Hacker News new | ask | show | jobs
by dv_dt 1135 days ago
If they buy another iPhone, how do they authenticate to the cloud account? A password that hasn’t been used in months or years? Standard credit collection agency data (which is stealable and has been stolen for many people already?)
1 comments

Yes, correct. Apple documents its restore process here:

- https://support.apple.com/en-us/HT210217

- https://support.apple.com/en-us/HT204974

They also have account recovery processes which use metadata about you to try and verify your identity.

Note, this is the system they are using today for passkeys. So this is not some kind of compromise or complexity with password vaults that passkeys eliminate, it's just the universal process of account recovery that we have today with all of its flaws, and passkeys don't add any additional protections or simplicity on top of this system.