Earlier quoted context omitted.
> And it requires FaceID without a passcode ID fallback for certain categories of authentication. Judging by how often finger print readers get false negatives, this seems like an incredibly bad and frustrating idea.
Good thing Apple hasn’t used TouchID on phones in a long time then?
Apple's new iPhone security setting keeps thieves out of your digital accounts
51–60 of 74 posts
Re: Apple's new iPhone security setting keeps thieves out of your digital accounts
#52What I really wish apple had is the ability to have multiple passcodes with different behavior. Something like one passcode for ordinary phone use, one that would immediately and covertly send an emergency text to your family with your current location, one that would instantly wipe the device and one that would give you access to the hidden gay dating app you don't want people to know about.
I understand, and they are not wrong for not thinking through all the brutal scenarios that real life likes to play out. But I believe that engineering teams that have a security focus should have at least some consultant from areas where violence is normal.
So, effectively, all scenarios they think about is normal theft: forgetting the phone someone, or someone snatching the phone from you. They never think about someone sticking a gun to your face and forcing you to unlock the phone so they can run away in a motorcycle, while depleting your accounts. A distress code could be extremely helpful for bank institutions to flag every transaction post-distress. And locking your digital accounts (iCloud, DropBox, etc)
Re: Apple's new iPhone security setting keeps thieves out of your digital accounts
#53Earlier quoted context omitted.
When the screen time settings are protected by a separate Apple ID with a separate phone number registered for 2FA (obviously the SIM card or eSIM shouldn’t be on the same phone), this works. In this situation you need access to that second account’s SIM card (which can be locked with a PIN) to remove the lock. Keep in mind afaict this is the situation with 2nd account having Rescue Code enabled. Things might be diff…
What is your email? :)
Re: Apple's new iPhone security setting keeps thieves out of your digital accounts
#54Related: Set up screen time, and disable password changes and account changes, and set a (different to your regular passcode) screen time passcode. Then you have a separate passcode that keeps sensitive account changes locked.
The last time this came up, it was pointed out this too can be bypassed.
Re: Apple's new iPhone security setting keeps thieves out of your digital accounts
#55Earlier quoted context omitted.
with an MDM and Apple's Device Enrollment Program you don't even need to worry about this anymore[0] [0]: https://www.apple.com/mx/business-docs/DEP_Guide.pdf
Hahahah when I worked at the hospital my director's answer to any of that was "Exchange is our MDM" despite me pushing for it, so I was stuck with the receipts regardless. ... My personal stuff is enrolled into my own personal Jamf instance and because I went through a bunch of motions with Apple Business my personal phones and Macs are all DEP locked ;)
Re: Apple's new iPhone security setting keeps thieves out of your digital accounts
#56After a iPhone theft in Europe earlier this year, I don't quite trust Apple's assurances with regard to stolen iPhones. My phone was snatched from my hands in the street. I was able to wipe it via 'Find Devices' within a few minutes; I was able to track its location for the rest of the day, until I requested that my carrier irrevocably disable its network service. There was no evidence of any accesses of my informati…
I'm unable to factory reset my own iPhone as it's linked to a friend's Apple account. I know the passcode. Apple are unwilling to do this for me unless I show proof of purchase (which I don't have as it was many years ago). Pretty high bar, so assuming must be inside job.
Show that to the right Apple employee, you should be good to go.
Re: Apple's new iPhone security setting keeps thieves out of your digital accounts
#57Earlier quoted context omitted.
Well I kind of did circumvent this hurdle. I got an iPhone from a relative, the relative had forgotten the passcode and the Apple ID password. I did a factory reset of it via iTunes and of course when it started up and I started with the setup it said it was locked to * @* .com. I contacted Apple support and they said I needed proof of purchase for them to unlock it. I did not have any proof of purchase and neither d…
> The Apple Genius went to get a manager or something and the manager checked the "proof of purchase" and then connected the iPhone to the store Wi-Fi and did some stuff on their iPad and rebooted the iPhone. The iPhone did a reset and then it was unlocked and ready to be setup without any hurdles. The thieves figured out you just need to know (or be) an employee of any of the 500+ Apple stores. I assume that some th…
It was reported in T-Mobile's systems as my personal visit, with supporting documentation/ID, to one of their retail locations in Oklahoma – thousands of miles from anywhere I'd recently been. So, while remotely possible that their employee gullibily-reviewed credible false documents, it seemed far more likely to be:…
- an insider abuse by a corrupt employee;
- a deep hack of T-Mobile's systems, allowing such admin actions with forged audit-trails; or…
- compromise of an authorized employee's credentials plus access to capable internal-system front-ends.
The Apple Support person I spoke to insisted that an analogous compromise here was impossible - that no Apple employee had the power take such an action without my Apple ID password. Based on other reports in this thread, I highly suspect she was lying to me, probably in conformance with Apple policy.
Re: Apple's new iPhone security setting keeps thieves out of your digital accounts
#58Earlier quoted context omitted.
Or they do have such logs, but don’t feel like taking the reputation hit of telling you what happened.
I worked on these systems when I worked there. I can tell you they have audit logs, but they're restricted to certain groups within Apple to see them
Re: Apple's new iPhone security setting keeps thieves out of your digital accounts
#59After a iPhone theft in Europe earlier this year, I don't quite trust Apple's assurances with regard to stolen iPhones. My phone was snatched from my hands in the street. I was able to wipe it via 'Find Devices' within a few minutes; I was able to track its location for the rest of the day, until I requested that my carrier irrevocably disable its network service. There was no evidence of any accesses of my informati…
Against their own advice, the moment it is stolen you should erase it from Find My as a priority. Until that is done it can be used to authenticate with your iCloud account as an MFA device and can then be removed anyway if they get past the device lock. In that window the security posture is somewhat unknown. I'm sure there is a good market of off the shelf exploits which can leverage that in some way, despite Apple…
But yes - it looks to me like dishonest actors managed to get the device out of my "iCloud account device list" without my permission, and thus evade the "provisioning / device lock".
Re: Apple's new iPhone security setting keeps thieves out of your digital accounts
#60Earlier quoted context omitted.
Makes sense. No theft deterrence is perfect, and your solution required a lot of investment of time and would not scale to a substantially large theft ring.
Eh, fake receipts are fairly easy to knock out. When I managed a hospital's iPhone deployment I made it a point to always back up our receipts electronically because I have... had to make quite a few emails to AppleCare Security to release a few Activation Locked devices. It's not a terribly difficult process once you've done it a couple times, and I reasonably think I could release as many phones as I wanted these d…