Why have FIDO/Security keys?
I added FIDO keys to my iPhone for additional protections for my Apple ID. If you read this article: support.apple.com/en-qa/HT213154 it lists three things that require the security key:
- Sign in with your Apple ID on a new device or on the web
- Reset your Apple ID password or unlock your Apple ID
- Add additional security keys or remove a security key
This made me think that adding the keys would prevent a malicious change to my Apple ID password. However, the article also states, "you need a trusted device or a security key" so accessing or changing anything under "Password and Security" is possible, even removing added security keys, because the iPhone is a trusted device. So, adding the FIDO keys don't do much, if anything, to improve your security posture or to assist in recovering your account and defeats the purpose of MFA.
A simple suggestion for Apple: if I add security keys, require one to access/change anything under "Password and Security" or maybe require it for anything under the top level "Apple ID/Name" settings.
iPhone 12 Pro Max, 16