4 ms·
To what extend is it two factor when one of the factors is the device you are working on? One of the biggest risks I see with iCloud is someone finding/stealin
by PanMan 14y ago
To what extend is it two factor when one of the factors is the device you are working on?
One of the biggest risks I see with iCloud is someone finding/stealing my phone, and using it to erase other devices. A code send to my phone won't prevent that.
For online services, a code to your phone makes lots of sense (something you have part). For phone services, I'm less sure.
- masnick 14y agoI think it will unless they can break your passcode.
- smackfu 14y agoTo use the code sent to the phone, you need to know the password or the recovery key as well. That's the two factor part. Contrast to someone getting your phone today... they can easily determine your iCloud account name in Settings, and then send a password reset for it that is delivered to the unprotected Mail app. So for most people, it's certainly more secure.
- natem345 14y agoWhat happens if you need a password reset with this new two-factor? Wouldn't it still just email you, leaving you with the same problem?
- smackfu 14y agoNo, the FAQ says: You can reset your password at My Apple ID by using your Recovery Key and one of your trusted devices. I think they do a pretty good job of emphasizing that there are three things involved here: Recovery Key, password, any trusted device. Any two will allow you to recover the third (except if you lose your phone). Not having any two and you lose your ID forever.
- deleted 14y ago[deleted]