> Apple's new-device-detection algorithm doesn't seem to be perfect - I was vacationing and bought an app, and it was flagged as a new device (I got the mail for my purchase), despite it being the same one I've been using for a few years.
I have had this happen with Steam countless times, it's made me hate the Steam Guard system. I have a long complex password for Steam and I don't play online so my account isn't high risk at all.
However I use a number of different browsers on different machines and reset them frequently. As a result, almost every purchase I've made through a browser from Steam since that system was implemented has required me re-authenticating the "new device".
Personally, I'm not a fan. I'm positive it would get an even worse reception from the general public, too. Steam users aren't necessarily savvy but they are typically willing to jump through technical hoops for a particular endgame. I wouldn't say the same for iOS users, by and large.
This is a tricky one. Increasing security without adding complexity or alienating users that have grown used to the current system is very difficult. I'm not ready to jump all over Apple for this, it's not a problem with an obvious & popular solution that they are just choosing to ignore, this is something every company in the world is struggling with right now and they all have a different way of combatting it, each with their own unique pros and cons.