Does work without any problems and I do NOT need any hardware key to do so!!Since you have hardware keys could you try changing your iCloud password using just you device passcode?
Does work without any problems and I do NOT need any hardware key to do so!!Since you have hardware keys could you try changing your iCloud password using just you device passcode?
This all makes me think of some movie I can't remember the name. They have this massive door with all kinds of locks and security, but the wall next to it is garbage, so the guy just punches through it and opens the door from the inside.I can do all that, turn on end to end encryption on my iCloud account and switch to hardware keys for 2FA. But if anyone obtains my passcode for any of my Apple Devices they can lock me out of all of them with just that passcode.
That is a huge flaw in Apple's security model. Unlike some people here I do expect Apple to fix it. I don't expect them to admit it is a huge flaw though because they will be expecting to be sued. If the woman in the WSJ video didn't have a lawyer before the video was published she does now.
Yes I never understood why it sends 2FA to the device you are on. Doesn't that defeat its purpose. If you don't have a second device, let you use on within your family, or a CTN or email separate from what is on your device.I think if 2FA is enabled and there is more than one Apple device on the account, the second device should be required. If hardware keys have been enable, one of them should be required.
Failing that, there are existing account recovery protocols that could and should be followed. If a recovery key has been set on the account, that key can be used. If a recovery contact has been enabled, that process can be followed.
Sounds like a plot for a Sherlock Holmes story, The Red-Headed League. Short version: crooks broke through bank vault floor via sewer system, bypassing the vault door completely.This all makes me think of some movie I can't remember the name. They have this massive door with all kinds of locks and security, but the wall next to it is garbage, so the guy just punches through it and opens the door from the inside.
That was like the one movie I just watched which I don't remember the name againSounds like a plot for a Sherlock Holmes story, The Red-Headed League. Short version: crooks broke through bank vault floor via sewer system, bypassing the vault door completely.
Thanks for confirming!Does work without any problems and I do NOT need any hardware key to do so!!
It also sounds a lot like WW2. The French built an elaborate set of fortifications called the Maginot Line to protect against invasion but the line did not extend to their border with Belgium. No prizes for guessing what happened next.Sounds like a plot for a Sherlock Holmes story, The Red-Headed League. Short version: crooks broke through bank vault floor via sewer system, bypassing the vault door completely.
Yes it’s totally stupid. Don’t understand why you need hardware keys at all. Looks like a big scam from Apple?!Thanks for confirming!
Yes I never understood why it sends 2FA to the device you are on. Doesn't that defeat its purpose. If you don't have a second device, let you use on within your family, or a CTN or email separate from what is on your device.
This all makes me think of some movie I can't remember the name. They have this massive door with all kinds of locks and security, but the wall next to it is garbage, so the guy just punches through it and opens the door from the inside.
An in-depth report published today by The Wall Street Journal's Joanna Stern and Nicole Nguyen highlights instances of thieves spying on a victim's iPhone passcode before stealing the device in order to gain access to the device, data, and money.
![]()
All of the victims interviewed said their iPhones were stolen while they were out socializing at bars and other public places at night. Some victims said the iPhones were grabbed out of their hands by strangers, while others said they were physically assaulted and intimidated. The report provides specific examples of these instances.
With knowledge of the iPhone's passcode, a thief can easily reset the victim's Apple ID password in the Settings app, even if Face ID or Touch ID is enabled. Subsequently, the thief can turn off Find My iPhone on the device, preventing the owner of the device from tracking its location or remotely erasing the device via iCloud. The thief can also remove other trusted Apple devices from the account to further lock out the victim.
The thief can also change an Apple ID's contact information and set up a recovery key in order to prevent a victim from recovering the account.
To make matters worse, knowing an iPhone's passcode allows a thief to use Apple Pay, send Apple Cash, and access banking apps using passwords stored in iCloud Keychain. Even if Face ID or Touch ID is enabled on the iPhone, thieves can simply bypass these authentication methods and an option to input the device's passcode is presented. In some cases, the report claims that thieves even opened an Apple Card by finding the victim's last four digits of their Social Security number in photos stored in apps like Photos or Google Drive.
Access to other passwords stored in iCloud Keychain allows the thief to further wreak havoc, as it could give them access to email accounts and other sensitive information. All in all, the report says thieves can essentially "steal your entire digital life."
Apple Responds
In response to the report, an Apple spokesperson said "security researchers agree that iPhone is the most secure consumer mobile device, and we work tirelessly every day to protect all our users from new and emerging threats."
"We sympathize with users who have had this experience and we take all attacks on our users very seriously, no matter how rare," the spokesperson added. "We will continue to advance the protections to help keep user accounts secure." Apple did not provide any specific details about any next steps it might take to increase security.
In a tweet, Stern recommended that Apple add extra protections to iOS and introduce additional Apple ID account recovery options.
How to Stay Protected
In a tweet, Stern recommended that users switch from a four-digit passcode to an alphanumeric passcode, which would be more difficult for thieves to spy on. This can be done in the Settings app under Face ID & Passcode → Change Passcode.
iPhone users can also use Face ID or Touch ID as much as possible when in public to prevent thieves from spying on their passcode. In situations where entering the passcode is necessary, users can hold their hands over their screen to hide passcode entry.
To protect a bank account, consider storing the password in a password manager that does not involve the device's passcode, such as 1Password.
Article Link: Apple Responds to Report About Thieves Spying on iPhone Passcodes to 'Steal Your Entire Digital Life'
Some people even on here keep saying it's more secure. Even if it is technically more secure, it is practically way less secure.
Agreed. Hard to believe Apple could be this stupid.Yes it’s totally stupid. Don’t understand why you need hardware keys at all. Looks like a big scam from Apple?!
Agreed. Hard to believe Apple could be this stupid.
For a long long time…Wonder how long this is been an issue.
On the Android side, I tried going into the security settings, and just like you do it from the web on a desktop you need to enter your Google account password before tweaking settings like password, 2FA, etc. So like a proper change password prompt, you are required to enter your existing password + a new password. That is the standard at most websites.
On Android you must reenter even at the minimum the current Google account password for it to be changed.
Even google and android asks for the old password to change it .
Not an Android issue. Google requires the current Google password to change the Google password. You can't change the Google password by just using the simple device passcode.
Aside from that, the way these “thieves” are ransacking iPhones is not possible on Android devices. Yes, you can still do damage but not cut someone out of their digital life.
If you don't have multiple Apple devices logged into the same account, you can't really do 2FA properly. So if every device is on its own account, 2FA with out hardware keys seems pointless.Have an iPhone and a MBP. I'm not at home (traveling?) and need to reset.
Have an iPhone and a bunch of Home items.
Have an iPhone and a wifi iPad for entertainment.
Haven multiple Apple devices but multiple Apple ID's (mine)
I can think of a number of instances like this.
We need something different that will not allow a "thief" to lock your digital world and Apple devices.
I can change my Google password on my Android phone with just my lock screen passcode.
Settings > Google > Manage your Google Account > Personal Info > Password > Forgot Password > Confirm your screen lock > Tap Yes on your phone or tablet
After following the above I was able to change my Google password. No need to enter my Google password and no need to confirm on a separate device. I have 2FA enabled on my Google account but I guess they consider my phone and it's screen lock code as two separate factors.
What special setting do you all have enabled to prevent the above method from working on on your Android devices?
If you don't have multiple Apple devices logged into the same account, you can't really do 2FA properly. So if every device is on its own account, 2FA with out hardware keys seems pointless.
I assume by "Home items" you mean things like HomePods and Apple TVs. You obviously can't use a HomePod for 2FA and if I had an Apple TV I would not log into using my main Apple ID.
If you are traveling maybe bring the MacBook or that Wifi iPad with you. You can setup a hotspot via your phone if you need to.
The preferred Apple device for 2FA should really be the Apple Watch. It's a separate device and you probably always have it with you.
A hardware key would be better of course assuming Apple actually implemented it properly.
btw - say they change the password. They still cannot cut you out of your digital life. You can use another device to get back in. They can do some damage for sure but unlike Apple you can get your digital life back and the ability to get into your finances is very limited
The Google account associated with my Android is not one that has a mail or other app on device.
TLDR: my personal reaction to the WSJ piece was to create a separate and limited Apple ID for my iPhone
I numbered your responses to better answer.1. Once they have your phone and have reset your Google password surely they can just remotely sign you out of other devices and sessions, disable find my device, and disable recovery methods. This would lock you out, wouldn't it?
2. Regarding finances - they are able to access Google wallet with your screen unlock code so could use any cards you have stored in there. They could access any financial apps that have screen unlock code as backup to biometrics (hopefully not many do but I think that's also true on iPhone). I'm not quite sure how the situation from financial theft perspective is worse on iPhone?
3. Are you saying you don't use the Google account associated with your Android device for email or any other important data? This is certainly an option for minimising the impact of this sort of crime, in the same way avoiding use of iCloud for email, document storage, and photo backup is an option for an iPhone user. But lots of people (maybe most Android users???) will be using their Android-linked Google account for these sorts of things.
Exactly. They are stealing two factors needed to control the account. If they knew your password, your passcode, and your Apple ID, they still couldn’t access your account without access to “something you have” which is your trusted device that has 2FA turned on and uses a passcode.
Yes. I’m hopeful that Apple can find an agreeable solution for users who forgot their passwords.
TLDR: my personal reaction to the WSJ piece was to create a separate and limited Apple ID for my iPhone.
I numbered your responses to better answer.