181 ms·
> using a separate PIN/passcode at application-level provides a separate (master) password which would be used for all your passwords (in case your AppleID pass
by zuprau 3y ago
> using a separate PIN/passcode at application-level provides a separate (master) password which would be used for all your passwords (in case your AppleID password gets compromised).
That already happens exactly as you mentioned.
You need a secondary encryption password for encrypted iCloud data as well. Having access to your Apple account isn't enough.
https://support.apple.com/en-ph/HT202303#:~:text=Apple%20will%20not%20have%20the%20encryption%20keys%20to%20help%20you%20recover%20it%20%E2%80%94%20you%E2%80%99ll%20need%20to%20use%20your%20device%20passcode%20or%20password%2C%20a%C2%A0recovery%20contact%2C%20or%20a%20personal%C2%A0recovery%20key https://support.apple.com/en-ph/HT202303#:~:text=Apple%20wil...
- egberts1 3y agoTHIS! Apple finally provides a modicum variant of Zero Knowledge password. But that is only available in next iOS version 16.2. [1] But, but ... BUT the Apple macOS/iOS issue of Three Form of Authentication being still being reduced into Two-Form with their merge (OR-logic) of what you have (FaceID/TouchID) and what you know (PIN/passcode) ... remains. That reduction of authentication is still the greatest weakest link to individual security (whether ADP is used after v16.2 or not). https://support.apple.com/en-ph/HT202303#:~:text=Apple%20will%20not%20have%20the%20encryption%20keys%20to%20help%20you%20recover%20it%20%E2%80%94%20you%E2%80%99ll%20need%20to%20use%20your%20device%20passcode%20or%20password%2C%20a%C2%A0recovery%20contact%2C%20or%20a%20personal%C2%A0recovery%20key https://support.apple.com/en-ph/HT202303#:~:text=Apple%20wil...