Apple Two-Step Verification Now Available for iMessage and FaceTime [Updated]

Apple's two-step verification system now covers FaceTime and iMessage, reports The Guardian. Signing into an iMessage or FaceTime account protected by two-step verification will ask users to input an app specific password, which can only be obtained by logging in to an Apple ID account on the web with an authentication code, thereby preventing any unauthorized login attempts.

IMG_3365
Two-factor verification is an opt-in system that was first introduced in March of 2013 to increase the security of Apple ID accounts. Prior to today, a verification code was only required for making changes to an account, signing into iCloud, or making iTunes/App Store purchases from a new device.

Two-factor authentication for iCloud is a recent addition that was implemented in September following the breach of several celebrity iCloud accounts, leading to a slew of leaked photos. The hacking incident led Apple to improve the security of iCloud and it also prompted the company to send out security emails when a device is restored, iCloud is accessed, or a password change is attempted.

Last month, a Medium post highlighting some of the remaining shortcomings of two-factor authentication was shared by several technology sites, which may have inspired Apple to update the service to protect iMessage and FaceTime accounts. The post pointed out that it was still possible to log into iMessage, FaceTime, iTunes, the App Store, and into the website using an account with two-factor authentication enabled without being asked for a verification code.

It seems two-factor authentication for iMessage and FaceTime may still be rolling out to users, as MacRumors was able to log into iMessage and FaceTime accounts with two-factor authentication enabled without a code.

Update: Two-factor authentication for iMessage and FaceTime seems to be more widely available now, and it appears that logging into an account requires an app specific password rather than a code to prevent unauthorized entry attempts.

Top Rated Comments

ad1815 Avatar
113 months ago
This is tooo complex!

Passcode, iCloud password, two-factor authentication, app specific password, recovery code, key chain passcoe..... This is way too complex. I have a background in IT and I cannot keep up with the complexity. I don't think the average use knows how to navigate through.

Apple has to give us something simpler. Maybe Apple Watch is the saviour?
Score: 13 Votes (Like | Disagree)
organic bond Avatar
113 months ago
What I don't like is that this is compulsory. Annoying.
Score: 4 Votes (Like | Disagree)
Apple_Robert Avatar
113 months ago
Good move by Apple.
Score: 4 Votes (Like | Disagree)
IHelpId10t5 Avatar
112 months ago
Passcode, iCloud password, two-factor authentication, app specific password, recovery code, key chain passcoe..... This is way too complex. I have a background in IT and I cannot keep up with the complexity. I don't think the average use knows how to navigate through.

Apple has to give us something simpler. Maybe Apple Watch is the saviour?

This hits it on the head. As an IT professional you would love to recommend that everyone turn on 2-factor wherever it exists. However, the reality is that for the MAJORITY of users, the probability of them getting hacked is much smaller than the probability of them locking themselves out of their own account! It's unfortunate, but true, that even many technically savvy people are horrible at organization and record-keeping. They are so used to just being able to reset forgotten passwords at will, that they are at great risk of forfeiting any account that they choose to enable 2-factor on.

Password managers certainly go a long way towards optimal use of unique passwords. However, how many users do you know would actually know how to use their password manager of choice well. How many people do you know that if they enabled 2-factor for a given service like an AppleID, would take the time to customize their vault entry to include their 2-factor recovery key?

How many people do you know that understand that they will forfeit their purchases, email, iCloud, etc, forever if they enable 2-factor on their AppleID but then get locked out and don't know their recovery key?

For these reasons, in 2014 I still find it tough to recommend 2F for anyone that I don't know well enough to understand their technical and credential management aptitude. For the other 99%, I just try to get them interested in using a password manager instead.
Score: 3 Votes (Like | Disagree)
Small White Car Avatar
113 months ago
I don't see the point? What is there in FaceTime or iMessage I need to secure? It's not like my SSN is stored there.
Well, considering that banks are now using a text message as THEIR 2-factor authentication and the fact that texts sync with iMessage and... well you start to see the problem. Your life is becoming a web and entire thing is only as strong as its weakest point.
Score: 3 Votes (Like | Disagree)
NMBob Avatar
113 months ago
Staying safe can be annoying, but the alternative can be a lot worse.:(

Yeah, someone could break into your phone and send an iMessage with one of the new emoticons that doesn't match your race, and then you could get sued for being racially insensitive. (colon, right parenthesis)
Score: 3 Votes (Like | Disagree)

Popular Stories

iPhone 16 Mock Header With Dynamic Island

Skipping the iPhone 15 Pro? Here's What's Rumored for iPhone 16 Pro

Friday September 22, 2023 9:29 am PDT by
Are you skipping the iPhone 15 Pro and waiting another year to upgrade? If so, we already have some iPhone 16 Pro rumors for you. Below, we recap new features rumored for the iPhone 16 Pro models so far:Larger displays: The iPhone 16 Pro and iPhone 16 Pro Max will be equipped with larger 6.3-inch and 6.9-inch displays, respectively, according to Ross Young, CEO of Display Supply Chain...
Update Your iPhone 15 to iOS 17

Warning: Update Your iPhone 15 to iOS 17.0.2 Before Transferring Data From Another iPhone

Friday September 22, 2023 6:36 am PDT by
If you are unboxing an iPhone 15, iPhone 15 Plus, iPhone 15 Pro, or iPhone 15 Pro Max today, make sure to update the device to iOS 17.0.2 before transferring data to the device from another iPhone, or else you might encounter issues. iOS 17.0.2 is only available for the iPhone 15 lineup. Apple says the update fixes an issue that may prevent transferring data directly from another iPhone...
iOS 17

Apple Releases iOS 17.0.1 and iPadOS 17.0.1 With Bug Fixes, Plus iOS 17.0.2 for iPhone 15 Models

Thursday September 21, 2023 10:28 am PDT by
Apple today released iOS 17.0.1 and iPadOS 17.0.1 updates for the iPhone and the iPad, adding bug fixes to the new software. The iOS 17.0.1 and iPadOS 17.0.1 updates come just a few days after Apple launched iOS 17 and iPadOS 17. The software, which is build 21A340, can be downloaded on eligible iPhones and iPads over-the-air by going to Settings > General > Software Update. There is a...
Apple Watch Ultra 2 double tap gesture 230912

watchOS 10.1 to Enable Apple Watch's New 'Double Tap' Gesture

Thursday September 21, 2023 12:52 pm PDT by
The new Double Tap gesture for the Apple Watch Series 9 and the Apple Watch Ultra 2 will be enabled starting with watchOS 10.1, according to Marques Brownlee, host of the popular tech-focused YouTube channel MKBHD. The first beta of watchOS 10.1 will likely be available by next week, and Apple announced that the software update will be released next month. Brownlee shared his impressions...