How to keep the Apple ID account safe?

I need a help on keeping Apple ID safe regarding the "changing password" process on iPhone (or iPad).

Unlike the browser environment, the field "current password" is not required and two-factor confirmation to the device is not required to complete the changing process. This seems potentially problematic because anyone who gets the iPhone's unlock code through threat, coercion or spying could be able to change the victim's Apple ID password, disable the Recovery Key or delete trusted contacts. The same if "Screen Time" code is activated to prevent "Account Changes"/"Code Changes" — again, with coercion or threat, a third-person could, potentially take control of the account.

Any thoughts?

Thank you.

Posted on Jul 1, 2022 12:42 PM

Reply
8 replies

Jul 1, 2022 3:12 PM in response to Katana-San

The obvious suggestion is to use the same process available on desktop device. I also provided that feedback, but nothing changed. I don't know if it is a developing limitation. That's why I'm here: maybe an expert could have another insight I didn't get.


Apple considers that is the expected behavior, if two-factor authentication is enabled, that any trusted device can change the password with the device passcode.


Once you're logged in, your device is automatically considered a trusted device. Or is it possible to keep the log in and the device won't be considered trusted device?



Jul 1, 2022 1:32 PM in response to leo.037

Hello ~ I have both a password and two factor enabled on my iPhone plus Find My activated. My password is an extra secure one not one that could be easily guessed … actually nearly impossible. Should my iPhone be stolen I would work through the steps here:


If your iPhone, iPad, or iPod touch is lost or stolen - Apple Support


Do you have a password (Lock Screen )set? No one can get to the last screen you have shown without your password …which you should share with no one. If someone were to keep guessing my passwords it would then disable the devices


~Katana-San~

Jul 1, 2022 2:20 PM in response to Katana-San

How could you log into iCloud if the robber changed your Apple ID password and can deactivate Recovery Key and delete trusted contacts?


My point here is:

If I want to change my Apple ID password on a desktop device I have to confirm access on an external device through two-factor authentication and type the "current password". Those are terrific security layers that seems not be available on the iOS environment.


Of course, no one should care about the device in a safety risk situation. But safety is about extreme situations. No one uses seat belt thinking on a crash, but "what if?". Everyone can buy a new device, but what about your privacy? What if your working on a secret project stored on iCloud, for example?


Again, my point is: why iOS doesn't provide the same security layers available on desktop devices?


I think this is hugely serious.

Jul 1, 2022 1:19 PM in response to khajotia

Thank you.


But in the iOS, the screen Password & Security doesn't have the "current password" field. Once a third-person has the lock screen code, he or she just can create a new Apple ID password. The two-factor authentication also isn't required if a password change is made on iPhone or iPad.


My point here is: the browser environment requires both security layers. But mobile devices like iPhone or iPad, which are more likely to be stolen, do not (or doesn't seem to require).


See the difference:




Jul 1, 2022 1:40 PM in response to Katana-San

The problem is that anyone who gets the iPhone's unlock code through threat or coercion could be able to change the victim's Apple ID password, disable the Recovery Key or delete trusted contacts, for example.


Imagine robbery situation. The thief takes the mobile device and forces to provide the unlock code. He will be able to change Apple ID password and disable security features because the two-factor confirmation is not prompted.



This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

How to keep the Apple ID account safe?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.