thomas_r. wrote:
I think you need to do more research about how this works:
http://www.cultofmac.com/280450/heres-easy-hack-past-apples-activation-lock-miss ing-iphone/
The person wanting to unlock the phone must be in possession of the device. They need not be in possession of the server providing the hack, but the server cannot do the work by itself. This is not related to the Oleg Pliss hack.
If the hacker can achieve some kind of DNS poisoning attack that is, for whatever reason, predominantly affecting Aussies, then there would still be no need for doulCi to be involved. The hackers would simply capture Apple ID credentials and attack the phones through Find My iPhone, as has been stated.
Thanks for your reply, in fact the website article you point too helps to enforce my point. In step 4 of the website article,
"4) After the DoulCi servers have spoofed the activation request, the iPhone is good to go as though it has been authenticated with the owner’s Apple ID login. Sort of…",
The device is unlocked with the original owner's Apple ID. The doulCi code could be modified to apply activation lock, in my opinion.
Please do not change the context of your original argument "That hack requires the hackers to have the devices being unlocked in their physical possession." to
"The person wanting to unlock the phone must be in possession of the device."
I already understand this and perhaps you do too, but you did not originally word your reply that way. I am not considering the people who want to unlock locked devices to be hackers, just users, whether they are legitimate or nefarious. I consider the hackers the guys who did the work to write the code that allows them to unlock these devices.
You wrote "Due to the methods used, it cannot be applied remotely, and cannot be used to remotely lock devices."
Once again I believe you arre incorrect, how do u think activiation lock works in the first place, by sending a valid remote code via wifi, cellular or even cable to your device running the find my device services to lock it. If the device is not running the service then AFAIK this will not work. Thus if a device is communicating thru a spoofed server, the activation lock code could be injected and the device will accept it, same concept as what the doulCi code does. The biggest difference would be that the people seeking to unlock phones are intentionally going to a spoofed site, where as, the others are most likely accessing a spoofed site without intention.
I did not say doulCi needs to be involved, but that someone could have used their code and modified it, thus it is not doulCi doing the hack.
Hopefully it will come out soon as too how this hack was made possible. I currently believe that the doulCi code was modified to propogate the Oleg Pliss hack; however, I could be proven wrong in the future.