It is interesting that Apple has no way of viewing phone number histories.
It is interesting that Apple has no way of viewing phone number histories.
Feels like there’s a missing password prompt there. And maybe confirmation on a second device, if you have one.
The fact that "I'm going to change my phone number, which is an important credential to this account" has less security than "I want to buy an app for $0.99" just goes to show you that sometimes, particular emergent properties of a system are not what any logical person would come up with deliberately.
That or someone just needs to make a big enough stink and try to get the liability shifted to Apple for negligence here on account takeovers, and they'll figure out how to change.
Don’t know how it is implemented exactly, but on the OS level they can do a lot of clever tricks. From their servers they can literally send a challenge-response protocol to the secure enclave of your computer, thus verifying that on the other end of the encrypted connection they are trully talking with a computer manufactured by them, and that computer is the one which is registered to your account.
If they implement this correctly they can make an attack against this chain of trust very costly.
On the other hand on the web they get a http querry with some cookie attached. Maybe. Lot harder to gain the same level of assurances there. And a simple cross site scripting attack, or a compromised browser extension can steal said cookie.
Known to belong to me, yes. Known to be in my possession, no.
You'd still need one further thing to go on as far as I can figure - I'd need the password to type into my browser first - but treating "browser session" and "machine the browser is running on" as separate levels of trust seems naive in terms of what someone who steals the machine can do.
The real question here, IMO, is how do you prevent against this. Because to the Apple engineers in the US of A, having your phone stolen at gunpoint is almost unheard of, and getting it swiped from your hand is also barely a problem anymore since thieves in the US typically don't go through all this effort to phish the Apple ID password from you (at most they sell it to a 3p service that ships it overseas to China for teardowns and parts salvaging).
0: https://apple.stackexchange.com/q/382190 (note that it prompts for local user account password because the long-lived token that performs a new grant for the Safari session is stored in local Keychain; so if you have touch ID or watch unlock on your Mac, it'll use that first)