Two-factor authentication for Apple ID
support.apple.com
support.apple.com
Edit: Reason for that being that I prefer having all TFA codes in my Google Auth app/Authy with requires no internet connection. Using SMS/text or other devices is a bit inconvenient when traveling and using a local SIM.
Edit: to clarify, I originally tested it on my phone, but I've since tested on Mac and the result is the same.
If you happen to have the iCloud "Account" screen open before losing all connectivity (i.e. it's open, then you turn off wifi/etc), the regular "Get Verification Code" button will work.
In the more likely scenario that you just open up Settings/System Preferences > iCloud > Account, if you're offline it will tell you that you can't see your account details because you aren't online, but that you can generate a verification code while offline.
OP was referring to Google Auth working on phone regardless of current internet connection, the computer being disconnected in unrelated.
However, TFA for Apple Accounts have been available for some time. I think I turned mine on a few months ago.
That RSA handshake saying "hey, it's me-- check the Web of Trust & the fingerprint of this public key I gave to you in person")/identity verification(there's a reason why you not only encrypt but sign your data with PGP) is especially now important to run on your own server & effectively trivialto set up with Docker (which I'd bet at least 70 percent of the readers here use.) To add SSO support for SAML2 (or JWT, or whatever you want-- passport.js supports it all) so others can use their own IdP's to authenticate in via WS-Federation is now trivial.
One day there's going to be some catastrophic data leak of the magnitude of the Philippines leak, of the social importance of the Panama Papers, and of the shock value of the Ashley Madison leak and we'll only have ourselves to blame for making our fun toy web-apps auth against only FB and Google.
[1] This has been a "solved" (mathematically + progmatically via PGP 2.0 for ~25 years with Zimmerman's implementation of the Web of Trust). Who remembers key-signing parties?! Haha. If you lose your key, you call up your buddy Bob who has an authentication claim with the sole ability to talk to the Identification Provider, Alice (whom you and Bob both trust to run your SSO) and your certificate is immediately revoked, so even if your private key and passphrase and device are all lost, no new data the second your key's state moves to 'compromised'. Alice can pull the plug on her RasPi's IdP, killing the whole and I might sound like a tin-foil hatter but re-decentralization for the internet has never been more important. She can pull the plug on it or have a cron-dead-mans-switch that discharges ESD to the volatile RAMdisk and kills the power, at worst she'll get an obstruction of justice charge. Multi-national corporations will comply court-orders if their in-house counsel says the demand isn't viably disputable.
The internet was rooted in academic/sharing culture, and ARPAnet was designed with decentralization as such a fundamental component that redundancies were put in place to literally route information successfully with a significant part of the nation offline as a result of nuclear war. Walled gardens like this are inherently vulnerable to government intervention. That Israeli firm compromised (as I understand it) the iPhone in the 'pwned' sense. If this is a reaction to the public distrust of iPhone as a platform, this isn't any more secure than before. Apple still has to have the initialization vector/nonce/whatever that's seeding the pseudo-random number generator.
From the BSD[2] culture we came, to there we must return.
-- [2] More so referring to the culture of EDA semi-conductor tooling & the attitude of "here, take it, use it, and enhance it, and release it back into public domain, more so than the whole BSD 'the SysV UNIX competitor' and all of the derivatives were spawned from it).
See: https://en.wikipedia.org/wiki/VLSI_Project, https://www.mosis.com/products/fab-processes (which yielded SPARC), http://wiki.geda-project.org/, etc. IBM was also was the other instrumental player in the 70s/80s to enable chip-houses to get past that proverbial wall of a few hundred k components on an IC. Rumors around the EE scene has it that low-run-custom-SoC's are the next B2B move chip houses are going to push, but we'd still be on System/36s and VAXstations if if it weren't for some associate professor in his 30s and a few 25 year old PhD candidates who pushed out the chiptooling that's still in use today (MAGIC, SPICE, and all the subsequent derivatives).
It would be nice if we could get some decent two-factor authentication in the next iteration. I hope Idensys (DigiD's successor) will get the hardware factor right, and provide a truly cross-platform solution that does not involve mobile phone numbers.
but if you are already trying to login to Apple ID it means you already have Internet connection on your computer, what prevents you from using the same Internet connection for other devices that could get the key?
Edit to clarify my confusion: is this new? What's the difference between this and two factor verification (which we've had for a while)?
> Is this different than Apple’s current two-step verification feature?
> Yes. Two-factor authentication is a new service built directly into iOS 9 and OS X El Capitan. It uses different methods to trust devices and deliver verification codes, and offers a more streamlined user experience. The current two-step verification feature will continue to work separately for users who are already enrolled.
Since I was already using two-step verification, I had to turn it off for the new, two-factor authentication, option to appear. I turned it on and it looks like it's working now.
I have to agree that this was very confusing.
EDIT: looks like I can authenticate from OS X now, nice. Before I had to always unlock my phone.
This can be very confusing and should be made more clear in Apple's documentation the iCloud Preferences UI on OS X.
Here is how I understand it, there are two methods: 1. Two-Step verification 2. Two-Factor authentication
1 is the old method. 2 is new.
With method 1 you can add devices manually as 'trusted'. Auth is a simple 4 digit code and contains no interesting info.
With method 2 devices are automatically added if they are supported and you sign in. You cannot add devices via your account info manually. Codes are 6 digit and auth dialog includes a map with approximate location of login attempt. The new method also seems to be a more 'native' and better experience.
Obviously, method 2 is preferred due to the 6-digit code and more info about the potential attacker (or trustee for those who do such things).
Also, I did have to add at least my iPhone manually at first.
It seems like you might have it backwards?
EDIT: My bad. I tried to set up 2FA, by following the "Manage your Account" link from the 2FA info page, but actually set up the old 2SV, with no 2FA options in sight... This is a grungier experience than I would (naively) expect from Apple, as a new Apple customer. Turns out you must set this up on a device, not through the website! They detail this halfway down the page in the "turn on" instructions.
I guess they first roll-out the feature on people like me who didn't activate old method. If everything goes fine I guess they will prompt everyone to switch to the new method on the next update.
> Yes. Two-factor authentication is a new service built directly into iOS 9 and OS X El Capitan. It uses different methods to trust devices and deliver verification codes, and offers a more streamlined user experience. The current two-step verification feature will continue to work separately for users who are already enrolled.
Wish they would expound a bit more...
Neat.
Had she simply not informed me I might have been in your exact same situation.
Also, if someone WOULD log in with your account in iMessage (or FaceTime), you would know this because you get a notification like this on EVERY device: https://support.apple.com/library/content/dam/edam/applecare...
Wasn't an issue until I wanted to change my Apple ID password, for which the security questions are required.
Phoned Apple Support, and they took me through a dazzling array of security steps, involving my Mac, iPhone, payment methods, and the Apple ID website, before they allowed me to create new questions.
It appears that anyone using the older 2 step verification will need to disable that before you're able to enable the newer system.
On the plus side, I believe the security questions become irrelevant again once you've setup the new 2FA.
just my experience.
I do not have keychain syncing enabled in iCloud, just contacts/calendars.
I much prefer having the recovery key that is provided with two-step; I don't see that the two-factor method offers a recovery key.
Having any security feature associated with either my landline or mobile phone makes me feel uncomfortable for multiple reasons, some that have already been articulated by others here plus some more I can't really put my finger on, except to say that both landline and mobile phones seem inherently untrustworthy to me.
Am I just being paranoid?
Devices are automatically trusted the first time you login and enter a verification code.
When anyone tries to login to your account on the web or from an untrusted device, all of your trusted devices notify you with location of the login attempt. It's a pretty good setup.
Anybody seeing it in there devices?
See https://support.apple.com/en-us/HT204152 and look near the bottom for "How do I turn off two-step verification?"
once you're logged in, go to the "security" section and hit the "edit" button.
The new 2 Factor Verification doesn't require you to pick a device, and it doesn't use 4 digit codes.
as I can not see any reason not to implement a system for it because it would probably only help the company to get more customer.
There are a lot of sites that don't even use TLS, which is a lot simpler & cheaper to implement than a secure 2FA solution.
Two factor auth: * Six-digit code sent to your device/via text
Two factor verification: * Four-digit code sent to your device/via text
Or what exactly is the difference? Surprised Apple would launch something like this.
The old system pushed 4-digit OTP's from Apple to a trusted device of your choice using the Find-My-(iPhone|iPad|Mac) system or an SMS. Only iOS devices could be registered as "trusted" for this system.
The new system shows login attempts on all trusted devices (iOS9 or OS X 10.11 devices) automatically including basic GeoIP location, and will show a six-digit OTP if you want to allow the session. It also allows trusted devices to generate verification codes (a six digit OTP) when offline, e.g. if you need to login to iCloud.com from a public computer but your phone has no data/cell service. Or if for example you have your Macbook with you, but no Wifi access, and your phone battery is flat, and you need to access your account via another computer.
> Surprised Apple would launch something like this
Why is this surprising? They've had 2-step verification available for several years, this is an improvement over that.
> Yes. Two-factor authentication is a new service built directly into iOS 9 and OS X El Capitan. It uses different methods to trust devices and deliver verification codes, and offers a more streamlined user experience.
Basically, it uses a (presumably) more secure method for handling verification. One benefit of this is OS X computers can now be trusted devices that display verification codes (Two-Step Authentication only allows iOS devices to be trusted devices)