This topic made me think about the single point of vulnerability in my digital life. I am too dependent on Apple. Granted, Apple is still the more secure platform. Reviewing my trusted device in the Security page in Settings, I have like 5-6 devices. Every time I login to a Apple id, all these devices start prompting showing me a map and wanting to give me the 6 digit code. Some of these devices, e.g. the iPad is being used by the kids. What happens if the social engineer worked the wife or the kids instead? There doesn’t seem to be a way to get Apple to only send prompt to mny iPhone, instead of the iPad or the MacBook Air. This is my concern.
According to the Apple support page, the only way is to remove the device from the Apple ID, but it means I am also disconnecting it from iCloud - for instance, the iPad will not have access to the photos.
Apparently, upon digging further, there is a way to tie a Yubikey instead of using trusted devices. I am wondering if anyone tried this and whether this will stop other devices from prompting.
I have set up Yubikeys. That is several of them. You should not use a single one with no backup (Apple requests you to set up at least two of them).
When you use Security Keys for Apple Account, you need a physical security key or another trusted Apple device to:
Sign in to your Apple Account on a new device or on the web
Reset your Apple Account password or unlock your Apple Account
Add additional security keys or remove a security key
If you don’t have a security key with you, you can use an iPhone or iPad that’s signed in to your Apple Account to sign in to a new device. Bring the trusted device near the device that you’re using to sign in and follow the instructions on both devices.
Keep your security keys in a safe place, and consider keeping a security key in more than one place. For example, keep one key at home and one key at work. If you’re traveling, you might want to leave one of your security keys at home.
This feature is designed for users who, often due to their public profile, face concerted threats to their online accounts, such as celebrities, journalists, and members of government. For users who opt in, Security Keys strengthens Apple’s two-factor authentication by requiring a hardware security key as one of the two factors. This takes our two-factor authentication even further, preventing even an advanced attacker from obtaining a user’s second factor in a phishing scam.
I turned the feature on when Apple offered it back in 2022. No regrets. Being no celebrity, I still am interested in keeping my data safe…
Thanks for sharing Christian. Just to be clear, after I use the hardware key, I won’t see the prompt with map to get the 6 digits code any longer, right? The reason is the article above said “need to bring a iPhone as trusted device near”… does that mean it still require 6 digit or that trusted device being near (i.e. Bluetooth or NFC) is good enough.
Secondly, I have 2 YubiKeys. If I used them, can one be my fingerprint and the other be my wife’s? I’m guessing there’s no restriction since it recognize by the physical key.
Exactly. You are prompted to connect one of your Yubikeys instead. The Yubikey is the key to add a new device to your account.
No, if you have your Yubikey with you, the Yubikey is the key. You connect the key to your new device when prompted, and that’s it. No more 6-digit code then.
To be honest, when I posted the link to Apple’s article, I wondered if that part already has been there back in 2022 when I set up my keys. I do not understand 100% what it actually means. Apparently, a trusted device can act as a backup when nearby (UWB?, NFC?) if no Yubikey is available? Honestly, I do not like that very much, if this is true… I get why they might have this potential option, but… Maybe, somebody else has more insight.
Apple wants every person to have individual accounts with them. All devices on that account are trusted devices. I do not know if Yubikeys can be set up with multiple accounts. Probably not, but I do not know.
The YubiKey has a fingerprint sensor. So I am assuming the way it works is that it need the hardware key and the fingerprint. In my case, I have one YubiKey with my fingerprint and another YubiKey with my wife’s fingerprint set up on my Apple ID. I just tried it and it registered both devices.
What I am not sure is whether I can use my wife’s YubiKey without her fingerprint. And so I opened Safari and logon to my iCloud. Sure enough, it does not prompt for the 6 digit code anymore and asked me to connect a YubiKey. I connected my wife’s YubiKey to the USB-C port, put in my finger print and it worked! That means, the hardware key is important, not the fingerprint.
Which means, if someone broke into my house and stole the keys and, if he happened to know my id and password (far fetched, I know), that hacker can crack into my iCloud account. That celebrity better have his/her YubiKey stored in a safe! It’s not safe to carry your YubiKey and go out!
If somebody has obtained all the keys that are needed to get into an Apple account or your home, she/he will be able to get in. That is true for the physical key on your keychain and for the Yubikey on your keychain. This is the reason why you need two factors - a password and a second factor that can be a 6 digit code on a trusted device or a FIDO key like a Yubikey.
With regards to fingerprints: there are a lot of different FIDO keys with different features. Fingerprint, no fingerprint.
There’s the gold circle with the Y logo. That’s where I place my finger. When I added Yubikey to Bitwarden and put my finger on it, I will see the 20-30 characters being read and generated in the Bitwarden hardware key’s field. If I lifted my finger up, the characters stopped generating. This gives me the impression that it’s reading my fingerprint.
From the product page, it doesn’t specify fingerprint reading. Maybe the impression from
Bitwarden was just a nice, animated way for Bitwarden to show its recording the hardware key code. Hmm, this is an interesting thing I discover today, as I always thought any YubiKey has fingerprint reading.
I also have two of these; your impression is incorrect:
With user presence , the intent is not to identify the user, but to ensure that a user is physically present and in control of the YubiKey. The YubiKey has a capacitive touch sensor that cannot be controlled by software. Presumably that user is the one who registered the YubiKey, but without user verification, it could be any individual who is physically present at the location where these ceremonies are performed.
Could you set AppleIDs up for the other members of your family (or a shared one for the kids) and use Apple Family to manage the devices. this would abstract them from your account, you can use a shared photo library also.
This is one of the reasons I retain my passwords in 1password. I hate the idea of my passwords being available to anyone who can unlock my phone, or who has gained access to my Apple Account.
Good move. I kept mine in Bitwarden but over the years, I find that some were conveniently saved into Password app, especially Passkeys. You know how Apple devices will helpfully prompt you to save passwords as it encounters them. I am
reviewing them and would suggest anyone to do the same once a year.
@Topre: What happens if the social engineer worked the wife or the kids instead?
The same thing probably applies to having your wife as a Recovery Contact. The best practice would probably be to do the following:
1. Setup a Recovery Key for your Apple Account
a. See: Set up a recovery key for your Apple Account - Apple Support
b. Setting up a Recovery Key turns off Apple’s standard account recovery process.
c. Save copies in multiple secure locations, but NOT in any place readily accessible through your Apple Account (such as Apple Mail, iCloud Drive, iCloud Photos, Notes, Messages, etc.). For example, you could print the code on paper (and seal it in an envelope) and store it in a fire safe, safety deposit box, in a locked drawer at work, at the home of a friend/family member, etc. If you wanted to be extra cautious, you should avoid identifying exactly what the code is on the sheet of paper so a malicious actor who got it wouldn’t even know what Apple Account it is associated with. You could mark it as Topre’s Code or something. 2. Do NOT setup (and remove if already setup) any Recovery Contacts for your Apple Account
a. See [I don’t have permission to share more than 2 URLs]
b. A Recovery Contact can generate a code that serves the same purpose as the Recovery Key. That’s convenient, but it also opens up the possibility that someone could target your Recovery Contact and trick them into sharing the recovery code. 3. Enable Security Keys for your Apple Account
a. See link shared by @Christian
b. As already noted, enabling Security Keys means you need either a physical security key or a trusted Apple device (that’s already signed into your Apple Account) to login to a new device or to reset your Apple Account password. Apple’s documentation isn’t completely clear, but I assume someone could gain access to an Apple Account with using the account recovery process + Recovery Key + Trusted Phone Number, without having a physical security key.
c. I would strongly recommend adding multiple Security Keys. (I believe Apple limits you to six.) I would suggest keeping one with you (e.g., on your keychain), one at your home, and at least one offsite somewhere (e.g., safe place at work, at the home of a friend/family member, etc.). 4. Turn on Advanced Data Protection for iCloud
a. See: How to turn on Advanced Data Protection for iCloud - Apple Support
b. Unless you’re in the UK, in which case your government says you can’t have good security.
c. Advanced Data Protection for iCloud turns on end-to-end encryption for virtually all of the data in your iCloud account (except Mail, Contacts, Calendars, and Invites). It also means that it would be impossible for anyone to gain access to the content of your Apple Account without either control of a trusted device (and, presumably, the device passcode/password), your Recovery Key, or the code generated by a Recovery Contact. 5. Secure your E-mail Account(s)
a. Make sure any e-mail accounts associated with your important accounts are similarly secured. Most online accounts allow passwords to be reset by a simple password recovery link sent to the account e-mail address. That makes your e-mail account a critical point of failure. 6. Secure your Phone Number / Mobile Phone Service Account
a. Many online accounts allow passwords to be reset, or identities to be verified, by sending a code by text (or sometimes voice call) to your mobile phone number. Thus, it is important to make sure your mobile phone number is protected. (The Trusted Phone Number also plays an important role in Apple Account recovery, even with a Recovery Key enabled.)
b. Steps to take:
(1) Enable SIM lock / SIM protection (or equivalent) with your carrier
(2) Enable Number Lock (port out lock) with your carrier
(3) Use a unique, strong password for your account with your carrier
(4) Enable MFA/2FA for the account
(5) Enable any other account/number protection features available
(6) If you have a family plan, make sure anyone else on the account who is an owner/manager does all of the above too. 7. Use 1Password or Bitwarden (not Apple Passwords)
a. Don’t let your Apple Account be a single point of failure. I would strongly recommend using 1Password or Bitwarden (or Keepassium/Strongbox/KeePass XC or another carefully selected reputable password manager).
b. Use all available options to secure your password manager account/database.
c. Maintain offline backups of your password database.