Apple Tightens Passcode Security on iPhones to Thwart Thieves (coming soon)
Paywalled at Bloomberg. Use the archive https://archive.is/W4Ief
Problem: A thief can see you enter your device passcode. They steal the phone and the way to unlock your passwords is THE SAME DEVICE PASSCODE.
This happens with devices without touch ID or Face ID, OR when Apple decides (usually when I am checking out in a damn store) to require the device passcode to be typed in regardless of touch ID or Face ID.
It is also used to change your Apple ID, so the first thing they do is lock you out of your Apple ID.
With this change, a thief can see you type in a passcode (or otherwise steal it) and then steal the phone, and not have immediate access to your passwords in the keychain or Apple ID with the same device passcode that they just stole. It will take more than that.
FINALLY!
On Tuesday, the company released the first beta-test version of iOS 17.3, which includes a new Stolen Device Protection feature. The enhancement will require Face ID or Touch ID with no option to use a passcode when accessing stored passwords, changing Apple ID settings, looking at payment information and disabling Find My iPhone.
In some cases, thieves have been able to access personal data on iPhones, steal money and upend a persons digital life by knowing the device passcode. For instance, a thief could watch users input their passcode into their iPhone in a public place before stealing the device.
By requiring Face ID or Touch ID for accessing critical parts of the iPhone, a thief wouldnt be able to cause as much damage. In particular, it would be harder to wipe the device and resell it. Apple didnt say when the new feature will roll out to all customers, but the company is planning to release iOS 17.3 publicly early next year.
...
The enhancement will add a one-hour delay and require a second Face ID or Touch ID scan for the most sensitive tasks, including changing an Apple ID password, turning off the Stolen Device Protection feature, creating a new passcode, and disabling Touch ID or Face ID. There will be no delay, however, if users are at a known location like their home or work.
Did you notice that Apple Pay turns on location services?
It wants to know that you are at the store that is getting paid.
I don't know if it checks location for online payments.
Coming with 17.3