Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

BlueMoose

macrumors regular
Original poster
Sep 23, 2019
242
122
if data on iPhone is encrypted, is it necessary to remotely erase my iPhone if it's ever lost or stolen?

can the person who found or stole my iPhone somehow get access to my data? (unless he/she managed to guess my 6-digit PIN code within the first few tries?)
 
Yes.

A couple of levels of encryption going on. You have at-rest encryption (eg. full disk encryption, unreadable when powered off). But at the app level, things start getting a bit more complex. Basically, depending on the app and what protection class they use, data could always require the device unlocked, data available after first/one unlock, or data never protected.

So, you start getting into things like the news stories re: forensic tools that can scrape data off the device by exploiting bugs in OS, jailbreaking, etc. allowing some access to get at your data. Or try breaking your PIN.

Years ago, there was a bug with "erase after 10 attempts" where if one powered off/on the device (iirc) after 9 attempts, you got 9 new attempts.

6 PIN is ok, 6 character or more would be better.

Depending on how your lock screen is configured, could be giving up personal information, temporary authorization codes/2-factor codes.

Now, rando on the streets will probably not be able to get into it, but never know who might get their hands on it after the rando.

If you lose the device, you do want to sign into appleid.apple.com to remove any Apple Pay information, possibly remove from your account (ie. not have it as a trusted device), not much more effort to go to Find My and erase device.
Heck, erase the device via Find My and you've taken care of the other stuff in one step.

As the old computer nerd saying goes, if it's accessible/usable, it's vulnerable. There are always bugs, holes, exploits.

If you want to get into the weeds re: Apple device security, a great, long read can be found here. Link to the PDF at bottom of the page (and page 75 in the PDF is where iOS protection classes get discussed).
 
  • Like
Reactions: tedley
If someone were to get lucky and guess your 6 digit PIN, said person would have access to a lot of the data on your phone. In my opinion, it is best to turn on the option that automatically erases your phone after 10 failed attempts at the passcode.

Settings > Passcode > scroll to the bottom option Erase Data and toggle on.

Edited to add: I use a 12 digit passcode for extra security. No way someone is going to be able to guess it, much less in 10 attempts or less.
 
Last edited:
Don't set a 6 digit passcode that lets you in after entering the last digit, set up a custom passcode that requires the user to hit "OK" at the top of the login screen after entering the correct passcode. Passcode can then be of any length too. That way the intruder doesn't know how many digits the passcode contains so guessing it in 10 try's is for all intents & purposes impossible
 
  • Like
Reactions: NoBoMac
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.