4 ms·
Author here. I just want to clarify some of the points I've seen repeatedly mentioned in the comments: AFAIK my brother didn't hand over his iCloud password. T
by probably_wrong 4y ago
Author here. I just want to clarify some of the points I've seen repeatedly mentioned in the comments:
AFAIK my brother didn't hand over his iCloud password. That's what the phishing messages were for. Had he not fallen for that (as the article in Spanish explains) the thieves could have only sold the phone for parts. As for how they changed the recovery number, lstamour [1] has what I consider a good guess.
My brother did have a screen lock, but it was a 4-digit numeric code. My guess is that the smudges on the screen revealed quite easily what the code was as AFAIK the thieves didn't ask for it. He chose that code because he often shares the phone with his wife and having to show his face every time was annoying. He didn't know you can have two registered faces, and I don't have the heart to tell him now.
And finally, many of you correctly pointed out that there are steps that could have mitigated this attack. I wanted to share this story mostly [2] because I think it's an interesting example of what iPhone security is like for the type of user who would never set foot in HN. I could have easily followed the steps delineated in this comment [3] from the other thread, but my brother is not that type of user.
[1] https://news.ycombinator.com/item?id=34407683 https://news.ycombinator.com/item?id=34407683
[2] Okay, the main reason I published this story was to find someone who can help (wink wink). But the other reason was definitely in the top 3.
[3] https://news.ycombinator.com/item?id=33602627 https://news.ycombinator.com/item?id=33602627
- WirelessGigabit 4y agoWell, remember the old days where we had fingerprints on iPhones? I remember. My thumb was registered on my wife's phone and hers on mine. Never an issue with sharing a phone. I'm sorry this happened to you.
- limitedsupply 4y agoYou still had a pin code, in addition to the fingerprint. It's an identical situation.
- egberts1 4y agoiOS supports both fingerprinting AND inputting of a PIN ... in iOS? Did not know that. Then again, not sure how we can do that ... in iOS. https://discussions.apple.com/thread/7647773 https://discussions.apple.com/thread/7647773
- egberts1 4y agoSeems like only at iOS power up, one cannot do both fingerprint and PIN. https://discussions.apple.com/thread/7647773?answerId=30570043022#30570043022 https://discussions.apple.com/thread/7647773?answerId=305700...
- limitedsupply 4y agoI am sorry this happened to your brother. I think the information you added makes the majority of the discussion in this thread irrelevant. If the thieves phished the password in a separate attack and then used that to perform iCloud account hijacking - then that's a fairly expected outcome that is not unusual in the industry. Having both the password and the phone basically proves full ownership. I empathize with your frustration, but realistically speaking, the outcome very likely would have been the same if he used any other phone from a major tech company.
- fsckboy 4y agoI use a 4 digit unlock code, and every now and then I get curious and look to see if I have smudges over those numbers. I've never seen telltale smudges on mine. Of course MMV
- probably_wrong 4y ago> Having both the password and the phone basically proves full ownership. The thieves changed the phone number immediately while they only obtained the password around 5 days after stealing the phone. Had Apple support been more... well, supportive, we would have been able to recover the account long before the thieves got the second factor. There was a big window of time in which Apple could have helped, but they chose to send us in circles instead. As for "proving full ownership", those factors cannot prove full ownership because the thieves are not the legal owners of the account. There are multiple ways in which we can prove ownership (legal documents, access to the iCloud email, photos of us inside the account, etc) but Apple doesn't want to provide real tech support (as this commenter [1] pointed out). Also, related: had this happened in Europe, the GDPR would force Apple to provide my brother his data (as I've written before regarding Google and a locked account [2]). So it's not like they can't, but rather that they don't want to, and I think it's perfectly fair to criticize them for that. [1] https://news.ycombinator.com/item?id=34407647 https://news.ycombinator.com/item?id=34407647 [2] https://7c0h.com/blog/new/lost_gmail_ii.html https://7c0h.com/blog/new/lost_gmail_ii.html
- limitedsupply 4y ago