[HN Gopher] iOS 17.3 to Include Stolen Device Protection Feature
       ___________________________________________________________________
        
       iOS 17.3 to Include Stolen Device Protection Feature
        
       Author : ls612
       Score  : 29 points
       Date   : 2023-12-12 18:44 UTC (4 hours ago)
        
 (HTM) web link (www.wsj.com)
 (TXT) w3m dump (www.wsj.com)
        
       | allears wrote:
       | A non-paywall link would be appreciated.
        
       | zshrc wrote:
       | https://www.macrumors.com/2023/12/12/ios-17-3-stolen-device-...
       | 
       | For those who don't want to pay. Goes over the WSJ in depth lol.
        
       | jerlam wrote:
       | From the MacRumors article:
       | 
       | > For especially sensitive actions, including changing the
       | password of the Apple ID account associated with the iPhone, the
       | feature adds a security delay on top of biometric authentication.
       | [...] However, Apple said there will be no delay when the iPhone
       | is in familiar locations, such as at home or work.
       | 
       | It's fascinating how the device is using location as another
       | security factor.
        
         | hnburnsy wrote:
         | > From the MacRumors article: > > > For especially sensitive
         | actions, including changing the password of the Apple ID
         | account associated with the iPhone, the feature adds a security
         | delay on top of biometric authentication. [...] However, Apple
         | said there will be no delay when the iPhone is in familiar
         | locations, such as at home or work. > > It's fascinating how
         | the device is using location as another security factor.
         | 
         | Another vector for law enforcement or state actors to request
         | private information. We will see warrants for all users who
         | have these coordinates near their "familiar location"
        
           | toomuchtodo wrote:
           | Why would they go to Apple when they can simply go to your
           | mobile service provider?
           | 
           | https://www.vice.com/en/article/m7vqkv/how-fbi-gets-phone-
           | da...
           | 
           | https://propertyofthepeople.org/document-detail/?doc-
           | id=2108...
           | 
           | > The presentation provides more recent figures on how long
           | telecoms retain data for. AT&T holds onto data such as call
           | records, cell site, and tower dumps for 7 years. T-Mobile
           | holds similar information for 2 years, and Verizon holds it
           | for 1 year.
           | 
           | This might not apply if your opsec avoids mobile providers
           | and you're running only wifi, but that seems like a rare edge
           | case. This fight is fought in court and legislation
           | unfortunately.
        
           | olliej wrote:
           | How would that warrant work? It would require apple being
           | forced to send a software update that told every phone about
           | every geofence and then have those phones report back if they
           | intersected.
           | 
           | _or_ they can just ask the carriers which cellphones are
           | where, which they are already able to do despite it being
           | fairly questionable to me.
        
             | manwe150 wrote:
             | I assume the query from Apple to the phone is not "are
             | these (potentially spoofed) coordinates X trusted", but
             | rather "is your current location trusted". The later
             | doesn't seem like it would leak any useful information to
             | law enforcement, as well as being harder for an attacker to
             | forge during the password-change process. The easier
             | software update for Apple, technically speaking, then would
             | probably just be to have a particular phone by a particular
             | user continuously report its particular location. It seems
             | doubtful Apple would currently add such a backdoor though.
             | 
             | However, the radio towers need to triangulate your location
             | to be able to communicate with you, which is not
             | questionable, since that is their purpose. But then storing
             | that information for any non-trivial length of time seems
             | fairly questionable to me too.
        
       | toomuchtodo wrote:
       | https://archive.today/IFOmd
        
       | tinus_hn wrote:
       | A delay for all these things after a password reset should have
       | been there from the start and should not require an iOS upgrade
       | as it should be server side.
        
       ___________________________________________________________________
       (page generated 2023-12-12 23:01 UTC)