11 ms·
From article comments: "If your phone is locked, how did they get your iCloud email address? " "As said, I’m guessing they googled my name (available via the Me
by barnaclejive 10y ago
From article comments:
"If your phone is locked, how did they get your iCloud email address? "
"As said, I’m guessing they googled my name (available via the Medical ID functionality) and found an email address for me."
How does phishing like this scale? I would think the vast majority of the time the thief is going to have no idea what the email or phone number of the victim is. Seems like a pretty elaborate scam for something that relies on stealing phones where Medical ID is enabled.
Is there some other way that the thief would be able to easily contact the victim by email or text?
Even with Medical ID enabled, that only shows name, DOB, medications.. I would think for most people that still isn't going to be enough info to get an email and phone number from by googling.
Not saying it isn't possible, I just think that it seems odd that the difficulty of making the scam work seems out of balance with the polish of it.
- schlowmo 10y ago> "How does phishing like this scale?" I assume that the thief which actually steals the phone isn't the same guy which puts this kind of scam on. And if you're the one which buys the stolen phones at larger scale (e.g. by running a used-phone-shop) this kind of scam scales very well I would think.
- dsfyu404ed 10y agoPay flat fee for locket, stolen iPhones, which aren't very useful to most thieves (a few % less than the break even price for using them as parts). Before using them as parts you see if the victim's ID is worth pursing (low hanging fruit). If it's worth pursuing you script out most of what was done in the article. All the IDs you get you sell weekly and you use the phones as parts for a phone repair service and make money charging people for parts that you're not paying much for (or just sell the parts at a discount). The free market at it's finest.
- hn_user2 10y agoPop the SIM card into another phone to get the phone number. Wait a couple weeks to give the victim time to get a new replacement phone with the same phone number.
- chipperyman573 10y agoPut the SIM in another phone to view the number. Call 611 from that phone and say you "forgot the email you used to make your online account", pray they used the same to sign up for iCloud.
- barnaclejive 10y agoAh, yea that seems more reliable than getting lucky googling info on the medical ID display.
- lokedhs 10y agoI'm guessing that people in the US knows what 611 is, but I never heard about it. Could you tell me what that number is?
- cgriswald 10y ago"Today" which lists Calendar events among other things, as well as "Notifications", which lists all kinds of things depending on settings, either of which could reveal personal information are both accessible on a locked iPhone.
- caseysoftware 10y ago> How does phishing like this scale? I think this is the wrong question. You only need "scale" when your response rate or "take per device" is relatively low. In this case, I suspect the success rate is incredibly high and/or if it lets you unlock and disassociate the the device from the account, the device itself becomes more valuable. It's a win-win for the bad guys.
- eastbayjake 10y agoIs it worth asking whether the author, as a company's managing director, is a high-profile target and perhaps his phone was specifically stolen for a high-touch scam? I'd imagine corporate espionage insights for even a minor company would be more valuable than the $800 iPhone itself; someone handling material non-public information about a publicly-traded company could yield stock tips worth thousands or millions.
- chillaxtian 10y agono
- joonaski 10y agoHi, I'm the orig post author, and I did think of that too. But no - it was far from home on a holiday trip in a rental car. If someone really wanted my phone, there are many simpler ways. Also, it wasn't the only car with a broken window on the same parking lot when we came back to the car. In addition, we're a really open company and not that great a target for espionage. We have very few secrets worth significant money. I just got unlucky.
- dunham 10y agoIf you have a contact card set up, ask Siri "What is my name", then click on the mail icon. It will present all of your email addresses. (This works for me when I activate siri with my pinkie finger, which isn't a registered fingerprint.)
- jsmthrowaway 10y ago"Who owns this phone?" or "who does this phone belong to?" will answer the question, too, if Siri is enabled, and is useful knowledge if you find an iPhone. This includes numbers if they are on the "Me" contact card. I just tried it on mine and it dumped everything from my contact card including my mother and father, BUT, I have had my phone returned in minutes from someone who knew to ask so it's a mixed bag. If you're not cool with that, you can configure Siri to only function when unlocked. I used to operate that way, but especially controlling music in the car and fumbling with Touch ID when fingers aren't cooperating, I grew tired of it and went back.
- tuna-piano 10y agoGood catch, works for me as well. Pops up with my first name, last name and email address.
- developer2 10y agoThis is the reason why I disable Siri from being used on the locked screen. It's barely inconvenient to have to unlock with fingerprint before being able to activate Siri, and the amount of information you can grab from a "locked" phone via Siri is scary.
- squeaky-clean 10y agoIs there no way to disable sensitive requests from the lock screen? My Android phone has an option under voice settings to disable "Personal results" when the phone is locked.
- developer2 10y agoWith Siri, it's all or nothing. Either it is enabled on the lock screen, or completely inaccessible. It does have limits when enabled, where it will force you to unlock before inquiring deeper into the system. I can't remember exactly what kind of tasks I was able to accomplish with it enabled, but it was too much for me were it to land into a thief's hands. In any case, with the Touch ID it's barely an inconvenience to unlock before holding the home button to activate Siri. It's like 1.5 presses of the home button rather than a full 2. I'm not sure why they haven't put in the effort to allow you to hold down the home button once to activate Siri with a read of the fingerprint. They prioritized that action for Apple Pay. shrug
- cyberferret 10y ago> How does phishing like this scale? I saw in another long blog post how something like 80% of all stolen phones in the world end up in about a half dozen locations in Asia that act as bulk resellers. (I think the article was about the guy in SF who lost his phone at a bar and it ended being used by an orange farmer in Shanghai?!? - it was a cool story). I daresay these bulk 'processing' plants for lost/stolen phones may have a team in place that try and identify the previous owners and send out bulk scam emails to try and hook them?
- cosmotron 10y ago> guy in SF who lost his phone at a bar and it ended being used by an orange farmer For those interested: https://www.buzzfeed.com/mjs538/i-followed-my-stolen-iphone-across-the-world-became-a-celebr https://www.buzzfeed.com/mjs538/i-followed-my-stolen-iphone-...
- Throwaway23412 10y agoYou two really undersold this. Jesus Christ. How is this first time I've heard of this story? It is absolutely absurd.
- goldenkey 10y agoThat was heart warming!
- rangibaby 10y agoI hope the author gave "Brother Orange" a new iPhone after remote bricking it after all those months.