iPhone security when stolen

HI all:


Very recently I was a victim of violent theft, where the thieves demanded I gave them the passcode for my FaceID enabled iPhone, which I did.


I was surprised to see how easy it is to access certain private information that can endanger your life!!! Once they have the passcode, they can register themselves into FaceID, and with that, have access to apps that authenticate and authorize via biometric information (the same for Fingerprints)


iOS11 and iOS12 have a massive security issue with this!!! I sooo missed an extra second level passocde (as when there was the "old" restriction one required to make certain sensitive changes back in older versions of iOS)


Yes, there is "Lost lock" and "Remote Erase"... But until you make it home, or find a laptop to logon to iCloud to perform these taks, the thieves could have already accessed to very sensitive information like your full name, address (which is available in many apps just by opening them) , email addresses used in the system (like your Cloud ID) , other emals and account added to your iPhone(like for email and calendars) , photos that you can make of certain documents , and so on, so on.


My point being , and this is towards Apple, thieves are no longer just "stealing the phone" thay are demanding by very violent means -which clearly theaten life- the main passcode.


For instance, find my iphone (and I measured this) , can be disabled in lest than 45 seconds... Just by having the main passcode.


We need (and FAST) to improve and add more layers on the security... Think of what happened to me : " Attacked violently, threatened to surrender the main passcode , the assaltants clearly want to leave quick : What is stopping them from finding more information about me ? The current approach compromises not only my current security, but also all my future one!!!"


Say, one hour until you make it home to trigger Icloud remote erase... Do the exercise , dear reader (and Apple) : Whatever you can access in your phone in that hour is what a violent person can (...and learn about you, risking your property life and family) ...


Scary uh?

iPhone XR, Theft , security

Posted on Dec 3, 2018 1:59 PM

Reply

Similar questions

7 replies

Dec 3, 2018 2:18 PM in response to alelon

I've had iPhones from the beginning, and I'm not aware of any other layer of security to prevent these situations. With the passcode, the device is wide open. They can remove the passcode, or as you mentioned, disable Face ID and/or reset it. If you have setup an app to use Face ID, then yes, they could have access to that as well. The alternative is for you to require logging in with the password for the app each time. But we enable the Face ID for case of access for ourselves. There is nothing more secure than your passcode, and unfortunately, you were coerced into providing that. While what happened to you is unfortunate, I couldn't say there is another layer.

Dec 3, 2018 3:05 PM in response to alelon

Thank you everyone that has commented so far!


Indeed, there is no absolute security, but a mitigation of risks. And that is exactly my point! Sure there can be the scenario of the criminal willing to hold you and torture you. But it is way less frequent than users (like me) being victims of more violent crimes (I decided to write this post after speaking to friends about my experience in cities like NYC, London, Paris and Berlin) , where additional layers can provide additional security and mitigate/reduce the risk.


The reference info shared with me can be found by searching on your favourite search engine "ios 11 security horror story"

Surely Apple can do better? Considering it sells a "luxury" -in terms of value- item, then it needs to understand the unfortunate security risks that come by their intended market owning such a product



Thank you all for the participation, feel free (of course) to add your own.




[Link Edited by Host]

(Thank you host, i just inserted the reference and avoided the direct link)

Dec 3, 2018 2:04 PM in response to alelon

alelon wrote:


HI all:


Very recently I was a victim of violent theft, where the thieves demanded I gave them the passcode for my FaceID enabled iPhone, which I did.


I was surprised to see how easy it is to access certain private information that can endanger your life!!! Once they have the passcode, they can register themselves into FaceID, and with that, have access to apps that authenticate and authorize via biometric information (the same for Fingerprints)


iOS11 and iOS12 have a massive security issue with this!!! I sooo missed an extra second level passocde (as when there was the "old" restriction one required to make certain sensitive changes back in older versions of iOS)


Yes, there is "Lost lock" and "Remote Erase"... But until you make it home, or find a laptop to logon to iCloud to perform these taks, the thieves could have already accessed to very sensitive information like your full name, address (which is available in many apps just by opening them) , email addresses used in the system (like your Cloud ID) , other emals and account added to your iPhone(like for email and calendars) , photos that you can make of certain documents , and so on, so on.


My point being , and this is towards Apple, thieves are no longer just "stealing the phone" thay are demanding by very violent means -which clearly theaten life- the main passcode.


For instance, find my iphone (and I measured this) , can be disabled in lest than 45 seconds... Just by having the main passcode.


We need (and FAST) to improve and add more layers on the security... Think of what happened to me : " Attacked violently, threatened to surrender the main passcode , the assaltants clearly want to leave quick : What is stopping them from finding more information about me ? The current approach compromises not only my current security, but also all my future one!!!"


Say, one hour until you make it home to trigger Icloud remote erase... Do the exercise , dear reader (and Apple) : Whatever you can access in your phone in that hour is what a violent person can (...and learn about you, risking your property life and family) ...


Scary uh?



Sorry this happen to you, but you gave them your passcode to unlock the phone, that what protects your phone from gaining access by a stranger.


There is no Apple here so you can leave them a feedback here Product Feedback - Apple

Dec 3, 2018 2:11 PM in response to razmee209

Yes, and I acknowledge that! But we used to have in previous versions of iOS another layer precisely to prevent these situations, and got removed!. I have had a few chats with security experts in the industry and I did not know this had been massively criticized!!


For instance! One idea!! Adding a policy where a particular section of the phone can onl be "unlocked"/Enabled after X minutes of inputting the correct passcode and secondary passcode. That would buy time until you would get to a safe place and delete the device! or lost lock it!

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

iPhone security when stolen

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.