If, like me, you skipped over the recovery key step when switching on two-factor authentication for your Apple ID, thinking that having the password plus a trusted device was sufficient, you’ll want to correct that.
TheNextWeb‘s Owen Williams recently found that if someone tries to hack your account, and you get locked out, there’s no way back in without a recovery key.
While Apple states on its website that a new recovery key can be generated so long as you know your password and have access to one of your trusted devices, this is not true once the account is locked. No recovery key, no access. No amount of pleading by Williams would persuade Apple to help. Apple increased its security measures following the phishing attack on iCloud.
In Owen’s case, he did have a key, he just couldn’t find it. It was only by digging it out of a Time Machine backup that he was able to regain access to his account.
So, if you don’t yet have a recovery key, or can’t lay your hands on one, here’s what you need to do:
-
Go to My Apple ID
-
Select Manage your Apple ID and sign in with your password and trusted device
-
Select Password and Security
-
Under Recovery Key, select Replace Lost Key
FTC: We use income earning auto affiliate links. More.
This information needs to be emailed to customers pronto… With 3 monthly reminders! Very important stuff this is.
Apple discourage storing the key on a device. Everything that can connect to the internet can be hacked, especially your e-mail inbox. Apple recommend that you physically write the key somewhere.
Also, the recovery key is not known by Apple. To remind you every 3 months, it’d have to reset it every time for you. I already see 2 problems with that approach.
If I read your comment wrongly and you meant to e-mail you a reminder every 3 months (opt-out) to make sure you still have the key and know where it is, I totally agree.
Thank you for the PSA! :-)
I’m going to check my keys now. I’ve also put a reminder repeating every 3 months.
What are the chances of getting hacked? can they unlock my phone?