9 ms·
Thieves took their iPhones. Apple won't give their digital lives back
- nashashmi 1y agoMy cousin’s phone was stolen in San Francisco. My mom’s phone was hooked up to the same account. Somehow the thief was able to change the account password and email account to something else. Now my mom cannot reset her phone because she doesn’t have access to the thieves account.
- lxgr 1y ago> Somehow the thief was able to change the account password and email account That would be the fact that Apple lets anybody that knows the passcode reset the iCloud password as well, without any further authentication. And the passcode can be shoulder surfed by the thief... "Stolen device protection" was developed as a response to a wave of such thefts: https://support.apple.com/en-us/120340 https://support.apple.com/en-us/120340 It seems like a good step forward but still not perfect, and I believe it's not on by default. On the other side, with Advanced Data Protection, it seems shockingly easy to permanently lock oneself out of an iCloud account: As far as I understand, there is absolutely no way to recover an account protected that way if the recovery code is lost – not even by deleting all data currently stored on it and starting from scratch (e.g. from a local backup). Given the fact that an iCloud account doesn't only contain a big pile of data, but access to some purchased products and services (subscriptions, app purchases, iTunes songs, the Apple Card etc.), that seems like a pretty big oversight.
- XorNot 1y agoAdmittedly we in security do a very poor job on equipping users with useful threat models: i.e. the number of times people either don't turn on any sort of security, or turn on extremely aggressive security but don't write down and store a recovery code is too damn high.
- crote 1y agoAnd it's made even worse by companies not wanting to deal with meatspace. Secure account recovery isn't too difficult if you're willing to do ID verification in physical stores, but no tech company wants to do that.
- nativeit 1y ago> That would be the fact that Apple lets anybody that knows the passcode reset the iCloud password as well, without any further authentication Doesn't this require at least one other device to allow access and provide a one-time code? I can't log in to iCloud in a browser, update payment information, or do anything even remotely sensitive with just one device and my screen lock mechanism(s). EDIT: I stand corrected. On a device that's designated as "trusted" you can indeed change the password using only the screen unlock using the instructions at https://support.apple.com/en-us/102656 https://support.apple.com/en-us/102656
- seec 1y agoIn the end, locking a hardware device to an online account is just stupid. They marketed it as a tool to prevent theft (and recover if lost) but in reality, it has not prevented theft at all (if anything it has increased as the phones value has ballooned). Apple is the only one who truly profits the most from this "innovation". I have had an iPad stolen, and while I could track, it definitely didn't make any difference.
- jbombadil 1y agohttps://archive.is/1NMCR https://archive.is/1NMCR
- mmmlinux 1y agoThis sounds a lot like "I forgot my ultimate recovery password, but its someone else's fault."
- bell-cot 1y agoYes. But in general, the way that most humans "naturally expect" such things to work is simply incompatible with the usually-extremely-convenient nature of computer accounts and cloud services.
- throwaway48476 1y agoThen it is too convenient.
- throwaway48476 1y agoA security model that the user does not understand and contains traps is not a good security model.
- Hizonner 1y agoOK, but what model would you suggest? Apple has no adequate way to actually verify who anybody is without (a) forcing them to physically visit one of a small number of offices (it can't be every store), and (b) probably charging a significant fee to cover the cost of doing real verification. And even that demands assuming that the identifying information on the account is right.
- wmf 1y agoThe person in the article who has their whole professional life in a stolen Apple account would probably be happy to visit Apple HQ in person.
- throwaway48476 1y agoFor account recovery in store verification is viable. They're already collected data on their customers via payment processors. I would also force users to watch a video explaining the security features and quiz them before turning them on. You can't expect users to immediately understand how the security model works.
- crazygringo 1y agoI'm curious why Apple has let it get this far that court cases are underway and WaPo is writing an article about it. What's in it for Apple? Surely it's easy enough to define some kind of verification process based on various pieces -- phone number, credit card, purchase receipt, etc. -- and requiring a police report to be filed or something. And this isn't like Google or Facebook where accounts are free, preventing manual account recovery from being scalable. People spend thousands of dollars on Apple devices across phones and laptops and more. People who don't spend money on Apple generally aren't keeping their data in iCloud. I'm confused because it seems like the rational, profitable thing for Apple to do here is to have these procedures for account recovery. So what's stopping them? Is there some kind of huge liability question if they ever facilitate giving access to the wrong person?
- wmf 1y agoIf Apple can unlock the account from your stolen iPhone they can also unlock your account for the gestapo. Whether it's worth throwing normal people under the bus to protect a few dissidents is a matter of values on which people are going to have differing opinions of course.
- Forgeties79 1y ago>to protect a few dissidents Your opinion seems to be to trivialize how important this can be, which fine you do you, but I think saying it only protects "a few dissidents" is a bit ridiculous. Every protest I've filmed at I hit the lock button 5 times so it forces a passcode. I feel secure knowing the police can't just take it and start scrolling - they need a warrant or they're bust. You don't have to be a dissident to need your privacy.
- SR2Z 1y agoI think the point here is that either Apple has the technical ability to access your account (in which case they will be forced to do it by the government regardless) or they don't (in which case this lawsuit is ridiculous). The middle ground option where Apple has the ability to do this but is also somehow able to take a stand against the government is kind of difficult to support, because it doesn't make much sense.
- alabastervlog 1y agoIt took me a minute to figure out how this works, but it must have something to do with using a "lost password" email reset on the iCloud account, and having the relevant email account logged in (or saved to the password manager) on the phone itself, so that all you need is the passcode to get into the iCloud account. Something like that?
- JKCalhoun 1y agoI still can't figure it out. My daughter had her iPhone stolen in L.A. — she immediately wiped it remotely. The thieves were unable to access it. I got her a new iPhone pretty fast (the budget one) and she was back in business, back in her iCloud account. (She was one of those that saw her device head to Asia. She got a handful of text messages pleading with her to remove the stolen device from her account but she ignored them.)
- alabastervlog 1y agoYeah, that's why I'm having to think at it some to figure out what's going on here. Usually I need my iCloud password to do anything related to that account, so I guess they're using some kind of iCloud password reset bypass that relies on the phone having access to necessary reset-related accounts (like email—though, IDK, I don't think I've ever tried to "lost password" reset my iCloud account, so I'm not sure if even that's enough)
- wmf 1y agoYou got lucky with dumb thieves.
- Mystery-Machine 1y ago> she immediately wiped it remotely > She was one of those that saw her device head to Asia What, the guy just jumped into the Pacific and started swimming?
- justjonathan 1y agoI believe “She” here refers to the original owner (the victim). Apple offers a feature to remotely wipe your device if lost, and that was what I understood the owner to have done. I’ve done the same thing for a stolen iPhone.
- tacker2000 1y agoWhy should Apple open this can of worms and give users access to locked out data. How would this process even work on a larger scale? In the end if you dont backup your data locally, then its not your data and you risk losing it. If your business shuts down because you lost your phone its your own fault for not mitigating this type of risk enough.
- mingus88 1y agoHave you ever tried to fully backup data from iCloud? I try to do it every month because I am that type of techie. They don’t make it easy. For photos, i have a 2TB family plan. There is no export functionality I can centrally backup my families photos and shared albums The supported way to do this is to use a Mac, force it to store all images locally in settings, then highlight all your albums and File->export This takes hours. I need to stay connected to my network drive because I don’t have 4TB of local storage on my laptop. If there is a failure it’s game over. You can’t resume or even know what failed. There is a tiny progress bar icon to work with. That’s all iCloud Drive? Same thing. You need to force it to sync all your files, and there is no way to know if it’s hung or what. You can’t do this as family account owner for everyone. What about all that app data that is saved to iCloud? I don’t even know how to access that to back it up. Apple makes many things very easy and other things practically impossible. Backing up your entire iCloud data for disaster recovery is one of those things that’s basically impossible.
- deadbabe 1y agoThis isn’t that hard, you can just automate this with a script and cron job running on a cheap Mac mini.
- monster_truck 1y agoI've found it much easier to request a copy of my data and download it all in 25gb chunks. It's still not great, the download speeds are extremely slow and they are prone to failure. For being something that I (used to) pay for, this was one of the reasons I stopped.
- abetancort 1y ago
- JCattheATM 1y agoNot exactly helpful, but I have little sympathy for people who put their digital lives in the control of a free service from a company, that, frankly, doesn't care about you at all - 'consumers are the product', etc etc.
- voidspark 1y agoIt's not a free service. One of them had a 2TB+ iCloud account. That has a monthly cost. Not free. The free plan only gives you 5GB storage. Apple is not an advertising company. We pay for the phone and we pay for iCloud.
- ddtaylor 1y agoYou pay to rent the phone I'm pretty sure.
- voidspark 1y agoI don't know what you are talking about. You can buy an iPhone. They sell 200 million iPhones every year. Just go to the shop and buy one.
- JCattheATM 1y agoIf you own it, you can put whatever apps you want on it, right?
- eesmith 1y agoApple is too an advertising company. https://www.wired.com/story/apple-is-an-ad-company-now/ https://www.wired.com/story/apple-is-an-ad-company-now/ > Oct 20, 2022 - Apple Is an Ad Company Now > There’s a side to Apple most iPhone owners don’t know. There's Apple the hardware company, the one that has spent the past several weeks showing off new phones, a more rugged Apple Watch and some confusing new iPads. Then there’s the other, quieter Apple, focused on something of a dirty word: advertising. And that part of Apple is getting bigger by the day. https://appleinsider.com/articles/25/04/14/apple-rebrands-its-advertising-business-as-apple-ads https://appleinsider.com/articles/25/04/14/apple-rebrands-it... > Apr 14, 2025 - Apple rebrands its advertising business as 'Apple Ads' > As Apple expands its advertising business, the company has renamed its former "Apple Search Ads" to "Apple Ads," reflecting the expansion of ad placement. > Previously, when a business bought ads on the App Store, they would be suggested at the top of the search screen. In 2022, Apple began expanding its advertising practices adding slots in the Today tab and in the "You Might Also Like" slot below individual app listings.
- betimsl 1y agoApple’s encryption, is designed with end-to-end encryption for many types of data. Some facts: Only the user's devices hold the keys to decrypt the data. Apple cannot decrypt it, even if served a subpoena. Apple chose privacy over convenience. Sue all you want, you're going to lose.
- lelandbatey 1y agoRead the article, that's not true by default, the only way you get that level of cryptographic protection is if you enable "Advanced Data Protection". None of the people in the article did that, all of them can trivially prove they are who they say they are via government documents, Apple could decrypt their data and return it, but Apple is refusing to do so.
- betimsl 1y agoIt's simply not Apple's responsibility. Person's data, their responsibility. Any other way and people lose trust in Apple which BTW they protect it by any means. Trust. Instead of wanting something impossible, accept the reality.
- lxgr 1y agoThen delete that data and let the user start over. How come Apple gets to hold iTunes purchases (apps, movies etc.) and somebody's email address hostage just because they also happen to store some end-to-end encrypted data on the same cloud account? Just imagine Google letting people "brick" their accounts because they have a password protected PDF in their Google Drive they don't remember the password for... And that's to say nothing about the not end-to-end encrypted data, which is still the default for most things in iCloud accounts (without ADP enabled).
- deleted 1y ago[deleted]
- anonym29 1y agoTrust the megacorporations. Trust your government. "It works well for everyone else, why are you being so weird by not doing what everyone else does?" Grant the megacorporations control over your entire life. Your government will protect you from the megacorporations. "Self hosting? Open source? Linux? You're weird, just get an iPhone." The megacorporations never make mistakes. The government never makes mistakes either. "What's wrong with you? Are you seriously too poor to afford an iPhone? Get a blue bubble already." The megacorporations never lie to you, they never manipulate you. Even if they tried, your trustworthy government would stop them. This message brought to you by social conformity norms that are most certainly NOT subtly reinforced by the same billionaires and trillion dollar companies that benefit from them. /s
- encom 1y agoSocial Credit Score++
- someonehere 1y agoI don’t trust Apple for this exact reason. For those interested in the silver bullet to backup iCloud. Get a Mac mini with enough space for your photo library and wire it into your network. Sign into iCloud. For photos open the app and change the settings to store full res photos locally. Enable iCloud desktop and documents sync. Two options 1 - Sign up for Backblaze and ensure you map the folders from iCloud and photos that are being synced to the device. Let it run and do a full sync. I use this option. 2 - Buy an external drive with a lot of space and use Carbon Copy Cloner to mirror your drive. The caveat is your at the mercy of a local copy that a home fire or electrical incident can destroy. I like Backblaze for the sheer constant syncing it does and they allow me to set up an encryption key so they don’t have access to my data.
- weikju 1y agoI do that, and I'm also planning to use icloud photos downloader [0], a python script to download photos, so I can download those directly on another machine running Linux. [0] https://github.com/icloud-photos-downloader/icloud_photos_downloader https://github.com/icloud-photos-downloader/icloud_photos_do...
- gu009 1y agoIs there a consensus on what you should actually do in the event your phone is stolen? Someone I know's phone was stolen and I helped them through it (remotely) in real time, and I remember looking up what to do and having to sort through a lot of straight up bad advice, including articles that seem naive as to what actually happens in real life when thieves steal a phone. In this case, the phone was marked as lost immediately, but a couple of days later the thieves started trying to reset the password on the owner's iCloud account using various methods, the first of which produced 1st party push notifications asking to confirm the account password reset that were sent to the owner's other signed-in devices that were still in their possession. In the moment, it would be so easy for a confused & stressed person to accidentally or mistakenly tap those notifications and enable their own account hijacking. The thieves then evidently called Apple Support and tried to get the iCloud account password reset over the phone, but by this point the owner had already gotten a new phone and SIM for their phone number, which meant that Apple Support's 2FA SMS codes were received by their replacement phone (in their possession) instead of the stolen phone (in the thieves' possession, and which no longer had cell service). It seems like if they had delayed in getting their new phone and left the stolen device with functional cell service, the hijacking might have succeeded at this point. Apple's own "What to do if your iPhone is stolen" page [0] has no info these tactics that are actually used in the moment by phone thieves. That page does link to a page about social engineering scams [1] but approaches that in a general sense. I think Apple's way of handling it should be way more intuitive. For example, they should differentiate between phones that are lost and stolen. If your phone is lost, you want to protect against someone finding it and being able to access the phone's contents. If your phone is stolen, the thieves will most likely try to hijack your iCloud account as well, and they'll try and social engineer both the owner and Apple Support to do so, so add a "Mark as Stolen" option that also adds protections against iCloud account hijacking. [0] https://support.apple.com/en-us/120837 https://support.apple.com/en-us/120837 [1] https://support.apple.com/en-us/102568 https://support.apple.com/en-us/102568
- Aloisius 1y ago> In the moment, it would be so easy for a confused & stressed person to accidentally or mistakenly tap those notifications and enable their own account hijacking. That won't give them access. When you respond to the reset password notifications, it then asks for a new password on the same device you responded on, not on the device that requested the reset.
- QuiEgo 1y agoThe 3-2-1 rule is wisdom of the ages. The "2" in the rule is all about having your data in at least two different types of "media". A modern read on this is anything tied to the same account counts as the same type of "media". So, you need at least one copy of your data not tied to your Apple ID. A few things you can do here: - Own a mac with enough storage to download your entire iCloud / Apple Photos data set. Configure your mac to do so. Your mac is still activation locked to your Apple ID though, so backup that local copy through Time Machine or the service of your choice (e.x. Backblaze). A NAS is very helpful to automate this. - Use app(s) on your phone that will copy of your data to the location of your choice, such as Photo Sync.
- ralan5515 1y ago[flagged]
- theklahomate 1y ago[dead]