At some point the computer science community needs to deal with, and fully embrace, the flaws, caveats and characteristics of the population it serves: the human beings.
It would be stupid not to.
There's also a big difference in the passcode and Apple ID password. The passcode is required several times a day. Failing a FaceID unlock is very common. Having an alpha-numeric passcode is, honestly, a huge pain in the behind. The Apple ID password on the other hand is not required very often, and can easily be stored in a password manager. Storing the passcode in a password manager doesn't make much sense, as you'd then need to unlock a second device to open your password manager to read the passcode to unlock the first device.
Please re-read what I said.
In particular I point you to the "AND" in capital letters. ;-)
As I said. Apple gives you the tools. Use them.
Guessable passwords are of course not good, but to a human a six digit password is actually pretty hard to guess.
The auto-wipe feature introduces a new vulnerability where anyone with physical access to your phone for a minute can wipe it for you. This is a very high-risk threat scenario for people with toddlers in their home.
Remote-wiping the phone from the Apple website is fine, but from what I understand in the article, the thief has already taken control of your account by the time you're home/have access to a second device to do so.
However, it seems Apple actually does provide the tools to avoid the issue in the article, which is to use a second password for Screen Time and add some restrictions. So we can agree on that point :)
Its called backup.
What happens if you loose your phone or drop it in a river ?
You'll be in the same boat in those scenarios as you would if someone local-wiped your phone.
A rate-limited 4-digit passcode gives you breathing room to login to your Apple account and report your phone as stolen.
There are currently insufficient tools to deal with that situation
It will never be possible to deal with that situation.
Its also why many governments have taken to locking people up until they give up their passwords.
Its a scenario that has been immortalised in the famous XKCD wrench conundrum: https://xkcd.com/538/
The only real way to deal with it is to get away from the situation and remote wipe (or hope they type in your password wrong N times so local wipe happens)
Those consequences are design choices - convenience over security. There could be features (tighter Face ID, multiple passcodes, etc) that reduce the blast radius of a leaked iPhone passcode. But Apple hasn’t implemented them. It hasn’t given users the tools to protect themselves, if they value that more than convenience.
You have to type it while outside, cameras and other ppl being around. Even if you have a alphanumeric password as passcode, it can't be too complex because you have to remember it and type it (password manager is behind this lock).
And as soon as someone can record you typing the password, they can now steal your phone and ruin everything.
Ever hear of telephoto lenses? Ever hear of coercion (and, yes, it IS possible to guard against coercion, for example by introducing delays or requiring a third party to be involved in some actions)? Ever hear of good old fashioned sneakiness? ANY password that's used on a regular basis is relatively easy to compromise.
Furthermore, a phone is a convenience device. It NEEDS to be simple to unlock your phone, or it is useless. A "strong unlock password" is a bad fit for actual use of the phone. Therefore, it's stupid to design a system that makes the mere ability to unlock your phone into something that can take over other devices or cloud services.
A phone should NOT be a "trusted device" in the sense that it can do anything major to anything other than itself. It also should not put especially high-stakes assets, on or off of the phone itself, at risk based on a mere unlock. Any system architecture that violates either of those is a shitty, lazy system architecture.
> then that's YOUR problem, not Apple's.
Yes, by being stupid enough to use an Apple device, and thereby subjecting myself to Apple's brain-dead design, I would indeed create a problem for myself. Good thing I have the luxury of not doing that. I mean, I'm also not dumb enough to store my only copies of anything important in any cloud service. But that doesn't make it not Apple's problem if Apple's own cloud service is insecure.
> The point is that with the Secure Enclave, Apple are able to rely on the iPhone being a "Trusted Device" to enable you to reset the Recovery Key. It is up to YOU to respect the "Trusted Device" status and (a) secure the device accordingly and (b) remove said device from your Apple account as soon as it is no longer in your possession.
If a device is to be "trusted", then it needs to be TRUSTWORTHY, which means that it needs to not cause havoc without reasonable authentication. By locking you out of your cloud account without anything more than a screen unlock PIN, the phone is abusing the trust placed in it.
It is also stupid to put unlimited trust in anything anyway, especially complicated, bug-prone things like "Secure Enclaves" and phone operating systems.
There's no reason losing something 100% of people keep on them 100% of the time should equal losing their online digital identity.