Losing Two-Factor Recovery Key Could Permanently Lock Apple ID

In March 2013, Apple introduced two-factor authentication to provide additional security for Apple IDs. It expanded the feature to several new countries earlier this year and introduced it to the company's iCloud.com website this September. This was after CEO Tim Cook promised to broaden use of its two-factor authentication system in the wake of a hacking incident that saw several celebrities' iCloud accounts hacked.

recoverykey
The system requires a user to have a second "trusted" device that is used to verify a user's identity in addition to an extra security code called the "Recovery Key". However, in a new account from The Next Web's Owen Williams, that Recovery Key also has the potential to completely lock a person out of their account if they're being hacked.

Williams found that someone had tried to hack his iCloud account. Apple's two-factor system kicked in and locked the account, denying entry to the would-be hacker while also denying entry to Williams. When he went to iForgot, Apple's account recovery service, he assumed two of his password, Recovery Key or trusted device would unlock his account, as he was led to believe by an Apple Support document.

When I headed to the account recovery service, dubbed iForgot, I discovered that there was no way back in without my recovery key. That’s when it hit me; I had no idea where my recovery key was or if I’d ever even put the piece of paper in a safe place. I’ve moved since I set up two-factor on iCloud.

Williams contends he took a screenshot of the Recovery Key and printed that out as well as taking a photo on his iPhone to keep as a backup, but could not locate either and was on the verge of losing his "digital life". He called Apple customer support and was told  that he had forfeited his Apple ID by losing his Recovery Key and that there was no way Apple could help him. He called back a second time.

When she got back on the line, the story was just as bleak. “We take your security very seriously at Apple” she told me “but at this time we cannot grant you access back into your Apple account. We recommend you create a new Apple ID.”

After a couple more days of talking to Apple customer support and even friends who worked at Apple, he continued to receive same responses: he was locked out of his account due to someone trying to hack into it and couldn't unlock it without a Recovery Key even though Apple's support document says it's possible with a trusted device. Eventually, Williams located his Recovery Key in what he calls the "depths" of his Time Machine backup, allowing him to finally unlock his account.

Williams concludes with a warning that anyone with two-factor authentication should take far greater care in protecting and remembering where they store their Recovery Keys, as losing it could permanently lock a user out of their Apple ID with Apple unable to do anything to help. The entire account, which is a fascinating and worthwhile read, can be read at The Next Web.

Top Rated Comments

kitsap2 Avatar
78 months ago
Breaking News!

System works as designed!
Score: 101 Votes (Like | Disagree)
leman Avatar
78 months ago
I am also confused how this is news. Apple explicitly states that losing the key will make the recovery impossible. And anyway, do you want secure accounts or not? If yes, then you are personally responsible for your stuff. Putting this silly article on MacRumours is entirely pointless.
Score: 29 Votes (Like | Disagree)
lolkthxbai Avatar
78 months ago
Extra! Extra! Read all about it! Man discovers responsibility!
Score: 28 Votes (Like | Disagree)
Rigby Avatar
78 months ago

Two-Factor Authentication is just that:
A user will need 2 out of the 3;
1. Password
2. Device
3. Recovery Key

The name of service describes it.

Except that it apparently doesn't work that way if Apple decides to lock your account due to hack attempts. In that case you have to have the recovery key, even if you have the 2 other factors. I think it is a bit draconian to permanently lock the account like that, given the value attached to it (you could lose not only your iTunes purchases, email, cloud documents etc., but also effectively brick your devices if you use Find my iPhone and need to restore a device for some reason).

They could perhaps release the lock after 48 hours, or unlock the account if you supply password, trusted device, and some additional verification (like showing a photo ID at an Apple store or sending a verification code to an alternate email address).
Score: 26 Votes (Like | Disagree)
swingerofbirch Avatar
78 months ago
Almost all the posts in here are incorrect about the purpose of the Recovery Key.

The Recovery Key is required if you forget your Apple ID password or lose access to a trusted device.

According to this article, the person in question knew his password and had a trusted device. He shouldn't have needed the Recovery Key.

The only thing Apple says about an account being compromised is that you need to reset your Apple ID password. And it says nothing about needing a Recovery Key to do that.
Score: 26 Votes (Like | Disagree)
TheJae Avatar
78 months ago
So now they are saying Apple is too strict?
Score: 26 Votes (Like | Disagree)

Top Stories

0 Deals Hero

Black Friday 2020: Best Apple Deals to Plan For

Saturday November 21, 2020 10:00 am PST by
In the lead-up to Black Friday next week, we've been putting a spotlight on the best deals coming from various retailers like Best Buy and Walmart. In an effort to further prepare our readers for the best Black Friday deals, we're breaking down what we think should be on your radar for Black Friday in 2020. Note: MacRumors is an affiliate partner with some of these vendors. When you click a...
m1 mac mini vignette

Apple Lists M1-Based Mac Mini Logic Boards With 10 Gigabit Ethernet in Internal Parts Ordering System

Friday November 20, 2020 9:32 am PST by
While the new Mac mini with the M1 chip is only available with Gigabit Ethernet, Apple has listed multiple M1-based Mac mini logic boards with 10 Gigabit Ethernet in an internal parts list for Apple Authorized Service Providers. For every Mac mini logic board with Gigabit Ethernet in the parts list, obtained by MacRumors, there is a corresponding logic board with 10 Gigabit Ethernet:...
new m1 chip

Craig Federighi: Native Windows on M1 Macs is 'Really up to Microsoft'

Friday November 20, 2020 11:57 am PST by
Following the release of the M1 Macs Apple executives have been doing interviews with a range of publications, and today, Ars Technica published another interview with software engineering chief Craig Federighi, hardware technologies lead Johny Srouji, and marketing VP Greg Joswiak. Much of the interview focuses on topics that the three have already covered in prior discussions, but there is ...
14

Apple Releases iOS 14.2.1 With Fix for Text Message Bug and iPhone 12 Mini Lock Screen Issues

Thursday November 19, 2020 10:16 am PST by
Apple today released iOS 14.2.1, a bug fix update that comes two weeks after the launch of iOS 14.2 and is available for Apple's new iPhone 12 models. The iOS 14.2.1 update can be downloaded for free and it is available on all eligible devices over-the-air in the Settings app. To access the new software, go to Settings > General > Software Update. According to Apple's release notes, iOS...
Walmart November Deals Hero

Black Friday Spotlight: Walmart Will Have AirPods Pro Down to Lowest Price of $169, and More Apple Deals

Thursday November 19, 2020 8:05 am PST by
We've been tracking early Black Friday deals in our dedicated Black Friday Roundup, and in an effort to prepare our readers for the big shopping event we're highlighting sales store-by-store in the lead-up to November 27. Note: MacRumors is an affiliate partner with Walmart. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running. Next ...
apple leather sleeve

Leather Sleeve for iPhone 12 Models Now Available From Apple

Friday November 20, 2020 12:16 pm PST by
Apple today began selling the Leather Sleeve for the new iPhone 12 models, with the accessory having first been announced alongside the updated iPhones in October. Priced at $129, the Leather Sleeve is not a case and is designed to be removed when the iPhone is in use. It features a cutout at the front that displays the time, and it comes with a matching leather strap. According to Apple, it ...
iOS14AntitrackFacebookSadfeature

Apple Confirms Commitment to App Tracking Transparency in Letter Condemning Facebook's Data Collection [Updated]

Thursday November 19, 2020 11:58 am PST by
Apple in iOS 14 is planning to introduce a new App Tracking Transparency feature that will let users know when companies want to track them across apps and website. Following outcry from developers like Facebook and ad networks unprepared for the change, Apple delayed the implementation of the anti-tracking functionality until early 2021. Eight civil society organizations recently sent a...
maxresdefault

CrossOver Allows x86 Windows Apps to Run on Apple M1 Macs

Wednesday November 18, 2020 6:07 pm PST by
Codeweavers posted a blog post and video tonight showing off CrossOver running on an Apple M1 MacBook Air. This video shows Team Fortress 2 running on a new M1 MacBook Air: CrossOver is software (based on Wine Project) that runs Microsoft Windows apps on the Mac by translating Windows APIs into their Mac equivalents. The Codeweavers team was able to run the current version of CrossOver on...
macbookpro13large

Apple Offers Instructions on What to Do if macOS Big Sur Causes Installation Errors on 2013 and 2014 MacBook Pro

Thursday November 19, 2020 6:12 pm PST by
Following the release of macOS Big Sur last week, a number of 2013 and 2014 MacBook Pro owners found that the update bricked their machines. Affected users saw their Macs get stuck displaying a black screen after attempting to install the new software. Apple has now addressed this issue in a new support document that provides instructions on what to do if macOS Big Sur can't be installed on...
128gb m1 macbook air education cropped

$799 M1 MacBook Air With 128GB Storage for Education Institutions Spotted Online

Friday November 20, 2020 5:15 am PST by
A new configuration of the M1 MacBook Air with 128GB of storage and a lower $799 price has today been spotted on Apple's U.S. Education Institution Hardware and Software Price List. The M1 MacBook Air is only available with 256GB, 512GB, 1TB, or 2TB of storage. There is currently no 128GB configuration on the Apple Store. However, Reddit user "u/dduci97" noticed that Apple has listed...