Why? Because freaking iPhone asks for that when I want to download something from App Store. How do you guys handle that?
Why? Because freaking iPhone asks for that when I want to download something from App Store. How do you guys handle that?
You have a physical device in your possession. Apple don't seem to have heard about two factor auth. If the only company on the planet that obsessively ties consumer hardware and software into a single cohesive product can't get their shit together the future worries me.
It should be the default (with an opt out for access from non-apple devices) for every Apple service to authenticate with the device as well as the password. Anyone who steals your Apple login but not your phone should have zero chance of accessing your data.
"this is a really dumb password" is probably actually a really good password. ;-)
And also, your "problem" is simply your decision to trade security for convenience.
You need to weigh the risks vs. reward and make the choice for yourself. If something goes wrong, at least you'll know why.
The only good passwords are ones that stay well away from dictionary words..
Six words chosen from this list http://world.std.com/~reinhold/diceware.wordlist.asc truly at random gives you almost 80 bits of entropy. And six random words are easier to remember than 16 totally random letters.
EDIT seriously, 221073919720733357899776 is a really big search space. If you have a computer that can search a billion per second, it's going to take 1000 computers 1000 years to catalog just 14% of the search space.
Against an attacker who knows exactly how you chose your password, it's (roughly) the same level of security as a 14-digit numeric code, or an 8 letter case-sensitive alphanumeric code. It's just supposed to be easier to remember.
How many people use this kind of approach, I don't know. Schneier seems to focus on "three random letters" kind of attacker.
There are archives of know passwords -- millions of them. These should be rejected on any online service.
There are tools for guessing passwords. Any password which falls into any of he likely-to-be-guessed divisions should _also_ be rejected.
Dictionary words _could_ work in a sufficiently large namespace. But that's pretty iffy.
In fact, the Schneier method for generating passwords is probably worse than the xkcd method because a significant percentage of the people who try to use his method will choose a password with low entropy such as "wtpotusio2fampu" (We The People of he United States...) or "igmhaohcr" (I'm gonna make him an offer he can't refuse).
All I have to do is crawl the internet and calculate, say, the top 5 million n-grams. The resulting 5 million candidate passwords would be far more likely to match a typical Schneier-based password than a corresponding list of 5 million candidate passwords designed to match an xkcd-based password.
The simple rule is this: Don't let users choose a password. They suck at it.
This goes for Game Center as well. You can use a different one for your mean, nasty, trash talking Gamer persona.
Apple doesn't always make this clear, and I see a lot of people confused about this, but this is an option.
Another login that can use a different Apple ID is Find My iDevice.
If you want to use this for your App Store account, go into Settings then "iTunes & App Store", and sign out of the previous account. Log in using then different (new) Apple ID.
If you want to use this for your iCloud account, go into your iDevice's Settings, then iCloud, then "Delete Account". It will delete the iCloud data on your phone, but it should still be available on iCloud servers, and any other device hooked up to that account. I haven't looked into how to transfer data from one iCloud into another.
I also have my phone set up for iOS not to ask for the password for 5 or 15 minutes (can't remember the exact option) after I entered it.
So, I never had a chance to just hold my thumb on the home button and go my way.
1. open the App store but don't click on anything 2. hit home button 3. launch keepass client 4. navigate to apple account entry 5. copy password 6. double tap home button to bring up multitasking menu 7. tap app store 8. click install 9. paste password
It feels really stupid doing it, but you can get pretty quick at it. I can't wait for my next iPhone upgrade with touchid.
If you can manage to memorize one, you can memorize two.
I use 1P on my laptop most of the time so it's not a huge deal. Everything else on the iPhone just remembers credentials.
I know I can force myself to use a great password for iCloud but my point is that most of the time, I'd go for an idiot password rather than forcing myself. Just like most people.
for example, pass2'word would only require you to hit the alt-keyboard switch once.