Yeah, riiiiight. I hope you never find out the hard way...Yes I can, and I do.
Yeah, riiiiight. I hope you never find out the hard way...Yes I can, and I do.
Yeah, riiiiight. I hope you never find out the hard way...
That's not my goal -- my goal is just to both keep people aware of what can happen with the way things are now with authentication, and to hopefully to wake Apple, Google, and others to rethink a few things! (2FA doesn't help in the trusted device scenario as is)Ok, you win. I'm really panicking now...
It's not about what they can or can't do if they see me putting in my ATM pin or iPhone passcode, it's about the principle of simply not letting others see me input codes into any machine, period.
you don't keep yours on a sticky note?It's not about what they can or can't do if they see me putting in my ATM pin or iPhone passcode, it's about the principle of simply not letting others see me input codes into any machine, period.
Using Face ID to authenticate on recent years' models of iPhone and iPad is great, but even then, iOS and iPadOS demand pass code authentication once a week (minimum).This is why you should enable Face ID
Face ID - and biometrics in general - are not protected by any type of privacy regulation.This is why you should enable Face ID
you don't keep yours on a sticky note?
I locked myself out because all the numbers were backwardsYes I do, on my forehead.
The difference between the house keys and the iphone passcode, is that the house key only opens the house door. That's it. It doesn't open your safe in the bedroom. It doesn't open your bank account. It might not even open your locked shed in the backyard. The iphone passcode, on the other hand, opens way more than just the iphone itself. If you use the iphone as Apple intends on you using it, then that passcode not only opens the iphone, but also opens up your password manager, which opens up all of your passwords, unlocking your bank and financial accounts, and any other sensitive data you might have. So while the analogy is cute, it isn't really analgous to the harm described in the report. FaceID and TouchID are not helpful, as again, that same iphone passcode allows you to change that. And like the report says, that same iphone passcode allows you to change the Apple ID and completely lock you out. That can't happen with your house. A thief can steal the house key and get inside. He could then steal anything in there that isn't locked, but that's it. He couldn't get into your computer, or into your accounts, and he certainly couldn't steal the house either....what, exactly, was the point of the 'report'?
"If someone steals your house keys, they could get in your house and take your stuff!" - Joanna Stern later today, probably.
All one has to do is turn on Screen Time > Content & Privacy Restrictions > Passcode Changes > Don't Allow, as well as Account Changes > Don't Allow. Be sure to use a different passcode for Screen Time.
I already do that with my work phone (IT requirement) looks like I’m going to have to do this with my personal phone also.I bumped my password length to something fairly long. It's a bit of a pain when I have to enter it in but that's the idea.
Apple need to get their **** together.Then there is this - latest from the WSJ
surprised that Joanna Stern has nothing better to do.Then there is this - latest from the WSJ
@sk1ski1, can this flaw be avoided by skipping Screen Time Passcode Recovery when the Screen Time passcode is first setup? The "Forgot Apple ID or Password?" prompt presumably would no longer appear, and the device passcode would therefore no longer be sufficient to bypass Screen Time restrictions (i.e., Content & Privacy Restrictions | Account Changes = Don't Allow)?The big hole in this solution is that Apple foolishly lets you turn-off/change the screen time password by using the device password.
Here’s the flaw. Go to screen time. Then go to “change screen time passcode”. Then go to “turn off screen time passcode”. Then select “forget passcode”. You now have to enter your Apple ID. Which can be easily found by searching your email. Then select ‘forgot password’ for the Apple ID. After it asks for the device passcode, it will then let you enter a new Apple ID password from this screen.
If you get the apple ID from the phone, you can change the password from the web, as long as you have a trusted device passcode.@sk1ski1, can this flaw be avoided by skipping Screen Time Passcode Recovery when the Screen Time passcode is first setup? The "Forgot Apple ID or Password?" prompt presumably would no longer appear, and the device passcode would therefore no longer be sufficient to bypass Screen Time restrictions (i.e., Content & Privacy Restrictions | Account Changes = Don't Allow)?
Thank you for your assistance.
On my iPhone (I activated Screen Time for various things), in Settings the Apple ID is greyed out so they cannot see the email address.If you get the apple ID from the phone, you can change the password from the web, as long as you have a trusted device passcode.
Thank you, @bobcomer.If you get the apple ID from the phone, you can change the password from the web, as long as you have a trusted device passcode.
Except others say that you can recover the screen time passcode with the device passcode, and a search of the web shows there's software to do it too.On my iPhone (I activated Screen Time for various things), in Settings the Apple ID is greyed out so they cannot see the email address.
Not really -- some people's only email access is the iPhone. It seems odd to us of course. For me it would work, but not everyone I think.Thank you, @bobcomer.
In the spirit of brainstorming, consider this approach: change your Apple ID email to one that (a) is used for Apple account authentication exclusively, and (b) is not stored on the iPhone (e.g., not in Contacts or Mail). Is this a practical solution to the problem of preventing a thief with an iPhone and device passcode from changing a user's Apple ID password?
P.S.: I am assuming that a Screen Time restriction is also in place to prevent viewing the Apple ID on the iPhone (i.e., suppressing access to Settings | [name] by configuring Settings | Screen Time | Content & Privacy Restrictions | Account Changes = Don't Allow).
That's possible, yes.Except others say that you can recover the screen time passcode with the device passcode, and a search of the web shows there's software to do it too.