Security firm says iPhone bug can thwart remote wipe

When you are at or near the top of a market, you become a target. Microsoft lived that life for many years. Now, the emergence of the mobile market has shifted the spotlight, as well as the security risk, over to iOS and Android. Though the rigor of Apple’s app inspection and certification process does keep the iOS app ecosystem significantly safer than Android, iOS devices are just as highly valued a target for hackers.

The point is, these attacks are going to keep coming. Apple’s job is to keep tweaking their processes to keep the bad guys at bay. So far, Apple has done their job well.

This new attack takes advantage of a flaw in the “Find my iPhone” process. The video below does an excellent job laying out the scenario. In a nutshell, the thief steals an iPhone and immediately turns on airplane mode to prevent the iPhone from being remotely wiped. This gives the thief enough time to break into your phone and use your credentials to reset your Apple ID password, take control of your phone, Apple account, and other accounts.

The video also offers 5 suggestions for fixing this problem:

  1. Apple should make Airplane Mode inaccessible from the lock screen by default and require a passcode – not just a fingerprint – any time Airplane Mode was activated or the SIM card was removed
  2. During Apple ID creation, Apple should warn users not to store credentials to password-reset accounts on their registered devices

  3. On Find My iPhone, Apple should differentiate between likely-temporary and likely-permanent loss scenarios, and in the latter, should advise users to immediately revoke the devices’s access to all accounts it has credentials for, e.g. email-, social media-, and telephony accounts

  4. The iOS lock screen should not display whether the phone is protected by a simple 4-digit PIN or a more complex passcode, and on devices with Touch ID, it should not display whether fingerprint authentication is being used

  5. Upon reconnecting to the Internet, iOS should not allow email retrieval before the device’s wipe- or don’t-wipe status can be retrieved

As with every other legitimate problem of this nature that Apple has faced, the problem has a fix. No doubt, Apple will do their analysis, find the best possible fix, and roll it out quickly so we can all sleep safely again.



25 thoughts on “Security firm says iPhone bug can thwart remote wipe”

  1. Not a very realistic attack, most thieves out there don’t want to spend an hour working over one phone and/or are not equipped to do something like this.

    The suggestion to restrict airplane mode is more a nuisance for genuine users than for a determined attacker. Surely those who have access to a hi-res fingerprint lab equipment will also have access to mobile radio jammers.

    Finally if you’re still concerned just enroll your pinkie for Touch ID. You rarely or never use it anywhere else so you won’t leave any prints that can be lifted.

  2. Was anyone be able to hack Touch ID in a REAL situation? Not on a lab? Meaning you hunted for a REAL fingerprint and successfully hacked the 5s? Did anyone achieve this yet?
    I guess the Paranoid Mode is actually the answer for the guy who did the video.

  3. What you’re doing is called “moving the goalpost”. First, Apple fans said that you’d need a living finger to unlock Touch ID. Now that this turned out to be completely false, you’re just pretending that the goal really was much further away.

    When people hack a phone with a stolen fingerprint (which is technically no different from doing it with an intentionally created fingerprint), you’ll just find something else that you don’t like.

    You know, maybe it’s not them. Maybe it’s you.

  4. Yeah, and after you bully Apple into requiring a password to turn on Airplane mode, some “security expert” is going to … shack … horror… discover that Find my Phone/Remote Wipe won’t work if you power off the iPhone either, and passwords will now be required to power off.

    This will result in most users who wish to remain sane turning off all security. End result: less security for a majority of users. If you want a “paranoid mode”, sure BUT HAVE IT OFF BY DEFAULT. And leave my Airplane mode alone!!!

  5. No, it’s not moving the goalposts. The living finger comments were just to rebut the idea that a thief would just cut off your finger to unlock your phone. It still does need a living finger – the one below the latex copy. Your dead finger would not work except to make a copy, so it’s not completely false.

    While the scenario in the video is possible, it’s only barely so. Thieves get 10 chances to guess your unlock code, which even if it’s only 4 digits, is a long shot. They also only get 5 chances to unlock with a fingerprint before the phone requires the passcode. Again, it’s possible, but for the events in the above video to happen, it would be a series of perfect events for the thief. Every step would have to go nearly perfectly, and in most cases would be unlikely. This is also assuming that your average iphone thief has a lab and the know-how to do all these things perfectly.

    It’s also extremely easy for users (disable Control Panel on the lock screen, use pinky, etc) or Apple (require the remote wipe info before getting mail) to fix to make the video impossible. It’s not like Apple implemented a facial unlocking scheme that could be fooled by your publicly available Facebook profile image. 😉

  6. On Android you just steal the phone and you’ll have everything. The video would be too short and not very interesting.

    Actually not even steal the phone, just write an app that steals the user’s info and uploads it to servers in Russia. Then give it a popular name like “GTA V” on Google Play.

    1. Apple should make control center on the lock screen off by default would solve that for many users.

    2. I will agree that the timing on requiring the password needs tweaking. 48 hours before demands the password just seems to long to me. Either drop it to more like 12 or let us decide.

    3. I rather like the option of when it’s in airplane mode/sim removed. requiring the passcode immediately etc. And I like the suggestion that the software be set that the first thing it does when reconnecting is to check for lost mode etc. And then goes to email etc.

  7. No I don’t believe that anyone has proven that a stranger, using a ‘real world’ print and only a print can break the system.

    An owner, using a pristine print gathered just for his test, applied to a different finger (so still using a living finger that might even be similar to the one registered) did ‘break’ it. And a couple of other folks also using pristine prints have apparently also had some luck.

    But it doesn’t mean that these suggestions aren’t worth considering. Especially the timing and the call out to the server issues

  8. Yeah, the airplane mode change would just be a nuisance. It’s just as easy to shut the phone off and take it to a secure location with no reception. Or wrap it in foil or something.

  9. If this worries you, you can always turn off lock screen access to Control Center until Apple addresses it. This is a minimum inconvenience if you use TouchID since your finger will already be at the bottom of the screen and you can immediately swipe up once the phone is unlocked.

  10. The real problem I see here is that device is able to access the internet and even receive some emails before it receives instructions to wipe itself. This is an extremely dangerous behaviour and I think that this should be stressed much, much more than relative simplicity of fooling a fingerprint scanner. This needs to be fixed asap before everything else.

  11. iOS 7 has a good mix of convenience vs security, want easy airplane mode access via control panel on lock screen, done. Disable for More security 🙂

    Dave Mark contends via twitter thinks disabling control center is a work around, but the ‘bug’ claimed is access to airplane mode from the lock screen.

    The fact that ‘airplane mode circumvents wipe’ merits attention. And it has gotten attention, iOS 7 offers a bevy of higher security choices that you can choose right now, without waiting for implementation of those 5 ‘odd’ suggested fixes.

    Suggestion #2 boils down to not staying signed in to the email accounts that receive reset requests. OK, if you want to implement it yourself, you could decide to only use an email account accessed/protected through 1Password to receive your reset requests.

  12. Requiring authentication for airplane mode must extend beyond the lock screen. What if a thief steals it right out of your hands while you’re using it (and it’s presumably unlocked)? Disabling it on the lock screen is the best interim solution, but it’s not a permanent one.

    Also, this measure should be enabled by default. If you travel or need airplane mode frequently, disable it. TouchID makes authenticating trivial, and worries about its circumvention are pointless in my opinion. If someone wants your information badly enough to fake a fingerprint, they’re probably going to be determined enough to brute force their way in no matter how long it takes.

  13. It’s all about the mix of convenience vs security.

    iOS offers a great default mix right now. If you personally want to choose more, great.

    If you want default security settings address an unlocked iPhone grabbed from your hands, you are wrong.

    But, you can do it for yourself – Set your phone to go to lock screen as often as possible. Disable fingerprint unlocking. Use a super secure passcode. Order a custom case that shorts the phone out if it gets out of iBeacon range.

    Keep & use the phone in a secure bunker, if you insist on addressing every conceivable situation.

  14. You’re only asking for a software changes around ‘airplane mode’ that will give you enough time to achieve a wipe.

    I understand that, but in for a penny in for a pound. Especially when you consider all the millions of people who would ask for just one little thing.

  15. You don’t need to address every conceivable situation. That’s ridiculous.

    My guess is that the number of people who use Airplane Mode so frequently that this would be a major inconvenience is low enough that the default should err on the side of security rather than convenience.

    My friend is a good example of a typical, non-techie user. Her phone was stolen and she did not even know about Find My iPhone. People like her represent the majority of Apple’s users. Is she reading articles about thieves and Airplane Mode? No. And neither are the majority of Apple’s users. The default should protect them so long as it doesn’t cost another portion of the user base too much convenience.

  16. Yes, it is ridiculous to address every conceivable situation.

    Apple may decide that changing airplane mode in the way you suggest is a good move.

    Perhaps putting it & power off under restrictions if it isn’t already there.

    Not as a default. 🙂

  17. You seem to be erring on the side of convenience rather than truly weighing convenience against security. You’re immediately dismissing power-off authentication seemingly without asking questions. Namely, how often would that measure inconvenience users?

    I almost never power off my iPhone; the first and only time I ever powered off my 5 was right before I put it back in its box and started using my 5s. I never powered off my 4S before it was stolen. A friend I just happened to be texting now also has also never powered her iPhone off (she actually didn’t know how haha).

    Two people is hardly a sufficient sample set, but if Apple does the research and we reflect the majority, authenticating before powering off is of almost no inconvenience because it happens so rarely. These are the things Apple weighs when it decides where things should fall on the convenience/security spectrum.

  18. Restrictions tab is the place for all these authentication choices even if most people never use the underlying ability, e.g. Power-off.

    I did think about it when I proposed where power-off authentication should live. 🙂

    But we’re not too far afield of each other, since we’re just discussing defaults/locations of these options.

  19. Right, we generally agree the option should be there, but defaults are a very important part of the discussion as many – if not most – users never change them. My mom’s iPhone home screen had all the system apps in their factory default positions for months before she realized she could move them.

  20. If you have Apple’s two-step verification enabled, then this attack will fail because you would be prompted for your two-step verification code when attempting to reset your iCloud password.

  21. Very good point.

    The ‘attack’ on the video is a whole series of different procedures bunched together to make the result as worrisome as possible.

    Thank you for reminding me about enabling two-step verification on iCloud.

    It’s really important to keep control of iCloud and associated iOS devices.

  22. The only problem with Apple’s two-step verification is that it’s currently only available in a very limited number of countries

Leave a Reply

Your email address will not be published. Required fields are marked *