8 ms·
The iPhone Setting Thieves Use to Lock You Out of Your Apple Account
- pawelos 3y agoTo recover photos and notes from a locked account, would it work in EU to file a GDPR request for a copy of personal data?
- LelouBil 3y agoMaybe, you would also need to provide enough proof that this data refers to you, so apple could ask about proving ownership of the account.
- niemandhier 3y agoI can prove ownership of the account that pays for the storage.
- Waterluvian 3y agoI would certainly hope so. But this sounds like a very clever way around the whole “Apple can’t be bothered to care” problem.
- rickdeckard 3y agoIndeed. But as a technical guy I wonder which kind of "shared secret" one could provide to a (call center) service-agent to prove the legitimate ownership of an account without doubt? Companies circumvent this complexity by simply asking you to login before you can request anything. If someone has full access to your account, all information accessible should be considered as insufficient to validate you... In the end such a GDPR-request without login would probably again be a case-by-case topic which needs to cross the desk of some legal department to approve the action. But yeah, at least there are strict guidelines for response-times and other obligations for the company.
- Waterluvian 3y agoIt’s more of a legal problem than a technical one and has existed for very long time. How have companies handled this since before the Internet?
- rickdeckard 3y agoGood question. As per usual process of Google, Amazon, Apple et al, the process for this GDPR Request is done online AFTER you've logged in with your ID. In case of Apple this is done in the "Manage your Apple Account" area of your account settings, for which you need to be able to login first. I'm not sure these companies have a process in place to provide you this data without you having access to your own account. Filing a GDPR Request like that might turn into a topic requiring support from a lawyer / consumer protection agency...
- theshrike79 3y ago"iPhone thieves with your passcode" That's the article.
- throwaway290 3y agoOr just an unlocked iPhone? I can't confirm bc the article is paywalled but if this trick works with any unlocked iPhone then I am very interested. Plenty of cases where it is snatched from your hands on the street and accessed while unlocked, and then it's a race of whether you can wipe it first. Don't have another device at hand... unlucky.
- dogma1138 3y agoIt doesn’t in order to reset the PW on your account with a device you need to re-confirm the passcode.
- matwood 3y agoI believe they have to shoulder surf first because the passcode is asked again when they trigger the password change. I also think Android has a similar issue.
- traceroute66 3y ago> if this trick works with any unlocked iPhone then I am very interested No it doesn't. For any security sensitive stuff, you'll be asked to reconfirm your device password (and potentially also the password of another device on your account).
- loonginthetooth 3y agoYeah it's maybe not a concern for everyone, but where I live every once in a while someone gets held at knifepoint and forced to unlock their phone. I set up a screen time password just in case.
- bejd 3y agoObligatory: https://archive.is/Y8eCV https://archive.is/Y8eCV
- ceva 3y agoI love it! Thanks!
- ralfd 3y ago> In February, we reported that thieves, often in and around bars at night, watch iPhone owners tap in their passcodes, then steal the targets’ phones. With this short four- or six-digit string, criminals can change the Apple account password and rack up thousands of dollars in charges using Apple Pay and financial apps. […] > Apple introduced the optional recovery key in 2020 to protect users from online hackers. […] > iPhone thieves with your passcode can flip on the recovery key and lock you out. And if you already have the recovery key enabled, they can easily generate a new one, which also locks you out. […] > So long as you can access your iPhone, you can add or reset a recovery key without any extra credentials. Apple says this is a convenience measure. However, it also gives thieves easier access. Uff! Security vs convenience is a difficult problem, but only protecting against remote/online hacking is a massive oversight! One shouldn’t underestimate the incentives for thiefs stealing your passcode and device in real life.
- JanisErdmanis 3y agoBut why do the iPhone users tap in their passcodes in the first place when there is faceID and touchID available?
- sanitycheck 3y agoMy wife got an iPhone recently, based on her experience users tap in the passcodes almost constantly because FaceID doesn't f**king work, and no fingerprint reader is present on the device. Most of the time she still reaches for her old Android because it unlocks instantly (and properly, not to a stupid lock screen!) with a fingerprint.
- Etheryte 3y agoThe WSJ wrote an article on this two months ago as well, discussed at [0], seems like they've run out of new topics so they're just rehashing content they've already released. You can protect yourself against this type of attack by using Screen Time restrictions [1]. [0] https://news.ycombinator.com/item?id=34936015 https://news.ycombinator.com/item?id=34936015 [1] https://www.karltarvas.com/2023/02/25/protecting-your-iphone-against-shoulder-surfing-password-theft.html https://www.karltarvas.com/2023/02/25/protecting-your-iphone...
- Waterluvian 3y agoIt’s the same authors as well. This is weird.
- thathndude 3y agoI’d say they’re going back to the well. But it seems they’re defecating what was already consumed back into the well, hauling it up, and calling it new. All this for a security “flaw” that isn’t really a flaw. It’s functionality that is consistent with industry standards —(Google/Android) works the same way. Your cellphone might as well be an extension of your brain. Secure it with a strong password, and try to be mindful of shoulder surfers.
- cr3ative 3y agoThanks, the Screen Time tip is very useful. Bit annoying that it can't prompt to let you use the Apple ID settings (they're now just unavailable until you go to Screen Time settings again) but better safe than sorry.
- probably_wrong 3y ago> After months of calls to Apple customer support and letters to the company (...), he said he finally reached a representative who was willing to do more. Once Mr. Allen answered additional verification questions, Apple disabled the recovery key, he said. (...). Mr. Allen said he uses some Apple business services, which might explain why he was able to recover his account. As someone whose brother lost years of his children's videos when thieves locked him out of his iCloud account [1] this part confirms two things. First, it gives me hope that we might one day recover the account, seeing as the data is not cryptographically locked. And second, it confirms that the reason we couldn't get the access back is not because Apple can't do it, but rather because they don't care. If you have an iPhone, user gkiely shared this tip on how to further protect your account: https://news.ycombinator.com/item?id=33602627 https://news.ycombinator.com/item?id=33602627 [1] https://news.ycombinator.com/item?id=34406619 https://news.ycombinator.com/item?id=34406619
- traceroute66 3y ago> seeing as the data is not cryptographically locked. I assume your account dates from the days before Advanced Data Protection[1]. Nowadays, you can configure it so that the majority of iCloud data is now encrypted with a key that only you control. [1]https://support.apple.com/en-gb/guide/iphone/iph584ea27f5/ios https://support.apple.com/en-gb/guide/iphone/iph584ea27f5/io...
- mmh0000 3y agoTo avoid future data lose, you can backup all your icloud photos locally. Checkout icloud_photos_downloader[1], they have a docker container that is drop-dead simple to use. I run this[3] about once a month, I could probably automate it, but that feel like it'll take more time than it'll save[2]. [1] https://github.com/icloud-photos-downloader/icloud_photos_downloader https://github.com/icloud-photos-downloader/icloud_photos_do... [2] https://xkcd.com/1319/ https://xkcd.com/1319/ [3] #!/bin/bash mkdir "$(pwd)"/{photos,cookies} 2> /dev/null if [[ -z "${ICLOUD_PASSWORD}" ]]; then exit 1 fi podman container run -it --rm --name icloud \ -v $(pwd)/photos:/data \ -v $(pwd)/cookies:/cookies \ -e TZ=America/Boise \ icloudpd/icloudpd:latest \ icloudpd --directory /data \ --cookie-directory /cookies \ --folder-structure {:%Y/%Y-%m-%d} \ --username mysuperduper@username.com \ --password "${ICLOUD_PASSWORD}" \ --size original
- larsnystrom 3y agoIMHO, the crazy part is that it is possible to create a new Recovery Key with just the iPhone passcode (and the iPhone). So basically, the iPhone passcode is mightier than the Recovery Key. The only purpose of the Recovery Key is to protect against SIM swapping attacks. I didn't know this. So an attacker with the iPhone passcode can lock you out of your Apple account on all devices, even if they don't have your Apple ID password or your Recovery Key. Basically, the iPhone passcode is your only defense if you lose your iPhone. I had always assumed the Apple account password would be needed, and that the passcode is not as important as it is so common for it to be only four or six digits. I'm going to go setup a stronger passcode now.
- traceroute66 3y ago[flagged]
- jraph 3y ago> stupid enough to set a guessable password At some point the computer science community needs to deal with, and fully embrace, the flaws, caveats and characteristics of the population it serves: the human beings. It would be stupid not to.
- zamnos 3y agoIt has: password managers, which both mobile operating system manufacturers have implemented, not to mention 3rd parties like 1Password. And then there is Login with Google/Microsoft/Apple/GitHub/Twitter/etc. And now also Passkey with Apple, Google, and Microsoft being on board.
- eertami 3y agoAre you suggesting people unlock their phone with a randomly generated 24 character string they have to read from their password manager?
- kosievdmerwe 3y ago
- konha 3y agoI recently reevaluated my approach to identity & recovery across all the services I rely on and it’s a mess. Apple and Google both provide sensible security settings but you can only guess how recovery might work if you are locked out of your account from their docs. Even with their advanced security programs (requiring a hardware token) I’m not entirely sure that I’m not defeating the whole purpose of these measures by putting a mobile number in my account that can be sim swapped. On the other hand I’m also not entirely sure if I could recover access from what I think I’d need to provide to prove my identity (recovery codes, trusted contacts, …) I get why they might not want to lay out the whole process and every heuristic they use, but it’s not really reassuring.
- AdamN 3y agoIt's a good callout and I think these things should be documented just so security researchers can expose flaws in the process publicly. Basically, these companies have unlock keys for our accounts and we don't know enough about their internal processes to know how secure we are from social engineering attacks or internal threats.
- ignite 3y agoGoogle recovery is a disaster. I lost an account that had a recovery email. I got locked out of the account, and it said the recovery email wasn't enough! WTF!? That's exactly what it is for. So, you can lose your google account, even with recovery set up.
- stacktrust 3y agoDear Apple, to avoid passcode leakage to human observers and cameras, can we please have an option to disable keypress highlights and transient display of passcode characters? This lock screen behavior could be dropped when "Lockdown" mode has been enabled. https://apple.stackexchange.com/questions/217704/disable-display-of-passwords-on-an-iphone https://apple.stackexchange.com/questions/217704/disable-dis... > This transient display lasts 3 seconds to avoid too big a security problem. But this is still largely sufficient for anyone behind you to read it really easily. Moreover this transient display can be easily captured by any camera
- jrootabega 3y agoUsing phones as all-powerful fallbacks is great when you're at home or the office, and wondering if your computer or online accounts are being compromised. Not when the phone itself could be compromised (physically). This sounds stupid to say because it is - stupid-ly obvious. Major phone OS makers (all, what, 2 of them?) need to allow you to have at least 2 authentication paths - one when you are in a physically secure location, and one when your phone could be snooped or stolen. It's a fundamental need for phones. To mitigate the problem of muggers demanding both codes, they should also allow location-based locking, where you could tell the phone to only allow the trusted functions to be accessed at certain GPS coordinates.
- CatWChainsaw 3y ago>This sounds stupid to say because it is - stupid-ly obvious. But since it is also stupidly profitable, it's a problem without any solution. In the US, phone numbers are now as important as social security numbers, in that you need one to access a bunch of online services. That so much else is attached to that phone number and that the phone is its own weakness is unforgivable. I worry, however, that the mitigation will come in the form of tying identity into the phone to an even greater degree.
- jrootabega 3y agoWe've had a misunderstanding here. I think there is a clear improvement: a set of phone credentials that you use in public situations where you might be snooped or robbed. Those credentials can only let you do limited things, and most certainly would not be allowed to modify device or account security.
- CatWChainsaw 3y agoYour original comment was unclear on what the differing credentials would be used for, and it's not a bad idea. It does depend on people being conscientious in public and using the passcodes appropriately, but programming can't mitigate that much. I'm more concerned about how much a phone is expected in the first place, for more and more things. Last year I went on a trip with some friends, and half of the places we went required apps for tickets or even parking, and even a hotel we stayed at was strongly pushing an app. If I'm flying somewhere, I still get a printed boarding pass because I don't want my phone to be the single point of failure that prevents me from flying if a freak accident happens between check-in and the gate.
- fori1to10 3y agoIsn't it a good idea to just set your passcode to be the same as your Apple ID password?
- zamnos 3y agothat's a bad idea. When face id unlock fails, which it will, you then gave to type it out in front of nearby people, which is what this attack is about. secondly, it's a pita to type in a properly secure password every time you want to get into your phone.