Sounds like the only solution there is to buy another Mac. Apple really needs to address this and quickly.Your problem is your AppleID would be locked. So how do you get back into your Mac to utilize TM?
Sounds like the only solution there is to buy another Mac. Apple really needs to address this and quickly.Your problem is your AppleID would be locked. So how do you get back into your Mac to utilize TM?
Here is a video on how to mitigate this exploit till Apple releases a patch to fix it. This obviously can't prevent them from accessing the information on your phone but it prevents them from changing your Apple account password and stealing your entire account. This is not my video but just one I found on YouTube.
I believe it can. However, there will still be some protection if someone grabs your unlocked phone - without knowing the device passcode or the email address you use with your Apple ID. (My understanding is they’d need either of those to circumvent.)Apparently the screen time passcode can be circumvented...
It can.I believe it can.
The exploit that this whole thread started with was the act of stealing ones' passcode by observing it in a social situation, then stealing the phone itself, so assume they have the passcode, and this workaround video only makes things very slightly harder. I wish they would have mentioned that in the video as it gives false hope.However, there will still be some protection if someone grabs your unlocked phone - without knowing the device passcode or the email address you use with your Apple ID. (My understanding is they’d need either of those to circumvent.)
They definitely need to do something, but so far Apple is treating it as a non-issue -- at least publicly. It bothers me most that you can't recover your account and the data there-in if the password gets changed and your devices get disabled.Apple 🍏: Please fix this!
So if there is no reference to the email address on the phone (and the mail app turned off in Screen Time) this bypass of Screen Time would not work?Do this steps:
- change screen time passcode
- turn off screen time passcode
- on the bottom on the screen on top of the keyboard, there is a Forgot Passcode button
- type your email
- Press OK
- Press Forgot ID or Password
- Then it ask your passcode BUT if you wait 5-10 seconds a popup ask for your iPhone passcode (not the screen time passcode)
- it ask the new iCloud password
And what about this one? Does it also require knowledge of the email address?Or even simpler, just go to Privacy & Security > Safety check and go through the procedure until you have the choice to change iCloud password.
Even with a time passcode set (and warning saying I could not do some actions because of the screen time passcode), I was able to disconnect all my devices and reset my iCloud password...
So if there is no reference to the email address on the phone (and the mail app turned off in Screen Time) this bypass of Screen Time would not work?
And what about this one? Does it also require knowledge of the email address?
Well maybe this exploit will be patched as well. We can hopeDo this steps:
- change screen time passcode
- turn off screen time passcode
- on the bottom on the screen on top of the keyboard, there is a Forgot Passcode button
- type your email
- Press OK
- Press Forgot ID or Password
- Then it ask your passcode BUT if you wait 5-10 seconds a popup ask for your iPhone passcode (not the screen time passcode)
- it ask the new iCloud password
Or even simpler, just go to Privacy & Security > Safety check and go through the procedure until you have the choice to change iCloud password.
Even with a time passcode set (and warning saying I could not do some actions because of the screen time passcode), I was able to disconnect all my devices and reset my iCloud password...
So if there is no reference to the email address on the phone (and the mail app turned off in Screen Time) this bypass of Screen Time would not work?
And what about this one? Does it also require knowledge of the email address?
The email is listed in Settings right under the user name.
Very true if they have the passcode and I agree the video should have made things clearer. However, if screen time can offer SOME protection in SOME circumstances it seems worthwhile doing for now.The exploit that this whole thread started with was the act of stealing ones' passcode by observing it in a social situation, then stealing the phone itself, so assume they have the passcode, and this workaround video only makes things very slightly harder. I wish they would have mentioned that in the video as it gives false hope.
People messed with me in the past because I have an unusually long alphanumerical password, but it's exactly for stories like this that I have it. I use FaceID anyway, but good luck guessing my password.
Mobile phones today basically have access to every aspect of our lives. We cannot be lazy on the device password strength
I think it was posted earlier in this lengthy discussion that the thief was able to reset the Apple ID password using the phone's passcode. In that case, they will know the Apple ID password because they have chosen it."Subsequently, the thief can turn off Find My iPhone on the device, preventing the owner of the device from tracking its location or remotely erasing the device via iCloud."
You need your Apple ID password to turn FindMy off, which should not be the same as your phone's passcode.
I think it was posted earlier in this lengthy discussion that the thief was able to reset the Apple ID password using the phone's passcode. In that case, they will know the Apple ID password because they have chosen it.
If you are, I am too.This article says, "Apple users should set their own Apple ID recovery key, which prevents anyone else from doing it." But it looks like the recovery key can be turned off and replaced with another just by using your iPhone's passcode. Am I missing something?
Looks like those Yubikeys are totally useless at the moment.Am I missing something?
I still don’t understand this.
It appears that every time I login to a new device - or even change passwords or go into anything account related - I get popups and notifications just about eveywhere.
Even when I call Apple.
I have a 10+ digit passcode due to MDM/corp policy on phone, iPad, and watch. But again - a lot of this seems like an edge case, by somewhat careless users.
You're not always in an alcove made for privacy and the iPhone has this nasty habit of asking for the passcode at the most inopportune times. So they watch you put in the code and they own you.Why should my iPhone, with 6 digits be any different?
You're not always in an alcove made for privacy and the iPhone has this nasty habit of asking for the passcode at the most inopportune times. So they watch you put in the code and they own you.
The difference is that there’s a lot less damage (depending on the owner) someone could do with an ATM card and PIN than with a trusted device iPhone and a passcode.
It's not about what they can or can't do if they see me putting in my ATM pin or iPhone passcode, it's about the principle of simply not letting others see me input codes into any machine, period.
Can you hide it from all the cameras around, some that you might not even be able to see? Can you hide it in a busy bar or store? I don't think you can, and that's how this thread started, describing how someone lifted a passcode, and then phone...If it's an inopportune time, it can wait 3 seconds for me to turn around or hide the key pad. I don't need access to my phone 24/7/365.
I don't think that makes any difference, but I too was born WAY before cell phones.I was born before cell phones were invented, so I think I know when is or is not an appropriate time to use them.
Can you hide it from all the cameras around, some that you might not even be able to see? Can you hide it in a busy bar or store?