3 ms·
I am on iOS 11. Here is an Apple knowledge base article about it: https://support.apple.com/en-us/HT208072 https://support.apple.com/en-us/HT208072
by 0culus 9y ago
I am on iOS 11. Here is an Apple knowledge base article about it: https://support.apple.com/en-us/HT208072 https://support.apple.com/en-us/HT208072
- deleted 9y ago[deleted]
- graeme 9y agoThanks. Curious, I don't see it. I just have change password, two factor, phone number, get verification code
- 0culus 9y agoAlso see the reply I just made to my comment. It's no bueno.
- graeme 9y agoYikes. This seems a serious weakness. I get why they would make it easier to do backups, but not why they would make it so easy to get icloud. I guess the only consolation is that eventually the phone will logout, so the attack would have to be done soon after getting the phone? Update: It's much worse than that. I just got a login notification on my ipad for my apple id. So I'm not signed in. But, I went to reset the password, and it said I can do it with a passcode since I'm signed in to icloud. So icloud signin lasts far longer than apple ID signin for the app store. This seems like a serious vulnerability. Makes me rethink having multiple idevices, or putting anything in icloud keychain. Any one of them gives access to everything. I am not a security expert though, so take this with a grain of salt.
- 0culus 9y agoOK, I just tried setting it up. Here's the problem. You can certainly set the recovery key, but you can easily create a new one just with the phone passcode. So if your passcode is compromised, your iCloud account is basically gone.