Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

MacRumors

macrumors bot
Original poster
Apr 12, 2001
67,944
38,646


The first iOS 17.3 beta rolling out to developers today includes a new "Stolen Device Protection" feature that is designed to add an additional layer of security in the event someone has stolen your iPhone and also obtained the device's passcode.

ios-stolen-device-protection.jpg

Earlier this year, The Wall Street Journal's Joanna Stern and Nicole Nguyen reported about instances of thieves spying on a victim's iPhone passcode before stealing the device, often in public places like bars. The thief can then reset the victim's Apple ID password, turn off Find My, view passwords stored in iCloud Keychain for banking and email accounts, and more. All in all, the report said thieves can essentially "steal your entire digital life."

When Stolen Device Protection is turned on, Face ID or Touch ID authentication is required for additional actions, including viewing passwords or passkeys stored in iCloud Keychain, applying for a new Apple Card, turning off Lost Mode, erasing all content and settings, using payment methods saved in Safari, and more. No passcode fallback is available in the event that the user is unable to complete Face ID or Touch ID authentication.

For especially sensitive actions, including changing the password of the Apple ID account associated with the iPhone, the feature adds a security delay on top of biometric authentication. In these cases, the user must authenticate with Face ID or Touch ID, wait one hour, and authenticate with Face ID or Touch ID again. However, Apple said there will be no delay when the iPhone is in familiar locations, such as at home or work.

The opt-in feature can be found in the Settings app under Face ID & Passcode → Stolen Device Protection. iPhone users who update to the iOS 17.3 beta will be prompted with the option to test a preview of the feature following installation, but Apple said this screen will not be shown to users who install the public version of iOS 17.3 coming later.

Actions that will require Face ID or Touch ID authentication when the feature is turned on:
  • Viewing/using passwords or passkeys saved in iCloud Keychain
  • Applying for a new Apple Card
  • Viewing an Apple Card virtual card
  • Turning off Lost Mode
  • Erasing all content and settings
  • Taking certain Apple Cash and Savings actions in Wallet
  • Using payment methods saved in Safari
  • Using your iPhone to set up a new device
Actions that will require Face ID or Touch ID authentication and have a one-hour security delay when the feature is turned on:
  • Changing your Apple ID password
  • Updating select Apple ID account security settings, including adding or removing a trusted device, trusted phone number, Recovery Key, or Recovery Contact
  • Changing your iPhone passcode
  • Adding or removing Face ID or Touch ID
  • Turning off Find My
  • Turning off Stolen Device Protection
Apple said it plans to share additional documentation about Stolen Device Protection over time to clarify how the feature works. The option will be available on all iPhone models that are compatible with iOS 17, including the iPhone XS and newer. iOS 17.3 will likely be released to the public in January or February.

Article Link: iOS 17.3 Beta Adds New Stolen Device Protection Feature to iPhone
 
Last edited:
I’ve rebooted refreshed and still not seeing the update. My watch shows the update.
 
Does this mean the thief would need to enter the faceId or touchId WITHOUT the passcode backup method? The WSJ article linked is about how they can do anything with a stolen iphone passcode. This would be great if they addressed that. I suppose not so if the faceId/touchId HW died though 🤔
 
It'd be cool if you could remotely do things to lock down a lost device from say icloud.com too, eventually. Like if my iPhone's been stolen and is in China or wherever, let me disable iMessage from being able to send messages, require TouchID to go from the homescreen to any app/settings/whatever, etc.
 
Does this mean the thief would need to enter the faceId or touchId WITHOUT the passcode backup method? The WSJ article linked is about how they can do anything with a stolen iphone passcode. This would be great if they addressed that. I suppose not so if the faceId/touchId HW died though 🤔
I would assume since a lot of those things on that list already require Face/Touch ID but allow you to enter in a password if it fails.
 
Only thing missing for me is shut down of device to require faceid/touchid (maybe an extra optin) and it has all I would want! really good move nonetheless by Apple.
 
  • Like
Reactions: zapmymac and MLVC
It'd be cool if you could remotely do things to lock down a lost device from say icloud.com too, eventually. Like if my iPhone's been stolen and is in China or wherever, let me disable iMessage from being able to send messages, require TouchID to go from the homescreen to any app/settings/whatever, etc.
Yeah, “Lost mode” makes your iPhone completely unusable
 
  • Like
Reactions: zecanard
This is great. The delay is a creative solution around the issue of thieves changing your password.

Though I’d like to see both Face ID and Touch ID on the iPhone so you have an additional biometric route if for some reason one fails.
I was thinking this, and I’m not usually one clamoring for the return of Touch ID. But it does strike me as potentially problematic if you’re in some freak accident that could cause your face or fingerprints to no longer be recognized by Face ID or Touch ID. I realize that’s a very unlikely scenario, but it will probably happen to someone, and I hope that doesn’t mean they’re forever unable to get a new device, change their password, etc. because they can’t authenticate biometrically
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.