10 ms·
How my brother's iCloud account was stolen
- kurthr 4y agoHaving a single apple device on an iCloud account sounds like a security risk. I was in a similar situation out of sheer stupidity (new device, went on vacation, forgot unlock code), but I was eventually able to recover using an old linked iPad, the iCloud password, email, and time. The interesting bit is theives ability to disable FindMy, it's effects, and following sequence of events.
- pianoben 4y ago> out of sheer stupidity I have to push back on this. It's not stupidity to not realize you need another Apple device to have any reasonable chance of navigating their support channels. It's not something they go out of their way to teach you about, until you learn the hard way. Indeed it's an infuriating (IMO) dark pattern. Don't blame yourself or others - this is on Apple! EDIT My personal brush with this was when my wife's phone was lost/stolen/etc and she forgot her iCloud password. Even though she had not one but two active macbooks, the fact that the credit card she'd registered with iCloud caused weeks of delay from Apple. They wouldn't budge unless we entered the original CC number, but their system rejected it due to the expiration. Madness! I'm glad that I had an internal contact - most people would have been locked out for good. These days I use a thinkpad...
- infotogivenm 4y agoI think parent’s use of “stupid” is referring to themself going on vacation and immediately forgetting their unlock code. Regaining access to a single device that has been robbed and unlocked at gunpoint is a tough scenario. But I agree that there must be better support patterns to recognize and deal with such a scenario… the rather unfortunate thing I see here is his brother falling for a phishing scam, which yes ultimately will lose the device for good (physical access + password). That is harder to deal with from the support end, I’d imagine.
- srmarm 4y agoMany years ago I had my iPad stolen on a train. Realised what had happened while we were still between stations. In theory all I needed to do was use the find my device function on my phone and walk the train until my iPad connected to my phone. Except the bloody thing wouldn't work on my Android phone. The page was just telling me to download the iCloud app from an Apple device. I didn't get the iPad back and haven't purchased anything from Apple since.
- plebianRube 4y agoIt does especially when learning from the article, with Argentina's average income, earning an extra device is no small feat: "An iPhone is not cheap in general, and in Argentina less so. The current price for an iPhone 13 is ca. 400.000 ARS, which roughly translates to 2200 USD or 1300 USD at the unofficial rate (it's complicated). With an average monthly salary of 427 USD (according to Numbeo) you can see that getting a new iPhone is not a choice to take lightly."
- benatkin 4y agoI thought it was rupees. Oops. The Rs in ARS doesn't mean Rupees. Less than an order of magnitude difference, though. More countries have Rupees than I thought: https://en.wikipedia.org/wiki/Rupee https://en.wikipedia.org/wiki/Rupee
- Someone1234 4y agoHow they changed the trusted phone number is the biggest mystery here and the biggest concern. They linked to a HN thread, and I guess by implication they're saying that the phone was unlocked when it was stolen and that is somehow how it was changed? It is interesting that Apple has no way of viewing phone number histories.
- limitedsupply 4y agoOn an iPhone you can go to Settings -> Name, Phone Numbers, Email -> Edit Reachable At. That's one way I guess. Haven't used this menu before so not 100% positive.
- judge2020 4y agoTrue - maybe it shows it afterwards, but adding a new phone number doesn't require password entry or Face ID. As for removing the existing number, I can't remove mine until I de-register it from iMessage & Facetime (since it's the number on the phone), so maybe they turned those off or they popped in a new SIM card.
- majormajor 4y agoSomething that's always confused/concerned me - at least on Mac - is that when I get asked for a 2FA code logging into the icloud web UI or similar, the same computer I'm logging in from pops up a popup with the code the Apple site is requesting. Wonder if that sort of thing comes into play here - if you are trying to do something "untrusted" on a device, the trust check shouldn't rely on that same device? But then if you only had a single device you're in trouble...
- nerdponx 4y agoI imagine the problem is that, from the perspective of the web browser, the computer you happen to be using is a separate device, because it's a separate logged-in application. Seems like an obvious hole, but I don't know how you would fix that.
- 4y ago
- VectorLock 4y agoWouldn't figure the person doing stickups for iPhones would be technically savvy enough to send phishing SMSs with associated site hosting. Presumably someone in the underworld is offering this "as a service?"
- pianoben 4y agoDivision of labor within a larger criminal organization - line workers snatch the phones, and IT "unlocks" them.
- addcn 4y agoUsually stolen goods are sold to a professional fencer for a price that factors in the risk of not being able to unlock/reset and move the phone. Some of the economics of the underworld are remarkably sophisticated. Everyone has a role and there are some parts of the supply chain that require different kinds of risk. Sometimes it’s risking cash, physical safety or personal-criminal repercussions.
- TheAdamist 4y agoThey are savvy to know enough to force people to disable security/ sign out of icloud so they can sell the phones. This was just in the news in Philadelphia recently where a whole house was forced at gunpoint one by one to unlock and sign out of their iphones. https://www.cbsnews.com/amp/philadelphia/news/how-philadelphia-police-tracked-down-temple-home-invasion-suspect/ https://www.cbsnews.com/amp/philadelphia/news/how-philadelph... Id be in trouble since my work iPhone has some password manager generated random nonsense that i would never be able to remember. All i know is it uas the second single tick on the keyboard, not the first, and they look visually identical on ios.
- VectorLock 4y agoI rather give up my wallet than try to recover all the 2FAs on my phone.
- schiffern 4y agoAs an iCloud user, this is absolutely terrifying. Apple needs to fix this _yesterday_, and close the relevant holes.
- limitedsupply 4y agoNot going to try to justify Apple but feel like a piece of info is missing from the post. How did they unlock the phone? Maybe the phone had no auth set up? In general, it's expected that you should be able to update your own phone number in your iCloud account.
- schiffern 4y agoThat's fine. The issue is that criminals can use it to lock you out of Find My, etc.
- limitedsupply 4y agoWould you prefer not being able to remove your own old phone from Find My? There is a lot of disappointment expressed in the comments here but we need level-headed solutions, not just rage against things that are actually useful in 99.9999……% situations.
- Gigachad 4y agoSeems like there are vanishingly few security measures which prevent the held at gunpoint scenario but still allow the user to do things.
- limitedsupply 4y agoOne fix that was mentioned in the comments that would have been easy to implement (and, frankly, bizarre it’s not implemented yet) is confirming password when performing such critical actions as removing or adding devices/telephone numbers.
- kepler1 4y agoI sympathize with the writer, but have to ask, what solution would make it possible to resolve this situation without weakening the security for another case that sounds the same but is being used by someone malicious? I think you have to activate the Apple 2-factor authentication so that your key Apple ID info cannot be changed without corroboration or that 28 character code. If Apple were to let this situation be reversed, who is to say a hacker wouldn't be using this exploit to take over someone else's account?
- hattmall 4y agoIf an icloud account becomes in dispute then it should be locked, generally. The problem isn't the technology it's the lack of actual tech support. There should be a reasonable way to speak to someone that can validate the account in someway. Similar to credit reports. Show an ID, answer questions about the account, like previous devices, when it was created. Provide pictures etc of the people in the pictures in the account. The problem boils down to one of the most profitable companies in the world becoming that way by cheaping out on support for their users.
- kepler1 4y agoThere is not a single tech company out there that wishes to get into the business of checking people's physical IDs or wanting to invite use of IDs (or making judgements about such authenticity) to manage their accounts. How would this work? You provide a certain number of photos to corroborate who you are? How would that not be vulnerable to hacking as well?
- Severian 4y agoLet me tell you, Apple's iCloud policies are STUPID. Once upon a time you could sign up to an account WITHOUT verifying your email. Someone signed up under my Gmail account, and it's been stuck there since. As the author found, support is useless . It took me close to 2 weeks after emailing Tim Cook about the situation, since I was seriously considering an iPhone. Executive liason had it reset for me. I was able to change the password, login, and the VERY next day the password was changed (presumably from whomever is using it on THIER phone). I've given up. My time is not worth chasing this down. I may eventually just start harassing the douchebag who thinks they have my email address, but there are like 3 or 4 people whom i get email for. AFAICT every single one is a boomer.
- sokoloff 4y agoCan you setup your iCloud using that gmail address but with a different number or placement of dots? sev.erian@gmail and severian@gmail are the same to gmail but many places treat them as different. (I don’t know what iCloud does.) https://support.google.com/mail/answer/7436150 https://support.google.com/mail/answer/7436150
- judge2020 4y agoMost services have figured this out now and normalize the field internally to prevent this, mostly for spam reasons.
- luckylion 4y agoI had a similar thing happen with an Australian insurance company sending me contract details for some woman who had her car and home insurance with them. I don't know if she added the wrong email by mistake or their IT fucked up connecting data from a third party service (I've never been in Australia, and have never made business with the insurance company), but it was hard work getting them to fix it. Their support did nothing. Their privacy department did nothing. What finally set things into motion was complaining to their regulatory authority. Wouldn't you know it, within two days, I had a personal email saying they'd remove my email from the account, and they haven't emailed me since.
- luckylion 4y agoThat's about the worst that can happen if you rely on any cloud. With that risk existing, I think people are massively miscalculating the time / money / complexity they save on cloud offerings. "You don't have to worry about anything, we've got you covered. But there's a 0.05% chance on any given day that you lose access to everything and we won't bring it back unless you personally know someone at our company."
- Gigachad 4y agoBecause people losing their data before the cloud was unheard of. The most safe option is to use the cloud but also download the data exports for local storage. This is very easy with Google Takeout but I was unable to work out how to do this with iCloud since they seem to think there would be no point ever exporting your data from iCloud.
- luckylion 4y agoNot unheard of, but usually your fault ("I didn't think I need a backup"), and easy to avoid once you've formed a habit. You're right that the safest option will be to have backups of your own, but at that point the cloud is only adding convenience for backing up your device for restoring, or for synchronizing files between cell and pc. To be sure you still have your data five years from now, you still need to do it yourself. I believe a lot of people understand the cloud to mean "I give you money, you make sure everything works and I don't have to get into the details".
- hoistbypetard 4y ago> Because people losing their data before the cloud was unheard of. That's not true at all. There were entire businesses before "the cloud" that did very little more than service people who had lost their data and help them recover it. I used to get billed out at near-lawyerly rates for recovering data in the mid 1990s. While I was in high school. Businesses like DriveSavers were even more lucrative.
- temende 4y agoI do wonder how you guard against the threat of you walking down the street staring at your phone and having someone snatch it out of your hand while it's still unlocked. A saavy thief could then disable the auto-sleep and as long as it doesn't run out of battery they could leave your phone plugged in and hence will never require the passcode again. A few apps (at least on iOS) give you the option to require your passcode again to access them (e.g. if you lock a note), but for the most part an unlocked phone is a treasure trove of personal information for the thief.
- xattt 4y agoDisabling autosleep should be behind an authentication step.
- wizeman 4y agoEven in that case, they could just install and start a game, which would also prevent autosleep. Or they could just start playing an extremely long video (e.g. x days long black screen) or a video stream.
- gruez 4y agobetter yet, https://nosleep.page/ https://nosleep.page/
- chrischen 4y agoAlso airplane mode
- zamadatix 4y agoIt really all boils down to "Part 1: Locked out of iCloud". Without that step you can remotely put the device in lost mode and it will lock. That loophole needs a fix.
- HomeDeLaPot 4y agoIt's probably worse than that. How would you guard against the threat of someone forcing you to unlock your phone at gunpoint? Call their bluff and just throw the phone in the gutter and run away? Stall for time like you forgot the password?
- 404mm 4y agoDoes anyone know if this is the case when you have the Recovery codes set up? Another idea, what about Legacy contact? I’d not be ashamed to “use it in any way possible” to re-gain access to something that was stolen from me.
- limitedsupply 4y agoFor 2FA - yes. Not for when you lose your password AFAIK.
- 404mm 4y agoHi, What I meant was the special security feature that Apple introduced last year (I think, all the years feel the same since 2020…). You can opt out of any “apple-assisted support” for account recovery and you receive 28char unlock key to recover your account.
- HomeDeLaPot 4y agoOne takeaway: a cloud account isn't a sufficient backup on its own. If you have to log into Apple/Google to download your files and photos, then they're at risk. Make regular backups to an external hard drive or something, and ideally have your stuff automatically back up to a NAS somewhere as well. Also, after reading this I'm going to have to think about what would happen if someone stole my phone. I take it everywhere with me. It's not an iPhone, but it's still worth a few hundred dollars and it has all kinds of data and logged-in accounts on it. I assume if it was stolen at gunpoint, I wouldn't be in a position to refuse to unlock it and unlock some apps/accounts.
- travisporter 4y agoCan you routinely and reliably back up iPhone photos to a NAS? I have a NAS but synlogy app is just not reliable
- Gigachad 4y agoWith Google I have it set up to email me the Takeout download link every 2 months which I then download manually
- sitkack 4y agohttps://takeout.google.com/ https://takeout.google.com/ I recommend everyone who hasn't done it before, to hit the above url while logged in and firing off an export. It will respond back after some time with URLs you can download. Great for downloading your Youtube playlists and history.
- CharlesW 4y agoBTW, Apple's version of Takeout is at privacy.apple.com. Once you log in, click on "Get a copy of your data".
- climb_stealth 4y agoDoesn't the takeout strip the metadata from the photos? Things like the location data. I vaguely remember looking into this in the past and from what I remember there was no good way around it. I haven't seen any alternatives to Google Photos either. Ente might be most promising, but their iOS app is not great at actually automatically uploading photos.
- benatkin 4y agoI disagree with the way it's presented. It starts off making it sound like his brother was taking every precaution and a few paragraphs in it has him being phished with these URLs: > https://apple.iforgot-ip.info https://apple.iforgot-ip.info and https://apple.located-maps.info https://apple.located-maps.info
- stingrae 4y agomaybe you should remove those links.
- judge2020 4y agoWould still be better to remove them, but the content on these subdomains have been taken down, so they don't work (and thus they aren't being flagged by Safe Browsing[0] when I report them). 0: https://safebrowsing.google.com/safebrowsing/report_phish/?hl=en https://safebrowsing.google.com/safebrowsing/report_phish/?h...
- benatkin 4y agoNah, I'm good :) Hell, I'll even go to them and send some fake stuff. Thanks for the idea. Edit: they're down. Too bad, I'll have to send junk elsewhere.
- mproud 4y agoIt helps having an active passcode lock. And you can put your phone into Lost Mode with Find My turned on, right away by signing into https://icloud.com/find https://icloud.com/find from any web-enabled device.
- Gigachad 4y agoThat does nothing when the situation is someone pointing a gun at you and saying "Hand over your phone and tell me the password"
- CharlesW 4y agoThat's not what happened though, as I read it. The thieves stole the phone at gunpoint, then tricked the victim into giving up their password later via a phishing SMS. So this action would've been useful.
- jrnichols 4y agoCurious what others think that Apple should have done in this situation. Social engineering and providing stolen information is a tactic that's been around for years. What are they supposed to do? Believe everyone that calls up with "I got locked out?" I kind of wish that they had a way to lock possibly stolen accounts and allow people to verify their ID at an Apple Store or something, though.
- Gigachad 4y agoI don't think there is anything they can do when someone is being held at gunpoint and told to hand over their phone and password. Perhaps they could prompt users to keep local backups of their icloud data rather than pretending it's impossible to lose info in the cloud.
- jrnichols 4y ago> someone is being held at gunpoint and told to hand over their phone and password. The article doesn't say that happened, though. It just says "My brother got his iPhone stolen at gunpoint." If the victim had been made to hand over his password, that's a very very huge detail the blogger did not include. I had my phone stolen from me at Pride in SF and went through a lot of the same steps. The thieves yanked the SIM immediately. I was able to follow the phone as it hopped onto public wifi networks (mostly at stores) that I had joined before. it finally wound up in Shenzhen, China.
- Gigachad 4y agoHow else could they have swapped the phone number on the iCloud account? That’s the only part of this story which is interesting.
- limitedsupply 4y agoThey phished the password in a separate attack.
- operator-name 4y ago
- dwighttk 4y agoI’m guessing the thieves with guns got him to leave them with an unlocked phone?
- gnicholas 4y agoApparently starting with iOS 15, you can now erase your iPhone remotely and still locate it in Find My. Previously you would lose the ability to track it after wiping. https://support.apple.com/guide/icloud/erase-a-device-mmfc0ef36f/icloud https://support.apple.com/guide/icloud/erase-a-device-mmfc0e... It sounds like this might not have worked in the author's situation, where the thieves changed the phone number immediately. It sounds like at that point it was pretty much game over.
- probably_wrong 4y agoAuthor here. I just want to clarify some of the points I've seen repeatedly mentioned in the comments: AFAIK my brother didn't hand over his iCloud password. That's what the phishing messages were for. Had he not fallen for that (as the article in Spanish explains) the thieves could have only sold the phone for parts. As for how they changed the recovery number, lstamour [1] has what I consider a good guess. My brother did have a screen lock, but it was a 4-digit numeric code. My guess is that the smudges on the screen revealed quite easily what the code was as AFAIK the thieves didn't ask for it. He chose that code because he often shares the phone with his wife and having to show his face every time was annoying. He didn't know you can have two registered faces, and I don't have the heart to tell him now. And finally, many of you correctly pointed out that there are steps that could have mitigated this attack. I wanted to share this story mostly [2] because I think it's an interesting example of what iPhone security is like for the type of user who would never set foot in HN. I could have easily followed the steps delineated in this comment [3] from the other thread, but my brother is not that type of user. [1] https://news.ycombinator.com/item?id=34407683 https://news.ycombinator.com/item?id=34407683 [2] Okay, the main reason I published this story was to find someone who can help (wink wink). But the other reason was definitely in the top 3. [3] https://news.ycombinator.com/item?id=33602627 https://news.ycombinator.com/item?id=33602627
- WirelessGigabit 4y agoWell, remember the old days where we had fingerprints on iPhones? I remember. My thumb was registered on my wife's phone and hers on mine. Never an issue with sharing a phone. I'm sorry this happened to you.
- limitedsupply 4y agoYou still had a pin code, in addition to the fingerprint. It's an identical situation.
- egberts1 4y agoiOS supports both fingerprinting AND inputting of a PIN ... in iOS? Did not know that. Then again, not sure how we can do that ... in iOS. https://discussions.apple.com/thread/7647773 https://discussions.apple.com/thread/7647773
- fmajid 4y agoApple is making changes to allow using Yubikeys and other FIDO keys to secure your account. There is now also a recovery code mechanism that disables the grossly insecure phone-based recovery mechanism. https://support.apple.com/en-us/HT208072 https://support.apple.com/en-us/HT208072
- ashildr 4y agoCan you elaborate on how the phone-based recovery mechanism is grossly insecure - I am genuinely curious…
- fmajid 4y agoWell, the OP said the thieves were able to change the phone number on the account, for starters. Even without changing the number, phone numbers are easy to hijack. The security of the scheme depends on how gullible a cell phone company customer service rep is, or how corrupt a phone shop employee is who is willing to do a "SIM swap" for the crooks. See Brian Krebs' website for a description of the process and how it was used to empty crypto wallets. Furthermore, telecom standards were designed by committee and rely mostly on security by obscurity. The SS.7 system used to carry text messages has no encryption or authentication and no security whatsoever, which is how Russia or Saudi Arabia have been using it to track dissidents in the US through their phones. Even if you don't have access to the SS7 network, you can also intercept them over the radio waves using about $1000's worth of PC and electronics because spy agencies have gimped the encryption standards to make them easy to tap.
- ashildr 4y agoIIRC changing the phone number associated to an AppleID involves knowing the device code, the AppleID passcode or having access to another device with 2FA. I may be wrong and I have multiple devices with 2FA activated, so my mileage may vary because of this. I’d always expect 2 factors to be necessary to make changes to my account. If changing the phone number with activated 2FA is possible without one of these elements present I’d consider it an oversight. I consider the SMS mostly a tool to make sure the user has access to the new phone number while setting it up and does not misstype. Since OP mentions a 4-digit smear code I am not convinced that Apples security is the weakest link.
- ashildr 4y agoI emphasize with you but I am not sure if Apple even should be able to help you in the ways you imagine.