Live data from Hacker News

Thieves took their iPhones. Apple won't give their digital lives back

washingtonpost.com

1–10 of 117 posts

Re: Thieves took their iPhones. Apple won't give their digital lives back

#2
My cousin’s phone was stolen in San Francisco. My mom’s phone was hooked up to the same account. Somehow the thief was able to change the account password and email account to something else. Now my mom cannot reset her phone because she doesn’t have access to the thieves account.

Re: Thieves took their iPhones. Apple won't give their digital lives back

#5
post #4

This sounds a lot like "I forgot my ultimate recovery password, but its someone else's fault."

Yes.

But in general, the way that most humans "naturally expect" such things to work is simply incompatible with the usually-extremely-convenient nature of computer accounts and cloud services.

Re: Thieves took their iPhones. Apple won't give their digital lives back

#7
post #4

This sounds a lot like "I forgot my ultimate recovery password, but its someone else's fault."

A security model that the user does not understand and contains traps is not a good security model.

OK, but what model would you suggest?

Apple has no adequate way to actually verify who anybody is without (a) forcing them to physically visit one of a small number of offices (it can't be every store), and (b) probably charging a significant fee to cover the cost of doing real verification.

And even that demands assuming that the identifying information on the account is right.

Re: Thieves took their iPhones. Apple won't give their digital lives back

#8
post #4

This sounds a lot like "I forgot my ultimate recovery password, but its someone else's fault."

A security model that the user does not understand and contains traps is not a good security model.

Is there a security model that's both highly secure, and foolproof regardless of the mental faculties of potentially billions of diverse users? I think the answer is, "Obviously not," so the real question is whether or not the necessary compromises made here represent acceptable measures.

Re: Thieves took their iPhones. Apple won't give their digital lives back

#9
I'm curious why Apple has let it get this far that court cases are underway and WaPo is writing an article about it.

What's in it for Apple? Surely it's easy enough to define some kind of verification process based on various pieces -- phone number, credit card, purchase receipt, etc. -- and requiring a police report to be filed or something.

And this isn't like Google or Facebook where accounts are free, preventing manual account recovery from being scalable. People spend thousands of dollars on Apple devices across phones and laptops and more. People who don't spend money on Apple generally aren't keeping their data in iCloud.

I'm confused because it seems like the rational, profitable thing for Apple to do here is to have these procedures for account recovery. So what's stopping them? Is there some kind of huge liability question if they ever facilitate giving access to the wrong person?

Re: Thieves took their iPhones. Apple won't give their digital lives back

#10
It took me a minute to figure out how this works, but it must have something to do with using a "lost password" email reset on the iCloud account, and having the relevant email account logged in (or saved to the password manager) on the phone itself, so that all you need is the passcode to get into the iCloud account. Something like that?
Post reply on HN