This topic made me think about the single point of vulnerability in my digital life. I am too dependent on Apple. Granted, Apple is still the more secure platform. Reviewing my trusted device in the Security page in Settings, I have like 5-6 devices. Every time I login to a Apple id, all these devices start prompting showing me a map and wanting to give me the 6 digit code. Some of these devices, e.g. the iPad is being used by the kids. What happens if the social engineer worked the wife or the kids instead? There doesn’t seem to be a way to get Apple to only send prompt to mny iPhone, instead of the iPad or the MacBook Air. This is my concern.
According to the Apple support page, the only way is to remove the device from the Apple ID, but it means I am also disconnecting it from iCloud - for instance, the iPad will not have access to the photos.
Apparently, upon digging further, there is a way to tie a Yubikey instead of using trusted devices. I am wondering if anyone tried this and whether this will stop other devices from prompting.
I have set up Yubikeys. That is several of them. You should not use a single one with no backup (Apple requests you to set up at least two of them).
When you use Security Keys for Apple Account, you need a physical security key or another trusted Apple device to:
Sign in to your Apple Account on a new device or on the web
Reset your Apple Account password or unlock your Apple Account
Add additional security keys or remove a security key
If you don’t have a security key with you, you can use an iPhone or iPad that’s signed in to your Apple Account to sign in to a new device. Bring the trusted device near the device that you’re using to sign in and follow the instructions on both devices.
Keep your security keys in a safe place, and consider keeping a security key in more than one place. For example, keep one key at home and one key at work. If you’re traveling, you might want to leave one of your security keys at home.
This feature is designed for users who, often due to their public profile, face concerted threats to their online accounts, such as celebrities, journalists, and members of government. For users who opt in, Security Keys strengthens Apple’s two-factor authentication by requiring a hardware security key as one of the two factors. This takes our two-factor authentication even further, preventing even an advanced attacker from obtaining a user’s second factor in a phishing scam.
I turned the feature on when Apple offered it back in 2022. No regrets. Being no celebrity, I still am interested in keeping my data safe…
Thanks for sharing Christian. Just to be clear, after I use the hardware key, I won’t see the prompt with map to get the 6 digits code any longer, right? The reason is the article above said “need to bring a iPhone as trusted device near”… does that mean it still require 6 digit or that trusted device being near (i.e. Bluetooth or NFC) is good enough.
Secondly, I have 2 YubiKeys. If I used them, can one be my fingerprint and the other be my wife’s? I’m guessing there’s no restriction since it recognize by the physical key.
Exactly. You are prompted to connect one of your Yubikeys instead. The Yubikey is the key to add a new device to your account.
No, if you have your Yubikey with you, the Yubikey is the key. You connect the key to your new device when prompted, and that’s it. No more 6-digit code then.
To be honest, when I posted the link to Apple’s article, I wondered if that part already has been there back in 2022 when I set up my keys. I do not understand 100% what it actually means. Apparently, a trusted device can act as a backup when nearby (UWB?, NFC?) if no Yubikey is available? Honestly, I do not like that very much, if this is true… I get why they might have this potential option, but… Maybe, somebody else has more insight.
Apple wants every person to have individual accounts with them. All devices on that account are trusted devices. I do not know if Yubikeys can be set up with multiple accounts. Probably not, but I do not know.
The YubiKey has a fingerprint sensor. So I am assuming the way it works is that it need the hardware key and the fingerprint. In my case, I have one YubiKey with my fingerprint and another YubiKey with my wife’s fingerprint set up on my Apple ID. I just tried it and it registered both devices.
What I am not sure is whether I can use my wife’s YubiKey without her fingerprint. And so I opened Safari and logon to my iCloud. Sure enough, it does not prompt for the 6 digit code anymore and asked me to connect a YubiKey. I connected my wife’s YubiKey to the USB-C port, put in my finger print and it worked! That means, the hardware key is important, not the fingerprint.
Which means, if someone broke into my house and stole the keys and, if he happened to know my id and password (far fetched, I know), that hacker can crack into my iCloud account. That celebrity better have his/her YubiKey stored in a safe! It’s not safe to carry your YubiKey and go out!
If somebody has obtained all the keys that are needed to get into an Apple account or your home, she/he will be able to get in. That is true for the physical key on your keychain and for the Yubikey on your keychain. This is the reason why you need two factors - a password and a second factor that can be a 6 digit code on a trusted device or a FIDO key like a Yubikey.
With regards to fingerprints: there are a lot of different FIDO keys with different features. Fingerprint, no fingerprint.
There’s the gold circle with the Y logo. That’s where I place my finger. When I added Yubikey to Bitwarden and put my finger on it, I will see the 20-30 characters being read and generated in the Bitwarden hardware key’s field. If I lifted my finger up, the characters stopped generating. This gives me the impression that it’s reading my fingerprint.
From the product page, it doesn’t specify fingerprint reading. Maybe the impression from
Bitwarden was just a nice, animated way for Bitwarden to show its recording the hardware key code. Hmm, this is an interesting thing I discover today, as I always thought any YubiKey has fingerprint reading.
I also have two of these; your impression is incorrect:
With user presence , the intent is not to identify the user, but to ensure that a user is physically present and in control of the YubiKey. The YubiKey has a capacitive touch sensor that cannot be controlled by software. Presumably that user is the one who registered the YubiKey, but without user verification, it could be any individual who is physically present at the location where these ceremonies are performed.
Could you set AppleIDs up for the other members of your family (or a shared one for the kids) and use Apple Family to manage the devices. this would abstract them from your account, you can use a shared photo library also.
This is one of the reasons I retain my passwords in 1password. I hate the idea of my passwords being available to anyone who can unlock my phone, or who has gained access to my Apple Account.
Good move. I kept mine in Bitwarden but over the years, I find that some were conveniently saved into Password app, especially Passkeys. You know how Apple devices will helpfully prompt you to save passwords as it encounters them. I am
reviewing them and would suggest anyone to do the same once a year.