iOS 17 Gives You 72 Hours To Undo An iPhone Passcode Change (macrumors.com) 16
In iOS 17, iPhone users who change their passcode will be able to reset it within 72 hours using the previous passcode. However, users can choose to expire the previous passcode immediately in the Settings app to increase security. MacRumors reports: If you enter an incorrect passcode, tapping on "Forgot Passcode?" at the bottom of the screen will lead to another screen with a "Try Passcode Reset" option. Tapping this option allows you to enter the iPhone's previous passcode and create a new passcode. As a safeguard, an option in the Settings app lets you expire the previous passcode immediately so that it cannot be used to reset the new passcode.
As of the first beta of iOS 17, it is still possible to change an Apple ID account's password with an iPhone's passcode, despite a Wall Street Journal report in February highlighting instances of thieves spying on an iPhone user's passcode in public and then stealing the device in order to gain widespread access to the device. In an interview with Daring Fireball's John Gruber last week, Apple's software engineering chief Craig Federighi said Apple has continued to "look at other ways to address this," but no changes have been made as of yet.
As of the first beta of iOS 17, it is still possible to change an Apple ID account's password with an iPhone's passcode, despite a Wall Street Journal report in February highlighting instances of thieves spying on an iPhone user's passcode in public and then stealing the device in order to gain widespread access to the device. In an interview with Daring Fireball's John Gruber last week, Apple's software engineering chief Craig Federighi said Apple has continued to "look at other ways to address this," but no changes have been made as of yet.
Is this news? (Score:1)
Is this an "Someone at Apple did a shit" website?
Re:Is this news? (Score:4, Informative)
No, it's a 'needlessly shit on Apple' site. Welcome.
Maybe not so good. (Score:2)
Not sure what good this will do... (Score:1)
I don't see the point of this:
1: If a person wants their password changed, they almost always want it changed now, on all devices, no going back.
2: If a bad guy gets someone's password by coercion, they can easily change it, add 2FA, purge the old request, and be off with that to demand ransom for the account. This is where the $$$ is, because a mugger can lock up thousands of dollars, if not tens of thousands in an instant with an AppleID code.
3: Same with someone snooping on a passcode entry. Get tha
Re:Not sure what good this will do... (Score:4, Insightful)
Re:Not sure what good this will do... (Score:4, Informative)
Or, user makes a typo and didn't realize it, and now cannot log in.
It happens. And the problem is the "password reset" is literally to reset the entire device and reload it from backup.
Re: (Score:2)
...
4. User realises that they forgot the new password and didn't write it down.
5. User realises their iPhone is a brick."
6. User buys a brand-new $1500 iPhone.
Re: (Score:2)
User buys a brand-new $1500 iPhone.
So are you saying this is an excellent move by Apple, saving some costumers $1,500, or a stupid move by Apple, totally upsetting customers who are then going to pay $1,500 for the most expensive Samsung phone?
Re: (Score:2)
My workplace uses MS and 2FA with annual password update. This month I updated my password, and I noticed I forgot to update it from the getmail6 conf file LAST YEAR. It still worked for a year. Heck I just checked I last time updated my password in .msmtprc in 2019! (I use msmtp with mutt and DavMail to connect to O365). I update my password annually and forgot to update it in .msmtprc for over FOUR YEARS... My conclusion is MS password changes are fake, or faker than Apple's.
This is literally (Score:3)
Re: (Score:2)
And please explain to me how this helps hackers. They need your phone for this. And your passcode. If they have your phone then _you_ cannot change the passcode, you can only disable the phone. If you think someone knows your passcode through shoulder surfing, you change your password and disable changing it back before someone steals your phone.
Re: This is literally (Score:2)
no brainer (Score:1)
It’s the pass*code* not the password.. (Score:2)
.. and it’s for the device, not the AppleID, as TFA makes clear. This is equivalent to a Windows laptop’s PIN, not a Microsoft account.
I still don’t think too much of the idea, though.
Re: (Score:2)
I wrote an app that had its own passcode, and could use biometrics