Hardware

Repairing Your iPhone Home Button From An Unofficial Repair Shop Can Brick Your Phone

Comment

Going to an unauthorized Apple technician to repair your home button can cost you a lot of money. On Friday, The Guardian reported that thousands of iPhone users encountered a mysterious “Error 53” error due to a new security feature to protect your Touch ID data. This error renders your iPhone useless as it bricks it.

If you break your home button and you need to replace it, you’ll want to go to an official Apple Store or an authorized repair shop to avoid the error 53. If a third-party repair shop replaces your home button and you’re running iOS 9, Apple automatically bricks your phone. Once your iPhone is bricked, there’s no way to unbrick it.

I know what you’re thinking: Apple is an evil company and wants to capture all the repairing revenue. Well, not really. There’s a reason why Apple wants you to pay between $269 and $329 to replace your home button, and it’s security.

When Apple introduced its Touch ID sensor for the iPhone 5s, the company needed to reassure its customers. Your fingerprints don’t get uploaded to Apple’s servers. They’re not even stored on your iPhone’s regular storage space. Similarly, you won’t find them in your iCloud or iTunes backup.

Instead, your fingerprints are stored on a secure enclave. The secure enclave is a coprocessor that utilizes a secure boot process to make sure that it’s uncompromized. It has a secret unique ID not accessible by the rest of the phone or Apple — it’s like a private key. The phone generates ephemeral keys (think public keys) to talk with the secure ecnlave. They only work with the unique ID to encrypt and decrypt the data on the coprocessor.

And finally, the Touch ID sensor is paired with the secure enclave for increased security — otherwise everything I just described would be useless. A hacker would be able to replace your home button with a faulty Touch ID sensor to access everything that is stored on the secure enclave, including your Apple Pay details.

With iOS 9, Apple checks that the Touch ID sensor and secure enclave are still intact. If iOS 9 can’t verify the Touch ID sensor, Apple blocks your iPhone with an error 53. That’s why unauthorized repair shops can’t fix the home button. Comparatively, Apple stores and authorized repair shops pair the new home button with the secure enclave so that you can keep using Touch ID after a home button replacement.

And this is where Apple has made some mistakes. The company treats security very seriously but should also take advantage of its own design. The secure enclave works independently from the main processor. If iOS 9 can’t verify the authenticity of the Touch ID sensor, the OS should brick the secure enclave, or disable all Touch ID-related features, such as Apple Pay.

The company shouldn’t prevent you from accessing your precious photos, contacts and apps. Today’s implementation of the error 53 is a bad one, and I hope that Apple is going to fix it in the next iOS release.

And even more important, Apple should have communicated about this “Error 53” when releasing iOS 9.0 — the current support page is not enough. Customers deserve to know what’s happening and why Apple is preventing them from accessing their phones. Otherwise, people will think that Apple is greedy and wants to kill third-party repair shops, which is not true.

According to The Guardian, the issue affects the iPhone 6 and 6 Plus. It’s likely that people using an iPhone 5s, iPhone 6s or iPhone 6s Plus are also affected as these devices also have a Touch ID sensor. iPad users could also face the same issue if their devices have a Touch ID sensor.

Apple sent TechCrunch the following statement:

We take customer security very seriously and Error 53 is the result of security checks designed to protect our customers. iOS checks that the Touch ID sensor in your iPhone or iPad correctly matches your device’s other components. If iOS finds a mismatch, the check fails and Touch ID, including for Apple Pay use, is disabled. This security measure is necessary to protect your device and prevent a fraudulent Touch ID sensor from being used. If a customer encounters Error 53, we encourage them to contact Apple Support.

More TechCrunch

London-based fintech Vitesse has closed a $93 million Series C round of funding led by investment giant KKR.

Vitesse, a payments and treasury management platform for insurers, raises $93M to fuel US expansion

Zen Educate, an online marketplace that connects schools with teachers, has raised $37 million in a Series B round of funding. The raise comes amid a growing teacher shortage crisis…

Zen Educate raises $37M and acquires Aquinas Education as it tries to address the teacher shortage

“When I heard the released demo, I was shocked, angered and in disbelief that Mr. Altman would pursue a voice that sounded so eerily similar to mine.”

Scarlett Johansson says that OpenAI approached her to use her voice

A new self-driving truck — manufactured by Volvo and loaded with autonomous vehicle tech developed by Aurora Innovation — could be on public highways as early as this summer.  The…

Aurora and Volvo unveil self-driving truck designed for a driverless future

The European venture capital firm raised its fourth fund as fund as climate tech “comes of age.”

ETF Partners raises €284M for climate startups that will be effective quickly — not 20 years down the road

Copilot, Microsoft’s brand of generative AI, will soon be far more deeply integrated into the Windows 11 experience.

Microsoft wants to make Windows an AI operating system, launches Copilot+ PCs

Hello and welcome back to TechCrunch Space. For those who haven’t heard, the first crewed launch of Boeing’s Starliner capsule has been pushed back yet again to no earlier than…

TechCrunch Space: Star(side)liner

When I attended Automate in Chicago a few weeks back, multiple people thanked me for TechCrunch’s semi-regular robotics job report. It’s always edifying to get that feedback in person. While…

These 81 robotics companies are hiring

The top vehicle safety regulator in the U.S. has launched a formal probe into an April crash involving the all-electric VinFast VF8 SUV that claimed the lives of a family…

VinFast crash that killed family of four now under federal investigation

When putting a video portal in a public park in the middle of New York City, some inappropriate behavior will likely occur. The Portal, the vision of Lithuanian artist and…

NYC-Dublin real-time video portal reopens with some fixes to prevent inappropriate behavior

Longtime New York-based seed investor, Contour Venture Partners, is making progress on its latest flagship fund after lowering its target. The firm closed on $42 million, raised from 64 backers,…

Contour Venture Partners, an early investor in Datadog and Movable Ink, lowers the target for its fifth fund

Meta’s Oversight Board has now extended its scope to include the company’s newest platform, Instagram Threads, and has begun hearing cases from Threads.

Meta’s Oversight Board takes its first Threads case

The company says it’s refocusing and prioritizing fewer initiatives that will have the biggest impact on customers and add value to the business.

SeekOut, a recruiting startup last valued at $1.2 billion, lays off 30% of its workforce

The U.K.’s self-proclaimed “world-leading” regulations for self-driving cars are now official, after the Automated Vehicles (AV) Act received royal assent — the final rubber stamp any legislation must go through…

UK’s autonomous vehicle legislation becomes law, paving the way for first driverless cars by 2026

ChatGPT, OpenAI’s text-generating AI chatbot, has taken the world by storm. What started as a tool to hyper-charge productivity through writing essays and code with short text prompts has evolved…

ChatGPT: Everything you need to know about the AI-powered chatbot

SoLo Funds CEO Travis Holoway: “Regulators seem driven by press releases when they should be motivated by true consumer protection and empowering equitable solutions.”

Fintech lender SoLo Funds is being sued again by the government over its lending practices

Hard tech startups generate a lot of buzz, but there’s a growing cohort of companies building digital tools squarely focused on making hard tech development faster, more efficient and —…

Rollup wants to be the hardware engineer’s workhorse

TechCrunch Disrupt 2024 is not just about groundbreaking innovations, insightful panels, and visionary speakers — it’s also about listening to YOU, the audience, and what you feel is top of…

Disrupt Audience Choice vote closes Friday

Google says the new SDK would help Google expand on its core mission of connecting the right audience to the right content at the right time.

Google is launching a new Android feature to drive users back into their installed apps

Jolla has taken the official wraps off the first version of its personal server-based AI assistant in the making. The reborn startup is building a privacy-focused AI device — aka…

Jolla debuts privacy-focused AI hardware

The ChatGPT mobile app’s net revenue first jumped 22% on the day of the GPT-4o launch and continued to grow in the following days.

ChatGPT’s mobile app revenue saw its biggest spike yet following GPT-4o launch

Dating app maker Bumble has acquired Geneva, an online platform built around forming real-world groups and clubs. The company said that the deal is designed to help it expand its…

Bumble buys community building app Geneva to expand further into friendships

CyberArk — one of the army of larger security companies founded out of Israel — is acquiring Venafi, a specialist in machine identity, for $1.54 billion. 

CyberArk snaps up Venafi for $1.54B to ramp up in machine-to-machine security

Founder-market fit is one of the most crucial factors in a startup’s success, and operators (someone involved in the day-to-day operations of a startup) turned founders have an almost unfair advantage…

OpenseedVC, which backs operators in Africa and Europe starting their companies, reaches first close of $10M fund

A Singapore High Court has effectively approved Pine Labs’ request to shift its operations to India.

Pine Labs gets Singapore court approval to shift base to India

The AI Safety Institute, a U.K. body that aims to assess and address risks in AI platforms, has said it will open a second location in San Francisco. 

UK opens office in San Francisco to tackle AI risk

Companies are always looking for an edge, and searching for ways to encourage their employees to innovate. One way to do that is by running an internal hackathon around a…

Why companies are turning to internal hackathons

Featured Article

I’m rooting for Melinda French Gates to fix tech’s broken ‘brilliant jerk’ culture

Women in tech still face a shocking level of mistreatment at work. Melinda French Gates is one of the few working to change that.

2 days ago
I’m rooting for Melinda French Gates to fix tech’s  broken ‘brilliant jerk’ culture

Blue Origin has successfully completed its NS-25 mission, resuming crewed flights for the first time in nearly two years. The mission brought six tourist crew members to the edge of…

Blue Origin successfully launches its first crewed mission since 2022

Creative Artists Agency (CAA), one of the top entertainment and sports talent agencies, is hoping to be at the forefront of AI protection services for celebrities in Hollywood. With many…

Hollywood agency CAA aims to help stars manage their own AI likenesses