I’m curious to know why you’re so vehemently opposed to 2FA.
As someone who values convenience, I concede it’s somewhat annoying at times (if it involves an authenticator app), but in the vast majority of circumstances Apple does a good job of handling passcodes, making it little more than a single click to authenticate. I’m wiling to accept this trivial inconvenience for the added security.
I think you’re at a paradoxical rubicon where refusing 2FA is causing you more inconvenience than adopting it.
I use 1Password, and it just requires the vault to be unlocked to store a new passkey. I just have to enter the vault password if Touch ID or Face ID isn’t available.
For Passwords, the fallback should be to enter the device passcode in the case of an iPhone or iPad or to enter your user account password to authenticate yourself if Touch ID or Face ID isn’t available. I verified this is indeed how it works for unlocking Passwords. For saving passkeys, however, it was a little weird as I describe below.
I disabled 1Password and enabled storing passkeys in Passwords in Safari. When Touch ID was enabled on my MacBook Pro, I was asked to authenticate when storing the passkey. After I disabled Touch ID, however, the passkey was saved in Passwords without any sort of authentication. I’m not sure what Apple’s logic there was or if it’s a bug in Sequoia.
On a possibly related note, while trying to disable Touch ID, I ran across a bug. I first tried disabling just unlocking Passwords with a fingerprint, but the system still let me use Touch ID to do so even after logging out and back in again. I had to delete the fingerprint completely before it resorted to asking for the password to my user account to unlock Passwords.
I understand their opposition comes from the fact that Apple is forcing adoption via a one-way street. If you later decide you want to go back (for whatever reason) you can’t. I too am usually weary of such corporate coercion (FTR I did adopt 2FA a long time ago).
Well they still have two weeks to decide, and they don’t seem too concerned about the one way street of needing an Apple ID to get updates, buy apps etc. ChatGPT tells me 2FA is required for a new account but I can’t verify if this is the case - my ID goes back way before 2FA was a thing.
I still don’t understand how having your account repeatedly locked is somehow more convenient than simply setting up 2FA and enjoying the added security.
Anytime my account was locked it was necessary to log back in to Messages, TV+, and the App Store so, yes, it can/does log you out of established connections.
I hope @j.albert will post again at some point so we can find out their views on the security vs. convenience tradeoff (or on what underlies their avoidance of 2FA).
OK, seems I need a memory upgrade myself! I was thinking it had something to do with fingerprint or facial ID. But oh, wait yes you could do that on some Macs!
Once you’ve set it up, you mean? I’ve never used face or finger ID on my Apple devices. I’m quite satisfied with using passwords and KeePassXC.
I sympathize with the OP, but his insistence is misplaced. I do however recognize in his observations that at some point, for everyone, ‘can’t be arsed’ applies.
I may have missed it earlier in the thread, but in response to the question about using a flip phone for 2FA, it’s definitely possible. You can even use a land line.
You can receive an authentication code via text or voice call. You just need a phone number that is easily accessible and that can be added to your Apple account as a trusted phone number.
Folks asked why I’m not interested in 2-factor authentication.
I’ll try to explain. I realize in advance that my explanation may not be enough for many of the calibre of users here.
I prefer my Macs to be “clean and simple”.
(2024 m4 Mini, 2021 m1pro MacBook Pro, 2018 Mini)
The first things I do when I set up a new one:
Turn off spotlight (no indexes, please), disable it as much as possible
Disable Startup Security (I want the LEAST “security” possible)
Disable Gatekeeper (I’ll open whatever app I want, thank you very much)
Disable System Integrity Protection (don’t want it!)
Make sure time machine is off (I use other backup apps)
I don’t use iCloud and don’t want it “managing” anything of mine (I realize the Messages app might be part of iCloud, that’s the ONLY app I use)
Turn off Siri and AI (prefer not to have them)
I want the OS “intruding” as little as possible into the “Mac geist” I’ve been comfortable with for forty years.
I realize how this is changing, due to Apple’s slow but relentless and inevitable push to transform “the Mac OS” into “the Mac iOS”. Essentially, the iPad iOS “with a finder”.
Some things I can’t control, but other things remain which I still CAN.
And THAT’S WHY I choose to do so.
Pretty much… just because I can.
When they make it impossible to use the Mac without 2-factor authentication, perhaps then I’ll use it. Until that time comes, so long as I still have “a choice”… I choose not to.
Perhaps I’m just a contrarian. I can’t explain it any better…
I think most people do, but actively disabling all built in security measures, then rejecting the primary method used by virtually all banks and financial institutions to secure your accounts, all whilst having a machine which accesses the Internet, seems like folly to me.
Forgive my bluntness but “just because I can” seems a poor reason to expose yourself. But to each their own, you do you.
This is perhaps a good moment to remind everybody that all are entitled to running their own Mac on their own terms. Nobody owes anybody an explanation for anything. Asking out of curiosity is fine, being inquisitive IMHO is not. I may not agree with how somebody else runs their Mac, perhaps I have even the best of reasons why that is dumb, but that doesn’t concern me and is neither a reason to ridicule or attack another poster. (not saying that happened, just getting a vibe that we’re approaching where these things become unpleasant)
“The scribes and the Pharisees sit in Moses’ seat: All therefore whatsoever they bid you observe, that observe and do; but do not ye after their works: for they say, and do not.”
J, I just want to clarify, in case there is any doubt, that I did not post here with any intention of attacking you. If you found anything I wrote to be confrontational, dismissive, insulting, aggressive, or patronizing, I apologize.
I never did anything to set up a passkey for my Apple ID as far as I know. I just noticed one day when I was signing in on an Apple website (in Safari), I wasn’t asked for my Apple ID, which was probably stored in a cookie, or a password. I just had to authenticate with Touch ID. When the FIDO Alliance introduced passkeys to the public, I recognized that’s what Apple had already been using on its sites for quite awhile.
I’m a 40-year Mac user also. I have and use two Macs - a Mini and a Macbook air. I am careful to keep them up to date where I can and benefiting from security fixes, etc. With two Macs I found iCloud super useful in keeping lots of stuff in sync between the two devices - I couldn’t imagine the complexity of not having this in place. I use 2FA and passkeys where I can because it makes good sense to do so. I have zero problems with my apple account. It may be that this is not unconnected. IMHO going online with a device that is not up to date ( and therefore insecure) is to invite disaster.