JF Mezei <
jfmezei...@vaxination.ca> wrote:
> On 2018-09-21 04:45, David Empson wrote:
>
> > I tried it again to confirm before my previous post. When you sign in to
> >
icloud.com, it invokes 2FA and prompts for the verification code, but
> > has a button to go to Find my iPhone without needing to enter the
> > verification code. This works even if someone else has your device and
> > rejects the 2FA request.
>
> Thanks. This is new as last year when I inquired, was not told about this.
It is not new. It has been possible to use Find my iPhone without
authenticating for way more than one year, probably since 2FA was
introduced.
I don't recall when I first found out about it, but it was certainly far
enough back that I wasn't worried about enabling 2FA when I did that
about two years ago for my main Apple ID.
I haven't found any documentation from Apple explicitly stating that
Find my iPhone can be used with 2FA enabled. Probably because it is
obvious that not being able to do so would defeat the purpose if you
only have one device and you need to find it.
Also...
Here is an article from August 2016 pointing out that Apple NOT
requiring 2FA on Find my iPhone is a security risk, because your devices
are vulnerable to being found, locked out or erased by someone else
getting hold of your Apple ID and its password, even if they don't have
physical access to any of your devices:
https://www.tomsguide.com/us/iphone-two-factor-authentification,news-23097.html
Use a strong and unique password for your Apple ID.
Just in case it isn't clear: this applies (and the security risk exists)
even if you DON'T enable 2FA.
> "Find My Phone" was the show stopper for em and if this is solved, then
> I could set it up. (You had already explained how to make oit work on my
> Snow Leopard server when I had asked about this last year).
Hunting through my previous posts I assume you are referring to the
mechanism whereby older OS versions which don't support 2FA attempting
to log in to services using your Apple ID (e.g. App Store) trigger a 2FA
request on your devices running a newer OS, then you need to append the
2FA code to the Apple ID password to complete the login on the old OS. I
had a discussion about you with that in January 2017.
--
David Empson
dem...@actrix.gen.nz