Hacker News new | ask | show | jobs
by Axien 1198 days ago
I’m stunned you can change your Apple password with just a passcode and the device.
1 comments

There was a large problem of websites showing fake Apple ID login screens to steal people's Apple passwords.

Since then, Apple has changed iCloud log-in to use a derived key that requires the 6-digit passcode. This has reduced the problem dramatically.

It's very strange that they don't require the old password or any sort of 2FA (for users with multiple Apple products) to change the password though.