Apple Adds Two-Step Verification to iCloud and Apple ID
11–20 of 51 posts
Re: Apple Adds Two-Step Verification to iCloud and Apple ID
#12Setting up "trusted devices" (iPhone, iPad, etc.) works really well: Apple already knows which devices you own, so all you have to do is select the device and you get an instant push notification to unlock to see the verification code.
Apple gives you a backup recovery code with very clear instructions to print/write it somewhere safe. They require you to re-enter it as part of the setup process to make sure you got it right.
When you need a code, you pick the device you want it sent to and Apple pushes it out instantly via some feature baked into iOS. You can also set up any phone to have a code delivered via SMS, but presumably this is less secure because it could be read even if your phone is locked.
Overall this is a great experience for the user -- much more friendly than Google Authenticator.
In fact I wish this process was open a la Google Authenticator so that other applications could use it (this will happen when hell freezes over).
Re: Apple Adds Two-Step Verification to iCloud and Apple ID
#13To what extend is it two factor when one of the factors is the device you are working on? One of the biggest risks I see with iCloud is someone finding/stealing my phone, and using it to erase other devices. A code send to my phone won't prevent that. For online services, a code to your phone makes lots of sense (something you have part). For phone services, I'm less sure.
Re: Apple Adds Two-Step Verification to iCloud and Apple ID
#14Can't see any easy way to change my language on the page. How annoying!
Re: Apple Adds Two-Step Verification to iCloud and Apple ID
#15Argh! Incredibly annoying edge case! I'm in Poland, but have all my language settings set to English, and the only country codes for receiving SMSs are those of English-speaking countries! Can't see any easy way to change my language on the page. How annoying!
And, as it's stated in the FAQ [1], SMS option is only available in those countries at the moment, regardless of where you're located. When it becomes available in Poland, they'll text you and you can activate it. But until then, you can safely use 2FA without an SMS backup (as I did).
Re: Apple Adds Two-Step Verification to iCloud and Apple ID
#16Apple has done a great job walking users through this process. Setting up "trusted devices" (iPhone, iPad, etc.) works really well: Apple already knows which devices you own, so all you have to do is select the device and you get an instant push notification to unlock to see the verification code. Apple gives you a backup recovery code with very clear instructions to print/write it somewhere safe. They require you to…
Re: Apple Adds Two-Step Verification to iCloud and Apple ID
#17There is nothing on two-factor in my UI. Perhaps it's limited to some geographies? (I'm not in the US)
Nothing on the linked page, nothing in my account settings... so I have no idea how this works.
EDIT: never mind, it's completely hidden behind "Password and Security" in your account, and then you have to answer your security questions to even SEE what things you can do. ARGH. It took me several tries -- security questions should NEVER be character-matched. How am I supposed to remember if I typed in "Mike" or "Michael" or "Crazy Mike" for my childhood best friend, or "Honda" or "Accord" or "Honda Accord" for my first car? (Those are obviously not my actual answers). Security questions should ONLY ever be "matched" by a human operator over the phone. And God forbid you should ever mistype your initial answers! There's ZERO warning that these will ever be used in a "password"-style sense.
Re: Apple Adds Two-Step Verification to iCloud and Apple ID
#18Re: Apple Adds Two-Step Verification to iCloud and Apple ID
#19Re: Apple Adds Two-Step Verification to iCloud and Apple ID
#20To what extend is it two factor when one of the factors is the device you are working on? One of the biggest risks I see with iCloud is someone finding/stealing my phone, and using it to erase other devices. A code send to my phone won't prevent that. For online services, a code to your phone makes lots of sense (something you have part). For phone services, I'm less sure.
Contrast to someone getting your phone today... they can easily determine your iCloud account name in Settings, and then send a password reset for it that is delivered to the unprotected Mail app.
So for most people, it's certainly more secure.