5 ms·
Would you prefer not being able to remove your own old phone from Find My? There is a lot of disappointment expressed in the comments here but we need level-he
by limitedsupply 4y ago
Would you prefer not being able to remove your own old phone from Find My?
There is a lot of disappointment expressed in the comments here but we need level-headed solutions, not just rage against things that are actually useful in 99.9999……% situations.
- Gigachad 4y agoSeems like there are vanishingly few security measures which prevent the held at gunpoint scenario but still allow the user to do things.
- limitedsupply 4y agoOne fix that was mentioned in the comments that would have been easy to implement (and, frankly, bizarre it’s not implemented yet) is confirming password when performing such critical actions as removing or adding devices/telephone numbers.
- Gigachad 4y agoI just tested this on my iphone and it absolutely asks you for a password before you can touch the icloud phone number. I suspect the victim was compelled to either enter or hand over this password when the phone was stolen. It's not out of the question that the brother forgot this happening consider how stressful the situation would have been. This is essentially the famous xkcd "5 dollar wrench" problem https://xkcd.com/538/ https://xkcd.com/538/
- limitedsupply 4y agoThanks for testing this, Gigachad! At this point I will just stop commenting on this post as it seems like either Apple already fixed this or some of the most critical information has been omitted by the author. So we are just guessing and raging for no reason.
- probably_wrong 4y agoAuthor here. Unfortunately I don't have an iPhone to check, but another comment [1] suggests that this may happen if you physically change SIMs. My brother said they didn't ask for his iCloud password, which makes sense: if they had the password then they wouldn't have needed the phishing step afterwards. [1] https://news.ycombinator.com/item?id=34407683 https://news.ycombinator.com/item?id=34407683
- b3morales 4y agoHaving a "re-enter your password to confirm" step is bog standard for critical actions like that. It would be no serious burden for a legitimate user, and an extra hurdle for a thief.