Live data from Hacker News

FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

404media.co

491–500 of 565 posts

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#491

Earlier quoted context omitted.

Link which doesn't directly support website owned by unscrupulous trillionaire: https://xcancel.com/runasand/status/2017659019251343763?s=20

There are trillionaires?

I guess technically musk rounds to a trillion. 852B acc to Forbes

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#492

Earlier quoted context omitted.

I want to say that is generous of her, but one thing that is weird is if I didn’t want someone to go into my laptop and they tried to force me to use my fingerprint to unlock it, I definitely wouldn’t use the finger I use to unlock it on the first try. Hopefully, Apple locks it out and forces a password if you use the wrong finger “accidentally” a couple of times.

Correct. That’s why my Touch ID isn’t configured to use the obvious finger.

Honestly, that's clever.

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#493

Earlier quoted context omitted.

I really wish Apple would offer a pin option on macos. For this reason, precisely. Either that, or an option to automatically disable touchid after a short amount of time (eg an hour or if my phone doesn't connect to the laptop)

uhm, are you saying its not possible to require an actual password to unlock osx?

My guess is they want to have a PIN as a short-term credential analogous to the Touch ID, that is, it only works for X hours per password auth before needing password auth again, and then you only get X tries on the PIN before it either locks the PIN out and you need the full password to reactivate it (or I guess it could wipe the laptop à la iPhone).

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#494

Remember...they can make you use touch id...they can't make you give them your password. https://x.com/runasand/status/2017659019251343763?s=20 The FBI was able to access Washington Post reporter Hannah Natanson's Signal messages because she used Signal on her work laptop. The laptop accepted Touch ID for authentication, meaning the agents were allowed to require her to unlock it.

> they can't make you give them your password. Except when they can: https://harvardlawreview.org/print/vol-134/state-v-andrews/

75 footnotes for 89 sentences, nice! I guess that's how they roll over at the HLR.

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#495
Can anyone speak to the relative safety or lack thereof using FaceID on individual apps while requiring a PIN to login to the device?

I have my phone setup this way because FaceID can be so convenient. I know it opens up more attack vectors than not using it but is it possible for a powerful actor to utilize the fact that it is enabled at all to gain access to a locked phone?

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#496

Earlier quoted context omitted.

I really wish Apple would offer a pin option on macos. For this reason, precisely. Either that, or an option to automatically disable touchid after a short amount of time (eg an hour or if my phone doesn't connect to the laptop)

uhm, are you saying its not possible to require an actual password to unlock osx?

> uhm, are you saying its not possible to require an actual password to unlock osx?

uhm, are saying that i'm saying that? if so, please show me where i said that. thank you

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#497

Earlier quoted context omitted.

I previously commented a solution to another problem, but it assists here too: https://news.ycombinator.com/item?id=44746992 This command will make your MacBook hibernate when lid is closed or the laptop sleeps, so RAM is written to disk and the system powers down. The downside is that it does increase the amount of time it takes to resume. A nice side benefit though, is that fingerprint is not accepted on first unlo…

> I believe secrets are still encrypted at this stage similar to cold boot. Does this mean that the Signal desktop application doesn't lock/unlock its (presumably encrypted) database with a secret when locking/unlocking the laptop?

It wouldn’t matter because the whole OS would be evicted from memory and the entire storage encrypted.

Signal itself wouldn’t even be detectable as an app

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#498

Earlier quoted context omitted.

But is not legal testimonial

Right. Like I said, that's not logical, that's just legalese to gain access where you didn't have it before.

My fiancé is an attorney and I'm an engineer, and she looked at me incredulously when point out anything that is not logical in her legal work. I'm thankful my father talked me out of becoming a lawyer.

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#499
post #303

Earlier quoted context omitted.

In case anyone is wondering: In newer versions of MacOS, the user must log out to require a password. Locking screen no longer requires password if Touch ID is enabled.

Settings -> lock screen -> “Require password after screen saver begins or display is turned off”

Even with that option set to "Immediately" you can still use Touch ID after locking.

Re: FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

#500
post #438

Earlier quoted context omitted.

Good reminder to also set up something that does this automatically for you: https://news.ycombinator.com/item?id=46526010

I generally avoid extensions that can read all sites (even if technically necessary), so use the suggestion found here [1] instead. A few bookmarklets: javascript:(function(){if (location.host.endsWith('x.com')) location.host='xcancel.com';})() javascript:(function(){if (location.host.endsWith('youtube.com')) location.host='inv.nadeko.net';})() javascript:(function(){if (location.hostname.endsWith('instagram.com')) {…

Wow, where did these come from. these are great alternatives, especially the youtube. I like using the duck player but that's only in that browser.

For example duck://player/fqtK3s7PE_k where the video id in youtube url https://www.youtube.com/watch?v=fqtK3s7PE_k

But it doesn't have that overview page like inv.nadeko.net does

Post reply on HN