This is an atypical choice, but I always lock when I’m done and don’t encounter any issues from this choice.
I try to avoid modern Boeing aircraft as well.
I hear your point, but everything really important on my phone is behind another wall of passwords/pin protection, and I am meticulous about backups. The physical device doesn’t matter much. I’ll put it on stolen mode remotely, force an email sign out, and just assume it’s dead because they won’t be able to turn off Find My.
I also work from home, so I’m more suited to having it in this mode of operation.
That said, from now on I'll probably have auto-lock turned on when flying.
I think you are far far more likely to have a random cardiac arrest or stroke while you are looking at your phone than have it ripped out of your hands in an airplane. The former has happened to several otherwise healthy people I know and the plane thing happened to a few people ever.
Also do you turn it on while you are a passenger in a car or bus?
I also almost never use apps like dedicated banking apps or social media apps; instead, using Safari.
I know folks that don’t lock, and don’t use Face/Touch ID, because convenience (or paranoia).
I’m not sure that’s a good idea. We have our whole lives in these devices, and they could do a lot of damage.
There’s an old movie, called Taking Care of Business[0], where Jim Belushi finds Charles Grodin’s date planner, and takes over his life.
[0] https://en.m.wikipedia.org/wiki/Taking_Care_of_Business_(fil...
Nearly every bank I know of recommends using apps over their website, since in general they're safer than using their websites. But I'm in The Netherlands and I don't know whether banking apps in different countries have the same security standards.
The security model for US banks is that it's illegal to do crimes to people's bank accounts. It doesn't involve "super secure apps", bank account numbers and credit card numbers are super insecure and there is little reason you should care about this insofar as you're not liable for leaking them.
But it's fun when you get your checking account drained, and it takes weeks to get it back.
I've seen that happen to a couple of folks.
That's also why I don't like to link my account to sites like PayPal and Venmo.
With a web browser, there's no way of doing that by design as the user has full control over their user agent, so you need to trust the end user is following good security practices and hasn't allowed their user agent to become compromised.
However, in the EU, banks are legally liable for financial loss caused by unauthorised transfers, so they are increasingly not willing to trust that the user hasn't just loaded their browser up with malicious extensions and malware.
Credit cards will give you the benefit of the doubt with a credit while they investigate. Banks (and credit unions) are going to be VERY hesitant to give you a 5-figure advance into a new checking out while they investigate how your account got drained when it initially looks like you did it. Even the most pro-customer policies practicable won't help when now all your automatic payments start failing. It's certainly a recipe for ruining your week and you'll likely spend the next month or two dealing with the fallout, and that's assuming you don't face crippling financial penalties because of it, which the majority of Americans would.
Social media and store loyalty apps are basically just PID harvesters.
In fact, I have a couple of solitaire games that are constantly nagging me to join leaderboards and take community challenges.
All my financial transactions are done with my Mac, which sits behind a fairly robust home network.
I know, for certain, that banking apps are the #1 first target, for hackers.
Even though some scum corps like Chase make it a PITA to manage my account from a desktop through firefox, that's the only way I'm going to interact with them.
"Download the app!"
Hard no!
In fact these are the only apps I think that appear regularly on my phone, but only when I'm traveling: AirBnB, Uber/Lyft, and whatever airline I'm currently flying on next. I think if I'm crossing borders I've installed whatever gov spyware makes TSA/Global Entry easier. They're already groping me hard, why not.
LA Fitness gets to stay because it's dumb and silent. I don't see anything else not security related. On mobile I talk to the outside world with K-9, firefox, signal, whatsapp, sms. I'm happy.
My fix was to create an entirely new profile, with no customization, no cookies restrictions, no add-ons, and use it only for financial sites.
I then exit my current FF, and switch to it, and back again.
All my issues vanished after doing that.
You could also create a different user in Linux, and isolate that way.
Hope it helps.
FWIW, you can also run multiple profiles simultaneously. They are independent processes, sharing no resources or permissions.
This is my model for difficult sites. If I'm really concerned, I use FF network config to allow access only to the domains I think are proper.
Although in the case of banking, I prefer to use the official mobile apps. Some are actually pretty good. Others are awful. But I trust the iOS app sandbox and I trust my banks.
I also block traffic at the network level, so if the bank app attempted something egregious (e.g. tracking via the basket of Internet deplorables), it would fail.
Of course this is actually "phone factor authentication" and not two-factor authentication, but I kinda need a bank account.
When I first run an app, and it asks for access to camera, microphone, photos, calendar, contacts, and location, I tend to immediately plonk it; regardless of its purpose.
I have a PMB, and the store has an app that uses the phone to unlock the door, after hours.
There is a keypad, but that hasn't actually worked, in months, and the store has ignored my reports.
I just go there, during business hours, even though it's inconvenient.
Basically the phone is the 2FA generator.
If they have access to the recovery email and your phone then they have the keys to the house anyway.
My phone has the fingerprint sensor. I don't use faceid.
I found someone’s Apple Watch that had no password. I could have done a ton of nefarious things if I’d been inclined. Had a different person picked it up, they might have had all their accounts hijacked.
I have a co worker who I won't ride with anymore simply because of that.
The same person who's super disciplined about seat belts likely takes other risks that another person would deem at least as serious.
Having an optional reminder feature is great; forcing it, not so much.
Doesn't take much FOD on the highway for your unbuckled body to slam into something and now you have a driverless vehicle. Also every else in your car should be bucked too so you're not bumping noggins.
Is this how far you're willing to go to boss other people around to fit your preferences?
Or is it just the job of the survivors or your bullshit to sue your estate into non-existence?
Avoiding a car crash in the first place would definitely be the better alternative.
Do you think of the 6 million police reported auto crashes in 2022 (in the US if you're not from here) that most if not all the people involved would have rather not been in an accident in the first place?
Although it may well have been reconfigured, by default iPhones will lock up after a short inactivity.
simpler explanation, it's 2023 apple code...
But sometimes that's not worth the hassle. E.g. I disabled locks while my car was running.
The tradeoff is IMHO well worth it as I immediately take the phone from the car should I leave. So the overall risk is minimal. Yet should it ever distract me then that's a big issue.
And not being reachable was also not an option given family circumstances at that time.
It's just a risk vs. benefit tradeoff. And that's a very personal judgment call.
Most people don't expect a stranger to post photos of their phone's screen on the Internet either.
Being thoughtful is also important. I can think of no reason for anyone to share an innocent stranger's details on the Internet.
I set mine to lock and auto-turn off after a short moment.
Nonetheless, I have found that the phone will sometimes get in a state or screen which prevents autolocking. It does this usually at the same state or screen but it's easy to trigger accidentally without noticing.
...just pull down the top bar. That might happen if you're holding your phone and it gets sucked out of your fingers. Or stolen right out of your hand.