Apple ID locked daily, sometimes hourly. Please read details before responding.
My Apple ID gets locked daily, sometimes hourly (when I bother to unlock it). A few years back, I made it all the way to an actual Apple engineer, who informed me that because I have a mac.com address, I'm just out of luck. When Apple decided to add the me.com and icloud.com aliases to the mac.com domain, they basically doomed anyone with one of those addresses to a lifetime of bots attempting to hack the account. Especially early adopters such as myself - I obtained my address in 1996 (I think); immediately upon it becoming available. It's my first initial/last name at mac.com, and it's been my email address ever since.
My issue only became an issue when trying to use iMessage, as I have to be signed in to use it (although the same issue exists for the App Store, FaceTime, etc.). Eventually it got so frustrating that I escalated the issue and reached the above-mentioned engineer. It took some time, but he admitted finally that there was no way to separate my email address from the account. He also said that this is not the case for any other email domains, just the mac.com & family ones. To prove the concept, I set up an Apple ID using a convoluted yahoo address and added it as an alias to my mac.com address. Makes no difference, as Apple has nothing in place to mask the true address from the bot.
And before anyone suggests two-factor authentication; it's completely useless. The account is locked as soon as multiple attempts are made to access it, regardless of whether two-factor is turned on or off. And the recent advent of required two-factor (while unfortunate) is mildly better with the advent of the trusted phone element (as opposed to a device that might be hundreds of miles away).
So. My question is, has anyone heard of Apple attempting to remedy this situation, or are they just hoping all the early adopters eventually die off? I can't remember the steps I went through to actually reach an engineer, but thought maybe someone else has some insight. I'm not interested in ditching a 26 year old email address, and I WOULD like to use the features available on my devices without having to sign in and answer questions every five minutes or so.
Anyone?