all (by literally keeping the encryption keys for them locked away unless all conditions were met). If it's not even possible for you to comply when traveling in the first place and that's widely known and transparent it reduces the value in trying to coerce you.

Such a system could also be useful outside of security fwiw, just in ordering our lives. Someone finding distraction hard could lock all their games and social media apps in a view accessible only at home and forbid any app store purchases as an aid in avoiding temptation. Anti-engagement instead of trying to get more engagement.

Re: Apple's new iPhone security setting keeps thieves out of your digital accounts

#46
post #16

After a iPhone theft in Europe earlier this year, I don't quite trust Apple's assurances with regard to stolen iPhones. My phone was snatched from my hands in the street. I was able to wipe it via 'Find Devices' within a few minutes; I was able to track its location for the rest of the day, until I requested that my carrier irrevocably disable its network service. There was no evidence of any accesses of my informati…

I'm unable to factory reset my own iPhone as it's linked to a friend's Apple account. I know the passcode. Apple are unwilling to do this for me unless I show proof of purchase (which I don't have as it was many years ago). Pretty high bar, so assuming must be inside job.

Is the friend not a friend anymore?

Re: Apple's new iPhone security setting keeps thieves out of your digital accounts

#47
post #11
post #9

Finally. For current iOS versions, there is a workaround: use the “screentime” feature to disallow pincode changes. In screentime you can set a different code, so when anyone else can access your phone, they can’t change the code and lock you out of your phone.

Doesn't work. If you get the screen time password wrong a few times it will let you put the device passcode in.

Are you sure? According to Apple [0] it requires your Apple ID password. Also, I can't reproduce this on my iOS device: it's locked by a timer which increases exponentially.

[0]: https://support.apple.com/en-gb/102677

Re: Apple's new iPhone security setting keeps thieves out of your digital accounts

#48
post #38

Related: Set up screen time, and disable password changes and account changes, and set a (different to your regular passcode) screen time passcode. Then you have a separate passcode that keeps sensitive account changes locked.

The last time this came up, it was pointed out this too can be bypassed.

How so? That's good to know that it can be bypassed.

Re: Apple's new iPhone security setting keeps thieves out of your digital accounts

#49
post #26

Earlier quoted context omitted.

Well I kind of did circumvent this hurdle. I got an iPhone from a relative, the relative had forgotten the passcode and the Apple ID password. I did a factory reset of it via iTunes and of course when it started up and I started with the setup it said it was locked to * @* .com. I contacted Apple support and they said I needed proof of purchase for them to unlock it. I did not have any proof of purchase and neither d…

> The Apple Genius went to get a manager or something and the manager checked the "proof of purchase" and then connected the iPhone to the store Wi-Fi and did some stuff on their iPad and rebooted the iPhone. The iPhone did a reset and then it was unlocked and ready to be setup without any hurdles. The thieves figured out you just need to know (or be) an employee of any of the 500+ Apple stores. I assume that some th…

[deleted]

Re: Apple's new iPhone security setting keeps thieves out of your digital accounts

#50
post #11

Earlier quoted context omitted.

Doesn't work. If you get the screen time password wrong a few times it will let you put the device passcode in.

When the screen time settings are protected by a separate Apple ID with a separate phone number registered for 2FA (obviously the SIM card or eSIM shouldn’t be on the same phone), this works. In this situation you need access to that second account’s SIM card (which can be locked with a PIN) to remove the lock. Keep in mind afaict this is the situation with 2nd account having Rescue Code enabled. Things might be diff…

What is your email? :)
Post reply on HN