Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.
This is why removing TouchID was shortsighted on Apple's part. In situations where FaceID doesn't work, for whatever reason, having TouchID as a backup is a lot more secure than having to input your phone's master password in public (and while drunk or high, ha!).

TouchID had the same 'disabled, passcode/word required' limitations.

tl;dr: Shoulder Surfing attacks can happen with our phones too. This is why we have Face ID and Touch ID.

Once again: The iPhone and iPad ruined a generation of computer users. Apple's made so many people soft and forget basic cybersecurity as they think their phone and Apple will do it all for them.

Yeah, everyone was a computer expert prior to 2007. /s
 
Apple needs to make an iPhone reset both the passcode and a face scan. Not just the passcode. They don’t even need your Apple ID to reset it. Frankly it’s just some free lines of code to require a second step to do this. I had mine stolen after I drunkingly gave out my 6 digit. Thinking I was safe. Bye bye iPhone.
 
If you do any banking or other secure activities on your phone, you should use an alphanumeric password of >8 characters. The passcode really does allow full access to anything on an iPhone. Banking apps that allow logging in with Face ID are only as secure as your passcode.

The same really goes for any device that can receive email though. Most of your Internet accounts can be accessed and reset with just your email. Unless you do literally nothing on your phone besides calling, texting, and have never used your number for 2FA, anything less secure than an 8+ character alphanumeric password is irresponsible.
 
I never understood why FaceID is enough for some parts but for other parts you suddenly need the Passcode like why? Is Apple implying faceid is less secure than a 4 digits passcode?
And iPhone occasionally asks for the passcode to unlock the phone at the most unfortunate times, even if you have done nothing to it to warrant this. Should just stick with asking for passcode 1. on restart, 2. on multiple Face ID attempts, and 3. user manually disables Face ID through a combined button press gesture.
 
Last edited:
I don't think it should make it an iPhone issue, because the same thing is true for Android phones, and even our laptops. But it is a good point to never enter a passcode or password while someone can be watching. This is why biometrics are way better especially in public.
Android has a nice feature in that you can set multiple users. You can have a secondary user that only has access to a tightly locked down feature set and only use that in crowds. The users the phone signs into is dependent on which passcode you enter.
 
This is an interesting issue. There is an authentication model flaw here. If you get privileged access to any iOS device then it's game over as all the authentication factors (PIN, FaceID, iCloud keychain) are available on the same physical device. You can then make account changes and remove other devices.

So if you use FaceID and cock it up, then have to enter a PIN and someone swipes your phone then the attacker here can likely remove the activation lock from the device, change your account data, anything.

We require a completely separate physical device for MFA authentication for work (Yubikey NFC). There should be an MFA bounce through any account changes on device at the very least.
 
This is an interesting issue. There is an authentication model flaw here. If you get privileged access to any iOS device then it's game over as all the authentication factors (PIN, FaceID, iCloud keychain) are available on the same physical device. You can then make account changes and remove other devices.

So if you use FaceID and cock it up, then have to enter a PIN and someone swipes your phone then the attacker here can likely remove the activation lock from the device, change your account data, anything.

We require a completely separate physical device for MFA authentication for work (Yubikey NFC). There should be an MFA bounce through any account changes on device at the very least.

It's not a flaw, it's just tech illiterate iPhone users getting Shoulder Surfed because they were using a short passcode in public to unlock their phones. So just don't use your passcode in a public easily visible space.
 
tl;dr: Shoulder Surfing attacks can happen with our phones too. This is why we have Face ID and Touch ID.

Once again: The iPhone and iPad ruined a generation of computer users. Apple's made so many people soft and forget basic cybersecurity as they think their phone and Apple will do it all for them.
They didn't forget basic cybersecurity, they never learned it in the first place
 
This article and the fact that apple needed to even respond just shows how brain dead our society is. If you let your password get “stolen” by someone watching you enter it, that is completely on the user. Doesn’t matter what device they have. how is that at all Apple or any device makers issue? NEWs ALERT. Secuity researchers determine that passwords are not secure if someone watches you enter it. Really? How long did that study take

and the irony is they recommend 1password that was recently hacked.
 
Moreover, the lack of TouchID is the reason I still have a 2019 iPad. I HATED having to pick up my iPad Pro 10x every meeting to wake it up with FaceID (I use Notability for meeting notes as the pencil is organic and typing just feels and sounds rude). TouchID is quick and discreet...so I reverted to the last iPad Pro with ProMotion and TouchID. I would love to upgrade and use TouchID on the side button...but the iPad Air is a downgrade until it has ProMotion.

I think every iPhone and iPad Pro should have both.
Don't like one? Use the other.
Use your iPhone in nightclubs? Use both.

Just my $.02...
 
People get beatup at the ATM and forced to put in their pin and money gets withdrawn. Same same. Be aware of your surroundings and not have your head buried in your phone.
 
  • Like
Reactions: centauratlas
They didn't forget basic cybersecurity, they never learned it in the first place
And even with all the digital security, they still forget physical security like not letting people tailgate you through a secured door or throwing out secured docs instead of shredding. Always makes me thing of Luck where Bob complains about the obnoxiously long password but doesn't watch that he's still being followed? I also blame it on their system of leaving the portal open for 5-10s after Bob entered.
 
  • Like
Reactions: centauratlas
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.