TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

The ability to reset your iCloud password with a keycode is a security flaw

16 pointsby gkielyover 2 years ago
I just wanted to share this in the hopes that someone at Apple sees this and to make others aware of the scam.<p>A friend of mine over the weekend mistakenly tried to help someone and they saw him enter his passcode.<p>The thieves took his phone and then shortly after his iCloud password was reset, making it impossible to access the phone or disable the phone via find my phone.<p>The perps then had access to all his accounts, started making fraudulent charges and likely accessing his data.<p>This was a huge privacy breach for him and apple is unable to do anything other than reset the iCloud password, which takes 24 hours. I am unsure if this will rectify the issue.<p>My friend made a mistake but nonetheless this could&#x27;ve been prevented by a simple security question or 2 factor authorization from another device.<p>I&#x27;ve included a number of other occurrences of this happening below.<p>I call on anyone who works at Apple to raise this issue up the chain of command.<p>And also to reaffirm the advice to never give your phone to a stranger, which I unfortunately had not given to this friend.<p>People who have had this issue:<p>https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;applehelp&#x2F;comments&#x2F;t7hbxm&#x2F;iphone_stolen_and_icloud_password_and_backup&#x2F;<p>https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;ios&#x2F;comments&#x2F;womh4g&#x2F;iphone_stolen_icloud_password_and_trusted_phone&#x2F;<p>https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;ios&#x2F;comments&#x2F;ob19kv&#x2F;iphone_stolen_apple_id_hacked_and_password&#x2F;<p>https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;applehelp&#x2F;comments&#x2F;wquqr8&#x2F;my_iphone_was_stolen_and_it_seems_my_icloud&#x2F;<p>https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;ios&#x2F;comments&#x2F;pp0dua&#x2F;iphone_stolen_thieves_changed_my_apple_id&#x2F;<p>https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;applehelp&#x2F;comments&#x2F;wrjif9&#x2F;iphone_stolen_with_passcode_and_apple_id_password&#x2F;

3 comments

warning26over 2 years ago
Definitely a good reminder to use a secure passcode for your phone. (And to definitely avoid the 4-digit pincode.)<p>I suppose realistically since your phone is almost always the &quot;second factor&quot; in 2FA, if your phone is stolen+compromised you&#x27;re completely screwed. Do there exist 2FA solutions that don&#x27;t become 1FA if it&#x27;s just your phone?
评论 #33588768 未加载
gkielyover 2 years ago
After much digging, here is a way to prevent account changes from the device.<p>Steps:<p>1. Settings &gt; Screen time &gt; Use screen time pass code &gt; Enter a different passcode to your main one that you will remember<p>2. Settings &gt; Screen time &gt; Content &amp; Privacy Restrictions &gt; Scroll down to Account changes &gt; Don’t allow<p>This prevents account changes from the device, unless you have the second passcode.<p>This would not prevent a thief who was aware of this (they could attempt to disable screen time then request the second passcode), but it would prevent a pickpocket who happens to see your passcode being entered from changing your iCloud account details.
评论 #33607415 未加载
ojkellyover 2 years ago
Reading through this and those links this seems like a significantly harmful vulnerability that’s being actively exploited.<p>I can’t imagine many people who _wouldn’t_ give up their phones passcode at gunpoint.<p>What options do we have to protect against this?<p>If your life is threatened a dummy passcode is likely to aggravate and make things worse.<p>Would MDM enrolment help here?<p>What are the gains here for the thieves? Hardware that can be sold when unlocked, which needs iCloud changed — which the OP points out can be changed with just the device passcode.<p>Apps with FaceID (ie maybe your bank) would be safe, but they could also just force you to look at your phone.<p>Could there be a default 1 week countdown for removing activation lock? And automatically enable and broadcast via find my iPhone during that time?
评论 #33593082 未加载